Total
37627 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2018-19350 | 1 Seacms | 1 Seacms | 2024-11-21 | N/A |
In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element. | ||||
CVE-2018-19340 | 1 Guriddo | 1 Form Php | 2024-11-21 | N/A |
Guriddo Form PHP 5.3 has XSS via the demos/jqform/defaultnodb/default.php OrderID, ShipName, ShipAddress, ShipCity, ShipPostalCode, ShipCountry, Freight, or details parameter. | ||||
CVE-2018-19324 | 1 Kimsq | 1 Rb | 2024-11-21 | N/A |
kimsQ Rb 2.3.0 allows XSS via the second input field to the /?r=home&mod=mypage&page=info URI. | ||||
CVE-2018-19311 | 1 Centreon | 1 Centreon | 2024-11-21 | N/A |
Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated by the "Monitoring > Status Details > Services" screen. | ||||
CVE-2018-19301 | 1 Tp4a | 1 Teleport | 2024-11-21 | N/A |
tp4a TELEPORT 3.1.0 allows XSS via the login page because a crafted username is mishandled when an administrator later views the system log. | ||||
CVE-2018-19289 | 1 Valine.js | 1 Valine | 2024-11-21 | 6.1 Medium |
An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file. | ||||
CVE-2018-19288 | 1 Zohocorp | 1 Manageengine Opmanager | 2024-11-21 | N/A |
Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API. | ||||
CVE-2018-19287 | 1 Ninjaforma | 1 Ninja Forms | 2024-11-21 | N/A |
XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter. | ||||
CVE-2018-19286 | 1 Mubu | 1 Curtain | 2024-11-21 | 6.1 Medium |
The server in mubu note 2018-11-11 has XSS by configuring an account with a crafted name value (along with an arbitrary username value), and then creating and sharing a note. | ||||
CVE-2018-19280 | 1 Centreon | 1 Centreon | 2024-11-21 | N/A |
Centreon 3.4.x (fixed in Centreon 18.10.0) has XSS via the resource name or macro expression of a poller macro. | ||||
CVE-2018-19229 | 1 Laobancms | 1 Laobancms | 2024-11-21 | N/A |
An issue was discovered in LAOBANCMS 2.0. It allows XSS via the admin/art.php?typeid=1 biaoti parameter. | ||||
CVE-2018-19227 | 1 Laobancms | 1 Laobancms | 2024-11-21 | N/A |
An issue was discovered in LAOBANCMS 2.0. It allows XSS via the admin/liuyan.php neirong[] parameter. | ||||
CVE-2018-19223 | 1 Laobancms | 1 Laobancms | 2024-11-21 | N/A |
An issue was discovered in LAOBANCMS 2.0. It allows XSS via the first input field to the admin/type.php?id=1 URI. | ||||
CVE-2018-19222 | 1 Laobancms | 1 Laobancms | 2024-11-21 | N/A |
An issue was discovered in LAOBANCMS 2.0. It allows a /install/mysql_hy.php?riqi=0&i=0 attack to reset the admin password, even if install.txt exists. | ||||
CVE-2018-19206 | 2 Debian, Roundcube | 2 Debian Linux, Webmail | 2024-11-21 | N/A |
steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment. | ||||
CVE-2018-19202 | 1 Mybb | 1 Mybb | 2024-11-21 | N/A |
A reflected XSS vulnerability in index.php in MyBB 1.8.x through 1.8.19 allows remote attackers to inject JavaScript via the 'upsetting[bburl]' parameter. | ||||
CVE-2018-19201 | 1 Mybb | 1 Mybb | 2024-11-21 | N/A |
A reflected XSS vulnerability in the ModCP Profile Editor in MyBB before 1.8.20 allows remote attackers to inject JavaScript via the 'username' parameter. | ||||
CVE-2018-19195 | 1 Xiaocms | 1 Xiaocms | 2024-11-21 | N/A |
An issue was discovered in XiaoCms 20141229. There is XSS related to the template\default\show_product.html file. | ||||
CVE-2018-19193 | 1 Xiaocms | 1 Xiaocms | 2024-11-21 | N/A |
An issue was discovered in XiaoCms 20141229. There is XSS via the largest input box on the "New news" screen. | ||||
CVE-2018-19191 | 1 Webmin | 1 Webmin | 2024-11-21 | N/A |
Webmin 1.890 has XSS via /config.cgi?webmin, the /shell/index.cgi history parameter, /shell/index.cgi?stripped=1, or the /webminlog/search.cgi uall or mall parameter. |