Search Results (43097 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-17583 1 Wpfastestcache 1 Wp Fastest Cache 2024-11-21 N/A
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_exclude_pages action.
CVE-2018-17574 1 Ymfe 1 Yapi 2024-11-21 N/A
An issue was discovered in YMFE YApi 1.3.23. There is stored XSS in the name field of a project.
CVE-2018-17572 1 Influxdata 1 Influxdb 2024-11-21 4.8 Medium
InfluxDB 0.9.5 has Reflected XSS in the Write Data module.
CVE-2018-17571 1 Vanillaforums 1 Vanilla 2024-11-21 N/A
Vanilla before 2.6.1 allows XSS via the email field of a profile.
CVE-2018-17560 1 Teamwire 1 Teamwire 2024-11-21 N/A
The admin interface of the Grouptime Teamwire Client 1.5.1 prior to 1.9.0 on-premises messenger server allows stored XSS. All backend versions prior to prod-2018-11-13-15-00-42 are affected.
CVE-2018-17558 1 Abus 94 Tvip 10000, Tvip 10000 Firmware, Tvip 10001 and 91 more 2024-11-21 9.8 Critical
Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18, TVIP10051 LM.1.6.18, TVIP11050 MG.1.6.03.05, TVIP20550 LM.1.6.18, TVIP10050 LM.1.6.18, TVIP11550 MG.1.6.03, TVIP21050 MG.1.6.03, and TVIP51550 MG.1.6.03 cameras allow remote attackers to execute code as root.
CVE-2018-17556 1 Modx 1 Modx Revolution 2024-11-21 N/A
MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action.
CVE-2018-17533 1 Teltonika 6 Rut900, Rut900 Firmware, Rut950 and 3 more 2024-11-21 N/A
Teltonika RUT9XX routers with firmware before 00.05.01.1 are prone to cross-site scripting vulnerabilities in hotspotlogin.cgi due to insufficient user input sanitization.
CVE-2018-17492 1 Hidglobal 1 Easylobby Solo 2024-11-21 N/A
EasyLobby Solo contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.
CVE-2018-17443 1 Dlink 1 Central Wifimanager 2024-11-21 N/A
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateSite endpoint is vulnerable to stored XSS.
CVE-2018-17441 1 Dlink 1 Central Wifimanager 2024-11-21 N/A
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser endpoint is vulnerable to stored XSS.
CVE-2018-17423 1 E107 1 E107 2024-11-21 N/A
An issue was discovered in e107 v2.1.9. There is a XSS attack on e107_admin/comment.php.
CVE-2018-17421 1 Zrlog 1 Zrlog 2024-11-21 N/A
An issue was discovered in ZrLog 2.0.3. There is stored XSS in the file upload area via a crafted attached/file/ pathname.
CVE-2018-17413 1 Zzcms 1 Zzcms 2024-11-21 N/A
XSS exists in zzcms v8.3 via the /uploadimg_form.php noshuiyin parameter.
CVE-2018-17369 1 Springboot Authority Project 1 Springboot Authority 2024-11-21 N/A
An issue was discovered in springboot_authority through 2017-03-06. There is stored XSS via the admin/role/edit roleKey, name, or description parameter.
CVE-2018-17361 1 Weaselcms Project 1 Weaselcms 2024-11-21 N/A
Multiple XSS vulnerabilities in WeaselCMS v0.3.6 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php because $_SERVER['PHP_SELF'] is mishandled.
CVE-2018-17337 1 Intelbras 2 Nplug, Nplug Firmware 2024-11-21 N/A
Intelbras NPLUG 1.0.0.14 devices have XSS via a crafted SSID that is received via a network broadcast.
CVE-2018-17322 1 Yunucms 1 Yunucms 2024-11-21 N/A
Cross-site scripting (XSS) vulnerability in index.php/index/category/index in YUNUCMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the area parameter.
CVE-2018-17321 1 Seacms 1 Seacms 2024-11-21 N/A
An issue was discovered in SeaCMS 6.64. XSS exists in admin_datarelate.php via the time or maxHit parameter in a dorandomset action.
CVE-2018-17320 1 Ucms Project 1 Ucms 2024-11-21 N/A
An issue was discovered in UCMS 1.4.6. aaddpost.php has stored XSS via the sadmin/aindex.php minfo parameter in a sadmin_aaddpost action.