Latest CVE Feed
-
9.8
CRITICALCVE-2019-13086
core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.... Read more
Affected Products : csz_cms- Published: Jun. 30, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-13116
The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections... Read more
Affected Products : mule_runtime- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-13131
Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitrary commands via NRPE.... Read more
Affected Products : superdoctor_5- Published: Jul. 01, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0181
A vulnerability in the Redis implementation used by the Cisco Policy Suite for Mobile and Cisco Policy Suite Diameter Routing Agent software could allow an unauthenticated, remote attacker to modify key-value pairs for short-lived events stored by the Red... Read more
Affected Products : policy_suite cisco_policy_suite_diameter_routing_agent cisco_policy_suite_for_mobile- Published: Jan. 10, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17779
Paid To Read Script 2.0.5 has SQL injection via the referrals.php id parameter.... Read more
Affected Products : paid_to_read_script- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-2555
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.... Read more
Affected Products : atutor- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-13973
LayerBB 1.1.3 allows admin/general.php arbitrary file upload because the custom_logo filename suffix is not restricted, and .php may be used.... Read more
Affected Products : layerbb- Published: Jul. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17872
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.... Read more
Affected Products : jextn_video_gallery- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17906
PHP Scripts Mall Car Rental Script has SQL Injection via the admin/carlistedit.php carid parameter.... Read more
Affected Products : car_rental_script- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-16762
FUEL CMS 1.4.1 allows SQL Injection via the layout, published, or search_term parameter to pages/items.... Read more
Affected Products : fuel_cms- Published: Sep. 09, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-14237
On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by observing CPU registers and the effect of code/instruction execution.... Read more
Affected Products : kinetis_kv1x_firmware kinetis_kv3x_firmware kinetis_k8x_firmware kinetis_kv1x kinetis_kv3x kinetis_k8x- Published: Sep. 12, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17243
Global Search in Zoho ManageEngine OpManager before 12.3 123205 allows SQL Injection.... Read more
Affected Products : manageengine_opmanager- Published: Sep. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17382
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.... Read more
Affected Products : jobs_factory- Published: Sep. 28, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-14695
A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com/libs/Table.php... Read more
Affected Products : popup_builder- Published: Aug. 06, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17831
In REDAXO before 5.6.3, a critical SQL injection vulnerability has been discovered in the rex_list class because of the prepareQuery function in core/lib/list.php, via the index.php?page=users/users sort parameter. Endangered was the backend and the front... Read more
Affected Products : redaxo- Published: Oct. 01, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18375
goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the rand parameter.... Read more
- Published: Oct. 16, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11511
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI.... Read more
- Published: Aug. 16, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11545
md4c 0.2.5 has a heap-based buffer overflow in md_merge_lines because md_is_link_label mishandles the case of a link label composed solely of backslash escapes.... Read more
Affected Products : md4c- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18546
ThinkPHP 3.2.4 has SQL Injection via the order parameter because the Library/Think/Db/Driver.class.php parseOrder function mishandles the key variable.... Read more
Affected Products : thinkphp- Published: Oct. 21, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15574
Gesior-AAC before 2019-05-01 allows serviceID SQL injection in accountmanagement.php.... Read more
Affected Products : gesior-aac- Published: Aug. 26, 2019
- Modified: Nov. 21, 2024