Export limit exceeded: 377496 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (87444 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-20601 1 Ucms Project 1 Ucms 2024-11-21 N/A
UCMS 1.4.7 has XSS via the description parameter in an index.php list_editpost action.
CVE-2018-20600 1 Ucms Project 1 Ucms 2024-11-21 N/A
sadmin\cedit.php in UCMS 1.4.7 has XSS via an index.php sadmin_cedit action.
CVE-2018-20597 1 Ucms Project 1 Ucms 2024-11-21 N/A
UCMS 1.4.7 has XSS via the dir parameter in an index.php sadmin_fileedit action.
CVE-2018-20594 1 Hsweb 1 Hsweb 2024-11-21 N/A
An issue was discovered in hsweb 3.0.4. It is a reflected XSS vulnerability due to the absence of type parameter checking in FlowableModelManagerController.java.
CVE-2018-20593 2 Fedoraproject, Msweet 2 Fedora, Mini-xml 2024-11-21 N/A
In Mini-XML (aka mxml) v2.12, there is stack-based buffer overflow in the scan_file function in mxmldoc.c.
CVE-2018-20590 1 Generic Content Management System Project 1 Generic Content Management System 2024-11-21 4.8 Medium
Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 has XSS via the Administrator/users.php user ID.
CVE-2018-20589 1 Generic Content Management System Project 1 Generic Content Management System 2024-11-21 N/A
Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 has XSS via the Administrator/add_pictures.php article ID.
CVE-2018-20583 1 Thephpleague 1 Commonmark 2024-11-21 N/A
Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library versions 0.15.6 through 0.18.x before 0.18.1 allows remote attackers to insert unsafe URLs into HTML (even if allow_unsafe_links is false) via a newline character (e.g., writing javascript as javascri%0apt).
CVE-2018-20579 1 Contiki-ng Project 1 Contiki-ng 2024-11-21 N/A
Contiki-NG before 4.2 has a stack-based buffer overflow in the push function in os/lib/json/jsonparse.c that allows an out-of-bounds write of an '{' or '[' character.
CVE-2018-20567 1 Douco 1 Douphp 2024-11-21 N/A
An issue was discovered in DouCo DouPHP 1.5 20181221. \install\index.php allows a reload of the product in opportunistic circumstances in which install.lock cannot be read.
CVE-2018-20565 1 Douco 1 Douphp 2024-11-21 N/A
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/nav.php?rec=update has XSS via the nav_name parameter.
CVE-2018-20564 1 Douco 1 Douphp 2024-11-21 N/A
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/product_category.php?rec=update has XSS via the cat_name parameter.
CVE-2018-20563 1 Douco 1 Douphp 2024-11-21 N/A
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/mobile.php?rec=system&act=update has XSS via the mobile_name parameter.
CVE-2018-20562 1 Douco 1 Douphp 2024-11-21 N/A
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/article_category.php?rec=update has XSS via the cat_name parameter.
CVE-2018-20561 1 Douco 1 Douphp 2024-11-21 N/A
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/article.php?rec=update has XSS via the title parameter.
CVE-2018-20560 1 Douco 1 Douphp 2024-11-21 N/A
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/show.php?rec=update has XSS via the show_name parameter.
CVE-2018-20559 1 Douco 1 Douphp 2024-11-21 N/A
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/product.php?rec=update has XSS via the name parameter.
CVE-2018-20558 1 Douco 1 Douphp 2024-11-21 N/A
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/system.php?rec=update has XSS via the site_name parameter.
CVE-2018-20557 1 Douco 1 Douphp 2024-11-21 N/A
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/page.php?rec=edit has XSS via the page_name parameter.
CVE-2018-20541 1 Libxsmm Project 1 Libxsmm 2024-11-21 N/A
There is a heap-based buffer overflow in libxsmm_sparse_csc_reader at generator_spgemm_csc_reader.c in LIBXSMM 1.10, a different vulnerability than CVE-2018-20542 (which is in a different part of the source code and is seen at different addresses).