CVE-2018-16484
A XSS vulnerability was found in module m-server
A XSS vulnerability was found in module m-server
A deficiency in the access control in module express-cart
A server directory traversal vulnerability was found on node module mcstatic
A XSS vulnerability was found in html-page
A XSS vulnerability was found in module public
Path traversal vulnerability in http-live-simulator
A vulnerability in the "capro" (Call Processor) process component of Avaya Aura Communication Manager could allow a remote, unauthenticated user to cause denial of service. Affected versions include 6.3.x, all 7.x versions prior to...
Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.6 could allow remote attackers to access sensitive information on...
kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel attacks. Date...
Zen Load Balancer 3.10.1 allows remote authenticated admin users to execute arbitrary commands as root via shell metacharacters in the index.cgi?action=View_Cert certname parameter. Date published : 2019-02-01 http://www.securityfocus.com/bid/106812 https://code610.blogspot.com/2019/01/rce-in-zenload-balancer.html
Artica Proxy 3.06.200056 allows remote attackers to execute arbitrary commands as root by reading the ressources/settings.inc ldap_admin and ldap_password fields, using these credentials at logon.php, and then entering the commands in the admin.index.php command-line...
An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 request. This occurs when any HNAP API...
Cross-Site Request Forgery (CSRF) vulnerability in McAfee ePO (legacy) Cloud allows unauthenticated users to perform unintended ePO actions using an authenticated user’s session via unspecified vectors. Date published : 2019-02-01 http://www.securityfocus.com/bid/106830 https://kc.mcafee.com/corporate/index?page=content&id=SB10268