2

CVSS4.0

CVE-2026-21619 - Unsafe Deserialization of Erlang Terms in hex_core

Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.…

πŸ“… Published: Feb. 27, 2026, 5:57 p.m. πŸ”„ Last Modified: April 16, 2026, midnight

8.8

CVSS4.0

CVE-2019-25497 - osCommerce 2.3.4.1 SQL Injection via currency Parameter

osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the currency parameter. Attackers can send GET requests to shopping_cart.php with malicious currency values using boolean-based SQL injection …

πŸ“… Published: Feb. 27, 2026, 5:23 p.m. πŸ”„ Last Modified: April 7, 2026, 2:04 p.m.

8.8

CVSS4.0

CVE-2019-25496 - osCommerce 2.3.4.1 SQL Injection via products_id Parameter

osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the products_id parameter. Attackers can modify the products_id value in product_info.php requests and append boolean-based SQL injection payl…

πŸ“… Published: Feb. 27, 2026, 5:23 p.m. πŸ”„ Last Modified: April 7, 2026, 2:04 p.m.

8.8

CVSS4.0

CVE-2019-25495 - osCommerce 2.3.4.1 SQL Injection via reviews_id Parameter

osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the reviews_id parameter. Attackers can send GET requests to product_reviews_write.php with malicious reviews_id values using boolean-based SQ…

πŸ“… Published: Feb. 27, 2026, 5:23 p.m. πŸ”„ Last Modified: April 7, 2026, 2:04 p.m.

8.8

CVSS4.0

CVE-2019-25494 - Homey BNB V4 SQL Injection Authentication Bypass via Admin Panel

Homey BNB V4 contains an SQL injection vulnerability in the administration panel login that allows unauthenticated attackers to bypass authentication by injecting SQL syntax into username and password fields. Attackers can submit SQL operators like '=' 'or' in both credentials to manipulate the aut…

πŸ“… Published: Feb. 27, 2026, 5:23 p.m. πŸ”„ Last Modified: April 7, 2026, 2:04 p.m.

8.8

CVSS4.0

CVE-2019-25493 - Homey BNB V4 SQL Injection via getrecord.php

Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'val' parameter. Attackers can send GET requests to the admin/getrecord.php endpoint with malicious 'val' values to extract sensitive database …

πŸ“… Published: Feb. 27, 2026, 5:23 p.m. πŸ”„ Last Modified: April 7, 2026, 2:04 p.m.

8.8

CVSS4.0

CVE-2019-25492 - Homey BNB V4 SQL Injection via getcmsdata.php

Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'pt' parameter. Attackers can send GET requests to the admin/getcmsdata.php endpoint with malicious 'pt' values to extract sensitive database i…

πŸ“… Published: Feb. 27, 2026, 5:23 p.m. πŸ”„ Last Modified: April 7, 2026, 2:04 p.m.

8.8

CVSS4.0

CVE-2019-25491 - Homey BNB V4 SQL Injection via cms_getpagetitle.php

Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the catid parameter. Attackers can send GET requests to the admin/cms_getpagetitle.php endpoint with malicious catid values to extract sensitive da…

πŸ“… Published: Feb. 27, 2026, 5:23 p.m. πŸ”„ Last Modified: April 7, 2026, 2:04 p.m.

8.8

CVSS4.0

CVE-2019-25490 - Homey BNB V4 SQL Injection via admin edit.php

Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'id' parameter. Attackers can send GET requests to the admin/edit.php endpoint with time-based SQL injection payloads to extract sensitive datab…

πŸ“… Published: Feb. 27, 2026, 5:23 p.m. πŸ”„ Last Modified: April 7, 2026, 2:04 p.m.

8.8

CVSS4.0

CVE-2019-25489 - Homey BNB V4 SQL Injection via ajax_refresh_subtotal

Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the hosting_id parameter. Attackers can send GET requests to the rooms/ajax_refresh_subtotal endpoint with malicious hosting_id values to extract se…

πŸ“… Published: Feb. 27, 2026, 5:23 p.m. πŸ”„ Last Modified: April 7, 2026, 2:04 p.m.
Total resulsts: 349182
Page 1403 of 34,919
Β« previous page Β» next page
Filters