Common Vulnerabilities and Exposures (CVE) is a critical tool for maintaining software security, providing a standardized way to track and manage vulnerabilities across systems. Organizations should regularly monitor CVE databases, assess the impact of vulnerabilities, and apply patches promptly to reduce the risk of exploitation.
CVE (Common Vulnerabilities and Exposures) is a public database that provides a standardized method for identifying, tracking, and referencing publicly disclosed security vulnerabilities in software and hardware.
Each vulnerability receives a unique identifier called a CVE ID (e.g., CVE-2023-12345), making it easier to reference specific vulnerabilities across different tools and databases.
Total Search Results: 158437
CVE ID | Description | Severity | Published Date | Affected Vendor | Action |
---|---|---|---|---|---|
CVE-2018-20803 | A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which loop indefinitely in mathematics processing while retaining locks. This issue affects MongoDB Server v4.0 versions prior to 4.0.5; MongoDB Server v3.6 versions prior to 3.6.10 and MongoDB Server v3.4 versions prior to 3.4.19. | Unknown | N/A | MongoDB Inc. | |
CVE-2018-20804 | A user authorized to perform database queries may trigger denial of service by issuing specially crafted applyOps invocations. This issue affects MongoDB Server v4.0 versions prior to 4.0.10 and MongoDB Server v3.6 versions prior to 3.6.13. | Unknown | N/A | MongoDB Inc. | |
CVE-2018-20805 | A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which perform an $elemMatch . This issue affects MongoDB Server v4.0 versions prior to 4.0.5 and MongoDB Server v3.6 versions prior to 3.6.10. | Unknown | N/A | MongoDB Inc. | |
CVE-2018-20806 | Phamm (aka PHP LDAP Virtual Hosting Manager) 0.6.8 allows XSS via the login page (the /public/main.php action parameter). | Unknown | N/A | n/a | |
CVE-2018-20807 | An XSS issue has been found in welcome.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1.x before 8.1R12, 8.2.x before 8.2R9, and 8.3.x before 8.3R3 due to one of the URL parameters not being sanitized properly. | Unknown | N/A | n/a | |
CVE-2018-20808 | An XSS issue has been found with rd.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R3 due to improper header sanitization. This is not applicable to 8.1RX. | Unknown | 2019-03-16 | n/a | |
CVE-2018-20809 | A crafted message can cause the web server to crash with Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R5 and Pulse Policy Secure 5.4RX before 5.4R5. This is not applicable to PCS 8.1RX. | Unknown | 2019-03-16 | n/a | |
CVE-2018-20810 | Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX, PPS 5.2RX, or stand-alone devices. | Unknown | 2019-03-16 | n/a | |
CVE-2018-20811 | A hidden RPC service issue was found with Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2 and 8.1RX before 8.1R12. | Unknown | 2019-03-16 | n/a | |
CVE-2018-20812 | An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse Secure Pulse Secure Desktop 9.0R1 and below. This is applicable only to dual-stack (IPv4/IPv6) endpoints. | Unknown | 2019-03-16 | n/a | |
CVE-2018-20813 | An input validation issue has been found with login_meeting.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2. | Unknown | 2019-03-16 | n/a | |
CVE-2018-20814 | An XSS issue was found with Psaldownload.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.3R2 before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX or PPS 5.2RX. | Unknown | N/A | n/a | |
CVE-2018-20815 | In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image function, which has a buffer overflow risk. | Unknown | N/A | n/a | |
CVE-2018-20816 | An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" feature where users can receive a malicious attack through a phished URL, with script executed. | Unknown | N/A | n/a | |
CVE-2018-20817 | SV_SteamAuthClient in various Activision Infinity Ward Call of Duty games before 2015-08-11 is missing a size check when reading authBlob data into a buffer, which allows one to execute code on the remote target machine when sending a steam authentication request. This affects Call of Duty: Modern Warfare 2, Call of Duty: Modern Warfare 3, Call of Duty: Ghosts, Call of Duty: Advanced Warfare, Call of Duty: Black Ops 1, and Call of Duty: Black Ops 2. | Unknown | N/A | n/a | |
