Latest CVE Feed
-
9.8
CRITICALCVE-2019-12158
GoHTTP through 2017-07-25 has a GetExtension heap-based buffer overflow via a long extension.... Read more
Affected Products : gohttp- EPSS Score: %0.46
- Published: May. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-9466
The executable httpd on the TP-Link WR841N V8 router before TL-WR841N(UN)_V8_170210 contained a design flaw in the use of DES for block encryption. This resulted in incorrect access control, which allowed attackers to gain read-write access to system sett... Read more
- EPSS Score: %0.17
- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17587
FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or company/index.php c parameter.... Read more
Affected Products : indiamart_clone- EPSS Score: %2.38
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17594
DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter.... Read more
Affected Products : domainsale_php_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17595
Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.... Read more
Affected Products : beauty_parlour_booking_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17597
Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter.... Read more
Affected Products : nearbuy_clone_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-12348
An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter.... Read more
Affected Products : zzcms- EPSS Score: %0.40
- Published: May. 24, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14815
Fuji Electric V-Server 4.0.3.0 and prior, Several out-of-bounds write vulnerabilities have been identified, which may allow remote code execution.... Read more
- EPSS Score: %2.84
- Published: Sep. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14822
Entes EMG12 versions 2.57 and prior an information exposure through query strings vulnerability in the web interface has been identified, which may allow an attacker to impersonate a legitimate user and execute arbitrary code.... Read more
- EPSS Score: %0.95
- Published: Oct. 02, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-9730
SQL injection vulnerability in rdr.php in nuevoMailer version 6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the "r" parameter.... Read more
Affected Products : nuevomailer- EPSS Score: %1.15
- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-12598
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 1 of 3).... Read more
Affected Products : suitecrm- EPSS Score: %0.42
- Published: Jun. 07, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14925
Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegisecurity components.... Read more
Affected Products : banco- EPSS Score: %0.43
- Published: Aug. 03, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17610
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid parameter.... Read more
Affected Products : e-commerce_mlm_software- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-12771
Command injection is possible in ThinStation through 6.1.1 via shell metacharacters after the cgi-bin/CdControl.cgi action= substring, or after the cgi-bin/VolControl.cgi OK= substring.... Read more
Affected Products : thinstation- EPSS Score: %13.08
- Published: Jun. 07, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-2356
Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or password.... Read more
- EPSS Score: %3.51
- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12850
A query injection was possible in JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49168.... Read more
Affected Products : youtrack- EPSS Score: %0.01
- Published: Jul. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-13086
core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.... Read more
Affected Products : csz_cms- EPSS Score: %50.77
- Published: Jun. 30, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-13116
The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections... Read more
Affected Products : mule_runtime- EPSS Score: %2.66
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17621
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.... Read more
Affected Products : multivendor_penny_auction_clone_script- EPSS Score: %4.15
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-13131
Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitrary commands via NRPE.... Read more
Affected Products : superdoctor_5- EPSS Score: %2.11
- Published: Jul. 01, 2019
- Modified: Nov. 21, 2024