Export limit exceeded: 10193 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 87446 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (87446 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-20723 1 Cacti 1 Cacti 2024-11-21 N/A
A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Name field for a Color.
CVE-2018-20703 1 Cubecart 1 Cubecart 2024-11-21 N/A
CubeCart 6.2.2 has Reflected XSS via a /{ADMIN-FILE}/ query string.
CVE-2018-20682 1 Fork-cms 1 Fork Cms 2024-11-21 N/A
Fork CMS 5.0.6 allows stored XSS via the private/en/settings facebook_admin_ids parameter (aka "Admin ids" input in the Facebook section).
CVE-2018-20680 1 Frog Cms Project 1 Frog Cms 2024-11-21 N/A
Frog CMS 0.9.5 has XSS in the admin/?/page/edit/1 body field.
CVE-2018-20677 2 Getbootstrap, Redhat 8 Bootstrap, Ceph Storage, Enterprise Linux and 5 more 2024-11-21 N/A
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
CVE-2018-20676 2 Getbootstrap, Redhat 8 Bootstrap, Ceph Storage, Enterprise Linux and 5 more 2024-11-21 N/A
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.
CVE-2018-20673 2 Gnu, Redhat 2 Binutils, Enterprise Linux 2024-11-21 N/A
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create an array for saving the template argument values") that can trigger a heap-based buffer overflow, as demonstrated by nm.
CVE-2018-20671 1 Gnu 1 Binutils 2024-11-21 N/A
load_specific_debug_section in objdump.c in GNU Binutils through 2.31.1 contains an integer overflow vulnerability that can trigger a heap-based buffer overflow via a crafted section size.
CVE-2018-20663 1 Haulmont 2 Cuba Platform, Reporting 2024-11-21 N/A
The Reporting Addon (aka Reports Addon) through 2019-01-02 for CUBA Platform through 6.10.x has Persistent XSS via the "Reports > Reports" name field.
CVE-2018-20659 1 Axiosys 1 Bento4 2024-11-21 N/A
An issue was discovered in Bento4 1.5.1-627. The AP4_StcoAtom class in Core/Ap4StcoAtom.cpp has an attempted excessive memory allocation when called from AP4_AtomFactory::CreateAtomFromStream in Core/Ap4AtomFactory.cpp, as demonstrated by mp42hls.
CVE-2018-20657 3 F5, Gnu, Redhat 3 Traffix Signaling Delivery Controller, Binutils, Enterprise Linux 2024-11-21 N/A
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.
CVE-2018-20652 1 Tinyexr Project 1 Tinyexr 2024-11-21 N/A
An attempted excessive memory allocation was discovered in the function tinyexr::AllocateImage in tinyexr.h in tinyexr v0.9.5. Remote attackers could leverage this vulnerability to cause a denial-of-service via crafted input, which leads to an out-of-memory exception.
CVE-2018-20645 1 Basic B2b Script Project 1 Basic B2b Script 2024-11-21 N/A
PHP Scripts Mall Basic B2B Script 2.0.9 has HTML injection via the First Name or Last Name field.
CVE-2018-20640 1 Entrepreneur Job Portal Script Project 1 Entrepreneur Job Portal Script 2024-11-21 N/A
PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has stored Cross-Site Scripting (XSS) via the Full Name field.
CVE-2018-20639 1 Entrepreneur Job Portal Script Project 1 Entrepreneur Job Portal Script 2024-11-21 N/A
PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has HTML injection via the Search Bar.
CVE-2018-20636 1 Chartered Accountant \ 1 Auditor Website Project 2024-11-21 N/A
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has HTML injection via the First Name field.
CVE-2018-20632 1 Advance B2b Script Project 1 Advance B2b Script 2024-11-21 N/A
PHP Scripts Mall Advance B2B Script 2.1.4 has stored Cross-Site Scripting (XSS) via the FIRST NAME or LAST NAME field.
CVE-2018-20627 1 Consumer Reviews Script Project 1 Consumer Reviews Script 2024-11-21 N/A
PHP Scripts Mall Consumer Reviews Script 4.0.3 has HTML injection via the search box.
CVE-2018-20621 1 Microvirt 1 Memu 2024-11-21 N/A
An issue was discovered in Microvirt MEmu 6.0.6. The MemuService.exe service binary is vulnerable to local privilege escalation through binary planting due to insecure permissions set at install time. This allows code to be run as NT AUTHORITY/SYSTEM.
CVE-2018-20617 1 Ok-file-formats Project 1 Ok-file-formats 2024-11-21 N/A
ok-file-formats through 2018-10-16 has a heap-based buffer overflow in the ok_csv_decode2 function in ok_csv.c.