Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-07-03 CVE-2018-11636 Cross-Site Request Forgery (CSRF) vulnerability in Dialogic Powermedia XMS 3.5
Cross-site request forgery (CSRF) vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to execute malicious and unauthorized actions.
network
low complexity
dialogic CWE-352
8.8
2018-07-03 CVE-2018-11634 Insufficiently Protected Credentials vulnerability in Dialogic Powermedia XMS 3.5
Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local users to access the web application's user passwords in cleartext by reading /var/www/xms/xmsdb/default.db.
local
low complexity
dialogic CWE-522
7.8
2018-07-03 CVE-2018-11051 Path Traversal vulnerability in EMC RSA Certificate Manager 6.9
RSA Certificate Manager Versions 6.9 build 560 through 6.9 build 564 contain a path traversal vulnerability in the RSA CMP Enroll Server and the RSA REST Enroll Server.
network
low complexity
emc CWE-22
7.5
2018-07-03 CVE-2018-13102 Untrusted Search Path vulnerability in Anydesk
AnyDesk before "12.06.2018 - 4.1.3" on Windows 7 SP1 has a DLL preloading vulnerability.
local
low complexity
anydesk CWE-426
7.8
2018-07-03 CVE-2018-7783 XXE vulnerability in Schneider-Electric Somachine Basic
Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulnerability using the DTD parameter entities technique resulting in disclosure and retrieval of arbitrary data on the affected node via out-of-band (OOB) attack.
network
low complexity
schneider-electric CWE-611
7.5
2018-07-03 CVE-2018-7782 Insufficiently Protected Credentials vulnerability in Schneider-Electric products
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, authenticated users can view passwords in clear text.
network
low complexity
schneider-electric CWE-522
8.8
2018-07-03 CVE-2018-7781 Missing Encryption of Sensitive Data vulnerability in Schneider-Electric products
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, by sending a specially crafted request an authenticated user can view password in clear text and results in privilege escalation.
network
low complexity
schneider-electric CWE-311
8.8
2018-07-03 CVE-2018-7779 Unspecified vulnerability in Schneider-Electric products
In Schneider Electric Wiser for KNX V2.1.0 and prior, homeLYnk V2.0.1 and prior; and spaceLYnk V2.1.0 and prior, weak and unprotected FTP access could allow an attacker unauthorized access.
network
low complexity
schneider-electric
7.5
2018-07-03 CVE-2018-7777 Improper Input Validation vulnerability in Schneider-Electric U.Motion Builder 1.2.1
The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder software versions prior to v1.3.4.
network
low complexity
schneider-electric CWE-20
8.8
2018-07-03 CVE-2018-7774 SQL Injection vulnerability in Schneider-Electric U.Motion Builder 1.2.1
The vulnerability exists within processing of localize.php in Schneider Electric U.motion Builder software versions prior to v1.3.4.
network
low complexity
schneider-electric CWE-89
8.8