Export limit exceeded: 347860 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (347860 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2018-16389 | 1 E107 | 1 E107 | 2024-11-21 | N/A |
| e107_admin/banlist.php in e107 2.1.8 allows SQL injection via the old_ip parameter. | ||||
| CVE-2018-16388 | 1 E107 | 1 E107 | 2024-11-21 | N/A |
| e107_web/js/plupload/upload.php in e107 2.1.8 allows remote attackers to execute arbitrary PHP code by uploading a .php filename with the image/jpeg content type. | ||||
| CVE-2018-16387 | 1 Elefantcms | 1 Elefantcms | 2024-11-21 | N/A |
| An issue was discovered in Elefant CMS before 2.0.5. There is a CSRF vulnerability that can add an account via user/add. | ||||
| CVE-2018-16386 | 1 Swift | 1 Alliance Web Platform | 2024-11-21 | N/A |
| An issue was discovered in SWIFT Alliance Web Platform 7.1.23. A log injection (and an arbitrary log filename) can be achieved via the PATH_INFO to swp/login/EJBRemoteService/, related to com.swift.ejbgwt.j2ee.client.EjBlnvocationException error log information containing null@java:comp/env/ error messages. | ||||
| CVE-2018-16385 | 1 Thinkphp | 1 Thinkphp | 2024-11-21 | N/A |
| ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string. | ||||
| CVE-2018-16384 | 1 Owasp | 1 Owasp Modsecurity Core Rule Set | 2024-11-21 | 7.5 High |
| A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as "if") and b is the SQL statement to be executed. | ||||
| CVE-2018-16382 | 1 Nasm | 1 Netwide Assembler | 2024-11-21 | N/A |
| Netwide Assembler (NASM) 2.14rc15 has a buffer over-read in x86/regflags.c. | ||||
| CVE-2018-16381 | 1 E107 | 1 E107 | 2024-11-21 | N/A |
| e107 2.1.8 has XSS via the e107_admin/users.php?mode=main&action=list user_loginname parameter. | ||||
| CVE-2018-16380 | 1 Digimute | 1 Ogma Cms | 2024-11-21 | N/A |
| An issue was discovered in Ogma CMS 0.4 Beta. There is a CSRF vulnerability in users.php?action=createnew that can add an admin account. | ||||
| CVE-2018-16379 | 1 Digimute | 1 Ogma Cms | 2024-11-21 | N/A |
| Ogma CMS 0.4 Beta has XSS via the "Footer Text footer" field on the "Theme/Theme Options" screen. | ||||
| CVE-2018-16376 | 1 Uclouvain | 1 Openjpeg | 2024-11-21 | N/A |
| An issue was discovered in OpenJPEG 2.3.0. A heap-based buffer overflow was discovered in the function t2_encode_packet in lib/openmj2/t2.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact. | ||||
| CVE-2018-16375 | 1 Uclouvain | 1 Openjpeg | 2024-11-21 | N/A |
| An issue was discovered in OpenJPEG 2.3.0. Missing checks for header_info.height and header_info.width in the function pnmtoimage in bin/jpwl/convert.c can lead to a heap-based buffer overflow. | ||||
| CVE-2018-16374 | 1 Frog Cms Project | 1 Frog Cms | 2024-11-21 | N/A |
| Frog CMS 0.9.5 has stored XSS via /admin/?/plugin/comment/settings. | ||||
| CVE-2018-16373 | 1 Frog Cms Project | 1 Frog Cms | 2024-11-21 | N/A |
| Frog CMS 0.9.5 has an Upload vulnerability that can create files via /admin/?/plugin/file_manager/save. | ||||
| CVE-2018-16372 | 1 Ideacms | 1 Ideacms | 2024-11-21 | N/A |
| The issue was discovered in IdeaCMS through 2016-04-30. There is reflected XSS via the index.php?c=content&a=search kw parameter. NOTE: this product is discontinued. | ||||
| CVE-2018-16371 | 1 Pescms | 1 Pescms Team | 2024-11-21 | N/A |
| PESCMS Team 2.2.1 has multiple reflected XSS via the keyword parameter: g=Team&m=User&a=index&keyword=, g=Team&m=User_group&a=index&keyword=, g=Team&m=Department&a=index&keyword=, and g=Team&m=Bulletin&a=index&keyword=. | ||||
| CVE-2018-16370 | 1 Pescms | 1 Pescms Team | 2024-11-21 | N/A |
| In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by placing a .php file in a ZIP archive. | ||||
| CVE-2018-16369 | 1 Xpdfreader | 1 Xpdf | 2024-11-21 | N/A |
| XRef::fetch in XRef.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (stack consumption) via a crafted pdf file, related to AcroForm::scanField, as demonstrated by pdftohtml. NOTE: this might overlap CVE-2018-7453. | ||||
| CVE-2018-16368 | 1 Xpdfreader | 1 Xpdf | 2024-11-21 | N/A |
| SplashXPath::strokeAdjust in splash/SplashXPath.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm. | ||||
| CVE-2018-16367 | 1 Qduoj | 1 Onlinejudge | 2024-11-21 | N/A |
| In OnlineJudge 2.0, the sandbox has an incorrect access control vulnerability that can write a file anywhere. A user can write a directory listing to /tmp, and can leak file data with a #include. | ||||