CVE-2018-20818 | A buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions. It occurs in the modbus.cpp mapUnusedIO() function, which can cause a runtime crash of the PLC or possibly have unspecified other impact. | Unknown | N/A | n/a | |
CVE-2018-20819 | io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact by crafting a jpg image file. The root cause is a missing check of header payloads that may be (incorrectly) larger than the maximum file size. | Unknown | N/A | n/a | |
CVE-2018-20820 | read_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime crash because of an integer overflow) via a crafted file. | Unknown | N/A | n/a | |
CVE-2018-20821 | The parsing component in LibSass through 3.5.5 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass::Parser::parse_css_variable_value in parser.cpp). | Unknown | N/A | n/a | |
CVE-2018-20822 | LibSass 3.5.4 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass::Complex_Selector::perform in ast.hpp and Sass::Inspect::operator in inspect.cpp). | Unknown | N/A | n/a | |
CVE-2018-20823 | The gyroscope on Xiaomi Mi 5s devices allows attackers to cause a denial of service (resonance and false data) via a 20.4 kHz audio signal, aka a MEMS ultrasound attack. | Unknown | N/A | n/a | |
CVE-2018-20824 | The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cyclePeriod parameter. | Unknown | N/A | Atlassian | |
CVE-2018-20826 | The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter in issues via a missing authorisation check. | Unknown | N/A | Atlassian | |
CVE-2018-20827 | The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the country parameter. | Unknown | N/A | Atlassian | |
CVE-2018-20834 | A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2). | Unknown | N/A | n/a | |
CVE-2018-20835 | A vulnerability was found in tar-fs before 1.16.2. An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. | Unknown | N/A | n/a | |
CVE-2018-20836 | An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free. | Unknown | N/A | n/a | |
CVE-2018-20837 | include/admin/Menu/Ajax.php in Typesetter 5.1 has index.php/Admin/Menu/Ajax?cmd=AddHidden title XSS. | Unknown | N/A | n/a | |
CVE-2018-20838 | ampforwp_save_steps_data in the AMP for WP plugin before 0.9.97.21 for WordPress allows stored XSS. | Unknown | N/A | n/a | |
CVE-2018-20839 | systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstances, such as watching a shutdown, or using Ctrl-Alt-F1 and Ctrl-Alt-F2. This occurs because the KDGKBMODE (aka current keyboard mode) check is mishandled. | Unknown | N/A | n/a | |
CVE-2018-20840 | An unhandled exception vulnerability exists during Google Sign-In with Google API C++ Client before 2019-04-10. It potentially causes an outage of third-party services that were not designed to recover from exceptions. On the client, ID token handling can cause an unhandled exception because of misinterpretation of an integer as a string, resulting in denial-of-service and then other users can no longer login/sign-in to the affected third-party service. Once this third-party service uses Google Sign-In with google-api-cpp-client, a malicious user can trigger this client/auth/oauth2_authorization.cc vulnerability by requesting the client to receive the ID token from a Google authentication server. | Unknown | N/A | n/a | |
CVE-2018-20841 | HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell metacharacters in the mac parameter of a protocol.csp?function=set&fname=security&opt=mac_table request. | Unknown | N/A | n/a | |
CVE-2018-20843 | In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks). | Unknown | N/A | n/a | |
CVE-2018-20845 | Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash). | Unknown | N/A | n/a | |
CVE-2018-20846 | Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash). | Unknown | N/A | n/a | |
CVE-2018-20847 | An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can lead to an integer overflow. | Unknown | N/A | n/a | |
