Search
Search Results (87188 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2018-16660 | 1 Imperva | 1 Securesphere | 2024-11-21 | N/A |
| A command injection vulnerability in PWS in Imperva SecureSphere 13.0.0.10 and 13.1.0.10 Gateway allows an attacker with authenticated access to execute arbitrary OS commands on a vulnerable installation. | ||||
| CVE-2018-16655 | 1 Gxlcms | 1 Gxlcms | 2024-11-21 | N/A |
| Gxlcms 1.0 has XSS via the PATH_INFO to gx/lib/ThinkPHP/Tpl/ThinkException.tpl.php. | ||||
| CVE-2018-16654 | 1 Zurmo | 1 Zurmo Crm | 2024-11-21 | N/A |
| Zurmo 3.2.4 Stable allows XSS via app/index.php/accounts/default/details?id=2&kanbanBoard=1&openToTaskId=1. | ||||
| CVE-2018-16653 | 1 Rejucms Project | 1 Rejucms | 2024-11-21 | N/A |
| rejucms 2.1 has XSS via the ucenter/cms_user_add.php u_name parameter. | ||||
| CVE-2018-16645 | 4 Canonical, Debian, Imagemagick and 1 more | 4 Ubuntu Linux, Debian Linux, Imagemagick and 1 more | 2024-11-21 | N/A |
| There is an excessive memory allocation issue in the functions ReadBMPImage of coders/bmp.c and ReadDIBImage of coders/dib.c in ImageMagick 7.0.8-11, which allows remote attackers to cause a denial of service via a crafted image file. | ||||
| CVE-2018-16642 | 4 Canonical, Debian, Imagemagick and 1 more | 4 Ubuntu Linux, Debian Linux, Imagemagick and 1 more | 2024-11-21 | N/A |
| The function InsertRow in coders/cut.c in ImageMagick 7.0.7-37 allows remote attackers to cause a denial of service via a crafted image file due to an out-of-bounds write. | ||||
| CVE-2018-16641 | 1 Imagemagick | 1 Imagemagick | 2024-11-21 | N/A |
| ImageMagick 7.0.8-6 has a memory leak vulnerability in the TIFFWritePhotoshopLayers function in coders/tiff.c. | ||||
| CVE-2018-16640 | 3 Canonical, Imagemagick, Redhat | 3 Ubuntu Linux, Imagemagick, Enterprise Linux | 2024-11-21 | N/A |
| ImageMagick 7.0.8-5 has a memory leak vulnerability in the function ReadOneJNGImage in coders/png.c. | ||||
| CVE-2018-16639 | 1 Typesettercms | 1 Typesetter | 2024-11-21 | N/A |
| Typesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation. | ||||
| CVE-2018-16638 | 1 Modx | 1 Evolution Cms | 2024-11-21 | N/A |
| Evolution CMS 1.4.x allows XSS via the manager/ search parameter. | ||||
| CVE-2018-16637 | 1 Modx | 1 Evolution Cms | 2024-11-21 | N/A |
| Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI. | ||||
| CVE-2018-16636 | 1 Nucleuscms | 1 Nucleus Cms | 2024-11-21 | N/A |
| Nucleus CMS 3.70 allows HTML Injection via the index.php body parameter. | ||||
| CVE-2018-16635 | 1 Blackcat-cms | 1 Blackcat Cms | 2024-11-21 | N/A |
| Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php. | ||||
| CVE-2018-16633 | 1 Pluck-cms | 1 Pluck | 2024-11-21 | N/A |
| Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title. | ||||
| CVE-2018-16632 | 1 Jupo | 1 Mezzanine | 2024-11-21 | N/A |
| Mezzanine CMS v4.3.1 allows XSS via the /admin/blog/blogcategory/add/?_to_field=id&_popup=1 title parameter at admin/blog/blogpost/add/. | ||||
| CVE-2018-16631 | 1 Intelliants | 1 Subrion Cms | 2024-11-21 | N/A |
| Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter. | ||||
| CVE-2018-16630 | 1 Getkirby | 1 Kirby | 2024-11-21 | N/A |
| Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file. | ||||
| CVE-2018-16629 | 1 Intelliants | 1 Subrion Cms | 2024-11-21 | N/A |
| panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element. | ||||
| CVE-2018-16628 | 1 Getkirby | 1 Kirby | 2024-11-21 | N/A |
| panel/login in Kirby v2.5.12 allows XSS via a blog name. | ||||
| CVE-2018-16627 | 1 Getkirby | 1 Kirby | 2024-11-21 | N/A |
| panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature. | ||||