Export limit exceeded: 44050 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (44050 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-16638 1 Modx 1 Evolution Cms 2024-11-21 N/A
Evolution CMS 1.4.x allows XSS via the manager/ search parameter.
CVE-2018-16637 1 Modx 1 Evolution Cms 2024-11-21 N/A
Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI.
CVE-2018-16636 1 Nucleuscms 1 Nucleus Cms 2024-11-21 N/A
Nucleus CMS 3.70 allows HTML Injection via the index.php body parameter.
CVE-2018-16635 1 Blackcat-cms 1 Blackcat Cms 2024-11-21 N/A
Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php.
CVE-2018-16633 1 Pluck-cms 1 Pluck 2024-11-21 N/A
Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title.
CVE-2018-16632 1 Jupo 1 Mezzanine 2024-11-21 N/A
Mezzanine CMS v4.3.1 allows XSS via the /admin/blog/blogcategory/add/?_to_field=id&_popup=1 title parameter at admin/blog/blogpost/add/.
CVE-2018-16631 1 Intelliants 1 Subrion Cms 2024-11-21 N/A
Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter.
CVE-2018-16630 1 Getkirby 1 Kirby 2024-11-21 N/A
Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file.
CVE-2018-16629 1 Intelliants 1 Subrion Cms 2024-11-21 N/A
panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
CVE-2018-16628 1 Getkirby 1 Kirby 2024-11-21 N/A
panel/login in Kirby v2.5.12 allows XSS via a blog name.
CVE-2018-16626 1 Typesettercms 1 Typesetter 2024-11-21 N/A
index.php/Admin/Classes in Typesetter 5.1 allows XSS via the description of a new class name.
CVE-2018-16625 1 Typesettercms 1 Typesetter 2024-11-21 N/A
index.php/Admin/Uploaded in Typesetter 5.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
CVE-2018-16624 1 Getkirby 1 Kirby 2024-11-21 N/A
panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page.
CVE-2018-16623 1 Getkirby 1 Kirby 2024-11-21 N/A
Kirby V2.5.12 is prone to a Persistent XSS attack via the Title of the "Site options" in the admin panel dashboard dropdown.
CVE-2018-16622 1 Html-js 1 Doracms 2024-11-21 N/A
Multiple cross-site scripting (XSS) vulnerabilities in /api/content/addOne in DoraCMS v2.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) discription or (2) comments field, related to users/userAddContent.
CVE-2018-16619 1 Sonatype 1 Nexus Repository Manager 2024-11-21 N/A
Sonatype Nexus Repository Manager before 3.14 allows XSS.
CVE-2018-16607 1 Opmantek 1 Open-audit 2024-11-21 N/A
Cross-site scripting (XSS) vulnerability in the Orgs Page in Open-AudIT Professional edition in 2.2.7 allows remote attackers to inject arbitrary web script via the Orgs name field.
CVE-2018-16605 1 Dlink 2 Dir-600m, Dir-600m Firmware 2024-11-21 5.4 Medium
D-Link DIR-600M devices allow XSS via the Hostname and Username fields in the Dynamic DNS Configuration page.
CVE-2018-16555 1 Siemens 8 Scalance S602, Scalance S602 Firmware, Scalance S612 and 5 more 2024-11-21 N/A
A vulnerability has been identified in SCALANCE S602 (All versions < V4.0.1.1), SCALANCE S612 (All versions < V4.0.1.1), SCALANCE S623 (All versions < V4.0.1.1), SCALANCE S627-2M (All versions < V4.0.1.1). The integrated web server could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user must be logged into the web interface in order for the exploitation to succeed. At the stage of publishing this security advisory no public exploitation is known.
CVE-2018-16551 1 Lavalite 1 Lavalite 2024-11-21 N/A
LavaLite 5.5 has XSS via a /edit URI, as demonstrated by client/job/job/Zy8PWBekrJ/edit.