• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2018-9186
2019-04-22
N/A
6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF validation failure" page allows attacker to execute unauthorized script code via inject malicious scripts in HTTP referer header.
CVE-2018-9185
2018-08-27
N/A
8.1 HIGH
An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login credentials in a Javascript file sent to client-side when pages bookmarked in web portal use the Single Sign-On feature.
CVE-2018-9183
2018-05-02
N/A
5.4 MEDIUM
The Joom Sky JS Jobs extension before 1.2.1 for Joomla! has XSS.
CVE-2018-9182
2018-07-31
N/A
6.1 MEDIUM
Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section.
CVE-2018-9177
2018-07-12
N/A
6.1 MEDIUM
Twonky Server before 8.5.1 has XSS via a folder name on the Shared Folders screen.
CVE-2018-9175
2018-05-02
N/A
9.8 CRITICAL
DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_main.php because code within the database is accessible to uploads/dede/sys_cache_up.php.
CVE-2018-9174
2018-05-02
N/A
9.8 CRITICAL
sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents of modifytmp.inc are under an attacker's control.
CVE-2018-9173
2018-05-02
N/A
6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inject arbitrary web script or HTML, as demonstrated by the movieName parameter.
CVE-2018-9172
2018-05-10
N/A
5.4 MEDIUM
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.
CVE-2018-9169
2018-05-18
N/A
4.8 MEDIUM
Z-BlogPHP 1.5.1 has XSS via the zb_users/plugin/AppCentre/plugin_edit.php app_id parameter. The component must be accessed directly by an administrator, or through CSRF.
« Previous 1 … 1,407 1,408 1,409 1,410 1,411 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE