Search
Total
201818 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2018-13273 | 2019-01-07 | N/A | N/A | ||
| ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none. | |||||
| CVE-2018-13274 | 2019-01-07 | N/A | N/A | ||
| ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none. | |||||
| CVE-2018-13275 | 2019-01-07 | N/A | N/A | ||
| ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none. | |||||
| CVE-2018-13276 | 2019-01-07 | N/A | N/A | ||
| ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none. | |||||
| CVE-2018-13277 | 2019-01-07 | N/A | N/A | ||
| ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none. | |||||
| CVE-2018-20172 | 1 Nagios | 1 Nagios Xi | 2019-01-07 | 4.3 MEDIUM | 6.1 MEDIUM |
| An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not filtered, resulting in an XSS vulnerability. | |||||
| CVE-2018-20171 | 1 Nagios | 1 Nagios Xi | 2019-01-07 | 4.3 MEDIUM | 6.1 MEDIUM |
| An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in an XSS vulnerability. | |||||
| CVE-2018-20027 | 1 Lisa-lab | 1 Pylearn2 | 2019-01-07 | 7.5 HIGH | 9.8 CRITICAL |
| The yaml_parse.load method in Pylearn2 allows code injection. | |||||
| CVE-2018-2505 | 1 Sap | 1 Hybris | 2019-01-07 | 4.3 MEDIUM | 6.1 MEDIUM |
| SAP Commerce does not sufficiently validate user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability in storefronts that are based on the product. Fixed in versions (SAP Hybris Commerce, versions 6.2, 6.3, 6.4, 6.5, 6.6, 6.7). | |||||
| CVE-2018-20188 | 1 Thedaylightstudio | 1 Fuel Cms | 2019-01-07 | 6.8 MEDIUM | 8.8 HIGH |
| FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account. | |||||
| CVE-2018-19992 | 1 Dolibarr | 1 Dolibarr | 2019-01-07 | 3.5 LOW | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to adherents/type.php. | |||||
| CVE-2018-19993 | 1 Dolibarr | 1 Dolibarr | 2019-01-07 | 4.3 MEDIUM | 6.1 MEDIUM |
| A reflected cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the transphrase parameter to public/notice.php. | |||||
| CVE-2018-19995 | 1 Dolibarr | 1 Dolibarr | 2019-01-07 | 3.5 LOW | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to user/card.php. | |||||
| CVE-2018-18921 | 1 Phpservermonitor | 1 Php Server Monitor | 2019-01-07 | 5.8 MEDIUM | 6.5 MEDIUM |
| PHP Server Monitor before 3.3.2 has CSRF, as demonstrated by a Delete action. | |||||
| CVE-2018-19439 | 1 Oracle | 1 Secure Global Desktop | 2019-01-07 | 4.3 MEDIUM | 6.1 MEDIUM |
| XSS exists in the Administration Console in Oracle Secure Global Desktop 4.4 20080807152602 (but was fixed in later versions including 5.4). helpwindow.jsp has reflected XSS via all parameters, as demonstrated by the sgdadmin/faces/com_sun_web_ui/help/helpwindow.jsp windowTitle parameter. | |||||
| CVE-2018-20168 | 1 Google | 1 Gvisor | 2019-01-07 | 4.3 MEDIUM | 5.5 MEDIUM |
| Google gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which allows attackers to cause a denial of service ("physical address not valid" panic) via a crafted application. | |||||
| CVE-2018-1000854 | 1 Esigate | 1 Esigate | 2019-01-07 | 7.5 HIGH | 9.8 CRITICAL |
| esigate.org esigate version 5.2 and earlier contains a CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in ESI directive with user specified XSLT that can result in Remote Code Execution. This attack appear to be exploitable via Use of another weakness in backend application to reflect ESI directives. This vulnerability appears to have been fixed in 5.3. | |||||
| CVE-2018-1000856 | 1 Domainmod | 1 Domainmod | 2019-01-07 | 3.5 LOW | 4.8 MEDIUM |
| DomainMOD version 4.09.03 and above. Also verified in the latest version 4.11.01 contains a Cross Site Scripting (XSS) vulnerability in Segment Name field in the segments page that can result in Arbitrary script can be executed on all users browsers who visit the affected page. This attack appear to be exploitable via Victim must visit the vulnerable page. This vulnerability appears to have been fixed in No fix yet. | |||||
