More info:
https://wpvulndb.com/vulnerabilities/9103
Fabian Henneke discovered a cross-site scripting vulnerability in thepassword change form of GOsa, a web-based LDAP administration program.
More info:
https://www.debian.org/security/2018/dsa-4239
Several vulnerabilities have been discovered in Exiv2, a C++ library anda command line utility to manage image metadata which could result indenial of service or the execution of arbitrary code if a malformed fileis parsed.
More info:
https://www.debian.org/security/2018/dsa-4238