Export limit exceeded: 23935 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 23935 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 15678 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 20501 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 87444 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (87444 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-20448 1 Frog Cms Project 1 Frog Cms 2024-11-21 N/A
Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI.
CVE-2018-20434 1 Librenms 1 Librenms 2024-11-21 N/A
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.php during creation of a new device, and then making a /ajax_output.php?id=capture&format=text&type=snmpwalk&hostname=localhost request that triggers html/includes/output/capture.inc.php command mishandling.
CVE-2018-20432 1 Dlink 4 Covr-2600r, Covr-2600r Firmware, Covr-3902 and 1 more 2024-11-21 9.8 Critical
D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows unauthenticated attackers to gain privileged access to the router, and to extract sensitive data or modify the configuration.
CVE-2018-20421 1 Ethereum 1 Go Ethereum 2024-11-21 N/A
Go Ethereum (aka geth) 1.8.19 allows attackers to cause a denial of service (memory consumption) by rewriting the length of a dynamic array in memory, and then writing data to a single memory location with a large index number, as demonstrated by use of "assembly { mstore }" followed by a "c[0xC800000] = 0xFF" assignment.
CVE-2018-20420 1 Weberp 1 Weberp 2024-11-21 N/A
In webERP 4.15, Z_CreateCompanyTemplateFile.php has Incorrect Access Control, leading to the overwrite of an existing .sql file on the target web site by creating a template and then using ../ directory traversal in the TemplateName parameter.
CVE-2018-20418 1 Craftcms 1 Craft Cms 2024-11-21 N/A
index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.
CVE-2018-20410 1 Wellintech 1 Kingscada 2024-11-21 N/A
WellinTech KingSCADA before 3.7.0.0.1 contains a stack-based buffer overflow. The vulnerability is triggered when sending a specially crafted packet to the AlarmServer (AEserver.exe) service listening on TCP port 12401.
CVE-2018-20408 1 Axiosys 1 Bento4 2024-11-21 N/A
An issue was discovered in Bento4 1.5.1-627. There is a memory leak in AP4_StdcFileByteStream::Create in System/StdC/Ap4StdCFileByteStream.cpp, as demonstrated by mp42hls.
CVE-2018-20407 1 Axiosys 1 Bento4 2024-11-21 N/A
An issue was discovered in Bento4 1.5.1-627. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp, as demonstrated by mp42hls.
CVE-2018-20379 1 Technicolor 2 Dpc3928sl, Dpc3928sl Firmware 2024-11-21 N/A
Technicolor DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-160428a devices allow XSS via a Cross Protocol Injection attack with setSSID of 1.3.6.1.4.1.4413.2.2.2.1.18.1.2.1.1.3.10001.
CVE-2018-20376 1 Tinycc 1 Tinycc 2024-11-21 N/A
An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 8 byte out of bounds write in the asm_parse_directive function in tccasm.c.
CVE-2018-20375 1 Tinycc 1 Tinycc 2024-11-21 N/A
An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 8 byte out of bounds write in the sym_pop function in tccgen.c.
CVE-2018-20374 1 Tinycc 1 Tinycc 2024-11-21 N/A
An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 8 byte out of bounds write in the use_section1 function in tccasm.c.
CVE-2018-20373 1 Tendacn 2 Adsl, Adsl Firmware 2024-11-21 N/A
Tenda ADSL modem routers 1.0.1 allow XSS via the hostname of a DHCP client.
CVE-2018-20372 1 Tp-link 2 Td-w8961nd, Td-w8961nd Firmware 2024-11-21 N/A
TP-Link TD-W8961ND devices allow XSS via the hostname of a DHCP client.
CVE-2018-20370 1 The-sz 1 Netchat 2024-11-21 N/A
SZ NetChat before 7.9 has XSS in the MyName input field of the Options module. Attackers are able to inject commands to compromise the enabled HTTP server web frontend.
CVE-2018-20369 1 Barracuda 1 Message Archiver 2024-11-21 N/A
Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry.cgi module. The injection point of the issue is the Add_Update module.
CVE-2018-20368 1 Averta 1 Master Slider 2024-11-21 N/A
The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback.
CVE-2018-20367 1 Wstmart 1 Wstmart 2024-11-21 N/A
The "mall some commodity details: commodity consultation" component in WSTMart 2.0.8_181212 has stored XSS via the consultContent parameter, as demonstrated by the index.php/home/goodsconsult/add.html URI.
CVE-2018-20365 1 Libraw 1 Libraw 2024-11-21 N/A
LibRaw::raw2image() in libraw_cxx.cpp has a heap-based buffer overflow.