Latest CVE Feed
-
9.8
CRITICALCVE-2017-17610
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid parameter.... Read more
Affected Products : e-commerce_mlm_software- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-12771
Command injection is possible in ThinStation through 6.1.1 via shell metacharacters after the cgi-bin/CdControl.cgi action= substring, or after the cgi-bin/VolControl.cgi OK= substring.... Read more
Affected Products : thinstation- EPSS Score: %13.08
- Published: Jun. 07, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-2356
Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or password.... Read more
- EPSS Score: %3.51
- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12850
A query injection was possible in JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49168.... Read more
Affected Products : youtrack- EPSS Score: %0.01
- Published: Jul. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-13086
core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.... Read more
Affected Products : csz_cms- EPSS Score: %50.77
- Published: Jun. 30, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-13116
The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections... Read more
Affected Products : mule_runtime- EPSS Score: %2.66
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17621
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.... Read more
Affected Products : multivendor_penny_auction_clone_script- EPSS Score: %4.15
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-13131
Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitrary commands via NRPE.... Read more
Affected Products : superdoctor_5- EPSS Score: %2.11
- Published: Jul. 01, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0181
A vulnerability in the Redis implementation used by the Cisco Policy Suite for Mobile and Cisco Policy Suite Diameter Routing Agent software could allow an unauthenticated, remote attacker to modify key-value pairs for short-lived events stored by the Red... Read more
Affected Products : policy_suite cisco_policy_suite_diameter_routing_agent cisco_policy_suite_for_mobile- EPSS Score: %4.08
- Published: Jan. 10, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17779
Paid To Read Script 2.0.5 has SQL injection via the referrals.php id parameter.... Read more
Affected Products : paid_to_read_script- EPSS Score: %0.25
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-15888
An issue was discovered in ASPCMS 2.5.6. When registering ordinary users in the addUser function of the /member/reg.asp page, they can be registered with the super administrators GroupID directly.... Read more
- EPSS Score: %0.99
- Published: Aug. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-13373
An issue was discovered in the D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6. Input does not get validated and arbitrary SQL statements can be executed in the database via the /web/Public/Conn.php parameter dbSQL.... Read more
- EPSS Score: %90.08
- Published: Jul. 06, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-13582
An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufactured before March 2018, via the Parrot Faurecia Automotive FC6050W module. A stack overflow could lead to denial of service or arbitr... Read more
- EPSS Score: %1.20
- Published: Nov. 15, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-2555
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.... Read more
Affected Products : atutor- EPSS Score: %78.74
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-13973
LayerBB 1.1.3 allows admin/general.php arbitrary file upload because the custom_logo filename suffix is not restricted, and .php may be used.... Read more
Affected Products : layerbb- EPSS Score: %0.43
- Published: Jul. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17872
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.... Read more
Affected Products : jextn_video_gallery- EPSS Score: %1.41
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17906
PHP Scripts Mall Car Rental Script has SQL Injection via the admin/carlistedit.php carid parameter.... Read more
Affected Products : car_rental_script- EPSS Score: %0.25
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-16762
FUEL CMS 1.4.1 allows SQL Injection via the layout, published, or search_term parameter to pages/items.... Read more
Affected Products : fuel_cms- EPSS Score: %0.26
- Published: Sep. 09, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-14237
On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by observing CPU registers and the effect of code/instruction execution.... Read more
Affected Products : kinetis_kv1x_firmware kinetis_kv3x_firmware kinetis_k8x_firmware kinetis_kv1x kinetis_kv3x kinetis_k8x- EPSS Score: %0.94
- Published: Sep. 12, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10106
D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have permission bypass and information disclosure in /htdocs/web/getcfg.php, as demonstrated by a /getcfg.php?a=%0a_POST_SERVICES%3DDEVICE.ACCOUNT%0aAUTHORIZED_GROU... Read more
- EPSS Score: %0.76
- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024