Common Vulnerabilities and Exposures (CVE) is a critical tool for maintaining software security, providing a standardized way to track and manage vulnerabilities across systems. Organizations should regularly monitor CVE databases, assess the impact of vulnerabilities, and apply patches promptly to reduce the risk of exploitation.
CVE (Common Vulnerabilities and Exposures) is a public database that provides a standardized method for identifying, tracking, and referencing publicly disclosed security vulnerabilities in software and hardware.
Each vulnerability receives a unique identifier called a CVE ID (e.g., CVE-2023-12345), making it easier to reference specific vulnerabilities across different tools and databases.
Total Search Results: 158437
CVE ID | Description | Severity | Published Date | Affected Vendor | Action |
---|---|---|---|---|---|
CVE-2018-20912 | cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362). | Unknown | N/A | n/a | |
CVE-2018-20913 | cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364). | Unknown | N/A | n/a | |
CVE-2018-20914 | In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368). | Unknown | N/A | n/a | |
CVE-2018-20915 | cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369). | Unknown | N/A | n/a | |
CVE-2018-20916 | cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370). | Unknown | N/A | n/a | |
CVE-2018-20917 | cPanel before 70.0.23 allows any user to disable Solr (SEC-371). | Unknown | N/A | n/a | |
CVE-2018-20918 | cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372). | Unknown | N/A | n/a | |
CVE-2018-20919 | cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373). | Unknown | N/A | n/a | |
CVE-2018-20920 | cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374). | Unknown | N/A | n/a | |
CVE-2018-20921 | cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375). | Unknown | N/A | n/a | |
CVE-2018-20922 | cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376). | Unknown | N/A | n/a | |
CVE-2018-20923 | cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377). | Unknown | N/A | n/a | |
CVE-2018-20924 | cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378). | Unknown | N/A | n/a | |
CVE-2018-20925 | cPanel before 70.0.23 allows local privilege escalation via the WHM Legacy Language File Upload interface (SEC-379). | Unknown | N/A | n/a | |
CVE-2018-20926 | cPanel before 70.0.23 allows local privilege escalation via the WHM Locale XML Upload interface (SEC-380). | Unknown | N/A | n/a | |
CVE-2018-20927 | cPanel before 70.0.23 allows jailshell escape because of incorrect crontab parsing (SEC-382). | Unknown | N/A | n/a | |
CVE-2018-20928 | cPanel before 70.0.23 allows stored XSS via the cpaddons vendor interface (SEC-391). | Unknown | N/A | n/a | |
CVE-2018-20929 | cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392). | Unknown | N/A | n/a | |
CVE-2018-20930 | cPanel before 70.0.23 allows .htaccess restrictions bypass when Htaccess Optimization is enabled (SEC-401). | Unknown | N/A | n/a | |
CVE-2018-20931 | cPanel before 70.0.23 allows demo accounts to execute code via the Landing Page (SEC-405). | Unknown | N/A | n/a | |
CVE-2018-20932 | cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406). | Unknown | N/A | n/a | |
CVE-2018-20933 | cPanel before 70.0.23 has Stored XSS via an WHM Edit DNS Zone action (SEC-410). | Unknown | N/A | n/a | |
CVE-2018-20934 | cPanel before 70.0.23 does not prevent e-mail account suspensions from being applied to unowned accounts (SEC-411). | Unknown | N/A | n/a | |
CVE-2018-20935 | cPanel before 70.0.23 allows stored XSS in via a WHM "Reset a DNS Zone" action (SEC-412). | Unknown | N/A | n/a | |
CVE-2018-20936 | cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308). | Unknown | N/A | n/a | |
CVE-2018-20937 | cPanel before 68.0.27 does not validate database and dbuser names during renames (SEC-321). | Unknown | N/A | n/a | |
CVE-2018-20938 | cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324). | Unknown | N/A | n/a | |
CVE-2018-20939 | cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339). | Unknown | N/A | n/a | |
CVE-2018-20940 | cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342). | Unknown | N/A | n/a | |
CVE-2018-20941 | cPanel before 68.0.27 allows arbitrary file-read operations via restore adminbin (SEC-349). | Unknown | N/A | n/a | |
CVE-2018-20942 | cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab (SEC-351). | Unknown | N/A | n/a | |
CVE-2018-20943 | cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon a post-update task (SEC-352). | Unknown | N/A | n/a | |
