Latest CVE Feed
-
9.8
CRITICALCVE-2018-11792
In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a particular database allows a user to move the table to a database with ALL, which... Read more
Affected Products : impala- EPSS Score: %0.55
- Published: Oct. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13342
The server API in the Anda app relies on hardcoded credentials.... Read more
Affected Products : anda- EPSS Score: %0.36
- Published: Oct. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-10731
ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with the request parameter selected_clients, clients.php with the request paramete... Read more
Affected Products : projectsend- EPSS Score: %0.31
- Published: Oct. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-10732
ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-download.php, or add_user_form_* parameters to users-add.php.... Read more
Affected Products : projectsend- EPSS Score: %0.15
- Published: Oct. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18702
spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile content is base64 decoded, deserialized, and used for database insertion.... Read more
Affected Products : icms- EPSS Score: %0.26
- Published: Oct. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18728
An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code execution via shell metacharacters in the usbName field to the __fastcall function with a POST request.... Read more
- EPSS Score: %3.11
- Published: Oct. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18729
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a heap-based buffer overflow vulnerability in the router's web server -- httpd. W... Read more
Affected Products : ac9_firmware ac15_firmware ac18_firmware ac10_firmware ac7_firmware ac15 ac18 ac10 ac9 ac7- EPSS Score: %0.45
- Published: Oct. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18785
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php.... Read more
Affected Products : zzcms- EPSS Score: %0.26
- Published: Oct. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18786
An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie.... Read more
Affected Products : zzcms- EPSS Score: %0.26
- Published: Oct. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18791
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/search.php via a pxzs cookie.... Read more
Affected Products : zzcms- EPSS Score: %0.26
- Published: Oct. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18787
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie.... Read more
Affected Products : zzcms- EPSS Score: %0.26
- Published: Oct. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18832
admin/check.asp in DKCMS 9.4 allows SQL Injection via an ASPSESSIONID cookie to admin/admin.asp.... Read more
Affected Products : dkcms- EPSS Score: %0.26
- Published: Oct. 30, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18835
upload_template() in system/changeskin.php in DocCms 2016.5.12 allows remote attackers to execute arbitrary PHP code via a template file.... Read more
Affected Products : doccms- EPSS Score: %0.99
- Published: Oct. 30, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1851
IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization. By sending a specially-crafted request to the RP service, an attacker could exploit this vul... Read more
Affected Products : websphere_application_server- EPSS Score: %5.29
- Published: Oct. 31, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2007-4290
Multiple PHP remote file inclusion vulnerabilities in Guestbook Script 1.9 allow remote attackers to execute arbitrary PHP code via a URL in the script_root parameter to (1) delete.php, (2) edit.php, or (3) inc/common.inc.php; or (4) database.php, (5) ent... Read more
Affected Products : guestbook_script- EPSS Score: %0.97
- Published: Aug. 09, 2007
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2023-22388
Memory Corruption in Multi-mode Call Processor while processing bit mask API.... Read more
Affected Products : aqt1000_firmware qca6391_firmware qca6420_firmware qca6426_firmware qca6430_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware sd855_firmware +452 more products- EPSS Score: %0.16
- Published: Nov. 07, 2023
- Modified: Aug. 11, 2025
-
9.8
CRITICALCVE-2007-5565
PHP remote file inclusion vulnerability in includes/functions.php in phpSCMS 0.0.1-Alpha1 allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: this issue is disputed by CVE because the identified code is in a functi... Read more
Affected Products : phpscms- EPSS Score: %0.72
- Published: Oct. 18, 2007
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2008-0174
GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the passwords and gain privileges.... Read more
Affected Products : proficy_real-time_information_portal- EPSS Score: %3.73
- Published: Jan. 29, 2008
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2015-5052
SQL injection vulnerability in Sefrengo before 1.6.5 beta2.... Read more
Affected Products : sefrengo- EPSS Score: %0.31
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2009-1936
_functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass a protection mechanism to conduct remote file inclusion and directory traversal attacks, e... Read more
Affected Products : cpcommerce- EPSS Score: %3.62
- Published: Jun. 05, 2009
- Modified: Apr. 09, 2025