• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2018-20780
2019-02-11
N/A
8.8 HIGH
Traq 3.7.1 allows admin/users/new CSRF to create an admin account (aka group_id=1).
CVE-2018-2078
2019-01-22
N/A
N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.
CVE-2018-20779
2019-02-11
N/A
9.8 CRITICAL
Traq 3.7.1 allows SQL Injection via a tickets?search= URI.
CVE-2018-20778
2019-02-11
N/A
6.1 MEDIUM
admin/?/plugin/file_manager in Frog CMS 0.9.5 allows XSS by creating a new file containing a crafted attribute of an IMG element.
CVE-2018-20777
2019-02-11
N/A
5.4 MEDIUM
Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit/1 Body field.
CVE-2018-20776
2019-02-11
N/A
7.5 HIGH
Frog CMS 0.9.5 provides a directory listing for a /public request.
CVE-2018-20775
2019-02-11
N/A
7.2 HIGH
admin/?/plugin/file_manager in Frog CMS 0.9.5 allows PHP code execution by creating a new .php file containing PHP code, and then visiting this file under the public/ URI.
CVE-2018-20774
2019-02-11
N/A
5.4 MEDIUM
Frog CMS 0.9.5 has XSS via the admin/?/layout/edit/1 Body field.
CVE-2018-20773
2019-02-11
N/A
7.2 HIGH
Frog CMS 0.9.5 allows PHP code execution by visiting admin/?/page/edit/1 and inserting additional
CVE-2018-20772
2019-02-11
N/A
7.2 HIGH
Frog CMS 0.9.5 allows PHP code execution via
« Previous 1 … 2,002 2,003 2,004 2,005 2,006 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE