Export limit exceeded: 376404 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (87193 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2018-16776 | 1 Creatiwity | 1 Witycms | 2024-11-21 | N/A |
| wityCMS 0.6.2 has XSS via the "Site Name" field found in the "Contact" "Configuration" page. | ||||
| CVE-2018-16775 | 1 Victor Cms Project | 1 Victor Cms | 2024-11-21 | N/A |
| An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the site name in the "Categories" menu. | ||||
| CVE-2018-16773 | 1 Easycms | 1 Easycms | 2024-11-21 | N/A |
| EasyCMS 1.5 allows XSS via the index.php?s=/admin/fields/update/navTabId/listfields/callbackType/closeCurrent content field. | ||||
| CVE-2018-16772 | 1 Hoosk | 1 Hoosk | 2024-11-21 | N/A |
| Hoosk v1.7.0 allows XSS via the Navigation Title of a new page entered at admin/pages/new. | ||||
| CVE-2018-16763 | 1 Thedaylightstudio | 1 Fuel Cms | 2024-11-21 | 9.8 Critical |
| FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution. | ||||
| CVE-2018-16759 | 1 Easycms | 1 Easycms | 2024-11-21 | N/A |
| The removeXSS function in App/Common/common.php (called from App/Modules/Index/Action/SearchAction.class.php) in EasyCMS v1.4 allows XSS via an onhashchange event. | ||||
| CVE-2018-16752 | 1 Linknet-usa | 2 Lw-n605r, Lw-n605r Firmware | 2024-11-21 | N/A |
| LINK-NET LW-N605R devices with firmware 12.20.2.1486 allow Remote Code Execution via shell metacharacters in the HOST field of the ping feature at adm/systools.asp. Authentication is needed but the default password of admin for the admin account may be used in some cases. | ||||
| CVE-2018-16750 | 3 Canonical, Imagemagick, Redhat | 3 Ubuntu Linux, Imagemagick, Enterprise Linux | 2024-11-21 | 6.5 Medium |
| In ImageMagick 7.0.7-29 and earlier, a memory leak in the formatIPTCfromBuffer function in coders/meta.c was found. | ||||
| CVE-2018-16744 | 1 Mgetty Project | 1 Mgetty | 2024-11-21 | N/A |
| An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized. It could allow for command injection if untrusted input can reach it, because popen is used. | ||||
| CVE-2018-16743 | 1 Mgetty Project | 1 Mgetty | 2024-11-21 | N/A |
| An issue was discovered in mgetty before 1.2.1. In contrib/next-login/login.c, the command-line parameter username is passed unsanitized to strcpy(), which can cause a stack-based buffer overflow. | ||||
| CVE-2018-16742 | 1 Mgetty Project | 1 Mgetty | 2024-11-21 | N/A |
| An issue was discovered in mgetty before 1.2.1. In contrib/scrts.c, a stack-based buffer overflow can be triggered via a command-line parameter. | ||||
| CVE-2018-16741 | 2 Debian, Mgetty Project | 2 Debian Linux, Mgetty | 2024-11-21 | N/A |
| An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() does not properly sanitize shell metacharacters to prevent command injection. It is possible to use the ||, &&, or > characters within a file created by the "faxq-helper activate <jobid>" command. | ||||
| CVE-2018-16736 | 1 Rcfilters Project | 1 Rcfilters | 2024-11-21 | N/A |
| In the rcfilters plugin 2.1.6 for Roundcube, XSS exists via the _whatfilter and _messages parameters (in the Filters section of the settings). | ||||
| CVE-2018-16730 | 1 Chshcms | 1 Cscms | 2024-11-21 | N/A |
| \upload\plugins\sys\Install.php in CScms 4.1 has XSS via the site name. | ||||
| CVE-2018-16729 | 1 Pluck-cms | 1 Pluck | 2024-11-21 | N/A |
| Pluck 4.7.7 allows XSS via an SVG file that contains Javascript in a SCRIPT element, and is uploaded via pages->manage under admin.php?action=files. | ||||
| CVE-2018-16728 | 1 Feindura | 1 Feindura | 2024-11-21 | N/A |
| feindura 2.0.7 allows XSS via the tags field of a new page created at index.php?category=0&page=new. | ||||
| CVE-2018-16727 | 1 Razorcms | 1 Razorcms | 2024-11-21 | N/A |
| razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component. | ||||
| CVE-2018-16726 | 1 Razorcms | 1 Razorcms | 2024-11-21 | N/A |
| razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component. | ||||
| CVE-2018-16725 | 1 Baijiacms Project | 1 Baijiacms | 2024-11-21 | N/A |
| An issue is discovered in baijiacms V4. XSS exists via the assets/weengine/components/zclip/ZeroClipboard.swf id parameter, aka "Non-standard use of the flash component." | ||||
| CVE-2018-16718 | 1 Nih | 1 Ncbi Toolbox | 2024-11-21 | N/A |
| An XSS vulnerability exists in wwwblast.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox via a crafted -z1 argument. | ||||