Latest CVE Feed
-
9.8
CRITICALCVE-2018-13792
Multiple SQL injection vulnerabilities in the monitoring feature in the HTTP API in ABBYY FlexiCapture before 12 Release 2 allow an attacker to execute arbitrary SQL commands via the mask, sortOrder, filter, or Order parameter.... Read more
Affected Products : flexicapture- Published: Feb. 10, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13859
MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional before V9.34 build 13381 - 12.07.18, allow unauthorized remote attackers to reset the authentication via the "/xml/system/setAttribute.xml" URL, using the GET request "?id=0&a... Read more
- Published: Jul. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-8960
An Authentication Bypass vulnerability in HPE MSA 1040 and MSA 2040 SAN Storage IN version GL220P008 and earlier was found.... Read more
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-11682
A buffer overflow in the SMTP response service in MailCarrier 2.51 allows the attacker to execute arbitrary code remotely via a long HELP command, a related issue to CVE-2019-11395.... Read more
Affected Products : mailcarrier- Published: May. 02, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12147
The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special characters in the username field. Upon successful exploitation, a remote unauthenticated user can create a local system user with sudo ... Read more
- Published: Oct. 22, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12158
GoHTTP through 2017-07-25 has a GetExtension heap-based buffer overflow via a long extension.... Read more
Affected Products : gohttp- Published: May. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-9466
The executable httpd on the TP-Link WR841N V8 router before TL-WR841N(UN)_V8_170210 contained a design flaw in the use of DES for block encryption. This resulted in incorrect access control, which allowed attackers to gain read-write access to system sett... Read more
- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17587
FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or company/index.php c parameter.... Read more
Affected Products : indiamart_clone- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17594
DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter.... Read more
Affected Products : domainsale_php_script- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17597
Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter.... Read more
Affected Products : nearbuy_clone_script- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-12348
An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter.... Read more
Affected Products : zzcms- Published: May. 24, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14815
Fuji Electric V-Server 4.0.3.0 and prior, Several out-of-bounds write vulnerabilities have been identified, which may allow remote code execution.... Read more
- Published: Sep. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14822
Entes EMG12 versions 2.57 and prior an information exposure through query strings vulnerability in the web interface has been identified, which may allow an attacker to impersonate a legitimate user and execute arbitrary code.... Read more
- Published: Oct. 02, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-9730
SQL injection vulnerability in rdr.php in nuevoMailer version 6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the "r" parameter.... Read more
Affected Products : nuevomailer- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-12598
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 1 of 3).... Read more
Affected Products : suitecrm- Published: Jun. 07, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14925
Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegisecurity components.... Read more
Affected Products : banco- Published: Aug. 03, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12771
Command injection is possible in ThinStation through 6.1.1 via shell metacharacters after the cgi-bin/CdControl.cgi action= substring, or after the cgi-bin/VolControl.cgi OK= substring.... Read more
Affected Products : thinstation- Published: Jun. 07, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12850
A query injection was possible in JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49168.... Read more
Affected Products : youtrack- Published: Jul. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-13086
core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.... Read more
Affected Products : csz_cms- Published: Jun. 30, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-13116
The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections... Read more
Affected Products : mule_runtime- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024