Export limit exceeded: 10073 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 40017 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (40017 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2018-16803 | 1 Cimtechniques | 1 Cimscan | 2024-11-21 | N/A |
| In CIMTechniques CIMScan 6.x through 6.2, the SOAP WSDL parser allows attackers to execute SQL code. | ||||
| CVE-2018-16789 | 1 Shellinabox Project | 1 Shellinabox | 2024-11-21 | N/A |
| libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down. | ||||
| CVE-2018-16762 | 1 Thedaylightstudio | 1 Fuel Cms | 2024-11-21 | N/A |
| FUEL CMS 1.4.1 allows SQL Injection via the layout, published, or search_term parameter to pages/items. | ||||
| CVE-2018-16724 | 1 Baijiacms Project | 1 Baijiacms | 2024-11-21 | N/A |
| An issue is discovered in baijiacms V4. Blind SQL Injection exists via the order parameter in an index.php?act=index request. | ||||
| CVE-2018-16659 | 1 Rausoft | 1 Id.prove | 2024-11-21 | 9.8 Critical |
| An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked queries in the Username POST parameter. Hypothetically, an attacker can utilize master..xp_cmdshell for the further privilege elevation. | ||||
| CVE-2018-16646 | 4 Canonical, Debian, Freedesktop and 1 more | 4 Ubuntu Linux, Debian Linux, Poppler and 1 more | 2024-11-21 | N/A |
| In Poppler 0.68.0, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. | ||||
| CVE-2018-16620 | 1 Sonatype | 1 Nexus Repository Manager | 2024-11-21 | N/A |
| Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control. | ||||
| CVE-2018-16597 | 4 Linux, Netapp, Opensuse and 1 more | 5 Linux Kernel, Active Iq Performance Analytics Services, Element Software and 2 more | 2024-11-21 | N/A |
| An issue was discovered in the Linux kernel before 4.8. Incorrect access checking in overlayfs mounts could be used by local attackers to modify or truncate files in the underlying filesystem. | ||||
| CVE-2018-16591 | 1 Furuno | 4 Felcom 250, Felcom 250 Firmware, Felcom 500 and 1 more | 2024-11-21 | N/A |
| FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service accounts, as well as the password for the protected "SMS" panel via /cgi-bin/sm_changepassword.cgi and /cgi-bin/sm_sms_changepasswd.cgi. | ||||
| CVE-2018-16555 | 1 Siemens | 8 Scalance S602, Scalance S602 Firmware, Scalance S612 and 5 more | 2024-11-21 | N/A |
| A vulnerability has been identified in SCALANCE S602 (All versions < V4.0.1.1), SCALANCE S612 (All versions < V4.0.1.1), SCALANCE S623 (All versions < V4.0.1.1), SCALANCE S627-2M (All versions < V4.0.1.1). The integrated web server could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user must be logged into the web interface in order for the exploitation to succeed. At the stage of publishing this security advisory no public exploitation is known. | ||||
| CVE-2018-16522 | 1 Amazon | 1 Amazon Web Services Freertos | 2024-11-21 | N/A |
| Amazon Web Services (AWS) FreeRTOS through 1.3.1 has an uninitialized pointer free in SOCKETS_SetSockOpt. | ||||
| CVE-2018-16445 | 1 Seacms | 1 Seacms | 2024-11-21 | N/A |
| An issue was discovered in SeaCMS through 6.61. SQL injection exists via the tid parameter in an adm1n/admin_topic_vod.php request. | ||||
| CVE-2018-16436 | 1 Gxlcms | 1 Gxlcms | 2024-11-21 | N/A |
| Gxlcms 2.0 before bug fix 20180915 has SQL Injection exploitable by an administrator. | ||||
| CVE-2018-16432 | 1 Bluecms Project | 1 Bluecms | 2024-11-21 | N/A |
| BlueCMS 1.6 allows SQL Injection via the user_name parameter to uploads/user.php?act=index_login. | ||||
| CVE-2018-16410 | 1 Vanillaforums | 1 Vanilla | 2024-11-21 | N/A |
| Vanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/dashboard/models/class.invitationmodel.php and applications/dashboard/controllers/class.profilecontroller.php. | ||||
| CVE-2018-16389 | 1 E107 | 1 E107 | 2024-11-21 | N/A |
| e107_admin/banlist.php in e107 2.1.8 allows SQL injection via the old_ip parameter. | ||||
| CVE-2018-16385 | 1 Thinkphp | 1 Thinkphp | 2024-11-21 | N/A |
| ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string. | ||||
| CVE-2018-16384 | 1 Owasp | 1 Owasp Modsecurity Core Rule Set | 2024-11-21 | 7.5 High |
| A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as "if") and b is the SQL statement to be executed. | ||||
| CVE-2018-16357 | 1 Pbootcms | 1 Pbootcms | 2024-11-21 | 9.8 Critical |
| An issue was discovered in PbootCMS. There is a SQL injection via the api.php/Cms/search order parameter. | ||||
| CVE-2018-16356 | 1 Pbootcms | 1 Pbootcms | 2024-11-21 | 9.8 Critical |
| An issue was discovered in PbootCMS. There is a SQL injection via the api.php/List/index order parameter. | ||||