Export limit exceeded: 90131 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (90131 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2018-16744 | 1 Mgetty Project | 1 Mgetty | 2024-11-21 | N/A |
| An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized. It could allow for command injection if untrusted input can reach it, because popen is used. | ||||
| CVE-2018-16743 | 1 Mgetty Project | 1 Mgetty | 2024-11-21 | N/A |
| An issue was discovered in mgetty before 1.2.1. In contrib/next-login/login.c, the command-line parameter username is passed unsanitized to strcpy(), which can cause a stack-based buffer overflow. | ||||
| CVE-2018-16742 | 1 Mgetty Project | 1 Mgetty | 2024-11-21 | N/A |
| An issue was discovered in mgetty before 1.2.1. In contrib/scrts.c, a stack-based buffer overflow can be triggered via a command-line parameter. | ||||
| CVE-2018-16741 | 2 Debian, Mgetty Project | 2 Debian Linux, Mgetty | 2024-11-21 | N/A |
| An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() does not properly sanitize shell metacharacters to prevent command injection. It is possible to use the ||, &&, or > characters within a file created by the "faxq-helper activate <jobid>" command. | ||||
| CVE-2018-16736 | 1 Rcfilters Project | 1 Rcfilters | 2024-11-21 | N/A |
| In the rcfilters plugin 2.1.6 for Roundcube, XSS exists via the _whatfilter and _messages parameters (in the Filters section of the settings). | ||||
| CVE-2018-16730 | 1 Chshcms | 1 Cscms | 2024-11-21 | N/A |
| \upload\plugins\sys\Install.php in CScms 4.1 has XSS via the site name. | ||||
| CVE-2018-16729 | 1 Pluck-cms | 1 Pluck | 2024-11-21 | N/A |
| Pluck 4.7.7 allows XSS via an SVG file that contains Javascript in a SCRIPT element, and is uploaded via pages->manage under admin.php?action=files. | ||||
| CVE-2018-16728 | 1 Feindura | 1 Feindura | 2024-11-21 | N/A |
| feindura 2.0.7 allows XSS via the tags field of a new page created at index.php?category=0&page=new. | ||||
| CVE-2018-16727 | 1 Razorcms | 1 Razorcms | 2024-11-21 | N/A |
| razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component. | ||||
| CVE-2018-16726 | 1 Razorcms | 1 Razorcms | 2024-11-21 | N/A |
| razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component. | ||||
| CVE-2018-16725 | 1 Baijiacms Project | 1 Baijiacms | 2024-11-21 | N/A |
| An issue is discovered in baijiacms V4. XSS exists via the assets/weengine/components/zclip/ZeroClipboard.swf id parameter, aka "Non-standard use of the flash component." | ||||
| CVE-2018-16718 | 1 Nih | 1 Ncbi Toolbox | 2024-11-21 | N/A |
| An XSS vulnerability exists in wwwblast.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox via a crafted -z1 argument. | ||||
| CVE-2018-16717 | 1 Nih | 1 Ncbi Toolbox | 2024-11-21 | N/A |
| A heap-based buffer overflow exists in nph-viewgif.cgi in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox. | ||||
| CVE-2018-16715 | 1 Absolute | 1 Ctes Windows Agent | 2024-11-21 | N/A |
| An issue was discovered in Absolute Software CTES Windows Agent through 1.0.0.1479. The security permissions on the %ProgramData%\CTES folder and sub-folders may allow write access to low-privileged user accounts. This allows unauthorized replacement of service program executable (EXE) or dynamically loadable library (DLL) files, causing elevated (SYSTEM) user access. Configuration control files or data files under this folder could also be similarly modified to affect service process behavior. | ||||
| CVE-2018-16703 | 1 Gleeztech | 1 Gleez Cms | 2024-11-21 | N/A |
| A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple user enumerations, which can further help an attacker to perform login attempts in excess of the configured login attempt limit. The vulnerability is due to insufficient server-side access control and login attempt limit enforcement. An attacker could exploit this vulnerability by sending modified login attempts to the Portal login page. An exploit could allow the attacker to identify existing users and perform brute-force password attacks on the Portal, as demonstrated by navigating to the user/4 URI. | ||||
| CVE-2018-16666 | 1 Contiki-ng | 1 Contiki-ng. | 2024-11-21 | N/A |
| An issue was discovered in Contiki-NG through 4.1. There is a stack-based buffer overflow in next_string in os/storage/antelope/aql-lexer.c while parsing AQL (parsing next string). | ||||
| CVE-2018-16663 | 1 Contiki-ng | 1 Contiki-ng. | 2024-11-21 | N/A |
| An issue was discovered in Contiki-NG through 4.1. There is a stack-based buffer overflow in parse_relations in os/storage/antelope/aql-parser.c while parsing AQL (storage of relations). | ||||
| CVE-2018-16660 | 1 Imperva | 1 Securesphere | 2024-11-21 | N/A |
| A command injection vulnerability in PWS in Imperva SecureSphere 13.0.0.10 and 13.1.0.10 Gateway allows an attacker with authenticated access to execute arbitrary OS commands on a vulnerable installation. | ||||
| CVE-2018-16655 | 1 Gxlcms | 1 Gxlcms | 2024-11-21 | N/A |
| Gxlcms 1.0 has XSS via the PATH_INFO to gx/lib/ThinkPHP/Tpl/ThinkException.tpl.php. | ||||
| CVE-2018-16654 | 1 Zurmo | 1 Zurmo Crm | 2024-11-21 | N/A |
| Zurmo 3.2.4 Stable allows XSS via app/index.php/accounts/default/details?id=2&kanbanBoard=1&openToTaskId=1. | ||||