6.9

CVSS4.0

CVE-2026-4528 - trueleaf ApiFlow URL Validation http_proxy.service.ts validateUrlSecurity server-side request forge…

A vulnerability was determined in trueleaf ApiFlow 0.9.7. The impacted element is the function validateUrlSecurity of the file packages/server/src/service/proxy/http_proxy.service.ts of the component URL Validation Handler. This manipulation causes server-side request forgery. Remote exploitation o…

πŸ“… Published: March 21, 2026, 10:02 p.m. πŸ”„ Last Modified: April 24, 2026, 4:31 p.m.

2.3

CVSS4.0

CVE-2026-2756 - OmniPEMF NeoRhythm BLE missing authentication

A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication. The attack can only be initiated within the local network. This attack is characterized by high comple…

πŸ“… Published: March 21, 2026, 5:32 p.m. πŸ”„ Last Modified: April 24, 2026, 4:31 p.m.

7.1

CVSS4.0

CVE-2019-25582 - i-doit CMDB 1.12 Arbitrary File Download via file_manager Parameter

i-doit CMDB 1.12 contains an arbitrary file download vulnerability that allows authenticated attackers to download sensitive files by manipulating the file parameter in index.php. Attackers can send GET requests to index.php with file_manager=image and supply arbitrary file paths like src/config.in…

πŸ“… Published: March 21, 2026, 3:30 p.m. πŸ”„ Last Modified: March 25, 2026, 2:47 p.m.

8.8

CVSS4.0

CVE-2019-25581 - i-doit CMDB 1.12 SQL Injection via objGroupID Parameter

i-doit CMDB 1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the objGroupID parameter. Attackers can send GET requests with crafted SQL payloads in the objGroupID parameter to extract sensitive da…

πŸ“… Published: March 21, 2026, 3:30 p.m. πŸ”„ Last Modified: March 25, 2026, 2:47 p.m.

8.8

CVSS4.0

CVE-2019-25580 - ownDMS 4.7 SQL Injection via pdfstream.php imagestream.php

ownDMS 4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the IMG parameter. Attackers can send GET requests to pdfstream.php, imagestream.php, or anyfilestream.php with crafted SQL payloads in the I…

πŸ“… Published: March 21, 2026, 3:30 p.m. πŸ”„ Last Modified: April 15, 2026, 4:49 p.m.

8.7

CVSS4.0

CVE-2019-25579 - phpTransformer 2016.9 Directory Traversal via jQueryFileUpload

phpTransformer 2016.9 contains a directory traversal vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the path parameter. Attackers can send requests to the jQueryFileUploadmaster server endpoint with traversal sequences ../../../../../../ to list and re…

πŸ“… Published: March 21, 2026, 3:30 p.m. πŸ”„ Last Modified: April 22, 2026, 3:45 a.m.

8.8

CVSS4.0

CVE-2019-25578 - phpTransformer 2016.9 SQL Injection via GeneratePDF.php

phpTransformer 2016.9 contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the idnews parameter. Attackers can send crafted GET requests to GeneratePDF.php with SQL payloads in the idnews parameter to extract sensi…

πŸ“… Published: March 21, 2026, 3:30 p.m. πŸ”„ Last Modified: March 27, 2026, 9:21 a.m.

6.8

CVSS4.0

CVE-2019-25577 - SeoToaster Ecommerce 3.0.0 Local File Inclusion via backend_theme

SeoToaster Ecommerce 3.0.0 contains a local file inclusion vulnerability that allows authenticated attackers to read arbitrary files by manipulating path parameters in backend theme endpoints. Attackers can send POST requests to /backend/backend_theme/editcss/ or /backend/backend_theme/editjs/ with…

πŸ“… Published: March 21, 2026, 3:30 p.m. πŸ”„ Last Modified: April 15, 2026, 4:57 p.m.

8.8

CVSS4.0

CVE-2019-25576 - Kepler Wallpaper Script 1.1 SQL Injection via category

Kepler Wallpaper Script 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the category parameter. Attackers can send GET requests to the category endpoint with URL-encoded SQL UNION statements to extra…

πŸ“… Published: March 21, 2026, 3:30 p.m. πŸ”„ Last Modified: April 15, 2026, 5:07 p.m.

8.8

CVSS4.0

CVE-2019-25575 - SimplePress CMS 1.0.7 SQL Injection via p and s Parameters

SimplePress CMS 1.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'p' and 's' parameters. Attackers can send GET requests with crafted SQL payloads to extract sensitive database information in…

πŸ“… Published: March 21, 2026, 3:30 p.m. πŸ”„ Last Modified: April 15, 2026, 5:09 p.m.
Total resulsts: 348775
Page 948 of 34,878
Β« previous page Β» next page
Filters