• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2018-20600
2019-01-04
N/A
6.1 MEDIUM
sadmincedit.php in UCMS 1.4.7 has XSS via an index.php sadmin_cedit action.
CVE-2018-2060
2019-01-22
N/A
N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.
CVE-2018-20599
2019-01-04
N/A
8.8 HIGH
UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action.
CVE-2018-20598
2019-01-04
N/A
8.8 HIGH
UCMS 1.4.7 has ?do=user_addpost CSRF.
CVE-2018-20597
2019-01-04
N/A
4.8 MEDIUM
UCMS 1.4.7 has XSS via the dir parameter in an index.php sadmin_fileedit action.
CVE-2018-20596
2019-01-28
N/A
9.8 CRITICAL
Jspxcms v9.0.0 allows SSRF.
CVE-2018-20595
2019-01-14
N/A
8.8 HIGH
A CSRF issue was discovered in web/authorization/oauth2/controller/OAuth2ClientController.java in hsweb 3.0.4 because the state parameter in the request is not compared with the state parameter in the session after user authentication is successful.
CVE-2018-20594
2019-01-15
N/A
6.1 MEDIUM
An issue was discovered in hsweb 3.0.4. It is a reflected XSS vulnerability due to the absence of type parameter checking in FlowableModelManagerController.java.
CVE-2018-20593
2020-08-24
N/A
5.5 MEDIUM
In Mini-XML (aka mxml) v2.12, there is stack-based buffer overflow in the scan_file function in mxmldoc.c.
CVE-2018-20592
2019-04-03
N/A
5.5 MEDIUM
In Mini-XML (aka mxml) v2.12, there is a use-after-free in the mxmlAdd function of the mxml-node.c file. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted xml file, as demonstrated by mxmldoc.
« Previous 1 … 2,017 2,018 2,019 2,020 2,021 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE