Latest CVE Feed
-
9.8
CRITICALCVE-2007-0681
profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.... Read more
Affected Products : extcalendar- EPSS Score: %4.68
- Published: Feb. 03, 2007
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2006-7105
PHP remote file inclusion vulnerability in libs/Smarty.class.php in Smarty 2.6.9 allows remote attackers to execute arbitrary PHP code via a URL in the filename parameter. NOTE: in the original disclosure, filename is used in a function definition, so th... Read more
Affected Products : smarty- EPSS Score: %1.12
- Published: Mar. 03, 2007
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2023-43548
Memory corruption while parsing qcp clip with invalid chunk data size.... Read more
Affected Products : aqt1000_firmware qam8295p_firmware qca6391_firmware qca6420_firmware qca6430_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware sa6145p_firmware sa6150p_firmware +305 more products- Published: Mar. 04, 2024
- Modified: Aug. 11, 2025
-
9.8
CRITICALCVE-2007-2422
Multiple PHP remote file inclusion vulnerabilities in Modules Builder (modbuild) 4.1 for Comdev One Admin allow remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter to (1) config-bak.php or (2) config.php. NOTE: CVE dis... Read more
Affected Products : modules_builder- EPSS Score: %0.77
- Published: May. 02, 2007
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2007-4043
file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) before 4.6.3 allows remote attackers to bypass authentication via a name parameter ending with a "%00.gif" sequence. NOTE: a separate traversal vulnerability could be leveraged ... Read more
Affected Products : securityreporter- EPSS Score: %0.34
- Published: Jul. 27, 2007
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2018-11792
In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a particular database allows a user to move the table to a database with ALL, which... Read more
Affected Products : impala- EPSS Score: %0.55
- Published: Oct. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13342
The server API in the Anda app relies on hardcoded credentials.... Read more
Affected Products : anda- EPSS Score: %0.36
- Published: Oct. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-10731
ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with the request parameter selected_clients, clients.php with the request paramete... Read more
Affected Products : projectsend- EPSS Score: %0.31
- Published: Oct. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-10732
ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-download.php, or add_user_form_* parameters to users-add.php.... Read more
Affected Products : projectsend- EPSS Score: %0.15
- Published: Oct. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18702
spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile content is base64 decoded, deserialized, and used for database insertion.... Read more
Affected Products : icms- EPSS Score: %0.26
- Published: Oct. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18728
An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code execution via shell metacharacters in the usbName field to the __fastcall function with a POST request.... Read more
- EPSS Score: %3.11
- Published: Oct. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18729
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a heap-based buffer overflow vulnerability in the router's web server -- httpd. W... Read more
Affected Products : ac9_firmware ac15_firmware ac18_firmware ac10_firmware ac7_firmware ac15 ac18 ac10 ac9 ac7- EPSS Score: %0.45
- Published: Oct. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18785
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php.... Read more
Affected Products : zzcms- EPSS Score: %0.26
- Published: Oct. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18786
An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie.... Read more
Affected Products : zzcms- EPSS Score: %0.26
- Published: Oct. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18791
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/search.php via a pxzs cookie.... Read more
Affected Products : zzcms- EPSS Score: %0.26
- Published: Oct. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18787
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie.... Read more
Affected Products : zzcms- EPSS Score: %0.26
- Published: Oct. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18832
admin/check.asp in DKCMS 9.4 allows SQL Injection via an ASPSESSIONID cookie to admin/admin.asp.... Read more
Affected Products : dkcms- EPSS Score: %0.26
- Published: Oct. 30, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18835
upload_template() in system/changeskin.php in DocCms 2016.5.12 allows remote attackers to execute arbitrary PHP code via a template file.... Read more
Affected Products : doccms- EPSS Score: %0.99
- Published: Oct. 30, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1851
IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization. By sending a specially-crafted request to the RP service, an attacker could exploit this vul... Read more
Affected Products : websphere_application_server- EPSS Score: %5.29
- Published: Oct. 31, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2007-4290
Multiple PHP remote file inclusion vulnerabilities in Guestbook Script 1.9 allow remote attackers to execute arbitrary PHP code via a URL in the script_root parameter to (1) delete.php, (2) edit.php, or (3) inc/common.inc.php; or (4) database.php, (5) ent... Read more
Affected Products : guestbook_script- EPSS Score: %0.97
- Published: Aug. 09, 2007
- Modified: Apr. 09, 2025