Export limit exceeded: 23935 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 23935 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 15678 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 20501 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 87444 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (87444 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2018-20448 | 1 Frog Cms Project | 1 Frog Cms | 2024-11-21 | N/A |
| Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI. | ||||
| CVE-2018-20434 | 1 Librenms | 1 Librenms | 2024-11-21 | N/A |
| LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.php during creation of a new device, and then making a /ajax_output.php?id=capture&format=text&type=snmpwalk&hostname=localhost request that triggers html/includes/output/capture.inc.php command mishandling. | ||||
| CVE-2018-20432 | 1 Dlink | 4 Covr-2600r, Covr-2600r Firmware, Covr-3902 and 1 more | 2024-11-21 | 9.8 Critical |
| D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows unauthenticated attackers to gain privileged access to the router, and to extract sensitive data or modify the configuration. | ||||
| CVE-2018-20421 | 1 Ethereum | 1 Go Ethereum | 2024-11-21 | N/A |
| Go Ethereum (aka geth) 1.8.19 allows attackers to cause a denial of service (memory consumption) by rewriting the length of a dynamic array in memory, and then writing data to a single memory location with a large index number, as demonstrated by use of "assembly { mstore }" followed by a "c[0xC800000] = 0xFF" assignment. | ||||
| CVE-2018-20420 | 1 Weberp | 1 Weberp | 2024-11-21 | N/A |
| In webERP 4.15, Z_CreateCompanyTemplateFile.php has Incorrect Access Control, leading to the overwrite of an existing .sql file on the target web site by creating a template and then using ../ directory traversal in the TemplateName parameter. | ||||
| CVE-2018-20418 | 1 Craftcms | 1 Craft Cms | 2024-11-21 | N/A |
| index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab. | ||||
| CVE-2018-20410 | 1 Wellintech | 1 Kingscada | 2024-11-21 | N/A |
| WellinTech KingSCADA before 3.7.0.0.1 contains a stack-based buffer overflow. The vulnerability is triggered when sending a specially crafted packet to the AlarmServer (AEserver.exe) service listening on TCP port 12401. | ||||
| CVE-2018-20408 | 1 Axiosys | 1 Bento4 | 2024-11-21 | N/A |
| An issue was discovered in Bento4 1.5.1-627. There is a memory leak in AP4_StdcFileByteStream::Create in System/StdC/Ap4StdCFileByteStream.cpp, as demonstrated by mp42hls. | ||||
| CVE-2018-20407 | 1 Axiosys | 1 Bento4 | 2024-11-21 | N/A |
| An issue was discovered in Bento4 1.5.1-627. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp, as demonstrated by mp42hls. | ||||
| CVE-2018-20379 | 1 Technicolor | 2 Dpc3928sl, Dpc3928sl Firmware | 2024-11-21 | N/A |
| Technicolor DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-160428a devices allow XSS via a Cross Protocol Injection attack with setSSID of 1.3.6.1.4.1.4413.2.2.2.1.18.1.2.1.1.3.10001. | ||||
| CVE-2018-20376 | 1 Tinycc | 1 Tinycc | 2024-11-21 | N/A |
| An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 8 byte out of bounds write in the asm_parse_directive function in tccasm.c. | ||||
| CVE-2018-20375 | 1 Tinycc | 1 Tinycc | 2024-11-21 | N/A |
| An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 8 byte out of bounds write in the sym_pop function in tccgen.c. | ||||
| CVE-2018-20374 | 1 Tinycc | 1 Tinycc | 2024-11-21 | N/A |
| An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 8 byte out of bounds write in the use_section1 function in tccasm.c. | ||||
| CVE-2018-20373 | 1 Tendacn | 2 Adsl, Adsl Firmware | 2024-11-21 | N/A |
| Tenda ADSL modem routers 1.0.1 allow XSS via the hostname of a DHCP client. | ||||
| CVE-2018-20372 | 1 Tp-link | 2 Td-w8961nd, Td-w8961nd Firmware | 2024-11-21 | N/A |
| TP-Link TD-W8961ND devices allow XSS via the hostname of a DHCP client. | ||||
| CVE-2018-20370 | 1 The-sz | 1 Netchat | 2024-11-21 | N/A |
| SZ NetChat before 7.9 has XSS in the MyName input field of the Options module. Attackers are able to inject commands to compromise the enabled HTTP server web frontend. | ||||
| CVE-2018-20369 | 1 Barracuda | 1 Message Archiver | 2024-11-21 | N/A |
| Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry.cgi module. The injection point of the issue is the Add_Update module. | ||||
| CVE-2018-20368 | 1 Averta | 1 Master Slider | 2024-11-21 | N/A |
| The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback. | ||||
| CVE-2018-20367 | 1 Wstmart | 1 Wstmart | 2024-11-21 | N/A |
| The "mall some commodity details: commodity consultation" component in WSTMart 2.0.8_181212 has stored XSS via the consultContent parameter, as demonstrated by the index.php/home/goodsconsult/add.html URI. | ||||
| CVE-2018-20365 | 1 Libraw | 1 Libraw | 2024-11-21 | N/A |
| LibRaw::raw2image() in libraw_cxx.cpp has a heap-based buffer overflow. | ||||