CVE-2018-20944 | cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353). | Unknown | N/A | n/a | |
CVE-2018-20945 | bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354). | Unknown | N/A | n/a | |
CVE-2018-20946 | cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zones script (SEC-355). | Unknown | N/A | n/a | |
CVE-2018-20947 | cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356). | Unknown | N/A | n/a | |
CVE-2018-20948 | cPanel before 68.0.27 allows self XSS in cPanel Backup Restoration (SEC-383). | Unknown | N/A | n/a | |
CVE-2018-20949 | cPanel before 68.0.27 allows self XSS in WHM Apache Configuration Include Editor (SEC-385). | Unknown | N/A | n/a | |
CVE-2018-20950 | cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386). | Unknown | N/A | n/a | |
CVE-2018-20951 | cPanel before 68.0.27 allows self XSS in WHM Spamd Startup Config (SEC-387). | Unknown | N/A | n/a | |
CVE-2018-20952 | cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388). | Unknown | N/A | n/a | |
CVE-2018-20953 | cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389). | Unknown | N/A | n/a | |
CVE-2018-20954 | The "Security and Privacy" Encryption feature in Mailpile before 1.0.0rc4 does not exclude disabled, revoked, and expired keys. | Unknown | N/A | n/a | |
CVE-2018-20955 | Swann SWWHD-INTCAM-HD devices have the twipc root password, leading to FTP access as root. NOTE: all affected customers were migrated by 2020-08-31. | Unknown | N/A | n/a | |
CVE-2018-20956 | Swann SWWHD-INTCAM-HD devices leave the PSK in logs after a factory reset. NOTE: all affected customers were migrated by 2020-08-31. | Unknown | N/A | n/a | |
CVE-2018-20957 | The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 allows replay attacks. | Unknown | N/A | n/a | |
CVE-2018-20958 | The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 relies on Key1 and SerialNo for unlock operations; however, these are derived from the MAC address, which is broadcasted by the device. | Unknown | N/A | n/a | |
CVE-2018-20959 | Jura E8 devices lack Bluetooth connection security. | Unknown | N/A | n/a | |
CVE-2018-20960 | Nespresso Prodigio devices lack Bluetooth connection security. | Unknown | N/A | n/a | |
CVE-2018-20961 | In the Linux kernel before 4.16.4, a double free vulnerability in the f_midi_set_alt function of drivers/usb/gadget/function/f_midi.c in the f_midi driver may allow attackers to cause a denial of service or possibly have unspecified other impact. | Unknown | N/A | n/a | |
CVE-2018-20962 | The Backpack\CRUD Backpack component before 3.4.9 for Laravel allows XSS via the select field type. | Unknown | N/A | n/a | |
CVE-2018-20963 | The contact-form-to-email plugin before 1.2.66 for WordPress has XSS. | Unknown | N/A | n/a | |
CVE-2018-20964 | The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF. | Unknown | N/A | n/a | |
CVE-2018-20965 | The ultimate-member plugin before 2.0.4 for WordPress has XSS. | Unknown | N/A | n/a | |
CVE-2018-20966 | The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature. | Unknown | N/A | n/a | |
CVE-2018-20967 | The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF. | Unknown | N/A | n/a | |
CVE-2018-20968 | The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF. | Unknown | N/A | n/a | |
CVE-2018-20969 | do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-13638, but the ! syntax is specific to ed, and is unrelated to a shell metacharacter. | Unknown | N/A | n/a | |
CVE-2018-20970 | The pdf-print plugin before 2.0.3 for WordPress has multiple XSS issues. | Unknown | N/A | n/a | |
CVE-2018-20971 | The church-admin plugin before 1.2550 for WordPress has CSRF affecting the upload of a bible reading plan. | Unknown | N/A | n/a | |
CVE-2018-20972 | The companion-auto-update plugin before 3.2.1 for WordPress has CSRF. | Unknown | N/A | n/a | |
CVE-2018-20973 | The companion-auto-update plugin before 3.2.1 for WordPress has local file inclusion. | Unknown | N/A | n/a | |
CVE-2018-20974 | The js-jobs plugin before 1.0.7 for WordPress has CSRF. | Unknown | N/A | n/a | |
CVE-2018-20975 | Fat Free CRM before 0.18.1 has XSS in the tags_helper in app/helpers/tags_helper.rb. | Unknown | N/A | n/a | |
CVE-2018-20976 | An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel before 4.18. A use after free exists, related to xfs_fs_fill_super failure. | Unknown | N/A | n/a | |
CVE-2018-20977 | The all-in-one-schemaorg-rich-snippets plugin before 1.5.0 for WordPress has XSS on the settings page. | Unknown | N/A | n/a | |
CVE-2018-20978 | The wp-all-import plugin before 3.4.7 for WordPress has XSS. | Unknown | N/A | n/a | |
