Search Results (87250 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-18209 1 Dilicms 1 Dilicms 2024-11-21 N/A
XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_type parameter.
CVE-2018-18208 1 Virtualmin 1 Virtualmin 2024-11-21 N/A
Virtualmin 6.03 allows XSS via the query string, as demonstrated by the webmin_search.cgi URI.
CVE-2018-18207 1 Virtualmin 1 Virtualmin 2024-11-21 N/A
Virtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter.
CVE-2018-18199 1 Redaxo 1 Redaxo 2024-11-21 N/A
Mediamanager in REDAXO before 5.6.4 has XSS.
CVE-2018-18198 1 Redaxo 1 Redaxo 2024-11-21 N/A
The $opener_input_field variable in addons/mediapool/pages/index.php in REDAXO 5.6.3 is not effectively filtered and is output directly to the page. The attacker can insert XSS payloads via an index.php?page=mediapool/media&opener_input_field=[XSS] request.
CVE-2018-18098 2 Intel, Microsoft 3 Sgx Platform Software, Sgx Sdk, Windows 2024-11-21 N/A
Improper file verification in install routine for Intel(R) SGX SDK and Platform Software for Windows before 2.2.100 may allow an escalation of privilege via local access.
CVE-2018-18097 1 Intel 1 Solid State Drive Toolbox 2024-11-21 N/A
Improper directory permissions in Intel Solid State Drive Toolbox before 3.5.7 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2018-18094 1 Intel 1 Media Sdk 2024-11-21 N/A
Improper directory permissions in installer for Intel(R) Media SDK before 2018 R2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2018-18093 1 Intel 1 Vtune Amplifier 2024-11-21 N/A
Improper file permissions in the installer for Intel VTune Amplifier 2018 Update 3 and before may allow unprivileged user to potentially gain privileged access via local access.
CVE-2018-18087 1 Bixie 1 Portfolio 2024-11-21 N/A
The Bixie Portfolio plugin 1.2.0 for Pagekit has XSS: a logged-in user who has the "Manage portfolio" privilege can inject arbitrary web script or HTML via the Image URL field in the portfolio editor. The vulnerability is triggered by visiting /portfolio/${project_title}.
CVE-2018-18082 1 Bijiadao 1 Waimai Super Cms 2024-11-21 N/A
XSS exists in Waimai Super Cms 20150505 via the fname parameter to the admin.php?m=Food&a=addsave or admin.php?m=Food&a=editsave URI.
CVE-2018-18069 1 Wpml 1 Wpml 2024-11-21 N/A
process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as locale_file_name_en) in an authenticated theme-localization.php request to wp-admin/admin.php.
CVE-2018-18064 1 Cairographics 1 Cairo 2024-11-21 6.5 Medium
cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate and render_rows functions) and cairo-image-compositor.c (the _cairo_image_spans_and_zero function).
CVE-2018-18062 1 Tecrail 1 Responsive Filemanager 2024-11-21 N/A
An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. A reflected XSS vulnerability allows remote attackers to inject arbitrary web script or HTML.
CVE-2018-18035 1 Open-emr 1 Openemr 2024-11-21 N/A
A vulnerability in flashcanvas.swf in OpenEMR before 5.0.1 Patch 6 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.
CVE-2018-18029 1 Naviwebs 1 Navigate Cms 2024-11-21 N/A
Navigate CMS has Stored XSS via the navigate.php Title field in an edit action.
CVE-2018-18026 1 Iobit 1 Malware Fighter 2024-11-21 N/A
IMFCameraProtect.sys in IObit Malware Fighter 6.2 (and possibly lower versions) is vulnerable to a stack-based buffer overflow. The attacker can use DeviceIoControl to pass a user specified size which can be used to overwrite return addresses. This can lead to a denial of service or code execution attack.
CVE-2018-18019 1 Tribulant 1 Slideshow Gallery 2024-11-21 N/A
XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-slides&method=save Slide[title], Slide[media_file], or Slide[image_url] parameter.
CVE-2018-18017 1 Tribulant 1 Slideshow Gallery 2024-11-21 N/A
XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
CVE-2018-18016 2 Imagemagick, Redhat 2 Imagemagick, Enterprise Linux 2024-11-21 N/A
ImageMagick 7.0.7-28 has a memory leak vulnerability in WritePCXImage in coders/pcx.c.