8.8

CVSS4.0

CVE-2018-25203 - Online Store System CMS 1.0 SQL Injection via clientaccess

Online Store System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter. Attackers can send POST requests to index.php with the action=clientaccess parameter using boolean-based blind …

πŸ“… Published: March 26, 2026, 11:39 a.m. πŸ”„ Last Modified: March 27, 2026, 9:28 a.m.

8.8

CVSS4.0

CVE-2018-25202 - SAT CFDI 3.3 SQL Injection via signIn endpoint

SAT CFDI 3.3 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id' parameter in the signIn endpoint. Attackers can submit POST requests with boolean-based blind, stacked queries, or time-based blind SQL injection payloads…

πŸ“… Published: March 26, 2026, 11:39 a.m. πŸ”„ Last Modified: March 27, 2026, 8:36 a.m.

7.1

CVSS4.0

CVE-2018-25201 - School Management System CMS 1.0 Admin Login SQL Injection

School Management System CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can submit malicious payloads using boolean-based blind SQL injection techniques t…

πŸ“… Published: March 26, 2026, 11:39 a.m. πŸ”„ Last Modified: March 29, 2026, 8:27 p.m.

8.8

CVSS4.0

CVE-2018-25195 - Wecodex Hotel CMS 1.0 SQL Injection via Admin Login

Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticated attackers to bypass authentication by injecting SQL code. Attackers can submit malicious SQL payloads through the username parameter in POST requests to index.php with action=p…

πŸ“… Published: March 26, 2026, 11:39 a.m. πŸ”„ Last Modified: March 29, 2026, 8:27 p.m.

8.8

CVSS4.0

CVE-2018-25185 - Wecodex Restaurant CMS 1.0 SQL Injection via Login

Wecodex Restaurant CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the username parameter. Attackers can send POST requests to the login endpoint with malicious SQL payloads using boolean-based blind …

πŸ“… Published: March 26, 2026, 11:39 a.m. πŸ”„ Last Modified: March 29, 2026, 8:27 p.m.

8.8

CVSS4.0

CVE-2018-25183 - Shipping System CMS 1.0 SQL Injection via admin login

Shipping System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can submit malicious SQL payloads using boolean-based blind techniques in POST requests to the admin login e…

πŸ“… Published: March 26, 2026, 11:39 a.m. πŸ”„ Last Modified: March 27, 2026, 8:26 p.m.

8.7

CVSS4.0

CVE-2025-41368 - Multiple vulnerabilities in Small HTTP server by Smallsrv

Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended restrictions of SecurityManager and display any file if they have the appropriate permissions outside the document root configured on the server.

πŸ“… Published: March 26, 2026, 11:37 a.m. πŸ”„ Last Modified: March 27, 2026, 9:28 a.m.

6.1

CVSS3.1

CVE-2026-4887 - Gimp: gimp:memory disclosure and denial of service via specially crafted pcx image

A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible a…

πŸ“… Published: March 26, 2026, 11:35 a.m. πŸ”„ Last Modified: April 22, 2026, 8:57 a.m.

9.3

CVSS4.0

CVE-2026-4809 - Unsafe Client MIME Type Handling Can Enable Arbitrary File Upload in plank/laravel-mediable

plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote attacker can submit a file containing executable PHP code while de…

πŸ“… Published: March 26, 2026, 11:03 a.m. πŸ”„ Last Modified: March 27, 2026, 8:36 a.m.

8.8

CVSS3.1

CVE-2026-24068 - Missing XPC Client & NSXPC endpoint validation leads to privilege escalation in Vienna Assistant (M…

The VSL privileged helper does utilize NSXPC for IPC. The implementation of the "shouldAcceptNewConnection" function, which is used by the NSXPC framework to validate if a client should be allowed to connect to the XPC listener, does not validate clients at all.Β This means that any process can conn…

πŸ“… Published: March 26, 2026, 10:55 a.m. πŸ”„ Last Modified: April 3, 2026, 6:16 a.m.
Total resulsts: 349182
Page 863 of 34,919
Β« previous page Β» next page
Filters