8.8

CVSS4.0

CVE-2019-25439 - NoviSmart CMS SQL Injection via Referer HTTP Header

NoviSmart CMS contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the Referer HTTP header field. Attackers can craft requests with time-based SQL injection payloads in the Referer header to extract sensitive datab…

πŸ“… Published: Feb. 22, 2026, 1:34 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2019-25433 - XOOPS CMS 2.5.9 SQL Injection via gerar_pdf.php

XOOPS CMS 2.5.9 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cid parameter. Attackers can send GET requests to the gerar_pdf.php endpoint with malicious cid values to extract sensitive database informa…

πŸ“… Published: Feb. 22, 2026, 1:34 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2026-2947 - rymcu forest User Profile UserInfoController.java updateUserInfo cross site scripting

A vulnerability was detected in rymcu forest up to 0.0.5. This affects the function updateUserInfo of the file - src/main/java/com/rymcu/forest/web/api/user/UserInfoController.java of the component User Profile Handler. The manipulation results in cross site scripting. The attack can be executed re…

πŸ“… Published: Feb. 22, 2026, 1:32 p.m. πŸ”„ Last Modified: Feb. 25, 2026, 6:18 p.m.

8.8

CVSS4.0

CVE-2019-25452 - Dolibarr ERP/CRM 10.0.1 SQL Injection via elemid

Dolibarr ERP/CRM 10.0.1 contains an SQL injection vulnerability in the elemid POST parameter of the viewcat.php endpoint that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted POST requests with malicious SQL payloads in the elemid parameter to extract …

πŸ“… Published: Feb. 22, 2026, 1:18 p.m. πŸ”„ Last Modified: April 7, 2026, 2:04 p.m.

7.1

CVSS4.0

CVE-2019-25450 - Dolibarr ERP/CRM 10.0.1 SQL Injection via card.php

Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through POST parameters. Attackers can inject malicious SQL through parameters like actioncode, demand_reason_id, and availability_id in ca…

πŸ“… Published: Feb. 22, 2026, 1:18 p.m. πŸ”„ Last Modified: April 7, 2026, 2:04 p.m.

8.8

CVSS4.0

CVE-2019-25446 - DIGIT CENTRIS ERP Every version SQL Injection via datum1 Parameter

DIGIT CENTRIS ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the datum1, datum2, KID, and PID parameters. Attackers can send POST requests to /korisnikinfo.php with malicious SQL syntax in these paramete…

πŸ“… Published: Feb. 22, 2026, 1:18 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2019-25443 - Inventory Webapp SQL Injection via add-item.php

Inventory Webapp contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through GET parameters. Attackers can supply malicious SQL payloads in the name, description, quantity, or cat_id parameters to add-item.php to execute…

πŸ“… Published: Feb. 22, 2026, 1:18 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2019-25442 - Web Wiz Forums 12.01 SQL Injection via PF Parameter

Web Wiz Forums 12.01 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the PF parameter. Attackers can send GET requests to member_profile.asp with malicious PF values to extract sensitive database information.

πŸ“… Published: Feb. 22, 2026, 1:18 p.m. πŸ”„ Last Modified: April 7, 2026, 2:04 p.m.

5.1

CVSS4.0

CVE-2026-2946 - rymcu forest Article Content/Comments/Portfolio XssUtils.java XssUtils.replaceHtmlCode cross site s…

A security vulnerability has been detected in rymcu forest up to 0.0.5. Affected by this issue is the function XssUtils.replaceHtmlCode of the file src/main/java/com/rymcu/forest/util/XssUtils.java of the component Article Content/Comments/Portfolio. The manipulation leads to cross site scripting. …

πŸ“… Published: Feb. 22, 2026, 1:02 p.m. πŸ”„ Last Modified: Feb. 25, 2026, 6:34 p.m.

5.3

CVSS4.0

CVE-2026-2945 - JeecgBoot uploadImgByHttp server-side request forgery

A weakness has been identified in JeecgBoot 3.9.0. Affected by this vulnerability is an unknown functionality of the file /sys/common/uploadImgByHttp. Executing a manipulation of the argument fileUrl can lead to server-side request forgery. The attack may be launched remotely. The exploit has been …

πŸ“… Published: Feb. 22, 2026, 1:02 p.m. πŸ”„ Last Modified: March 3, 2026, 12:24 a.m.
Total resulsts: 344718
Page 1046 of 34,472
Β« previous page Β» next page
Filters