• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2018-16638
2019-02-26
N/A
5.4 MEDIUM
Evolution CMS 1.4.x allows XSS via the manager/ search parameter.
CVE-2018-16637
2019-02-26
N/A
5.4 MEDIUM
Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI.
CVE-2018-16636
2019-10-03
N/A
6.5 MEDIUM
Nucleus CMS 3.70 allows HTML Injection via the index.php body parameter.
CVE-2018-16635
2019-02-26
N/A
5.4 MEDIUM
Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php.
CVE-2018-16634
2019-02-26
N/A
8.8 HIGH
Pluck v4.7.7 allows CSRF via admin.php?action=settings.
CVE-2018-16633
2019-02-26
N/A
5.4 MEDIUM
Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title.
CVE-2018-16632
2019-02-26
N/A
4.8 MEDIUM
Mezzanine CMS v4.3.1 allows XSS via the /admin/blog/blogcategory/add/?_to_field=id&_popup=1 title parameter at admin/blog/blogpost/add/.
CVE-2018-16631
2019-02-26
N/A
5.4 MEDIUM
Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter.
CVE-2018-16630
2019-02-26
N/A
4.8 MEDIUM
Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file.
CVE-2018-1663
2019-10-09
N/A
5.9 MEDIUM
IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 144889.
« Previous 1 … 2,335 2,336 2,337 2,338 2,339 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE