Export limit exceeded: 336910 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 336910 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (44065 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-19351 1 Jupyter 1 Notebook 2024-11-21 N/A
Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript with access to the server API. In notebook/nbconvert/handlers.py, NbconvertFileHandler and NbconvertPostHandler do not set a Content Security Policy to prevent this.
CVE-2018-19350 1 Seacms 1 Seacms 2024-11-21 N/A
In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element.
CVE-2018-19340 1 Guriddo 1 Form Php 2024-11-21 N/A
Guriddo Form PHP 5.3 has XSS via the demos/jqform/defaultnodb/default.php OrderID, ShipName, ShipAddress, ShipCity, ShipPostalCode, ShipCountry, Freight, or details parameter.
CVE-2018-19324 1 Kimsq 1 Rb 2024-11-21 N/A
kimsQ Rb 2.3.0 allows XSS via the second input field to the /?r=home&mod=mypage&page=info URI.
CVE-2018-19311 1 Centreon 1 Centreon 2024-11-21 N/A
Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated by the "Monitoring > Status Details > Services" screen.
CVE-2018-19301 1 Tp4a 1 Teleport 2024-11-21 N/A
tp4a TELEPORT 3.1.0 allows XSS via the login page because a crafted username is mishandled when an administrator later views the system log.
CVE-2018-19289 1 Valine.js 1 Valine 2024-11-21 6.1 Medium
An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file.
CVE-2018-19288 1 Zohocorp 1 Manageengine Opmanager 2024-11-21 N/A
Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API.
CVE-2018-19287 1 Ninjaforma 1 Ninja Forms 2024-11-21 N/A
XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.
CVE-2018-19286 1 Mubu 1 Curtain 2024-11-21 6.1 Medium
The server in mubu note 2018-11-11 has XSS by configuring an account with a crafted name value (along with an arbitrary username value), and then creating and sharing a note.
CVE-2018-19280 1 Centreon 1 Centreon 2024-11-21 N/A
Centreon 3.4.x (fixed in Centreon 18.10.0) has XSS via the resource name or macro expression of a poller macro.
CVE-2018-19233 1 Comparex 1 Miss Marple 2024-11-21 N/A
COMPAREX Miss Marple Enterprise Edition before 2.0 allows local users to execute arbitrary code by reading the user name and encrypted password hard-coded in an Inventory Agent configuration file.
CVE-2018-19229 1 Laobancms 1 Laobancms 2024-11-21 N/A
An issue was discovered in LAOBANCMS 2.0. It allows XSS via the admin/art.php?typeid=1 biaoti parameter.
CVE-2018-19227 1 Laobancms 1 Laobancms 2024-11-21 N/A
An issue was discovered in LAOBANCMS 2.0. It allows XSS via the admin/liuyan.php neirong[] parameter.
CVE-2018-19223 1 Laobancms 1 Laobancms 2024-11-21 N/A
An issue was discovered in LAOBANCMS 2.0. It allows XSS via the first input field to the admin/type.php?id=1 URI.
CVE-2018-19222 1 Laobancms 1 Laobancms 2024-11-21 N/A
An issue was discovered in LAOBANCMS 2.0. It allows a /install/mysql_hy.php?riqi=0&i=0 attack to reset the admin password, even if install.txt exists.
CVE-2018-19206 2 Debian, Roundcube 2 Debian Linux, Webmail 2024-11-21 N/A
steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment.
CVE-2018-19202 1 Mybb 1 Mybb 2024-11-21 N/A
A reflected XSS vulnerability in index.php in MyBB 1.8.x through 1.8.19 allows remote attackers to inject JavaScript via the 'upsetting[bburl]' parameter.
CVE-2018-19201 1 Mybb 1 Mybb 2024-11-21 N/A
A reflected XSS vulnerability in the ModCP Profile Editor in MyBB before 1.8.20 allows remote attackers to inject JavaScript via the 'username' parameter.
CVE-2018-19195 1 Xiaocms 1 Xiaocms 2024-11-21 N/A
An issue was discovered in XiaoCms 20141229. There is XSS related to the template\default\show_product.html file.