| CVE-2018-20156 | 1 Designmodo | 1 Wp Maintenance Mode | 2019-01-07 | 6.5 MEDIUM | 7.2 HIGH |
| The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated "site administrator" users to execute arbitrary PHP code throughout a multisite network. | |||||
| CVE-2018-19933 | 1 Bolt | 1 Bolt Cms | 2019-01-07 | 4.3 MEDIUM | 6.1 MEDIUM |
| Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry. | |||||
| CVE-2018-20329 | 1 Chamilo | 1 Chamilo Lms | 2019-01-07 | 5.5 MEDIUM | 8.1 HIGH |
| Chamilo LMS version 1.11.8 contains a main/inc/lib/CoursesAndSessionsCatalog.class.php SQL injection, allowing users with access to the sessions catalogue (which may optionally be made public) to extract and/or modify database information. | |||||
| CVE-2018-20227 | 1 Eclipse | 1 Rdf4j | 2019-01-07 | 6.4 MEDIUM | 7.5 HIGH |
| RDF4J 2.4.2 allows Directory Traversal via ../ in an entry in a ZIP archive. | |||||
| CVE-2018-20610 | 1 Txjia | 1 Imcat | 2019-01-07 | 4.0 MEDIUM | 4.9 MEDIUM |
| imcat 4.4 allows directory traversal via the root/run/adm.php efile parameter. | |||||
| CVE-2017-18352 | 1 Google | 1 Rendertron | 2019-01-07 | 4.3 MEDIUM | 6.1 MEDIUM |
| Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs. | |||||
| CVE-2018-20154 | 1 Designmodo | 1 Wp Maintenance Mode | 2019-01-07 | 4.0 MEDIUM | 4.3 MEDIUM |
| The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated users to discover all subscriber e-mail addresses. | |||||
| CVE-2018-1000871 | 1 Digitaldruid | 1 Hoteldruid | 2019-01-07 | 7.5 HIGH | 9.8 CRITICAL |
| HotelDruid HotelDruid 2.3.0 version 2.3.0 and earlier contains a SQL Injection vulnerability in "id_utente_mod" parameter in gestione_utenti.php file that can result in An attacker can dump all the database records of backend webserver. This attack appear to be exploitable via the attack can be done by anyone via specially crafted sql query passed to the "id_utente_mod=1" parameter. | |||||
| CVE-2018-20159 | 1 I-doit | 1 I-doit | 2019-01-07 | 6.5 MEDIUM | 7.2 HIGH |
| i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. It has an upload feature that allows an authenticated user with the administrator role to upload arbitrary files to the main website directory. Exploitation involves uploading a ".php" file within a ".zip" file because a ZIP archive is accepted by /admin/?req=modules&action=add as a plugin, and extracted to the main directory. In order for the ".zip" file to be accepted, it must also contain a package.json file. | |||||
| CVE-2018-20327 | 1 Chamilo | 1 Chamilo Lms | 2019-01-07 | 3.5 LOW | 5.4 MEDIUM |
| Chamilo LMS version 1.11.8 contains XSS in main/template/default/admin/gradebook_list.tpl in the gradebook dependencies tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits. | |||||
| CVE-2018-20328 | 1 Chamilo | 1 Chamilo Lms | 2019-01-07 | 3.5 LOW | 5.4 MEDIUM |
| Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits. | |||||
| CVE-2018-20133 | 1 Ymlref Project | 1 Ymlref | 2019-01-07 | 7.5 HIGH | 9.8 CRITICAL |
| ymlref allows code injection. | |||||
| CVE-2018-20374 | 1 Tinycc | 1 Tinycc | 2019-01-06 | 4.3 MEDIUM | 5.5 MEDIUM |
| An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 8 byte out of bounds write in the use_section1 function in tccasm.c. | |||||
| CVE-2018-20375 | 1 Tinycc | 1 Tinycc | 2019-01-06 | 4.3 MEDIUM | 5.5 MEDIUM |
| An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 8 byte out of bounds write in the sym_pop function in tccgen.c. | |||||
| CVE-2018-20376 | 1 Tinycc | 1 Tinycc | 2019-01-06 | 4.3 MEDIUM | 5.5 MEDIUM |
| An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 8 byte out of bounds write in the asm_parse_directive function in tccasm.c. | |||||
