• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2018-19152
2019-11-06
N/A
7.5 HIGH
emercoin through 0.7 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service. The attacker sends invalid headers/blocks. The attack requires no stake and can fill the victim's disk and RAM.
CVE-2018-19151
2019-11-06
N/A
7.5 HIGH
qtum through 0.16 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service. The attacker sends invalid headers/blocks. The attack requires no stake and can fill the victim's disk and RAM.
CVE-2018-19150
2019-01-16
N/A
7.8 HIGH
Memory corruption in PDMODELProvidePDModelHFT in pdmodel.dll in pdfforge PDF Architect 6 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because of a "Data from Faulting Address controls Code Flow" issue.
CVE-2018-19149
2019-08-06
N/A
6.5 MEDIUM
Poppler before 0.70.0 has a NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment.
CVE-2018-19148
2019-01-30
N/A
3.7 LOW
Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumerate hostnames. Specifically, when unable to match a Host header with a vhost in its configuration, it serves the X.509 certificate for a randomly selected vhost in its configuration. Repeated requests (with a nonexistent hostname in the Host header) permit full enumeration of all certificates on the server. This generally permits an attacker to easily and accurately discover the existence of and relationships among hostnames that weren't meant to be public, though this information could likely have been discovered via other methods with additional effort.
CVE-2018-19146
2021-07-15
N/A
4.8 MEDIUM
Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTML data with a SCRIPT element.
CVE-2018-19145
2018-12-11
N/A
6.1 MEDIUM
An issue was discovered in S-CMS v1.5. There is an XSS vulnerability in search.php via the keyword parameter.
CVE-2018-19143
Open Ticket Request System, Otrs
Calendar_resource_planning, Cis_in_customer_frontend, Custom_contact_fields, Faq, Iphonehandle, Itsmconfigurationmanagement, Open_ticket_request_system, Otrscisincustomerfrontend, Otrs_help_desk, Otrs_itsm
2019-10-03
N/A
6.5 MEDIUM
Open Ticket Request System (OTRS) 4.0.x before 4.0.33, 5.0.x before 5.0.31, and 6.0.x before 6.0.13 allows an authenticated user to delete files via a modified submission form because upload caching is mishandled.
CVE-2018-19142
Open Ticket Request System, Otrs
Calendar_resource_planning, Cis_in_customer_frontend, Custom_contact_fields, Faq, Iphonehandle, Itsmconfigurationmanagement, Open_ticket_request_system, Otrscisincustomerfrontend, Otrs_help_desk, Otrs_itsm
2018-12-12
N/A
4.8 MEDIUM
Open Ticket Request System (OTRS) 6.0.x before 6.0.13 allows an admin to conduct an XSS attack via a modified URL.
CVE-2018-19141
Open Ticket Request System, Otrs
Calendar_resource_planning, Cis_in_customer_frontend, Custom_contact_fields, Faq, Iphonehandle, Itsmconfigurationmanagement, Open_ticket_request_system, Otrscisincustomerfrontend, Otrs_help_desk, Otrs_itsm
2018-12-12
N/A
4.8 MEDIUM
Open Ticket Request System (OTRS) 4.0.x before 4.0.33 and 5.0.x before 5.0.31 allows an admin to conduct an XSS attack via a modified URL because user and customer preferences are mishandled.
« Previous 1 … 2,142 2,143 2,144 2,145 2,146 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE