• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2018-14392
2018-09-13
N/A
6.1 MEDIUM
The New Threads plugin before 1.2 for MyBB has XSS.
CVE-2018-1439
2019-10-09
N/A
5.4 MEDIUM
IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139589.
CVE-2018-14389
2018-09-12
N/A
9.8 CRITICAL
joyplus-cms 1.6.0 has SQL Injection via the manager/admin_ajax.php val parameter.
CVE-2018-14388
2018-09-12
N/A
5.4 MEDIUM
joyplus-cms 1.6.0 has XSS via the manager/admin_ajax.php can_search_device array parameter.
CVE-2018-14387
2018-09-19
N/A
8.8 HIGH
An issue was discovered in WonderCMS before 2.5.2. An attacker can create a new session on a web application and record the associated session identifier. The attacker then causes the victim to authenticate against the server using the same session identifier. The attacker can access the user's account through the active session. The Session Fixation attack fixes a session on the victim's browser, so the attack starts before the user logs in.
CVE-2018-14384
2020-03-04
N/A
4.8 MEDIUM
The Website Manager module in SEO Panel 3.13.0 and earlier is affected by a stored Cross-Site Scripting (XSS) vulnerability, allowing remote authenticated attackers to inject arbitrary web script or HTML via the websites.php name parameter.
CVE-2018-14383
2019-08-14
N/A
7.5 HIGH
The Transition Technologies "The Scheduler" app 5.1.3 for Jira allows XXE due to a weakly configured/parameterized XML parser. It was fixed in the versions 5.2.1 and 3.3.7
CVE-2018-14382
2018-09-12
N/A
6.1 MEDIUM
InstantCMS 2.10.1 has /redirect?url= XSS.
CVE-2018-14381
2018-09-14
N/A
6.1 MEDIUM
Pagekit before 1.0.14 has a /user/login?redirect= open redirect vulnerability.
CVE-2018-14380
2018-09-14
N/A
6.1 MEDIUM
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.
« Previous 1 … 2,521 2,522 2,523 2,524 2,525 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE