8.7

CVSS4.0

CVE-2019-25671 - VA MAX 8.3.4 Remote Code Execution via changeip.php

VA MAX 8.3.4 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the mtu_eth0 parameter. Attackers can send POST requests to the changeip.php endpoint with malicious payload in the mtu_eth0 field to …

πŸ“… Published: April 5, 2026, 8:45 p.m. πŸ”„ Last Modified: April 16, 2026, 4:15 p.m.

8.6

CVSS4.0

CVE-2019-25670 - River Past Video Cleaner 7.6.3 Buffer Overflow via SEH

River Past Video Cleaner 7.6.3 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the Lame_enc.dll field. Attackers can craft a payload with 280 bytes of padding, a next structured exception …

πŸ“… Published: April 5, 2026, 8:45 p.m. πŸ”„ Last Modified: April 27, 2026, 1:35 p.m.

8.8

CVSS4.0

CVE-2019-25669 - qdPM 9.1 SQL Injection via search_by_extrafields Parameter

qdPM 9.1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the search_by_extrafields[] parameter. Attackers can send POST requests to the users endpoint with malicious search_by_extrafields[] values to trigger SQL syntax error…

πŸ“… Published: April 5, 2026, 8:45 p.m. πŸ”„ Last Modified: April 10, 2026, 9:45 a.m.

8.8

CVSS4.0

CVE-2019-25668 - News Website Script 2.0.5 SQL Injection via index.php

News Website Script 2.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the news ID parameter. Attackers can send GET requests to index.php/show/news/ with malicious SQL statements to extract sensitive data…

πŸ“… Published: April 5, 2026, 8:45 p.m. πŸ”„ Last Modified: April 20, 2026, 6:21 p.m.

6.9

CVSS4.0

CVE-2019-25667 - TaskInfo 8.2.0.280 Denial of Service Buffer Overflow

TaskInfo 8.2.0.280 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying oversized input to registration fields. Attackers can paste excessively long strings into the New User Name or New Serial Number textboxes in the Help menu's registration di…

πŸ“… Published: April 5, 2026, 8:45 p.m. πŸ”„ Last Modified: April 20, 2026, 6:04 p.m.

6.9

CVSS4.0

CVE-2019-25666 - SpotAuditor 3.6.7 Denial of Service Buffer Overflow

SpotAuditor 3.6.7 contains a local buffer overflow vulnerability in the Base64 Password Decoder component that allows attackers to crash the application. Attackers can supply an oversized Base64 string through the decoder interface to trigger a denial of service condition.

πŸ“… Published: April 5, 2026, 8:45 p.m. πŸ”„ Last Modified: April 20, 2026, 6:05 p.m.

6.9

CVSS4.0

CVE-2019-25665 - River Past Ringtone Converter 2.7.6.1601 Buffer Overflow DoS

River Past Ringtone Converter 2.7.6.1601 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying oversized input to activation fields. Attackers can paste 300 bytes of data into the Email textbox and Activation code textarea via the Help menu's Act…

πŸ“… Published: April 5, 2026, 8:45 p.m. πŸ”„ Last Modified: April 27, 2026, 1:34 p.m.

7.1

CVSS4.0

CVE-2019-25664 - SuiteCRM 7.10.7 SQL Injection via record Parameter

SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record parameter of the Users module DetailView action that allows authenticated attackers to manipulate database queries. Attackers can append SQL code to the record parameter in GET requests to the index.php endpoint to extr…

πŸ“… Published: April 5, 2026, 8:45 p.m. πŸ”„ Last Modified: April 20, 2026, 6:11 p.m.

7.1

CVSS4.0

CVE-2019-25663 - SuiteCRM 7.10.7 SQL Injection via parentTab Parameter

SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the parentTab parameter. Attackers can send GET requests to the email module with malicious parentTab values using boolean-based SQL injection tech…

πŸ“… Published: April 5, 2026, 8:45 p.m. πŸ”„ Last Modified: April 20, 2026, 6:11 p.m.

8.8

CVSS4.0

CVE-2019-25662 - ResourceSpace 8.6 SQL Injection via watched_searches.php

ResourceSpace 8.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'ref' parameter. Attackers can send GET requests to the watched_searches.php endpoint with crafted SQL payloads to extract sensiti…

πŸ“… Published: April 5, 2026, 8:45 p.m. πŸ”„ Last Modified: April 15, 2026, 4:30 p.m.
Total resulsts: 349182
Page 681 of 34,919
Β« previous page Β» next page
Filters