CVE-2018-20848 | Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in the couleurId[0] parameter to the latter. | Unknown | N/A | n/a | |
CVE-2018-20849 | Arastta eCommerce 1.6.2 is vulnerable to XSS via the PATH_INFO to the login/ URI. | Unknown | N/A | n/a | |
CVE-2018-20850 | Stormshield Network Security 2.0.0 through 2.13.0 and 3.0.0 through 3.7.1 has self-XSS in the command line interface of the SNS web server. | Unknown | N/A | n/a | |
CVE-2018-20851 | Helpy before 2.2.0 allows agents to edit admins. | Unknown | N/A | n/a | |
CVE-2018-20852 | http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may abuse this flaw by using a server with a hostname that has another valid hostname as a suffix (e.g., pythonicexample.com to steal cookies for example.com). When a program uses http.cookiejar.DefaultPolicy and tries to do an HTTP connection to an attacker-controlled server, existing cookies can be leaked to the attacker. This affects 2.x through 2.7.16, 3.x before 3.4.10, 3.5.x before 3.5.7, 3.6.x before 3.6.9, and 3.7.x before 3.7.3. | Unknown | N/A | n/a | |
CVE-2018-20853 | An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress. The plugin is vulnerable to SPAM attacks. | Unknown | N/A | n/a | |
CVE-2018-20854 | An issue was discovered in the Linux kernel before 4.20. drivers/phy/mscc/phy-ocelot-serdes.c has an off-by-one error with a resultant ctrl->phys out-of-bounds read. | Unknown | N/A | n/a | |
CVE-2018-20855 | An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace. | Unknown | N/A | n/a | |
CVE-2018-20856 | An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c, there is an __blk_drain_queue() use-after-free because a certain error case is mishandled. | Unknown | N/A | n/a | |
CVE-2018-20857 | Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with user@example.com followed by . and then the attacker's domain name. | Unknown | N/A | n/a | |
CVE-2018-20858 | Recommender before 2018-07-18 allows XSS. | Unknown | N/A | n/a | |
CVE-2018-20859 | edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem. | Unknown | N/A | n/a | |
CVE-2018-20860 | libopenmpt before 0.3.13 allows a crash with malformed MED files. | Unknown | N/A | n/a | |
CVE-2018-20861 | libopenmpt before 0.3.11 allows a crash with certain malformed custom tunings in MPTM files. | Unknown | N/A | n/a | |
CVE-2018-20862 | cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366). | Unknown | N/A | n/a | |
CVE-2018-20863 | cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452). | Unknown | N/A | n/a | |
CVE-2018-20864 | cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454). | Unknown | N/A | n/a | |
CVE-2018-20865 | cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459). | Unknown | N/A | n/a | |
CVE-2018-20866 | cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461). | Unknown | N/A | n/a | |
CVE-2018-20867 | cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462). | Unknown | N/A | n/a | |
CVE-2018-20868 | cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464). | Unknown | N/A | n/a | |
CVE-2018-20869 | cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465). | Unknown | N/A | n/a | |
CVE-2018-20870 | The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467). | Unknown | N/A | n/a | |
CVE-2018-20871 | In Univa Grid Engine before 8.6.3, when configured for Docker jobs and execd spooling on root_squash, weak file permissions ("other" write access) occur in certain cases (GE-6890). | Unknown | N/A | n/a | |
CVE-2018-20872 | DrayTek routers before 2018-05-23 allow CSRF attacks to change DNS or DHCP settings, a related issue to CVE-2017-11649. | Unknown | N/A | n/a | |
CVE-2018-20873 | cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409). | Unknown | N/A | n/a | |
CVE-2018-20874 | cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428). | Unknown | N/A | n/a | |
CVE-2018-20875 | cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433). | Unknown | N/A | n/a | |
CVE-2018-20876 | cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434). | Unknown | N/A | n/a | |
CVE-2018-20877 | cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437). | Unknown | N/A | n/a | |
