8.8
CVE-2019-25488 - Jettweb Hazir Rent A Car Scripti V4 SQL Injection via admin
Jettweb Hazir Rent A Car Scripti V4 contains multiple SQL injection vulnerabilities in the admin panel that allow unauthenticated attackers to manipulate database queries through GET parameters. Attackers can inject SQL code into the 'tur', 'id', and 'ozellikdil' parameters of the admin/index.php eβ¦
8.8
CVE-2019-25482 - Jettweb PHP Hazir Rent A Car Sitesi Scripti V2 SQL Injection
Jettweb PHP Hazir Rent A Car Sitesi Scripti V2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the arac_kategori_id parameter. Attackers can send POST requests to the endpoint with malicious SQL payloads to eβ¦
8.8
CVE-2019-25481 - iScripts ReserveLogic Lastest SQL Injection via search endpoint
iScripts ReserveLogic contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the jqSearchDestination parameter. Attackers can send POST requests to the search endpoint with crafted SQL payloads to extract sensitive β¦
8.8
CVE-2019-25479 - Inout RealEstate Lastest SQL Injection via agentlistdetails
Inout RealEstate contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the city parameter. Attackers can send POST requests to the agents/agentlistdetails endpoint with malicious SQL payloads in the city parameter β¦
7.1
CVE-2019-25473 - Clinic Pro SQL Injection via monthly_expense_overview month Parameter
Clinic Pro contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the month parameter. Attackers can send POST requests to the monthly_expense_overview endpoint with crafted month values using boolean-based blind, timeβ¦
5.1
CVE-2026-4044 - projectsend Delete import-orphans.php realpath path traversal
A vulnerability was detected in projectsend up to r1945. This affects the function realpath of the file /import-orphans.php of the component Delete Handler. Performing a manipulation of the argument files[] results in path traversal. Remote exploitation of the attack is possible. The exploit is nowβ¦
8.7
CVE-2026-4043 - Tenda i12 wifiSSIDget formwrlSSIDget stack-based overflow
A security vulnerability has been detected in Tenda i12 1.0.0.6(2204). The impacted element is the function formwrlSSIDget of the file /goform/wifiSSIDget. Such manipulation of the argument index leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosβ¦
8.8
CVE-2026-21668 -
A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.
10
CVE-2026-21669 -
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
9.1
CVE-2026-21671 -
A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.