Export limit exceeded: 15574 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 87267 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (87267 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2018-18715 | 1 Zohocorp | 1 Manageengine Opmanager | 2024-11-21 | N/A |
| Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS. | ||||
| CVE-2018-18714 | 1 Iobit | 1 Malware Fighter | 2024-11-21 | N/A |
| RegFilter.sys in IOBit Malware Fighter 6.2 and earlier is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E010. This can lead to denial of service (DoS) or code execution with root privileges. | ||||
| CVE-2018-18699 | 1 Gopro | 1 Gpmf-parser | 2024-11-21 | N/A |
| An issue was discovered in GoPro gpmf-parser 1.2.1. There is an out-of-bounds write in OpenMP4Source in GPMF_mp4reader.c. | ||||
| CVE-2018-18694 | 1 Monstra | 1 Monstra | 2024-11-21 | N/A |
| admin/index.php?id=filesmanager in Monstra CMS 3.0.4 allows remote authenticated administrators to trigger stored XSS via JavaScript content in a file whose name lacks an extension. Such a file is interpreted as text/html in certain cases. | ||||
| CVE-2018-18692 | 1 Semcosoft | 1 Semcosoft | 2024-11-21 | N/A |
| A reflected Cross-Site scripting (XSS) vulnerability in SEMCO Semcosoft 5.3 allows remote attackers to inject arbitrary web scripts or HTML via the username parameter to the Login Form. | ||||
| CVE-2018-18690 | 4 Canonical, Debian, Linux and 1 more | 5 Ubuntu Linux, Debian Linux, Linux Kernel and 2 more | 2024-11-21 | N/A |
| In the Linux kernel before 4.17, a local attacker able to set attributes on an xfs filesystem could make this filesystem non-operational until the next mount by triggering an unchecked error condition during an xfs attribute change, because xfs_attr_shortform_addname in fs/xfs/libxfs/xfs_attr.c mishandles ATTR_REPLACE operations with conversion of an attr from short to long form. | ||||
| CVE-2018-18678 | 1 Sir | 1 Gnuboard | 2024-11-21 | 6.1 Medium |
| GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board group extra contents" parameter, aka the adm/boardgroup_form_update.php gr_1~10 parameter. | ||||
| CVE-2018-18676 | 1 Sir | 1 Gnuboard | 2024-11-21 | N/A |
| GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board tail contents" parameter, aka the adm/board_form_update.php bo_mobile_content_tail parameter. | ||||
| CVE-2018-18675 | 1 Sir | 1 Gnuboard | 2024-11-21 | N/A |
| GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board title contents" parameter, aka the adm/board_form_update.php bo_mobile_subject parameter. | ||||
| CVE-2018-18674 | 1 Sir | 1 Gnuboard | 2024-11-21 | 6.1 Medium |
| GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board tail contents" parameter, aka the adm/board_form_update.php bo_content_tail parameter. | ||||
| CVE-2018-18673 | 1 Sir | 1 Gnuboard | 2024-11-21 | N/A |
| GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Menu Link" parameter, aka the adm/menu_list_update.php me_link parameter. | ||||
| CVE-2018-18672 | 1 Sir | 1 Gnuboard | 2024-11-21 | N/A |
| GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board head contents" parameter, aka the adm/board_form_update.php bo_content_head parameter. | ||||
| CVE-2018-18671 | 1 Sir | 1 Gnuboard | 2024-11-21 | N/A |
| GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board head contents" parameter, aka the adm/board_form_update.php bo_mobile_content_head parameter. | ||||
| CVE-2018-18670 | 1 Sir | 1 Gnuboard | 2024-11-21 | N/A |
| GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Extra Contents" parameter, aka the adm/config_form_update.php cf_1~10 parameter. | ||||
| CVE-2018-18669 | 1 Sir | 1 Gnuboard | 2024-11-21 | N/A |
| GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board title contents" parameter, aka the adm/board_form_update.php bo_subject parameter. | ||||
| CVE-2018-18668 | 1 Sir | 1 Gnuboard | 2024-11-21 | N/A |
| GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "homepage title" parameter, aka the adm/config_form_update.php cf_title parameter. | ||||
| CVE-2018-18660 | 1 Arcserve | 1 Udp | 2024-11-21 | 6.1 Medium |
| An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-21 Reflected Cross-site Scripting via /authenticationendpoint/domain.jsp issue. | ||||
| CVE-2018-18654 | 1 Debian | 1 Crossroads | 2024-11-21 | N/A |
| Crossroads 2.81 does not properly handle the /tmp directory during a build of xr. A local attacker can first create a world-writable subdirectory in a certain location under the /tmp directory, wait until a user process copies xr there, and then replace the entire contents of this subdirectory to include a Trojan horse xr. | ||||
| CVE-2018-18643 | 1 Gitlab | 1 Gitlab | 2024-11-21 | N/A |
| GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS. | ||||
| CVE-2018-18642 | 1 Gitlab | 1 Gitlab | 2024-11-21 | N/A |
| An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has XSS. | ||||