Latest CVE Feed
-
9.8
CRITICALCVE-2017-9980
In Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, the "PING" (aka tag_ipPing) feature within the web interface allows performing command injection, via the "pip" parameter.... Read more
- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-15387
A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. The vulnerability is due to improper certificate validation. An attacker could exploit this vulnerability ... Read more
- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17611
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.... Read more
Affected Products : doctor_search_script- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17671
vBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an unauthenticated request that can include directory traversal sequences to specify an arbitrary pathname, and because ../ traversal is bloc... Read more
- Published: Dec. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-15681
An issue was discovered in BTITeam XBTIT 2.5.4. When a user logs in, their password hash is rehashed using a predictable salt and stored in the "pass" cookie, which is not flagged as HTTPOnly. Due to the weak and predictable salt that is in place, an atta... Read more
Affected Products : xbtit- Published: Sep. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-13187
The Rich Text Formatter (Redactor) extension through v1.1.1 for Symphony CMS has an Unauthenticated arbitrary file upload vulnerability in content.fileupload.php and content.imageupload.php.... Read more
Affected Products : rich_text_formatter- Published: Sep. 05, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-13292
A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it is deserialized. Then, this deserialized data goes directly into a SQL query, with no sanitizing checks.... Read more
Affected Products : weberp- Published: Jul. 04, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-2473
The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 27777501.... Read more
Affected Products : android- Published: Jun. 13, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2017-17766
In wma_peer_info_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-03, the value of num_peers received from firmware is not properly validated so that an integer overflow vulnerability in the size of a buffer allocatio... Read more
Affected Products : android- Published: Mar. 30, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-1465
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping parameter, as demonstrated by modifying the application configuration using the ... Read more
Affected Products : cubecart- Published: Feb. 08, 2013
- Modified: Apr. 11, 2025
-
9.8
CRITICALCVE-2018-16159
The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request.... Read more
Affected Products : gift_vouchers- Published: Aug. 30, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-16354
An issue was discovered in FHCRM through 2018-02-11. There is a SQL injection via the index.php/User/read limit parameter.... Read more
Affected Products : fhcrm- Published: Sep. 02, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17873
Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.... Read more
Affected Products : marketplace_digital_products_php- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-10085
CMS Made Simple (CMSMS) through 2.2.6 allows PHP object injection because of an unserialize call in the _get_data function of \lib\classes\internal\class.LoginOperations.php. By sending a crafted cookie, a remote attacker can upload and execute code, or d... Read more
Affected Products : cms_made_simple- Published: Apr. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17110
Simple POS 4.0.24 allows SQL Injection via a products/get_products/ columns[0][search][value] parameter in the management panel, as demonstrated by products/get_products/1.... Read more
Affected Products : simple_pos- Published: Sep. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17172
The web application on Xerox AltaLink B80xx before 100.008.028.05200, C8030/C8035 before 100.001.028.05200, C8045/C8055 before 100.002.028.05200, and C8070 before 100.003.028.05200 allows unauthenticated command injection.... Read more
- Published: Jan. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17228
nmap4j 1.1.0 allows attackers to execute arbitrary commands via shell metacharacters in an includeHosts call.... Read more
Affected Products : nmap4j- Published: Sep. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17381
SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter.... Read more
Affected Products : dutch_auction_factory- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10617
Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length heap buffer where a value larger than the buffer can be read from a .dpa file into the buffer, causing the buffer to be overwritten. This may allow rem... Read more
Affected Products : delta_industrial_automation_dopsoft- Published: Jun. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10653
There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.... Read more
Affected Products : xenmobile_server- Published: May. 23, 2018
- Modified: Nov. 21, 2024