| CVE-2018-20552 | 1 Appneta | 1 Tcpreplay | 2019-01-06 | 6.8 MEDIUM | 7.8 HIGH |
| Tcpreplay before 4.3.1 has a heap-based buffer over-read in packet2tree in tree.c. | |||||
| CVE-2018-20553 | 1 Appneta | 1 Tcpreplay | 2019-01-06 | 6.8 MEDIUM | 7.8 HIGH |
| Tcpreplay before 4.3.1 has a heap-based buffer over-read in get_l2len in common/get.c. | |||||
| CVE-2018-1000813 | 1 Backdropcms | 1 Backdrop Cms | 2019-01-06 | 3.5 LOW | 4.8 MEDIUM |
| Backdrop CMS version 1.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Sanitization of custom class names used on blocks and layouts. that can result in Execution of JavaScript from an unexpected source.. This attack appear to be exploitable via A user must be directed to an affected page while logged in.. This vulnerability appears to have been fixed in 1.11.1 and later. | |||||
| CVE-2018-19828 | 1 Artica | 1 Integria Ims | 2019-01-04 | 4.3 MEDIUM | 6.1 MEDIUM |
| Artica Integria IMS 5.0.83 has XSS via the search_string parameter. | |||||
| CVE-2018-20564 | 1 Douco | 1 Douphp | 2019-01-04 | 3.5 LOW | 4.8 MEDIUM |
| An issue was discovered in DouCo DouPHP 1.5 20181221. admin/product_category.php?rec=update has XSS via the cat_name parameter. | |||||
| CVE-2018-20565 | 1 Douco | 1 Douphp | 2019-01-04 | 3.5 LOW | 4.8 MEDIUM |
| An issue was discovered in DouCo DouPHP 1.5 20181221. admin/nav.php?rec=update has XSS via the nav_name parameter. | |||||
| CVE-2018-20566 | 1 Douco | 1 Douphp | 2019-01-04 | 5.0 MEDIUM | 5.3 MEDIUM |
| An issue was discovered in DouCo DouPHP 1.5 20181221. It allows full path disclosure in "Smarty error: unable to read resource" error messages for a crafted installation page. | |||||
| CVE-2018-20427 | 1 Libming | 1 Libming | 2019-01-04 | 6.8 MEDIUM | 8.8 HIGH |
| libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file, a different vulnerability than CVE-2018-9132. | |||||
| CVE-2018-20429 | 1 Libming | 1 Libming | 2019-01-04 | 6.8 MEDIUM | 8.8 HIGH |
| libming 0.4.8 has a NULL pointer dereference in the getName function of the decompile.c file, a different vulnerability than CVE-2018-7872 and CVE-2018-9165. | |||||
| CVE-2018-20426 | 1 Libming | 1 Libming | 2019-01-04 | 6.8 MEDIUM | 8.8 HIGH |
| libming 0.4.8 has a NULL pointer dereference in the newVar3 function of the decompile.c file, a different vulnerability than CVE-2018-7866. | |||||
| CVE-2018-20425 | 1 Libming | 1 Libming | 2019-01-04 | 6.8 MEDIUM | 8.8 HIGH |
| libming 0.4.8 has a NULL pointer dereference in the pushdup function of the decompile.c file. | |||||
| CVE-2018-20428 | 1 Libming | 1 Libming | 2019-01-04 | 6.8 MEDIUM | 8.8 HIGH |
| libming 0.4.8 has a NULL pointer dereference in the strlenext function of the decompile.c file, a different vulnerability than CVE-2018-7874. | |||||
| CVE-2018-20557 | 1 Douco | 1 Douphp | 2019-01-04 | 3.5 LOW | 4.8 MEDIUM |
| An issue was discovered in DouCo DouPHP 1.5 20181221. admin/page.php?rec=edit has XSS via the page_name parameter. | |||||
| CVE-2018-20558 | 1 Douco | 1 Douphp | 2019-01-04 | 3.5 LOW | 4.8 MEDIUM |
| An issue was discovered in DouCo DouPHP 1.5 20181221. admin/system.php?rec=update has XSS via the site_name parameter. | |||||
| CVE-2018-20559 | 1 Douco | 1 Douphp | 2019-01-04 | 3.5 LOW | 4.8 MEDIUM |
| An issue was discovered in DouCo DouPHP 1.5 20181221. admin/product.php?rec=update has XSS via the name parameter. | |||||
| CVE-2018-20560 | 1 Douco | 1 Douphp | 2019-01-04 | 3.5 LOW | 4.8 MEDIUM |
| An issue was discovered in DouCo DouPHP 1.5 20181221. admin/show.php?rec=update has XSS via the show_name parameter. | |||||
| CVE-2018-20561 | 1 Douco | 1 Douphp | 2019-01-04 | 3.5 LOW | 4.8 MEDIUM |
| An issue was discovered in DouCo DouPHP 1.5 20181221. admin/article.php?rec=update has XSS via the title parameter. | |||||
