|
247671
|
6.5 |
MEDIUM
Network
|
controlbyweb
|
x-320m-i_firmware
|
A Denial of Service (DOS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisition module 1.05 with firmware revision v1.05. An authenticated user can configur…
|
NVD-CWE-noinfo
|
CVE-2018-18881
|
2024-11-21 12:56 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247672
|
8.8 |
HIGH
Network
|
bmc
|
remedy_mid-tier remedy_action_request_system
|
BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demonstrated by TLS%3APLR-Configuration+Details/Default+Admin+View/, AST%3AARServerCo…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2018-18862
|
2024-11-21 12:56 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247673
|
5.5 |
MEDIUM
Local
|
qemu opensuse fedoraproject canonical
|
qemu leap fedora ubuntu_linux
|
In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-18849
|
2024-11-21 12:56 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247674
|
6.1 |
MEDIUM
Network
|
advanced_comment_system_project
|
advanced_comment_system
|
internal/advanced_comment_system/index.php and internal/advanced_comment_system/admin.php in Advanced Comment System, version 1.0, contain a reflected cross-site scripting vulnerability via ACS_path.…
|
CWE-79
Cross-site Scripting
|
CVE-2018-18845
|
2024-11-21 12:56 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247675
|
9.8 |
CRITICAL
Network
|
school_attendance_monitoring_system_project
|
school_attendance_monitoring_system
|
Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and user/index.php?view=view.
|
CWE-89
SQL Injection
|
CVE-2018-18798
|
2024-11-21 12:56 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247676
|
6.5 |
MEDIUM
Network
|
saltos
|
saltos
|
SaltOS 3.1 r8126 contains a database download vulnerability.
|
CWE-200
Information Exposure
|
CVE-2018-18762
|
2024-11-21 12:56 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247677
|
5.4 |
MEDIUM
Network
|
tibco
|
jasperreports_server jaspersoft_reporting_and_analytics jaspersoft
|
The repository component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS w…
|
CWE-79
Cross-site Scripting
|
CVE-2018-18816
|
2024-11-21 12:56 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247678
|
9.8 |
CRITICAL
Network
|
tibco
|
jasperreports_server jaspersoft_reporting_and_analytics jaspersoft
|
The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS wit…
|
CWE-863
Incorrect Authorization
|
CVE-2018-18815
|
2024-11-21 12:56 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247679
|
6.5 |
MEDIUM
Network
|
tibco
|
jasperreports_server jasperreports_library jaspersoft_reporting_and_analytics jaspersoft
|
The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperRe…
|
CWE-22
Path Traversal
|
CVE-2018-18809
|
2024-11-21 12:56 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247680
|
7.5 |
HIGH
Network
|
tibco
|
jasperreports_server jaspersoft_reporting_and_analytics jaspersoft
|
The domain management component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft fo…
|
CWE-362
Race Condition
|
CVE-2018-18808
|
2024-11-21 12:56 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|