Export limit exceeded: 87214 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (87214 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-17037 1 Ucms Project 1 Ucms 2024-11-21 N/A
user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superuser level of 3.
CVE-2018-17034 1 Ucms Project 1 Ucms 2024-11-21 N/A
UCMS 1.4.6 has XSS via the install/index.php mysql_dbname parameter.
CVE-2018-17031 1 Gogs 1 Gogs 2024-11-21 N/A
In Gogs 0.11.53, an attacker can use a crafted .eml file to trigger MIME type sniffing, which leads to XSS, as demonstrated by Internet Explorer, because an "X-Content-Type-Options: nosniff" header is not sent.
CVE-2018-17026 1 Monstra 1 Monstra 2024-11-21 N/A
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page&name=error404 action, a different vulnerability than CVE-2018-10121.
CVE-2018-17025 1 Monstra 1 Monstra 2024-11-21 N/A
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page action for a page with no special role.
CVE-2018-17024 1 Monstra 1 Monstra 2024-11-21 N/A
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an add_page action.
CVE-2018-17022 1 Asus 2 Gt-ac5300, Gt-ac5300 Firmware 2024-11-21 N/A
Stack-based buffer overflow on the ASUS GT-AC5300 router through 3.0.0.4.384_32738 allows remote attackers to cause a denial of service (device crash) or possibly have unspecified other impact by setting a long sh_path0 value and then sending an appGet.cgi?hook=select_list("Storage_x_SharedPath") request, because ej_select_list in router/httpd/web.c uses strcpy.
CVE-2018-17021 1 Asus 2 Gt-ac5300, Gt-ac5300 Firmware 2024-11-21 N/A
Cross-site scripting (XSS) vulnerability on ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allows remote attackers to inject arbitrary web script or HTML via the appGet.cgi hook parameter.
CVE-2018-17003 1 Limesurvey 1 Limesurvey 2024-11-21 N/A
In LimeSurvey 3.14.7, HTML Injection and Stored XSS have been discovered in the appendix via the surveyls_title parameter to /index.php?r=admin/survey/sa/insert.
CVE-2018-17002 1 Ricoh 2 Mp 2001sp, Mp 2001sp Firmware 2024-11-21 N/A
On the RICOH MP 2001 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
CVE-2018-17001 1 Ricoh 2 Sp 4510sf, Sp 4510sf Firmware 2024-11-21 N/A
On the RICOH SP 4510SF printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
CVE-2018-16999 1 Nasm 1 Netwide Assembler 2024-11-21 N/A
Netwide Assembler (NASM) 2.14rc15 has an invalid memory write (segmentation fault) in expand_smacro in preproc.c, which allows attackers to cause a denial of service via a crafted input file.
CVE-2018-16986 1 Ti 5 Ble-stack, Cc1350, Cc2640 and 2 more 2024-11-21 N/A
Texas Instruments BLE-STACK v2.2.1 for SimpleLink CC2640 and CC2650 devices allows remote attackers to execute arbitrary code via a malformed packet that triggers a buffer overflow.
CVE-2018-16981 2 Debian, Nothings 2 Debian Linux, Stb Image.h 2024-11-21 8.8 High
stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function.
CVE-2018-16980 1 Dotcms 1 Dotcms 2024-11-21 N/A
dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters.
CVE-2018-16978 1 Monstra 1 Monstra 2024-11-21 N/A
Monstra CMS V3.0.4 has XSS when ones tries to register an account with a crafted password parameter to users/registration, a different vulnerability than CVE-2018-11473.
CVE-2018-16967 1 Filemanagerpro 1 File Manager 2024-11-21 N/A
There is an XSS vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.
CVE-2018-16965 1 Zohocorp 1 Manageengine Supportcenter Plus 2024-11-21 N/A
In Zoho ManageEngine SupportCenter Plus before 8.1 Build 8109, there is HTML Injection and Stored XSS via the /ServiceContractDef.do contractName parameter.
CVE-2018-16960 1 Buffalo 1 Open Xdmod 2024-11-21 N/A
An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/login.php has Reflected XSS via the xd_user_formal_name parameter.
CVE-2018-16958 1 Oracle 1 Webcenter Interaction 2024-11-21 N/A
An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The ASP.NET_SessionID primary session cookie, when Internet Information Services (IIS) with ASP.NET is used, is not protected with the HttpOnly attribute. The attribute cannot be enabled by customers. Consequently, this cookie is exposed to session hijacking attacks should an adversary be able to execute JavaScript in the origin of the portal installation. NOTE: this CVE is assigned by MITRE and isn't validated by Oracle because Oracle WebCenter Interaction Portal is out of support.