Search Results (82814 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-17051 1 Knet 1 Cisco Configuration Manager 2024-11-21 N/A
K-Net Cisco Configuration Manager through 2014-11-19 has XSS via devices.php.
CVE-2018-17049 1 Cqu Lankers Project 1 Cqu Lankers 2024-11-21 N/A
CQU-LANKERS through 2017-11-02 has XSS via the public/api.php callback parameter in an uploadpic action.
CVE-2018-17046 1 Translate Man Project 1 Translate Man 2024-11-21 N/A
translate man before 2018-08-21 has XSS via containers/outputBox/outputBox.vue and store/index.js.
CVE-2018-17044 1 Yzmcms 1 Yzmcms 2024-11-21 N/A
In YzmCMS 5.1, stored XSS exists via the admin/system_manage/user_config_add.html title parameter.
CVE-2018-17043 1 Doc2txt Project 1 Doc2txt 2024-11-21 N/A
An issue has been found in doc2txt through 2014-03-19. It is a heap-based buffer overflow in the function Storage::init in Storage.cpp, called from parse_doc in parse_doc.cpp.
CVE-2018-17039 2 1234n, Microsoft 2 Minicms, Internet Explorer 2024-11-21 N/A
MiniCMS 1.10, when Internet Explorer is used, allows XSS via a crafted URI because $_SERVER['REQUEST_URI'] is mishandled.
CVE-2018-17037 1 Ucms Project 1 Ucms 2024-11-21 N/A
user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superuser level of 3.
CVE-2018-17034 1 Ucms Project 1 Ucms 2024-11-21 N/A
UCMS 1.4.6 has XSS via the install/index.php mysql_dbname parameter.
CVE-2018-17031 1 Gogs 1 Gogs 2024-11-21 N/A
In Gogs 0.11.53, an attacker can use a crafted .eml file to trigger MIME type sniffing, which leads to XSS, as demonstrated by Internet Explorer, because an "X-Content-Type-Options: nosniff" header is not sent.
CVE-2018-17026 1 Monstra 1 Monstra 2024-11-21 N/A
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page&name=error404 action, a different vulnerability than CVE-2018-10121.
CVE-2018-17025 1 Monstra 1 Monstra 2024-11-21 N/A
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page action for a page with no special role.
CVE-2018-17024 1 Monstra 1 Monstra 2024-11-21 N/A
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an add_page action.
CVE-2018-17022 1 Asus 2 Gt-ac5300, Gt-ac5300 Firmware 2024-11-21 N/A
Stack-based buffer overflow on the ASUS GT-AC5300 router through 3.0.0.4.384_32738 allows remote attackers to cause a denial of service (device crash) or possibly have unspecified other impact by setting a long sh_path0 value and then sending an appGet.cgi?hook=select_list("Storage_x_SharedPath") request, because ej_select_list in router/httpd/web.c uses strcpy.
CVE-2018-17021 1 Asus 2 Gt-ac5300, Gt-ac5300 Firmware 2024-11-21 N/A
Cross-site scripting (XSS) vulnerability on ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allows remote attackers to inject arbitrary web script or HTML via the appGet.cgi hook parameter.
CVE-2018-17003 1 Limesurvey 1 Limesurvey 2024-11-21 N/A
In LimeSurvey 3.14.7, HTML Injection and Stored XSS have been discovered in the appendix via the surveyls_title parameter to /index.php?r=admin/survey/sa/insert.
CVE-2018-17002 1 Ricoh 2 Mp 2001sp, Mp 2001sp Firmware 2024-11-21 N/A
On the RICOH MP 2001 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
CVE-2018-17001 1 Ricoh 2 Sp 4510sf, Sp 4510sf Firmware 2024-11-21 N/A
On the RICOH SP 4510SF printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
CVE-2018-16999 1 Nasm 1 Netwide Assembler 2024-11-21 N/A
Netwide Assembler (NASM) 2.14rc15 has an invalid memory write (segmentation fault) in expand_smacro in preproc.c, which allows attackers to cause a denial of service via a crafted input file.
CVE-2018-16986 1 Ti 5 Ble-stack, Cc1350, Cc2640 and 2 more 2024-11-21 N/A
Texas Instruments BLE-STACK v2.2.1 for SimpleLink CC2640 and CC2650 devices allows remote attackers to execute arbitrary code via a malformed packet that triggers a buffer overflow.
CVE-2018-16981 2 Debian, Nothings 2 Debian Linux, Stb Image.h 2024-11-21 8.8 High
stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function.