Latest CVE Feed
-
9.8
CRITICALCVE-2017-16042
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.... Read more
Affected Products : growl- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-15970
PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter.... Read more
Affected Products : phpcityportal- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15983
MyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.... Read more
Affected Products : mymagazine_magazine_\&_blog_cms- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15978
AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.... Read more
Affected Products : school_erp_php_script- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15981
Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.... Read more
Affected Products : newspaper- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15966
The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parameter to index.php.... Read more
Affected Products : zh_yandexmap- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15967
Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the edit parameter to admin/template.... Read more
Affected Products : mailing_list_manager_pro- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15986
CPA Lead Reward Script allows SQL Injection via the username parameter.... Read more
Affected Products : cpa_lead_reward_script- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15972
SoftDatepro Dating Social Network 1.3 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15971.... Read more
Affected Products : dating_software- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15993
Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter.... Read more
Affected Products : zomato_clone_script- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15973
Sokial Social Network Script 1.0 allows SQL Injection via the id parameter to admin/members_view.php.... Read more
Affected Products : sokial- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-16020
Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands via the collection name.... Read more
Affected Products : summit- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-15964
Job Board Script Software allows SQL Injection via the PATH_INFO to a /job-details URI.... Read more
Affected Products : job_board_script- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15965
The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action.... Read more
Affected Products : ns_download_shop- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15988
Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008-6525.... Read more
Affected Products : nice_php_faq_script- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15960
Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php.... Read more
Affected Products : article_directory_script- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15982
Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.... Read more
Affected Products : news- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15969
PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_catalog/category.... Read more
Affected Products : allsharevideo- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15944
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.... Read more
Affected Products : pan-os- Actively Exploited
- Published: Dec. 11, 2017
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2017-15961
iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php.... Read more
Affected Products : iproject_management_system- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025