Vulnerabilities (CVE)

Total 316966 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-19907 1 Craftercms 1 Crafter Cms 2024-11-21 6.5 MEDIUM 8.8 HIGH
A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may execute OS commands by Creating/Editing a template file (.ftl filetype) that triggers a call to freemarker.template.utility.Execute in the FreeMarker library during rendering of a web page.
CVE-2018-19903 1 Xsltcms.org Project 1 Xsltcms.org 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Persistent XSS exists in XSLT CMS via the create/?action=items.edit&type=Page title field.
CVE-2018-19902 1 No-cms Project 1 No-cms 2024-11-21 3.5 LOW 4.8 MEDIUM
No-CMS 1.1.3 is prone to Persistent XSS via the blog/manage_article "keyword" parameter.
CVE-2018-19901 1 No-cms Project 1 No-cms 2024-11-21 3.5 LOW 4.8 MEDIUM
No-CMS 1.1.3 is prone to Persistent XSS via the blog/manage_article/index/ "article_title" parameter.
CVE-2018-19898 1 Thinkcmf 1 Thinkcmf 2024-11-21 6.5 MEDIUM 8.8 HIGH
ThinkCMF X2.2.2 has SQL Injection via the method edit_post in ArticleController.class.php and is exploitable by normal authenticated users via the post[id][1] parameter in an article edit_post action.
CVE-2018-19897 1 Thinkcmf 1 Thinkcmf 2024-11-21 6.5 MEDIUM 7.2 HIGH
ThinkCMF X2.2.2 has SQL Injection via the function _listorders() in AdminbaseController.class.php and is exploitable with the manager privilege via the listorders[key][1] parameter in a Link listorders action.
CVE-2018-19896 1 Thinkcmf 1 Thinkcmf 2024-11-21 6.5 MEDIUM 7.2 HIGH
ThinkCMF X2.2.2 has SQL Injection via the function delete() in SlideController.class.php and is exploitable with the manager privilege via the ids[] parameter in a slide action.
CVE-2018-19895 1 Thinkcmf 1 Thinkcmf 2024-11-21 6.5 MEDIUM 7.2 HIGH
ThinkCMF X2.2.2 has SQL Injection via the function edit_post() in NavController.class.php and is exploitable with the manager privilege via the parentid parameter in a nav action.
CVE-2018-19894 1 Thinkcmf 1 Thinkcmf 2024-11-21 6.5 MEDIUM 7.2 HIGH
ThinkCMF X2.2.2 has SQL Injection via the functions check() and delete() in CommentadminController.class.php and is exploitable with the manager privilege via the ids[] parameter in a commentadmin action.
CVE-2018-19893 1 Pbootcms 1 Pbootcms 2024-11-21 7.5 HIGH 9.8 CRITICAL
SearchController.php in PbootCMS 1.2.1 has SQL injection via the index.php/Search/index.html query string.
CVE-2018-19892 1 Domainmod 1 Domainmod 2024-11-21 3.5 LOW 4.8 MEDIUM
DomainMOD through 4.11.01 has XSS via the admin/dw/add-server.php DisplayName, HostName, or UserName field.
CVE-2018-19891 1 Audiocoding 1 Freeware Advanced Audio Coder 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Audio Coder (FAAC) 1.29.9.2. The vulnerability causes a segmentation fault and application crash, which leads to denial of service in the book 10 case.
CVE-2018-19890 1 Audiocoding 1 Freeware Advanced Audio Coder 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Audio Coder (FAAC) 1.29.9.2. The vulnerability causes a segmentation fault and application crash, which leads to denial of service in the book 2 case.
CVE-2018-19889 1 Audiocoding 1 Freeware Advanced Audio Coder 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Audio Coder (FAAC) 1.29.9.2. The vulnerability causes a segmentation fault and application crash, which leads to denial of service in the book 6 case.
CVE-2018-19888 1 Audiocoding 1 Freeware Advanced Audio Coder 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Audio Coder (FAAC) 1.29.9.2. The vulnerability causes a segmentation fault and application crash, which leads to denial of service in the HCB_ESC case.
CVE-2018-19887 1 Audiocoding 1 Freeware Advanced Audio Coder 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Audio Coder (FAAC) 1.29.9.2. The vulnerability causes a segmentation fault and application crash, which leads to denial of service in the book 4 case.
CVE-2018-19886 1 Audiocoding 1 Freeware Advanced Audio Coder 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Audio Coder (FAAC) 1.29.9.2. The vulnerability causes a segmentation fault and application crash, which leads to denial of service in the book 8 case.
CVE-2018-19882 1 Artifex 1 Mupdf 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
In Artifex MuPDF 1.14.0, the svg_run_image function in svg/svg-run.c allows remote attackers to cause a denial of service (href_att NULL pointer dereference and application crash) via a crafted svg file, as demonstrated by mupdf-gl.
CVE-2018-19881 1 Artifex 1 Mupdf 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by a fitz/xml.c fz_xml_att crash from excessive stack consumption) via a crafted svg file, as demonstrated by mupdf-gl.
CVE-2018-19879 1 Teltonika 2 Rut950, Rut950 Firmware 2024-11-21 5.0 MEDIUM 7.1 HIGH
An issue was discovered in /cgi-bin/luci on Teltonika RTU9XX (e.g., RUT950) R_31.04.89 before R_00.05.00.5 devices. The authentication functionality is not protected from automated tools used to make login attempts to the application. An anonymous attacker has the ability to make unlimited login attempts with an automated tool. This ability could lead to cracking a targeted user's password.