CVE-2018-20878 | cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441). | Unknown | N/A | n/a | |
CVE-2018-20879 | cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444). | Unknown | N/A | n/a | |
CVE-2018-20880 | cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445). | Unknown | N/A | n/a | |
CVE-2018-20881 | cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446). | Unknown | N/A | n/a | |
CVE-2018-20882 | cPanel before 74.0.8 allows arbitrary file-write operations in the context of the root account during WHM Force Password Change (SEC-447). | Unknown | N/A | n/a | |
CVE-2018-20883 | cPanel before 74.0.8 allows FTP access during account suspension (SEC-449). | Unknown | N/A | n/a | |
CVE-2018-20884 | cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367). | Unknown | N/A | n/a | |
CVE-2018-20885 | cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416). | Unknown | N/A | n/a | |
CVE-2018-20886 | cPanel before 74.0.0 insecurely stores phpMyAdmin session files (SEC-418). | Unknown | N/A | n/a | |
CVE-2018-20887 | cPanel before 74.0.0 allows SQL injection during database backups (SEC-420). | Unknown | N/A | n/a | |
CVE-2018-20888 | cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424). | Unknown | N/A | n/a | |
CVE-2018-20889 | cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425). | Unknown | N/A | n/a | |
CVE-2018-20890 | cPanel before 74.0.0 allows arbitrary zone file modifications during record edits (SEC-426). | Unknown | N/A | n/a | |
CVE-2018-20891 | cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436). | Unknown | N/A | n/a | |
CVE-2018-20892 | cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439). | Unknown | N/A | n/a | |
CVE-2018-20893 | cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442). | Unknown | N/A | n/a | |
CVE-2018-20894 | cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443). | Unknown | N/A | n/a | |
CVE-2018-20895 | In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393). | Unknown | N/A | n/a | |
CVE-2018-20896 | cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394). | Unknown | N/A | n/a | |
CVE-2018-20897 | cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395). | Unknown | N/A | n/a | |
CVE-2018-20898 | cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396). | Unknown | N/A | n/a | |
CVE-2018-20899 | cPanel before 71.9980.37 allows stored XSS in the WHM cPAddons installation interface (SEC-398). | Unknown | N/A | n/a | |
CVE-2018-20900 | cPanel before 71.9980.37 allows stored XSS in the YUM autorepair functionality (SEC-399). | Unknown | N/A | n/a | |
CVE-2018-20901 | cPanel before 71.9980.37 allows Remote-Stored XSS in WHM Save Theme Interface (SEC-400). | Unknown | N/A | n/a | |
CVE-2018-20902 | cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408). | Unknown | N/A | n/a | |
CVE-2018-20903 | cPanel before 71.9980.37 allows self XSS in the WHM Backup Configuration interface (SEC-421). | Unknown | N/A | n/a | |
CVE-2018-20904 | cPanel before 71.9980.37 allows attackers to make API calls that bypass the cron feature restriction (SEC-427). | Unknown | N/A | n/a | |
CVE-2018-20905 | cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429). | Unknown | N/A | n/a | |
CVE-2018-20906 | cPanel before 71.9980.37 allows attackers to make API calls that bypass the images feature restriction (SEC-430). | Unknown | N/A | n/a | |
CVE-2018-20907 | cPanel before 71.9980.37 does not enforce the Mime::list_hotlinks API feature restriction (SEC-432). | Unknown | N/A | n/a | |
CVE-2018-20908 | cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435). | Unknown | N/A | n/a | |
CVE-2018-20909 | cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338). | Unknown | N/A | n/a | |
CVE-2018-20910 | cPanel before 70.0.23 allows self XSS in the WHM cPAddons showsecurity Interface (SEC-357). | Unknown | N/A | n/a | |
CVE-2018-20911 | cPanel before 70.0.23 allows code execution because "." is in @INC during a Perl syntax check of cpaddonsup (SEC-359). | Unknown | N/A | n/a |
vunerability-insight.com © 2023 - 2025. All Rights Reserved.
Vulnerability Data Repositories v