Search Results (82829 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-17879 1 Abus 94 Tvip 10000, Tvip 10000 Firmware, Tvip 10001 and 91 more 2024-11-21 9.8 Critical
An issue was discovered on certain ABUS TVIP cameras. The CGI scripts allow remote attackers to execute code via system() as root. There are several injection points in various scripts.
CVE-2018-17876 1 Web-feet 1 Coaster Cms 2024-11-21 N/A
A Stored XSS vulnerability has been discovered in the v5.5.0 version of the Coaster CMS product.
CVE-2018-17874 1 Expressionengine 1 Expressionengine 2024-11-21 N/A
ExpressionEngine before 4.3.5 has reflected XSS.
CVE-2018-17873 1 Wifiranger 2 Wifiranger, Wifiranger Firmware 2024-11-21 N/A
An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3 and earlier allows an attacker with adjacent network access to read the SSH Private Key and log in to the root account.
CVE-2018-17872 1 Verint 2 Collaboration Compliance, Quality Management Platform 2024-11-21 N/A
Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Insecure Permissions.
CVE-2018-17868 1 Dasan 2 H660gw, H660gw Firmware 2024-11-21 N/A
DASAN H660GW devices have Stored XSS in the Port Forwarding functionality.
CVE-2018-17867 1 Dasannetworks 2 H660gw, H660gw Firmware 2024-11-21 N/A
The Port Forwarding functionality on DASAN H660GW devices allows remote attackers to execute arbitrary code via shell metacharacters in the cgi-bin/adv_nat_virsvr.asp Addr parameter (aka the Local IP Address field).
CVE-2018-17866 1 Ultimatemember 1 Ultimate Member 2024-11-21 N/A
Multiple cross-site scripting (XSS) vulnerabilities in includes/core/um-actions-login.php in the "Ultimate Member - User Profile & Membership" plugin before 2.0.28 for WordPress allow remote attackers to inject arbitrary web script or HTML via the "Primary button Text" or "Second button text" field.
CVE-2018-17865 1 Sap 1 J2ee Engine 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in SAP J2EE Engine 7.01 allows remote attackers to inject arbitrary web script via the wsdlPath parameter to /ctcprotocol/Protocol. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVE-2018-17862 1 Sap 1 J2ee Engine 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Fiori allows remote attackers to inject arbitrary web script via the sys_jdbc parameter to /TestJDBC_Web/test2. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVE-2018-17861 1 Sap 1 J2ee Engine 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Portal/EPP allows remote attackers to inject arbitrary web script via the wsdlLib parameter to /ctcprotocol/Protocol. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVE-2018-17849 1 Naviwebs 1 Navigate Cms 2024-11-21 N/A
Navigate CMS 2.8 has Stored XSS via a navigate_upload.php (aka File Upload) request with a multipart/form-data JavaScript payload.
CVE-2018-17835 1 Get-simple 1 Getsimple Cms 2024-11-21 N/A
An issue was discovered in GetSimple CMS 3.3.15. An administrator can insert stored XSS via the admin/settings.php Custom Permalink Structure parameter, which injects the XSS payload into any page created at the admin/pages.php URI.
CVE-2018-17832 1 Wuzhicms 1 Wuzhi Cms 2024-11-21 N/A
XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.
CVE-2018-17830 1 Redaxo 1 Redaxo 2024-11-21 N/A
The $args variable in addons/mediapool/pages/index.php in REDAXO 5.6.2 is not effectively filtered, because names are not restricted (only values are restricted). The attacker can insert XSS payloads via an index.php?page=mediapool/media&opener_input_field=&args[ substring.
CVE-2018-17795 1 Libtiff 1 Libtiff 2024-11-21 N/A
The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, a similar issue to CVE-2017-9935.
CVE-2018-17790 1 Prospecta 1 Master Data Online 2024-11-21 5.4 Medium
Prospecta Master Data Online (MDO) 2.0 has Stored XSS.
CVE-2018-17787 2 D-link, Dlink 2 Dir-823g Firmware, Dir-823g 2024-11-21 N/A
On D-Link DIR-823G devices, the GoAhead configuration allows /HNAP1 Command Injection via shell metacharacters in the POST data, because this data is sent directly to the "system" library function.
CVE-2018-17784 1 Sugarcrm 1 Sugarcrm 2024-11-21 6.1 Medium
Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.
CVE-2018-17783 1 Mantisbt 1 Mantisbt 2024-11-21 N/A
A cross-site scripting (XSS) vulnerability in the Edit Filter page (manage_filter_edit page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settings permit it) through a crafted project name.