Export limit exceeded: 89933 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (89933 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2018-10307 | 1 Ilias | 1 Ilias | 2024-11-21 | N/A |
| error.php in ILIAS 5.2.x through 5.3.x before 5.3.4 allows XSS via the text of a PDO exception. | ||||
| CVE-2018-10306 | 1 Ilias | 1 Ilias | 2024-11-21 | N/A |
| Services/Form/classes/class.ilDateDurationInputGUI.php and Services/Form/classes/class.ilDateTimeInputGUI.php in ILIAS 5.1.x through 5.3.x before 5.3.4 allow XSS via an invalid date. | ||||
| CVE-2018-10301 | 1 Web-dorado | 1 Wd Instagram Feed | 2024-11-21 | N/A |
| Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 Premium for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in a comment on an Instagram post. | ||||
| CVE-2018-10300 | 1 Web-dorado | 1 Wd Instagram Feed | 2024-11-21 | N/A |
| Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in an Instagram profile's bio. | ||||
| CVE-2018-10298 | 1 Discuz | 1 Discuzx | 2024-11-21 | N/A |
| Discuz! DiscuzX through X3.4 has reflected XSS via forum.php?mod=post&action=newthread because data/template/1_diy_portal_view.tpl.php does not restrict the content. | ||||
| CVE-2018-10297 | 1 Discuz | 1 Discuzx | 2024-11-21 | N/A |
| Discuz! DiscuzX through X3.4 has stored XSS via the portal.php?mod=portalcp&ac=article URI, related to mishandling of IMG elements associated with remote images. | ||||
| CVE-2018-10296 | 1 1234n | 1 Minicms | 2024-11-21 | N/A |
| MiniCMS V1.10 has XSS via the mc-admin/post-edit.php title parameter. | ||||
| CVE-2018-10294 | 1 Flexense | 1 Diskboss | 2024-11-21 | N/A |
| Flexense DiskBoss Enterprise v7.4.28 to v9.1.16 has XSS. | ||||
| CVE-2018-10285 | 1 Ericssonlg | 1 Ipecs Nms | 2024-11-21 | N/A |
| The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attacker might bypass authentication. | ||||
| CVE-2018-10268 | 1 Fastadmin | 1 Fastadmin | 2024-11-21 | N/A |
| An issue was discovered in FastAdmin V1.0.0.20180417_beta. There is XSS via the application\api\controller\User.php avatar parameter. | ||||
| CVE-2018-10259 | 1 Hrsale Project | 1 Hrsale | 2024-11-21 | N/A |
| An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user. | ||||
| CVE-2018-10250 | 1 Icmsdev | 1 Icms | 2024-11-21 | N/A |
| iCMS V7.0.8 has XSS via the admincp.php keywords parameter in a weixin_category action, aka a WeChat Classified Management keyword search. | ||||
| CVE-2018-10237 | 3 Google, Oracle, Redhat | 21 Guava, Banking Payments, Communications Ip Service Activator and 18 more | 2024-11-21 | 5.9 Medium |
| Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable. | ||||
| CVE-2018-10234 | 1 Ultimatemember | 1 User Profile \& Membership | 2024-11-21 | N/A |
| Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options§ion=account page. | ||||
| CVE-2018-10231 | 1 Topdesk | 1 Topdesk | 2024-11-21 | N/A |
| Cross-site scripting (XSS) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. | ||||
| CVE-2018-10230 | 1 Zend | 1 Zend Server | 2024-11-21 | N/A |
| Zend Debugger in Zend Server before 9.1.3 has XSS, aka ZSR-2455. | ||||
| CVE-2018-10227 | 1 1234n | 1 Minicms | 2024-11-21 | N/A |
| MiniCMS v1.10 has XSS via the mc-admin/conf.php site_link parameter. | ||||
| CVE-2018-10221 | 1 Wuzhicms | 1 Wuzhicms | 2024-11-21 | N/A |
| An issue was discovered in WUZHI CMS V4.1.0. There is a persistent XSS vulnerability that can steal the administrator cookies via the tag[tag] parameter to the index.php?m=tags&f=index&v=add&&_su=wuzhicms URI. After a website editor (whose privilege is lower than the administrator) logs in, he can add a new TAGS with the XSS payload. | ||||
| CVE-2018-10205 | 1 Hyper | 1 Hyperstart | 2024-11-21 | N/A |
| hyperstart 1.0.0 in HyperHQ Hyper has memory leaks in the container_setup_modules and hyper_rescan_scsi functions in container.c, related to runV 1.0.0 for Docker. | ||||
| CVE-2018-10204 | 1 Purevpn | 1 Purevpn | 2024-11-21 | N/A |
| PureVPN 6.0.1 for Windows suffers from a SYSTEM privilege escalation vulnerability in its "sevpnclient" service. When configured to use the OpenVPN protocol, the "sevpnclient" service executes "openvpn.exe" using the OpenVPN config file located at %PROGRAMDATA%\purevpn\config\config.ovpn. This file allows "Write" permissions to users in the "Everyone" group. An authenticated attacker may modify this file to specify a dynamic library plugin that should run for every new VPN connection attempt. This plugin will execute code in the context of the SYSTEM account. | ||||