8.8

CVSS4.0

CVE-2019-25702 - Kados R10 GreenBee SQL Injection via id_project Parameter

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_project parameter. Attackers can send crafted requests with malicious SQL statements in the id_project parameter to extract sensitive database informa…

📅 Published: April 5, 2026, 8:45 p.m. 🔄 Last Modified: April 5, 2026, 8:45 p.m.

8.8

CVSS4.0

CVE-2019-25700 - Kados R10 GreenBee SQL Injection via sort_direction Parameter

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the sort_direction parameter. Attackers can submit malicious SQL statements in the sort_direction parameter to extract sensitive database information or modi…

📅 Published: April 5, 2026, 8:45 p.m. 🔄 Last Modified: April 5, 2026, 8:45 p.m.

8.8

CVSS4.0

CVE-2019-25698 - Kados R10 GreenBee SQL Injection via id_to_delete Parameter

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_to_delete parameter. Attackers can send crafted requests with malicious SQL statements in the id_to_delete field to extract or modify sensitive databa…

📅 Published: April 5, 2026, 8:45 p.m. 🔄 Last Modified: April 5, 2026, 8:45 p.m.

8.8

CVSS4.0

CVE-2019-25696 - Kados R10 GreenBee SQL Injection via language_tag Parameter

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the language_tag parameter. Attackers can submit malicious SQL statements in the language_tag parameter to extract sensitive database information or modify d…

📅 Published: April 5, 2026, 8:45 p.m. 🔄 Last Modified: April 5, 2026, 8:45 p.m.

8.8

CVSS4.0

CVE-2019-25694 - Kados R10 GreenBee SQL Injection via user2reset

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user2reset parameter. Attackers can send crafted requests with malicious SQL payloads to extract sensitive database information or modify…

📅 Published: April 5, 2026, 8:45 p.m. 🔄 Last Modified: April 5, 2026, 8:45 p.m.

8.8

CVSS4.0

CVE-2019-25692 - Kados R10 GreenBee SQL Injection via id_to_modify Parameter

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id_to_modify' parameter. Attackers can send crafted requests with malicious SQL statements in the id_to_modify field to extract sensitive database infor…

📅 Published: April 5, 2026, 8:45 p.m. 🔄 Last Modified: April 5, 2026, 8:45 p.m.

8.8

CVSS4.0

CVE-2019-25690 - Kados R10 GreenBee SQL Injection via mng_profile_id

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the mng_profile_id parameter. Attackers can send crafted requests with malicious SQL payloads in the mng_profile_id parameter to extract sensitive database i…

📅 Published: April 5, 2026, 8:45 p.m. 🔄 Last Modified: April 5, 2026, 8:45 p.m.

8.8

CVSS4.0

CVE-2019-25688 - Kados R10 GreenBee SQL Injection via menu_lev1 Parameter

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the menu_lev1 parameter. Attackers can send crafted requests with malicious SQL payloads in the menu_lev1 parameter to extract sensitive data…

📅 Published: April 5, 2026, 8:45 p.m. 🔄 Last Modified: April 5, 2026, 8:45 p.m.

9.3

CVSS4.0

CVE-2019-25687 - Pegasus CMS 1.0 Remote Code Execution via extra_fields.php

Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated attackers to execute arbitrary commands by exploiting unsafe eval functionality. Attackers can send POST requests to the submit.php endpoint with malicious PHP code in the actio…

📅 Published: April 5, 2026, 8:45 p.m. 🔄 Last Modified: April 5, 2026, 8:45 p.m.

8.7

CVSS4.0

CVE-2019-25686 - Core FTP 2.0 build 653 PBSZ Unauthenticated Denial of Service

Core FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attackers to crash the service by sending a malformed command with an oversized buffer. Attackers can send a PBSZ command with a payload exceeding 211 bytes to trigger an access violati…

📅 Published: April 5, 2026, 8:45 p.m. 🔄 Last Modified: April 5, 2026, 8:45 p.m.
Total resulsts: 342367
Page 2 of 34,237
« previous page » next page
Filters