CVE-2018-20979 | The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type. | Unknown | N/A | n/a | |
CVE-2018-20980 | The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering. | Unknown | N/A | n/a | |
CVE-2018-20981 | The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests. | Unknown | N/A | n/a | |
CVE-2018-20982 | The media-library-assistant plugin before 2.74 for WordPress has XSS via the Media/Assistant or Settings/Media Library assistant admin submenu screens. | Unknown | N/A | n/a | |
CVE-2018-20983 | The wp-retina-2x plugin before 5.2.3 for WordPress has XSS. | Unknown | N/A | n/a | |
CVE-2018-20984 | The patreon-connect plugin before 1.2.2 for WordPress has Object Injection. | Unknown | N/A | n/a | |
CVE-2018-20985 | The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec. | Unknown | N/A | n/a | |
CVE-2018-20986 | The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors. | Unknown | N/A | n/a | |
CVE-2018-20987 | The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection. | Unknown | N/A | n/a | |
CVE-2018-20988 | The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation. | Unknown | N/A | n/a | |
CVE-2018-20989 | An issue was discovered in the untrusted crate before 0.6.2 for Rust. Error handling can trigger an integer underflow and panic. | Unknown | N/A | n/a | |
CVE-2018-20990 | An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or hardlink in a TAR archive. | Unknown | N/A | n/a | |
CVE-2018-20991 | An issue was discovered in the smallvec crate before 0.6.3 for Rust. The Iterator implementation mishandles destructors, leading to a double free. | Unknown | N/A | n/a | |
CVE-2018-20992 | An issue was discovered in the claxon crate before 0.4.1 for Rust. Uninitialized memory can be exposed because certain decode buffer sizes are mishandled. | Unknown | N/A | n/a | |
CVE-2018-20993 | An issue was discovered in the yaml-rust crate before 0.4.1 for Rust. There is uncontrolled recursion during deserialization. | Unknown | N/A | n/a | |
CVE-2018-20994 | An issue was discovered in the trust-dns-proto crate before 0.5.0-alpha.3 for Rust. There is infinite recursion because DNS message compression is mishandled. | Unknown | N/A | n/a | |
CVE-2018-20995 | An issue was discovered in the slice-deque crate before 0.1.16 for Rust. move_head_unchecked allows memory corruption because deque updates are mishandled. | Unknown | N/A | n/a | |
CVE-2018-20996 | An issue was discovered in the crossbeam crate before 0.4.1 for Rust. There is a double free because of destructor mishandling. | Unknown | N/A | n/a | |
CVE-2018-20997 | An issue was discovered in the openssl crate before 0.10.9 for Rust. A use-after-free occurs in CMS Signing. | Unknown | N/A | n/a | |
CVE-2018-20998 | An issue was discovered in the arrayfire crate before 3.6.0 for Rust. Addition of the repr() attribute to an enum is mishandled, leading to memory corruption. | Unknown | N/A | n/a | |
CVE-2018-20999 | An issue was discovered in the orion crate before 0.11.2 for Rust. reset() calls cause incorrect results. | Unknown | N/A | n/a | |
CVE-2018-21000 | An issue was discovered in the safe-transmute crate before 0.10.1 for Rust. A constructor's arguments are in the wrong order, causing heap memory corruption. | Unknown | N/A | n/a | |
CVE-2018-21001 | The anycomment plugin before 0.0.33 for WordPress has XSS. | Unknown | N/A | n/a | |
CVE-2018-21002 | The js-support-ticket plugin before 2.0.6 for WordPress has CSRF. | Unknown | N/A | n/a | |
CVE-2018-21003 | The buddyforms plugin before 2.2.8 for WordPress has SQL injection. | Unknown | N/A | n/a | |
CVE-2018-21004 | The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection. | Unknown | N/A | n/a | |
CVE-2018-21005 | The bbp-move-topics plugin before 1.1.6 for WordPress has code injection. | Unknown | N/A | n/a | |
CVE-2018-21006 | The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF. | Unknown | N/A | n/a | |
CVE-2018-21007 | The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders inside uploads. | Unknown | N/A | n/a | |
CVE-2018-21008 | An issue was discovered in the Linux kernel before 4.16.7. A use-after-free can be caused by the function rsi_mac80211_detach in the file drivers/net/wireless/rsi/rsi_91x_mac80211.c. | Unknown | N/A | n/a | |
CVE-2018-21009 | Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc. | Unknown | N/A | n/a | |
CVE-2018-21010 | OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c. | Unknown | N/A | n/a | |
CVE-2018-21011 | The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details. | Unknown | N/A | n/a |
vunerability-insight.com © 2023 - 2025. All Rights Reserved.
Vulnerability Data Repositories v