Search Results (326435 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-9035 1 Contact-form-7-to-database-extension Project 1 Contact-form-7-to-database-extension 2024-11-21 N/A
CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas into CSV files via the contact form.
CVE-2018-9034 1 Relevanssi 1 Relevanssi 2024-11-21 N/A
Cross-site scripting (XSS) vulnerability in lib/interface.php of the Relevanssi plugin 4.0.4 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the tab GET parameter.
CVE-2018-9032 1 Dlink 2 Dir-850l, Dir-850l Firmware 2024-11-21 9.8 Critical
An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Version : A1, B1; Firmware Version : 1.02-2.06) devices potentially allows attackers to bypass SharePort Web Access Portal by directly visiting /category_view.php or /folder_view.php.
CVE-2018-9031 1 Tnlsoftsolutions 1 Sentry Vision 2024-11-21 N/A
The login interface on TNLSoftSolutions Sentry Vision 3.x devices provides password disclosure by reading an "if(pwd ==" line in the HTML source code. This means, in effect, that authentication occurs only on the client side.
CVE-2018-9029 1 Broadcom 1 Privileged Access Manager 2024-11-21 N/A
An improper input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to conduct SQL injection attacks.
CVE-2018-9028 1 Broadcom 1 Privileged Access Manager 2024-11-21 N/A
Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking.
CVE-2018-9027 1 Ca 1 Ca Privileged Access Manager 2024-11-21 N/A
A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute malicious script with a specially crafted link.
CVE-2018-9026 1 Broadcom 1 Privileged Access Manager 2024-11-21 N/A
A session fixation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to hijack user sessions with a specially crafted request.
CVE-2018-9025 1 Broadcom 1 Privileged Access Manager 2024-11-21 N/A
An input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to poison log files with specially crafted input.
CVE-2018-9024 1 Broadcom 1 Privileged Access Manager 2024-11-21 N/A
An improper authentication vulnerability in CA Privileged Access Manager 2.x allows attackers to spoof IP addresses in a log file.
CVE-2018-9023 1 Broadcom 1 Privileged Access Manager 2024-11-21 N/A
An input validation vulnerability in CA Privileged Access Manager 2.x allows unprivileged users to execute arbitrary commands by passing specially crafted arguments to the update_crld script.
CVE-2018-9022 1 Broadcom 1 Privileged Access Manager 2024-11-21 9.8 Critical
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration file.
CVE-2018-9021 1 Broadcom 1 Privileged Access Manager 2024-11-21 9.8 Critical
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with specially crafted requests.
CVE-2018-9020 1 Pixelite 1 Events Manager 2024-11-21 N/A
The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature.
CVE-2018-9019 2 Dolibarr, Oracle 2 Dolibarr, Data Integrator 2024-11-21 9.8 Critical
SQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbitrary SQL commands via the sortfield parameter to /accountancy/admin/accountmodel.php, /accountancy/admin/categories_list.php, /accountancy/admin/journals_list.php, /admin/dict.php, /admin/mails_templates.php, or /admin/website.php.
CVE-2018-9018 2 Debian, Graphicsmagick 2 Debian Linux, Graphicsmagick 2024-11-21 N/A
In GraphicsMagick 1.3.28, there is a divide-by-zero in the ReadMNGImage function of coders/png.c. Remote attackers could leverage this vulnerability to cause a crash and denial of service via a crafted mng file.
CVE-2018-9017 1 Dsmall Project 1 Dsmall 2024-11-21 N/A
dsmall v20180320 allows XSS via the member search box at the public/index.php/home/membersnsfriend/findlist.html URI.
CVE-2018-9016 1 Dsmall Project 1 Dsmall 2024-11-21 N/A
dsmall v20180320 allows XSS via the main page search box at the public/index.php/home URI.
CVE-2018-9015 1 Dsmall Project 1 Dsmall 2024-11-21 N/A
dsmall v20180320 allows XSS via the public/index.php/home/predeposit/index.html pdr_sn parameter (aka the CMS search box).
CVE-2018-9014 1 Dsmall Project 1 Dsmall 2024-11-21 N/A
dsmall v20180320 allows physical path leakage via a public/index.php/home/predeposit/index.html?pdr_sn= request.