Latest CVE Feed
-
9.8
CRITICALCVE-2019-1010179
PHKP including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b is affected by: Improper Neutralization of Special Elements used in a Command ('Command Injection'). The impact is: It is possible to manipulate gpg-keys or execute commands remotely. The comp... Read more
Affected Products : phkp- Published: Jul. 24, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-7991
Exponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function of framework/modules/eaas/controllers/eaasController.php.... Read more
Affected Products : exponent_cms- Published: Apr. 22, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-10765
iobroker.admin before 3.6.12 allows attacker to include file contents from outside the `/log/file1/` directory.... Read more
Affected Products : iobroker.admin- Published: Nov. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10777
In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function without any sanitization. It is possible for a user to inject arbitrary commands to the "zipCmd" used within "config.... Read more
Affected Products : aws_lambda- Published: Jan. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-8297
A path traversal vulnerability exists in simple-file-manager before 2017-04-26, affecting index.php (the sole "Simple PHP File Manager" component).... Read more
Affected Products : simple-file-manager- Published: Apr. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-11076
Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request.... Read more
Affected Products : cribl- Published: Apr. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-11888
Go through 1.12.5 on Windows mishandles process creation with a nil environment in conjunction with a non-nil token, which allows attackers to obtain sensitive information or gain privileges.... Read more
- Published: May. 13, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17573
FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter.... Read more
Affected Products : ebay_clone- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-14485
BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.... Read more
Affected Products : blogengine.net- Published: May. 07, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14496
Vivotek FD8136 devices allow remote memory corruption and remote code execution because of a stack-based buffer overflow, related to sprintf, vlocal_buff_4326, and set_getparam.cgi. NOTE: The vendor has disputed this as a vulnerability and states that the... Read more
- Published: Jul. 10, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12150
Karamasoft UltimateEditor 1 does not ensure that an uploaded file is an image or document (neither file types nor extensions are restricted). The attacker must use the Attach icon to perform an upload. An uploaded file is accessible under the UltimateEdit... Read more
Affected Products : ultimateeditor- Published: May. 24, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17574
FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.... Read more
Affected Products : care_clone- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-12160
GoHTTP through 2017-07-25 has a sendHeader use-after-free.... Read more
Affected Products : gohttp- Published: May. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12271
Sandline Centraleyezer (On Premises) allows unrestricted File Upload with a dangerous type, because the feature of adding ".jpg" to any uploaded filename is not enforced on the server side.... Read more
Affected Products : centraleyezer- Published: Nov. 18, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12349
An issue was discovered in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id parameter.... Read more
Affected Products : zzcms- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12351
An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_print.php via an id parameter value with a trailing comma.... Read more
Affected Products : zzcms- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12377
A vulnerable upl/async_upload.asp web API endpoint in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 allows arbitrary file upload, which may lead to arbitrary remote code execution.... Read more
- Published: Jun. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-9615
Password exposure in Cognito Software Moneyworks 8.0.3 and earlier allows attackers to gain administrator access to all data, because verbose logging writes the administrator password to a world-readable file.... Read more
Affected Products : moneyworks- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-14826
Entes EMG12 versions 2.57 and prior The application uses a web interface where it is possible for an attacker to bypass authentication with a specially crafted URL. This could allow for remote code execution.... Read more
- Published: Oct. 02, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-9980
In Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, the "PING" (aka tag_ipPing) feature within the web interface allows performing command injection, via the "pip" parameter.... Read more
- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025