|
246331
|
4.8 |
MEDIUM
Network
|
influxdata
|
influxdb
|
InfluxDB 0.9.5 has Reflected XSS in the Write Data module.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17572
|
2024-11-21 12:54 |
2020-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246332
|
6.5 |
MEDIUM
Network
|
prospecta
|
master_data_online
|
Prospecta Master Data Online (MDO) allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2018-17789
|
2024-11-21 12:54 |
2019-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246333
|
9.8 |
CRITICAL
Network
|
apache
|
ofbiz
|
The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. This service takes the `serviceConten…
|
NVD-CWE-noinfo
|
CVE-2018-17200
|
2024-11-21 12:54 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246334
|
7.5 |
HIGH
Network
|
newgensoft
|
omniflow_intelligent_business_process_suite
|
Newgen OmniFlow Intelligent Business Process Suite (iBPS) 7.0 has an "improper server side validation" vulnerability where client-side validations are tampered, and inappropriate information is store…
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2018-17791
|
2024-11-21 12:54 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246335
|
5.4 |
MEDIUM
Network
|
prospecta
|
master_data_online
|
Prospecta Master Data Online (MDO) 2.0 has Stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17790
|
2024-11-21 12:54 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246336
|
8.8 |
HIGH
Network
|
printeron
|
central_print_services
|
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. A user without valid credentials can bypass the authentication process, obtaining a valid session cookie with guest/ps…
|
CWE-287
Improper Authentication
|
CVE-2018-17213
|
2024-11-21 12:54 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246337
|
5.3 |
MEDIUM
Network
|
printeron
|
central_print_services
|
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. An unauthenticated attacker can view details about the printers associated with CPS via a crafted HTTP GET request.
|
CWE-200
Information Exposure
|
CVE-2018-17211
|
2024-11-21 12:54 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246338
|
8.8 |
HIGH
Network
|
printeron
|
central_print_services
|
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and launch a print job do not perform complete verification of the session cookie that…
|
CWE-285
Improper Authorization
|
CVE-2018-17210
|
2024-11-21 12:54 |
2019-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246339
|
8.8 |
HIGH
Network
|
altn
|
mdaemon_webmail
|
MDaemon Webmail (formerly WorldClient) has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2018-17792
|
2024-11-21 12:54 |
2019-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246340
|
8.8 |
HIGH
Network
|
apache
|
kafka
|
In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write per…
|
NVD-CWE-noinfo
|
CVE-2018-17196
|
2024-11-21 12:54 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|