Search Results (343567 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-6592 1 Unisys 1 Stealth 2024-11-21 N/A
Unisys Stealth 3.3 Windows endpoints before 3.3.016.1 allow local users to gain access to Stealth-enabled devices by leveraging improper cleanup of memory used for negotiation key storage.
CVE-2018-6591 1 Conversejs 1 Converse.js 2024-11-21 N/A
Converse.js and Inverse.js through 3.3 allow remote attackers to obtain sensitive information because it is too difficult to determine whether safe publication of private data was configured or even intended. For example, users might have an expectation that chatroom bookmarks are private, but the various interacting software components do not necessarily make that happen.
CVE-2018-6590 1 Broadcom 1 Ca Api Developer Portal 2024-11-21 6.1 Medium
CA API Developer Portal 4.x, prior to v4.2.5.3 and v4.2.7.1, has an unspecified reflected cross-site scripting vulnerability.
CVE-2018-6589 1 Ca 1 Spectrum 2024-11-21 7.5 High
CA Spectrum 10.1 prior to 10.01.02.PTF_10.1.239 and 10.2.x prior to 10.2.3 allows remote attackers to cause a denial of service via unspecified vectors.
CVE-2018-6588 1 Ca 1 Api Developer Portal 2024-11-21 6.1 Medium
CA API Developer Portal 3.5 up to and including 3.5 CR5 has a reflected cross-site scripting vulnerability related to the apiExplorer.
CVE-2018-6587 1 Ca 1 Api Developer Portal 2024-11-21 6.1 Medium
CA API Developer Portal 3.5 up to and including 3.5 CR6 has a reflected cross-site scripting vulnerability related to the widgetID variable.
CVE-2018-6586 1 Ca 1 Api Developer Portal 2024-11-21 6.1 Medium
CA API Developer Portal 3.5 up to and including 3.5 CR6 has a stored cross-site scripting vulnerability related to profile picture processing.
CVE-2018-6585 1 Techjoomla 1 Jticketing 2024-11-21 N/A
SQL Injection exists in the JTicketing 2.0.16 component for Joomla! via a view=events action with a filter_creator or filter_events_cat parameter.
CVE-2018-6584 1 Dthdevelopment 1 Dt Register 2024-11-21 N/A
SQL Injection exists in the DT Register 3.2.7 component for Joomla! via a task=edit&id= request.
CVE-2018-6583 1 Quanticalabs 1 Timetable Responsive Schedule 2024-11-21 N/A
SQL Injection exists in the Timetable Responsive Schedule 1.5 component for Joomla! via a view=event&alias= request.
CVE-2018-6582 1 Zh Googlemap Project 1 Zh Googlemap 2024-11-21 N/A
SQL Injection exists in the Zh GoogleMap 8.4.0.0 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request.
CVE-2018-6581 1 Joommasters 1 Jms Music 2024-11-21 N/A
SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username parameter.
CVE-2018-6580 1 Janguo 1 Jimtawl 2024-11-21 N/A
Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true&tmpl=component request.
CVE-2018-6579 1 Jextn 1 Reverse Auction 2024-11-21 N/A
SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request.
CVE-2018-6578 1 Jextn 1 Je Paypervideo 2024-11-21 N/A
SQL Injection exists in the JE PayperVideo 3.0.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request.
CVE-2018-6577 1 Jextn 1 Membership 2024-11-21 N/A
SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request.
CVE-2018-6576 1 Ezcode 1 Event Manager 2024-11-21 N/A
SQL Injection exists in Event Manager 1.0 via the event.php id parameter or the page.php slug parameter.
CVE-2018-6575 1 Jextn 1 Classified 2024-11-21 N/A
SQL Injection exists in the JEXTN Classified 1.0.0 component for Joomla! via a view=boutique&sid= request.
CVE-2018-6574 3 Debian, Golang, Redhat 8 Debian Linux, Go, Devtools and 5 more 2024-11-21 N/A
Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command execution during source code build, by leveraging the gcc or clang plugin feature, because -fplugin= and -plugin= arguments were not blocked.
CVE-2018-6569 1 West-wind 1 Web Connection 2024-11-21 N/A
West Wind Web Server 6.x does not require authentication for /ADMIN.ASP.