Total
404108 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2018-16654 | 1 Zurmo | 1 Zurmo Crm | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Zurmo 3.2.4 Stable allows XSS via app/index.php/accounts/default/details?id=2&kanbanBoard=1&openToTaskId=1. | |||||
| CVE-2018-16653 | 1 Rejucms Project | 1 Rejucms | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| rejucms 2.1 has XSS via the ucenter/cms_user_add.php u_name parameter. | |||||
| CVE-2018-16651 | 1 Phpmyfaq | 1 Phpmyfaq | 2026-06-17 | 9.0 HIGH | 7.2 HIGH |
| The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports. | |||||
| CVE-2018-16650 | 1 Phpmyfaq | 1 Phpmyfaq | 2026-06-17 | 6.8 MEDIUM | 8.8 HIGH |
| phpMyFAQ before 2.9.11 allows CSRF. | |||||
| CVE-2018-16648 | 1 Artifex | 1 Mupdf | 2026-06-17 | 4.3 MEDIUM | 5.5 MEDIUM |
| In Artifex MuPDF 1.13.0, the fz_append_byte function in fitz/buffer.c allows remote attackers to cause a denial of service (segmentation fault) via a crafted pdf file. This is caused by a pdf/pdf-device.c pdf_dev_alpha array-index underflow. | |||||
| CVE-2018-16647 | 1 Artifex | 1 Mupdf | 2026-06-17 | 4.3 MEDIUM | 5.5 MEDIUM |
| In Artifex MuPDF 1.13.0, the pdf_get_xref_entry function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation fault in fz_write_data in fitz/output.c) via a crafted pdf file. | |||||
| CVE-2018-16646 | 3 Canonical, Debian, Freedesktop | 3 Ubuntu Linux, Debian Linux, Poppler | 2026-06-17 | 4.3 MEDIUM | 6.5 MEDIUM |
| In Poppler 0.68.0, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. | |||||
| CVE-2018-16645 | 3 Canonical, Debian, Imagemagick | 3 Ubuntu Linux, Debian Linux, Imagemagick | 2026-06-17 | 4.3 MEDIUM | 6.5 MEDIUM |
| There is an excessive memory allocation issue in the functions ReadBMPImage of coders/bmp.c and ReadDIBImage of coders/dib.c in ImageMagick 7.0.8-11, which allows remote attackers to cause a denial of service via a crafted image file. | |||||
| CVE-2018-16644 | 3 Canonical, Debian, Imagemagick | 3 Ubuntu Linux, Debian Linux, Imagemagick | 2026-06-17 | 4.3 MEDIUM | 6.5 MEDIUM |
| There is a missing check for length in the functions ReadDCMImage of coders/dcm.c and ReadPICTImage of coders/pict.c in ImageMagick 7.0.8-11, which allows remote attackers to cause a denial of service via a crafted image. | |||||
| CVE-2018-16643 | 3 Canonical, Debian, Imagemagick | 3 Ubuntu Linux, Debian Linux, Imagemagick | 2026-06-17 | 4.3 MEDIUM | 6.5 MEDIUM |
| The functions ReadDCMImage in coders/dcm.c, ReadPWPImage in coders/pwp.c, ReadCALSImage in coders/cals.c, and ReadPICTImage in coders/pict.c in ImageMagick 7.0.8-4 do not check the return value of the fputc function, which allows remote attackers to cause a denial of service via a crafted image file. | |||||
| CVE-2018-16642 | 3 Canonical, Debian, Imagemagick | 3 Ubuntu Linux, Debian Linux, Imagemagick | 2026-06-17 | 4.3 MEDIUM | 6.5 MEDIUM |
| The function InsertRow in coders/cut.c in ImageMagick 7.0.7-37 allows remote attackers to cause a denial of service via a crafted image file due to an out-of-bounds write. | |||||
| CVE-2018-16641 | 1 Imagemagick | 1 Imagemagick | 2026-06-17 | 4.3 MEDIUM | 6.5 MEDIUM |
| ImageMagick 7.0.8-6 has a memory leak vulnerability in the TIFFWritePhotoshopLayers function in coders/tiff.c. | |||||
| CVE-2018-16640 | 2 Canonical, Imagemagick | 2 Ubuntu Linux, Imagemagick | 2026-06-17 | 4.3 MEDIUM | 6.5 MEDIUM |
| ImageMagick 7.0.8-5 has a memory leak vulnerability in the function ReadOneJNGImage in coders/png.c. | |||||
| CVE-2018-16639 | 1 Typesettercms | 1 Typesetter | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| Typesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation. | |||||
| CVE-2018-16638 | 1 Modx | 1 Evolution Cms | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| Evolution CMS 1.4.x allows XSS via the manager/ search parameter. | |||||
| CVE-2018-16637 | 1 Modx | 1 Evolution Cms | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI. | |||||
| CVE-2018-16636 | 1 Nucleuscms | 1 Nucleus Cms | 2026-06-17 | 4.0 MEDIUM | 6.5 MEDIUM |
| Nucleus CMS 3.70 allows HTML Injection via the index.php body parameter. | |||||
| CVE-2018-16635 | 1 Blackcat-cms | 1 Blackcat Cms | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php. | |||||
| CVE-2018-16634 | 1 Pluck-cms | 1 Pluck | 2026-06-17 | 6.8 MEDIUM | 8.8 HIGH |
| Pluck v4.7.7 allows CSRF via admin.php?action=settings. | |||||
| CVE-2018-16633 | 1 Pluck-cms | 1 Pluck | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title. | |||||
