Search Results (327109 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-16361 1 Btiteam 1 Xbtit 2024-11-21 N/A
An issue was discovered in BTITeam XBTIT 2.5.4. news.php allows XSS via the id parameter.
CVE-2018-16359 1 Google 1 Gvisor 2024-11-21 N/A
Google gVisor before 2018-08-23, within the seccomp sandbox, permits access to the renameat system call, which allows attackers to rename files on the host OS.
CVE-2018-16358 1 Dotclear 1 Dotclear 2024-11-21 N/A
A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authenticated users to upload HTML content containing an XSS payload with the file extension .ahtml.
CVE-2018-16357 1 Pbootcms 1 Pbootcms 2024-11-21 9.8 Critical
An issue was discovered in PbootCMS. There is a SQL injection via the api.php/Cms/search order parameter.
CVE-2018-16356 1 Pbootcms 1 Pbootcms 2024-11-21 9.8 Critical
An issue was discovered in PbootCMS. There is a SQL injection via the api.php/List/index order parameter.
CVE-2018-16354 1 Fhcrm Project 1 Fhcrm 2024-11-21 N/A
An issue was discovered in FHCRM through 2018-02-11. There is a SQL injection via the index.php/User/read limit parameter.
CVE-2018-16353 1 Fhcrm Project 1 Fhcrm 2024-11-21 N/A
An issue was discovered in FHCRM through 2018-02-11. There is a SQL injection via the /index.php/Customer/read limit parameter.
CVE-2018-16352 1 Weaselcms Project 1 Weaselcms 2024-11-21 N/A
There is a PHP code upload vulnerability in WeaselCMS 0.3.6 via index.php because code can be embedded at the end of a .png file when the image/png content type is used.
CVE-2018-16350 1 Wuzhi Cms Project 1 Wuzhi Cms 2024-11-21 N/A
WUZHI CMS 4.1.0 has XSS via the index.php?m=core&f=set&v=basic form[statcode] parameter.
CVE-2018-16349 1 Wuzhi Cms Project 1 Wuzhi Cms 2024-11-21 N/A
WUZHI CMS 4.1.0 has XSS via the index.php?m=link&f=index&v=add form[remark] parameter.
CVE-2018-16348 1 Seacms 1 Seacms 2024-11-21 N/A
SeaCMS V6.61 has XSS via the admin_video.php v_content parameter, related to the site name.
CVE-2018-16347 1 Gleezcms 1 Gleez Cms 2024-11-21 N/A
An issue was discovered in Gleez CMS v1.2.0. There is XSS via media/imagecache/resize.
CVE-2018-16346 1 Chemcms Project 1 Chemcms 2024-11-21 N/A
ChemCMS 1.0.6 has XSS via the "setting -> website information" field.
CVE-2018-16345 1 Easycms 1 Easycms 2024-11-21 N/A
An issue was discovered in EasyCMS 1.5. There is a CSRF vulnerability that can update the admin password via index.php?s=/admin/rbacuser/update/navTabId/listusers/callbackType/closeCurrent.
CVE-2018-16344 1 Zzcms 1 Zzcms 2024-11-21 N/A
An issue was discovered in zzcms 8.3. It allows remote attackers to delete arbitrary files via directory traversal sequences in the flv parameter. This can be leveraged for database access by deleting install.lock.
CVE-2018-16343 1 Seacms 1 Seacms 2024-11-21 N/A
SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block use of $GLOBALS.
CVE-2018-16342 1 Showdoc 1 Showdoc 2024-11-21 N/A
ShowDoc v1.8.0 has XSS via a new page.
CVE-2018-16339 1 Phome 1 Empirecms 2024-11-21 N/A
An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators via upload/e/admin/user/AddUser.php?enews=AddUser.
CVE-2018-16338 1 Auracms 1 Auracms 2024-11-21 N/A
An issue was discovered in AuraCMS 2.3. There is a CSRF vulnerability that can change the administrator's password via admin.php?mod=users and subsequently add a page or menu, or submit a topic.
CVE-2018-16337 1 Chshcms 1 Cscms 2024-11-21 N/A
An issue was discovered in Cscms V4.1.8. There is a CSRF vulnerability that can modify a website's basic configuration via upload/admin.php/setting/save.