• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2018-16737
2022-10-25
N/A
5.3 MEDIUM
tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation.
CVE-2018-16736
2018-11-06
N/A
5.4 MEDIUM
In the rcfilters plugin 2.1.6 for Roundcube, XSS exists via the _whatfilter and _messages parameters (in the Filters section of the settings).
CVE-2018-16733
2018-11-07
N/A
7.5 HIGH
In Go Ethereum (aka geth) before 1.8.14, TraceChain in eth/api_tracer.go does not verify that the end block is after the start block.
CVE-2018-16732
2018-10-19
N/A
8.8 HIGH
uploadpluginssysadminSetting.php in CScms 4.1 allows CSRF via admin.php/setting/ftp_save.
CVE-2018-16731
2018-10-30
N/A
9.8 CRITICAL
CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .php pathname within fileurl JSON data.
CVE-2018-16730
2018-10-19
N/A
6.1 MEDIUM
uploadpluginssysInstall.php in CScms 4.1 has XSS via the site name.
CVE-2018-1673
2019-10-09
N/A
6.1 MEDIUM
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145108.
CVE-2018-16729
2018-11-09
N/A
5.4 MEDIUM
Pluck 4.7.7 allows XSS via an SVG file that contains Javascript in a SCRIPT element, and is uploaded via pages->manage under admin.php?action=files.
CVE-2018-16728
2018-11-02
N/A
5.4 MEDIUM
feindura 2.0.7 allows XSS via the tags field of a new page created at index.php?category=0&page=new.
CVE-2018-16727
2018-11-02
N/A
5.4 MEDIUM
razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component.
« Previous 1 … 2,328 2,329 2,330 2,331 2,332 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE