• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2018-16629
2019-02-26
N/A
4.8 MEDIUM
panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
CVE-2018-16628
2019-02-26
N/A
5.4 MEDIUM
panel/login in Kirby v2.5.12 allows XSS via a blog name.
CVE-2018-16627
2019-02-26
N/A
6.1 MEDIUM
panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.
CVE-2018-16626
2019-05-13
N/A
4.8 MEDIUM
index.php/Admin/Classes in Typesetter 5.1 allows XSS via the description of a new class name.
CVE-2018-16625
2019-05-13
N/A
4.8 MEDIUM
index.php/Admin/Uploaded in Typesetter 5.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
CVE-2018-16624
2019-05-13
N/A
5.4 MEDIUM
panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page.
CVE-2018-16623
2019-05-13
N/A
4.8 MEDIUM
Kirby V2.5.12 is prone to a Persistent XSS attack via the Title of the "Site options" in the admin panel dashboard dropdown.
CVE-2018-16622
2018-11-02
N/A
5.4 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in /api/content/addOne in DoraCMS v2.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) discription or (2) comments field, related to users/userAddContent.
CVE-2018-16621
2021-03-04
N/A
7.2 HIGH
Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection.
CVE-2018-16620
2020-08-24
N/A
7.5 HIGH
Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control.
« Previous 1 … 2,336 2,337 2,338 2,339 2,340 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE