Vulnerabilities (CVE)

Total 403696 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-14438 1 Wireshark 1 Wireshark 2026-06-17 5.0 MEDIUM 7.5 HIGH
In Wireshark through 2.6.2, the create_app_running_mutex function in wsutil/file_util.c calls SetSecurityDescriptorDacl to set a NULL DACL, which allows attackers to modify the access control arbitrarily.
CVE-2018-14437 2 Canonical, Imagemagick 2 Ubuntu Linux, Imagemagick 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
ImageMagick 7.0.8-4 has a memory leak in parse8BIM in coders/meta.c.
CVE-2018-14436 2 Canonical, Imagemagick 2 Ubuntu Linux, Imagemagick 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
ImageMagick 7.0.8-4 has a memory leak in ReadMIFFImage in coders/miff.c.
CVE-2018-14435 2 Canonical, Imagemagick 2 Ubuntu Linux, Imagemagick 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
ImageMagick 7.0.8-4 has a memory leak in DecodeImage in coders/pcd.c.
CVE-2018-14434 2 Canonical, Imagemagick 2 Ubuntu Linux, Imagemagick 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
ImageMagick 7.0.8-4 has a memory leak for a colormap in WriteMPCImage in coders/mpc.c.
CVE-2018-14432 3 Debian, Openstack, Redhat 3 Debian Linux, Keystone, Openstack 2026-06-17 3.5 LOW 5.3 MEDIUM
In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may bypass intended access restrictions on listing projects. An authenticated user may discover projects they have no authority to access, leaking all projects in the deployment and their attributes. Only Keystone with the /v3/OS-FEDERATION endpoint enabled via policy.json is affected.
CVE-2018-14430 1 Mondula 1 Multi Step Form 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Mondula Multi Step Form plugin through 1.2.5 for WordPress allows XSS via the fw_data [id][1], fw_data [id][2], fw_data [id][3], fw_data [id][4], or email field of the contact form, exploitable with an fw_send_email action to wp-admin/admin-ajax.php.
CVE-2018-14429 1 Man-cgi Project 1 Man-cgi 2026-06-17 5.0 MEDIUM 7.5 HIGH
man-cgi before 1.16 allows Local File Inclusion via absolute path traversal, as demonstrated by a cgi-bin/man-cgi?/etc/passwd URI.
CVE-2018-14425 1 Synacor 1 Zimbra Collaboration Suite 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
There is a Persistent XSS vulnerability in the briefcase component of Synacor Zimbra Collaboration Suite (ZCS) Zimbra Web Client (ZWC) 8.8.8 before 8.8.8 Patch 7 and 8.8.9 before 8.8.9 Patch 1.
CVE-2018-14424 1 Gnome 1 Gnome Display Manager 2026-06-17 4.6 MEDIUM 7.8 HIGH
The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-free via a specially crafted sequence of D-Bus method calls, resulting in a denial of service or potential code execution.
CVE-2018-14423 2 Debian, Uclouvain 2 Debian Linux, Openjpeg 2026-06-17 5.0 MEDIUM 7.5 HIGH
Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in lib/openjp3d/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).
CVE-2018-14422 1 Sanscms 1 Sanscms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
blog/index.php in SansCMS 0.7 has XSS via the q parameter.
CVE-2018-14421 1 Seacms 1 Seacms 2026-06-17 6.8 MEDIUM 8.8 HIGH
SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v_pic) to /admin/admin_video.php (aka /backend/admin_video.php). The code is executed by visiting /details/index.php. This can also be exploited through CSRF.
CVE-2018-14420 1 Metinfo 1 Metinfo 2026-06-17 6.8 MEDIUM 8.8 HIGH
MetInfo 6.0.0 allows a CSRF attack to add a user account via a doaddsave action to admin/index.php, as demonstrated by an admin/index.php?anyid=47&n=admin&c=admin_admin&a=doaddsave URI.
CVE-2018-14419 1 Metinfo 1 Metinfo 2026-06-17 3.5 LOW 4.8 MEDIUM
MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page.
CVE-2018-14418 1 Msvod 1 Msvod Cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
CVE-2018-14417 1 Softnas 1 Cloud 2026-06-17 10.0 HIGH 9.8 CRITICAL
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the 'recentVersion' parameter from the snserv endpoint, allowing an unauthenticated attacker to execute arbitrary commands with root permissions.
CVE-2018-14415 1 Icmsdev 1 Icms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in idreamsoft iCMS before 7.0.10. XSS exists via the fourth and fifth input elements on the admincp.php?app=prop&do=add screen.
CVE-2018-14404 3 Canonical, Debian, Xmlsoft 3 Ubuntu Linux, Debian Linux, Libxml2 2026-06-17 5.0 MEDIUM 6.5 MEDIUM
A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case. Applications processing untrusted XSL format inputs with the use of the libxml2 library may be vulnerable to a denial of service attack due to a crash of the application.
CVE-2018-14403 1 Techsmith 1 Mp4v2 2026-06-17 7.5 HIGH 9.8 CRITICAL
MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for associated atoms. The resulting type confusion can cause out-of-bounds memory access.