• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2018-14964
2018-10-04
N/A
5.4 MEDIUM
An issue was discovered in EMLsoft 5.4.5. XSS exists via the eml/upload/eml/?action=address&do=edit page.
CVE-2018-14963
2018-10-04
N/A
8.8 HIGH
zzcms 8.3 has CSRF via the admin/adminadd.php?action=add URI.
CVE-2018-14962
2018-10-04
N/A
5.4 MEDIUM
zzcms 8.3 has stored XSS related to the content variable in user/manage.php and zt/show.php.
CVE-2018-14961
2018-10-04
N/A
9.8 CRITICAL
dl/dl_sendmail.php in zzcms 8.3 has SQL Injection via the sql parameter.
CVE-2018-14960
2018-10-04
N/A
8.8 HIGH
Xiao5uCompany 1.7 has CSRF via admin/Admin.asp.
CVE-2018-1496
2019-10-09
N/A
5.4 MEDIUM
IBM Content Navigator 2.0.3, 3.0.0, 3.0.1, 3.0.2, and 3.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141219.
CVE-2018-14959
2018-10-04
N/A
8.8 HIGH
An issue was discovered in WeaselCMS v0.3.5. CSRF can create new pages via an index.php?b=pages&a=new URI.
CVE-2018-14958
2018-10-04
N/A
8.8 HIGH
An issue was discovered in WeaselCMS v0.3.5. CSRF can update the website settings (such as the theme, title, and description) via index.php.
CVE-2018-14957
2018-12-19
N/A
9.8 CRITICAL
CMS ISWEB 3.5.3 is vulnerable to directory traversal and local file download, as demonstrated by moduli/downloadFile.php?file=oggetto_documenti/../.././inc/config.php (one can take the control of the application because credentials are present in that config.php file).
CVE-2018-14956
2018-11-21
N/A
9.8 CRITICAL
CMS ISWEB 3.5.3 is vulnerable to multiple SQL injection flaws. An attacker can inject malicious queries into the application and obtain sensitive information.
« Previous 1 … 2,471 2,472 2,473 2,474 2,475 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE