8.8

CVSS4.0

CVE-2018-25197 - PlayJoom 0.10.1 SQL Injection via catid Parameter

PlayJoom 0.10.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the catid parameter. Attackers can send GET requests to index.php with option=com_playjoom&view=genre&catid=[SQL] to extract sensitive dโ€ฆ

๐Ÿ“… Published: March 6, 2026, 12:19 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 2:53 p.m.

8.8

CVSS4.0

CVE-2018-25196 - ServerZilla 1.0 SQL Injection via email Parameter

ServerZilla 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter. Attackers can send POST requests to reset.php with malicious email values containing SQL operators to bypass authenticationโ€ฆ

๐Ÿ“… Published: March 6, 2026, 12:19 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 2:53 p.m.

8.8

CVSS4.0

CVE-2018-25194 - Nominas 0.27 SQL Injection via username Parameter

Nominas 0.27 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the username parameter. Attackers can send POST requests to the login/checklogin.php endpoint with crafted UNION-based SQL injection payloaโ€ฆ

๐Ÿ“… Published: March 6, 2026, 12:19 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 2:53 p.m.

8.7

CVSS4.0

CVE-2018-25193 - Mongoose Web Server 6.9 Denial of Service via Socket Connection

Mongoose Web Server 6.9 contains a denial of service vulnerability that allows remote attackers to crash the service by establishing multiple socket connections. Attackers can repeatedly create connections to the default port and send malformed data to exhaust server resources and cause service unaโ€ฆ

๐Ÿ“… Published: March 6, 2026, 12:19 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 2:53 p.m.

8.8

CVSS4.0

CVE-2018-25192 - GPS Tracking System 2.12 SQL Injection via username Parameter

GPS Tracking System 2.12 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can submit crafted POST requests to the login.php endpoint with SQL injection payloads in the username fielโ€ฆ

๐Ÿ“… Published: March 6, 2026, 12:19 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 2:53 p.m.

7.1

CVSS4.0

CVE-2018-25191 - Facturation System 1.0 SQL Injection via editar_producto.php

Facturation System 1.0 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'mod_id' parameter. Attackers can send POST requests to the editar_producto.php endpoint with crafted SQL payloads in the mod_iโ€ฆ

๐Ÿ“… Published: March 6, 2026, 12:19 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 2:53 p.m.

6.9

CVSS4.0

CVE-2018-25190 - Easyndexer 1.0 Cross-Site Request Forgery via createuser.php

Easyndexer 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative accounts by submitting forged POST requests. Attackers can craft malicious web pages that submit POST requests to createuser.php with parameters including username, passโ€ฆ

๐Ÿ“… Published: March 6, 2026, 12:19 p.m. ๐Ÿ”„ Last Modified: March 16, 2026, 7:06 p.m.

8.8

CVSS4.0

CVE-2018-25189 - Data Center Audit 2.6.2 SQL Injection via username Parameter

Data Center Audit 2.6.2 contains an SQL injection vulnerability in the username parameter of dca_login.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted SQL payloads through POST requests to extract sensitive database information including userโ€ฆ

๐Ÿ“… Published: March 6, 2026, 12:19 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 2:53 p.m.

8.8

CVSS4.0

CVE-2018-25188 - Webiness Inventory 2.3 SQL Injection via WsModelGrid.php

Webiness Inventory 2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the order parameter. Attackers can send POST requests to the WsModelGrid.php endpoint with crafted SQL payloads to extract sensitโ€ฆ

๐Ÿ“… Published: March 6, 2026, 12:19 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 2:53 p.m.

8.8

CVSS4.0

CVE-2018-25187 - Tina4 Stack 1.0.3 SQL Injection and Database File Download

Tina4 Stack 1.0.3 contains multiple vulnerabilities allowing unauthenticated attackers to access sensitive database files and execute SQL injection attacks. Attackers can directly request the kim.db database file to retrieve user credentials and password hashes, or inject SQL code through the menu โ€ฆ

๐Ÿ“… Published: March 6, 2026, 12:19 p.m. ๐Ÿ”„ Last Modified: March 16, 2026, 7:12 p.m.
Total resulsts: 346581
Page 1016 of 34,659
ยซ previous page ยป next page
Filters