Latest CVE Feed
-
9.8
CRITICALCVE-2017-8297
A path traversal vulnerability exists in simple-file-manager before 2017-04-26, affecting index.php (the sole "Simple PHP File Manager" component).... Read more
Affected Products : simple-file-manager- Published: Apr. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-11076
Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request.... Read more
Affected Products : cribl- Published: Apr. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-11888
Go through 1.12.5 on Windows mishandles process creation with a nil environment in conjunction with a non-nil token, which allows attackers to obtain sensitive information or gain privileges.... Read more
- Published: May. 13, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17573
FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter.... Read more
Affected Products : ebay_clone- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-14485
BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.... Read more
Affected Products : blogengine.net- Published: May. 07, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14496
Vivotek FD8136 devices allow remote memory corruption and remote code execution because of a stack-based buffer overflow, related to sprintf, vlocal_buff_4326, and set_getparam.cgi. NOTE: The vendor has disputed this as a vulnerability and states that the... Read more
- Published: Jul. 10, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12150
Karamasoft UltimateEditor 1 does not ensure that an uploaded file is an image or document (neither file types nor extensions are restricted). The attacker must use the Attach icon to perform an upload. An uploaded file is accessible under the UltimateEdit... Read more
Affected Products : ultimateeditor- Published: May. 24, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17574
FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.... Read more
Affected Products : care_clone- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-12160
GoHTTP through 2017-07-25 has a sendHeader use-after-free.... Read more
Affected Products : gohttp- Published: May. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12271
Sandline Centraleyezer (On Premises) allows unrestricted File Upload with a dangerous type, because the feature of adding ".jpg" to any uploaded filename is not enforced on the server side.... Read more
Affected Products : centraleyezer- Published: Nov. 18, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12349
An issue was discovered in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id parameter.... Read more
Affected Products : zzcms- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12351
An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_print.php via an id parameter value with a trailing comma.... Read more
Affected Products : zzcms- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12377
A vulnerable upl/async_upload.asp web API endpoint in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 allows arbitrary file upload, which may lead to arbitrary remote code execution.... Read more
- Published: Jun. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-9615
Password exposure in Cognito Software Moneyworks 8.0.3 and earlier allows attackers to gain administrator access to all data, because verbose logging writes the administrator password to a world-readable file.... Read more
Affected Products : moneyworks- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-14826
Entes EMG12 versions 2.57 and prior The application uses a web interface where it is possible for an attacker to bypass authentication with a specially crafted URL. This could allow for remote code execution.... Read more
- Published: Oct. 02, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-9980
In Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, the "PING" (aka tag_ipPing) feature within the web interface allows performing command injection, via the "pip" parameter.... Read more
- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-15387
A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. The vulnerability is due to improper certificate validation. An attacker could exploit this vulnerability ... Read more
- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17611
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.... Read more
Affected Products : doctor_search_script- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17671
vBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an unauthenticated request that can include directory traversal sequences to specify an arbitrary pathname, and because ../ traversal is bloc... Read more
- Published: Dec. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-15681
An issue was discovered in BTITeam XBTIT 2.5.4. When a user logs in, their password hash is rehashed using a predictable salt and stored in the "pass" cookie, which is not flagged as HTTPOnly. Due to the weak and predictable salt that is in place, an atta... Read more
Affected Products : xbtit- Published: Sep. 05, 2018
- Modified: Nov. 21, 2024