Latest CVE Feed
-
9.8
CRITICALCVE-2017-9246
New Relic .NET Agent before 6.3.123.0 adds SQL injection flaws to safe applications via vectors involving failure to escape quotes during use of the Slow Queries feature, as demonstrated by a mishandled quote in a VALUES clause of an INSERT statement, aft... Read more
Affected Products : .net_agent- EPSS Score: %0.25
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-6368
SQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed action.... Read more
Affected Products : jomestate_pro- EPSS Score: %1.49
- Published: Feb. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-20032
A vulnerability was found in PHPList 3.2.6. It has been rated as critical. Affected by this issue is some unknown functionality of the component Subscription. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has be... Read more
Affected Products : phplist- EPSS Score: %0.23
- Published: Jun. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6370
SQL Injection exists in the NeoRecruit 4.1 component for Joomla! via the (1) PATH_INFO or (2) name of a .html file under the all-offers/ URI.... Read more
Affected Products : neorecruit- EPSS Score: %1.49
- Published: Feb. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6395
SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action.... Read more
Affected Products : visual_calendar- EPSS Score: %1.41
- Published: Jan. 30, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-3202
The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instantiation of arbitrary classes via their public parameter-less constructor and subsequently call arbitrary Java Beans setter methods. The... Read more
Affected Products : flamingo- EPSS Score: %11.08
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6578
SQL Injection exists in the JE PayperVideo 3.0.0 component for Joomla! via the usr_plan parameter in a view=myplans&task=myplans.usersubscriptions request.... Read more
Affected Products : je_paypervideo- EPSS Score: %1.41
- Published: Feb. 02, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6581
SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username parameter.... Read more
Affected Products : jms_music- EPSS Score: %1.41
- Published: Feb. 02, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6582
SQL Injection exists in the Zh GoogleMap 8.4.0.0 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request.... Read more
Affected Products : zh_googlemap- EPSS Score: %1.41
- Published: Feb. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6609
SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit action, or the id parameter in a statuslist (or prioritylist) edit action.... Read more
Affected Products : jsp_tickets- EPSS Score: %2.59
- Published: Feb. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6953
In CCN-lite 2, the Parser of NDNTLV does not verify whether a certain component's length field matches the actual component length, which has a resultant buffer overflow and out-of-bounds memory accesses.... Read more
Affected Products : ccn-lite- EPSS Score: %0.44
- Published: Feb. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7039
CCN-lite 2.0.0 Beta allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact because the ccnl_ndntlv_prependBlob function in ccnl-pkt-ndntlv.c can be called with wrong arguments. Specifically, there ... Read more
Affected Products : ccn-lite- EPSS Score: %0.66
- Published: Feb. 14, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-39070
IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to authenticate as any user on the system. IBM X-Force ID: 215353.... Read more
- EPSS Score: %0.67
- Published: Feb. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7213
The Password Manager Extension in Abine Blur 7.8.242* before 7.8.2428 allows attackers to bypass the Multi-Factor Authentication and macOS disk-encryption protection mechanisms, and consequently exfiltrate secured data, because the right-click context men... Read more
Affected Products : blur- EPSS Score: %0.17
- Published: Mar. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7246
A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. he integrated web server (Port 80/443/TCP) of the affected devices could allow re... Read more
Affected Products : 66074_mge_network_management_card_transverse mge_comet_ups mge_eps_6000 mge_eps_7000 mge_eps_8000 mge_galaxy_3000 mge_galaxy_4000 mge_galaxy_5000 mge_galaxy_6000 mge_galaxy_9000 +1 more products- EPSS Score: %0.16
- Published: Apr. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0448
A vulnerability in the identity management service of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and take complete control of identity management functions. The vulnerability is... Read more
- EPSS Score: %0.08
- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7319
SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system1, or laundry parameter.... Read more
Affected Products : os_property_real_estate- EPSS Score: %1.49
- Published: Feb. 22, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7518
In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, an attacker with network access to the integrated web server could retrieve default or user defined credentials stored and transmitted in an insecure manner.... Read more
- EPSS Score: %0.25
- Published: May. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0664
A vulnerability in NoMachine App for Android 5.0.63 and earlier allows attackers to alter environment variables via unspecified vectors.... Read more
Affected Products : nomachine- EPSS Score: %0.58
- Published: Sep. 04, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7778
In Schneider Electric Evlink Charging Station versions prior to v3.2.0-12_v1, the Web Interface has an issue that may allow a remote attacker to gain administrative privileges without properly authenticating remote users.... Read more
- EPSS Score: %0.69
- Published: Jul. 03, 2018
- Modified: Nov. 21, 2024