|
246341
|
6.1 |
MEDIUM
Network
|
teamwire
|
teamwire
|
The admin interface of the Grouptime Teamwire Client 1.5.1 prior to 1.9.0 on-premises messenger server allows stored XSS. All backend versions prior to prod-2018-11-13-15-00-42 are affected.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17560
|
2024-11-21 12:54 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246342
|
8.1 |
HIGH
Network
|
teamwire
|
teamwire
|
Grouptime Teamwire Desktop Client 1.5.1 prior to 1.9.0 on Windows allows code injection via a template, leading to remote code execution. All backend versions prior to prod-2018-11-13-15-00-42 are af…
|
CWE-94
Code Injection
|
CVE-2018-17170
|
2024-11-21 12:54 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246343
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Incorrect object lifetime calculations in GPU code in Google Chrome prior to 70.0.3538.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787 CWE-416
Out-of-bounds Write Use After Free
|
CVE-2018-17479
|
2024-11-21 12:54 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246344
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Incorrect array position calculations in V8 in Google Chrome prior to 70.0.3538.102 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
|
CWE-129
Improper Validation of Array Index
|
CVE-2018-17478
|
2024-11-21 12:54 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246345
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient data validation in filesystem URIs in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
|
CWE-20
Improper Input Validation
|
CVE-2018-17460
|
2024-11-21 12:54 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246346
|
9.8 |
CRITICAL
Network
|
ranksol
|
twilio_web_to_fax_machine_system
|
SQL Injection exists in Twilio WEB To Fax Machine System 1.0 via the email or password parameter to login_check.php, or the id parameter to add_email.php or edit_content.php.
|
CWE-89
SQL Injection
|
CVE-2018-17388
|
2024-11-21 12:54 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246347
|
8.8 |
HIGH
Network
|
ranksol
|
nimble_professional
|
CSRF exists in Nimble Messaging Bulk SMS Marketing Application 1.0 for adding an admin account.
|
CWE-352
Origin Validation Error
|
CVE-2018-17387
|
2024-11-21 12:54 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246348
|
9.8 |
CRITICAL
Network
|
thephpfactory
|
micro_deal_factory
|
SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.
|
CWE-89
SQL Injection
|
CVE-2018-17386
|
2024-11-21 12:54 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246349
|
9.8 |
CRITICAL
Network
|
thephpfactory
|
dutch_auction_factory
|
SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17381
|
2024-11-21 12:54 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246350
|
9.8 |
CRITICAL
Network
|
thephpfactory
|
auction_factory
|
SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17374
|
2024-11-21 12:54 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|