|
249381
|
5.3 |
MEDIUM
Network
|
synology
|
router_manager
|
Information exposure vulnerability in SYNO.FolderSharing.List in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote attackers to obtain sensitive information via the (1) folder_path or (…
|
CWE-200
Information Exposure
|
CVE-2018-13289
|
2024-11-21 12:46 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249382
|
5.3 |
MEDIUM
Network
|
synology
|
file_station
|
Information exposure vulnerability in SYNO.FolderSharing.List in Synology File Station before 1.2.3-0252 and before 1.1.5-0125 allows remote attackers to obtain sensitive information via the (1) fold…
|
CWE-200
Information Exposure
|
CVE-2018-13288
|
2024-11-21 12:46 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249383
|
6.5 |
MEDIUM
Network
|
synology
|
router_manager
|
Incorrect default permissions vulnerability in synouser.conf in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users to obtain sensitive information via the world reada…
|
CWE-276
Incorrect Default Permissions
|
CVE-2018-13287
|
2024-11-21 12:46 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249384
|
6.5 |
MEDIUM
Network
|
synology
|
diskstation_manager
|
Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to obtain sensitive information via the world r…
|
CWE-276
Incorrect Default Permissions
|
CVE-2018-13286
|
2024-11-21 12:46 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249385
|
8.8 |
HIGH
Network
|
synology
|
router_manager
|
Command injection vulnerability in ftpd in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command.
|
CWE-78
OS Command
|
CVE-2018-13285
|
2024-11-21 12:46 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249386
|
8.8 |
HIGH
Network
|
synology
|
diskstation_manager
|
Command injection vulnerability in ftpd in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command.
|
CWE-78
OS Command
|
CVE-2018-13284
|
2024-11-21 12:46 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249387
|
7.4 |
HIGH
Network
|
synology
|
ssl_vpn_client
|
Lack of administrator control over security vulnerability in client.cgi in Synology SSL VPN Client before 1.2.5-0226 allows remote attackers to conduct man-in-the-middle attacks via the (1) command, …
|
NVD-CWE-noinfo
|
CVE-2018-13283
|
2024-11-21 12:46 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249388
|
5.4 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite 7.8.4 and earlier allows XSS. Internal reference: 58742 (Bug ID)
|
CWE-79
Cross-site Scripting
|
CVE-2018-13104
|
2024-11-21 12:46 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249389
|
5.4 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite 7.8.4 and earlier allows SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-13103
|
2024-11-21 12:46 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249390
|
4.3 |
MEDIUM
Network
|
fortinet
|
fortiadc fortios
|
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGa…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-13374
|
2024-11-21 12:46 |
2019-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|