Latest CVE Feed
-
9.8
CRITICALCVE-2018-7477
SQL Injection exists in PHP Scripts Mall School Management Script 3.0.4 via the Username and Password fields to parents/Parent_module/parent_login.php.... Read more
Affected Products : school_management_script- Published: Feb. 28, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1000554
Trovebox version <= 4.0.0-rc6 contains a Unsafe password reset token generation vulnerability in user component that can result in Password reset. This attack appear to be exploitable via HTTP request. This vulnerability appears to have been fixed in afte... Read more
Affected Products : trovebox- Published: Jun. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-2034
SQL injection vulnerability in ClearPass Policy Manager 6.5.x through 6.5.6 and 6.6.0.... Read more
Affected Products : clearpass- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5358
Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbitrary code via the server argument to the (1) i5_connect, (2) i5_pconnect, or (3) i5_private_connect API function.... Read more
Affected Products : easycom_for_php- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-10284
Adaltech G-Ticket v70 EME104 has SQL Injection via the mobile-loja/mensagem.asp eve_cod parameter.... Read more
Affected Products : g-ticket- Published: Apr. 21, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-9580
A Elevation of privilege vulnerability in the HTC bootloader. Product: Android. Versions: Android kernel. Android ID: A-76222002.... Read more
Affected Products : android- Published: Nov. 14, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-9847
In Gxlcms QY v1.0.0713, the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to execute arbitrary PHP code by placing this code into a template.... Read more
Affected Products : gxlcms_qy- Published: Apr. 07, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-6080
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protection mechanism involving HTTP Access-Control headers. To exploit the vulnerability, an attacker can send cross-domain requests directly t... Read more
Affected Products : zammad- Published: Mar. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-0172
A logic issue in Intel Unite(R) Client for Android prior to version 4.0 may allow a remote attacker to potentially enable escalation of privilege via network access.... Read more
Affected Products : unite- Published: May. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-1010009
DGLogik Inc DGLux Server All Versions is affected by: Insecure Permissions. The impact is: Remote Execution, Credential Leaks. The component is: IoT API. The attack vector is: Any Accessible Server.... Read more
Affected Products : dglux_server- Published: Jul. 15, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-7405
On the D-Link DIR-615 before v20.12PTb04, once authenticated, this device identifies the user based on the IP address of his machine. By spoofing the IP address belonging to the victim's host, an attacker might be able to take over the administrative sess... Read more
- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-10104
In several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for Tomcat, Jetty, Resin, or CloudBees) with the default setting allowed a remote attacker to execute code when the configuration is running, because a JMX serv... Read more
Affected Products : intellij_idea- Published: Jul. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-7464
It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for parsing.... Read more
Affected Products : jboss_enterprise_application_platform- Published: Jul. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-7581
SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.... Read more
Affected Products : news_system- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7974
A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can execute arbitrary code and exfiltrate files.... Read more
Affected Products : u.motion_builder- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8015
EMC AppSync (all versions prior to 3.5) contains a SQL injection vulnerability that could potentially be exploited by malicious users to compromise the affected system.... Read more
Affected Products : appsync- Published: Sep. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-10776
In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. This affects git-diff-apply all versions prior to 0.22.2.... Read more
Affected Products : git-diff-apply- Published: Jan. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7679
Micro Focus Solutions Business Manager versions prior to 11.4 when ASP.NET is configured with execute permission on the virtual directories and does not validate the contents of user avatar images, could lead to remote code execution.... Read more
Affected Products : solutions_business_manager- Published: Jun. 21, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-11362
app/controllers/frontend/PostController.php in ROCBOSS V2.2.1 has SQL injection via the Post:doReward score paramter, as demonstrated by the /do/reward/3 URI.... Read more
Affected Products : rocboss- Published: Apr. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-8789
An issue was discovered on Accellion FTA devices before FTA_9_12_180. A report_error.php?year='payload SQL injection vector exists.... Read more
Affected Products : file_transfer_appliance- Published: May. 05, 2017
- Modified: Apr. 20, 2025