Export limit exceeded: 90271 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (90271 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-17997 1 Layerbb 1 Layerbb 2024-11-21 N/A
LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).
CVE-2018-17990 1 Dlink 2 Dsl-3782, Dsl-3782 Firmware 2024-11-21 N/A
An issue was discovered on D-Link DSL-3782 devices with firmware 1.01. An OS command injection vulnerability in Acl.asp allows a remote authenticated attacker to execute arbitrary OS commands via the ScrIPaddrEndTXT parameter.
CVE-2018-17989 1 Dlink 2 Dsl-3782, Dsl-3782 Firmware 2024-11-21 N/A
A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 that allows authenticated attackers to inject a JavaScript or HTML payload inside the ACL page. The injected payload would be executed in a user's browser when "/cgi-bin/New_GUI/Acl.asp" is requested.
CVE-2018-17985 1 Gnu 1 Binutils 2024-11-21 N/A
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption problem caused by the cplus_demangle_type function making recursive calls to itself in certain scenarios involving many 'P' characters.
CVE-2018-17981 1 Lifesize 4 Express 220, Express 220 Firmware, Room 220i and 1 more 2024-11-21 6.1 Medium
Lifesize Express ls ex2_4.7.10 2000 (14) devices allow XSS via the interface/interface.php brand parameter.
CVE-2018-17967 2 Imagemagick, Redhat 2 Imagemagick, Enterprise Linux 2024-11-21 N/A
ImageMagick 7.0.7-28 has a memory leak vulnerability in ReadBGRImage in coders/bgr.c.
CVE-2018-17966 2 Imagemagick, Redhat 2 Imagemagick, Enterprise Linux 2024-11-21 N/A
ImageMagick 7.0.7-28 has a memory leak vulnerability in WritePDBImage in coders/pdb.c.
CVE-2018-17965 1 Imagemagick 1 Imagemagick 2024-11-21 N/A
ImageMagick 7.0.7-28 has a memory leak vulnerability in WriteSGIImage in coders/sgi.c.
CVE-2018-17964 1 Aryanic 1 Highportal 2024-11-21 N/A
Aryanic HighPortal 12.5 has XSS via an Add Tags action.
CVE-2018-17960 1 Ckeditor 1 Ckeditor 2024-11-21 N/A
CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.
CVE-2018-17952 1 Microfocus 1 Edirectory 2024-11-21 N/A
Cross site scripting vulnerability in eDirectory prior to 9.1 SP2
CVE-2018-17949 1 Microfocus 1 Imanager 2024-11-21 N/A
Cross site scripting vulnerability in iManager prior to 3.1 SP2.
CVE-2018-17947 1 Atmist 1 Snazzy Maps 2024-11-21 N/A
The Snazzy Maps plugin before 1.1.5 for WordPress has XSS via the text or tab parameter.
CVE-2018-17946 1 Tribulant 1 Slideshow Gallery 2024-11-21 N/A
The Tribulant Slideshow Gallery plugin before 1.6.6.1 for WordPress has XSS via the id, method, Gallerymessage, Galleryerror, or Galleryupdated parameter.
CVE-2018-17942 1 Gnu 1 Gnulib 2024-11-21 N/A
The convert_to_decimal function in vasnprintf.c in Gnulib before 2018-09-23 has a heap-based buffer overflow because memory is not allocated for a trailing '\0' character during %f processing.
CVE-2018-17937 3 Debian, Gpsd Project, Microjson Project 3 Debian Linux, Gpsd, Microjson 2024-11-21 8.8 High
gpsd versions 2.90 to 3.17 and microjson versions 1.0 to 1.3, an open source project, allow a stack-based buffer overflow, which may allow remote attackers to execute arbitrary code on embedded platforms via traffic on Port 2947/TCP or crafted JSON inputs.
CVE-2018-17930 1 Teledynedalsa 1 Sherlock 2024-11-21 9.8 Critical
A stack-based buffer overflow vulnerability has been identified in Teledyne DALSA Sherlock Version 7.2.7.4 and prior, which may allow remote code execution.
CVE-2018-17929 1 Deltaww 1 Tpeditor 2024-11-21 7.8 High
In Delta Industrial Automation TPEditor, TPEditor Versions 1.90 and prior, multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files lacking user input validation before copying data from project files onto the stack and may allow an attacker to remotely execute arbitrary code.
CVE-2018-17927 1 Deltaww 1 Tpeditor 2024-11-21 N/A
In Delta Industrial Automation TPEditor, TPEditor Versions 1.90 and prior, multiple out-of-bounds write vulnerabilities may be exploited by processing specially crafted project files lacking user input validation, which may cause the system to write outside the intended buffer area and may allow remote code execution.
CVE-2018-17919 1 Xiongmaitech 1 Xmeye P2p Cloud Server 2024-11-21 N/A
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumented user account "default" with its default password to login to XMeye and access/view video streams.