8.8

CVSS4.0

CVE-2019-25494 - Homey BNB V4 SQL Injection Authentication Bypass via Admin Panel

Homey BNB V4 contains an SQL injection vulnerability in the administration panel login that allows unauthenticated attackers to bypass authentication by injecting SQL syntax into username and password fields. Attackers can submit SQL operators like '=' 'or' in both credentials to manipulate the aut…

πŸ“… Published: Feb. 27, 2026, 5:23 p.m. πŸ”„ Last Modified: April 7, 2026, 2:04 p.m.

8.8

CVSS4.0

CVE-2019-25493 - Homey BNB V4 SQL Injection via getrecord.php

Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'val' parameter. Attackers can send GET requests to the admin/getrecord.php endpoint with malicious 'val' values to extract sensitive database …

πŸ“… Published: Feb. 27, 2026, 5:23 p.m. πŸ”„ Last Modified: April 7, 2026, 2:04 p.m.

8.8

CVSS4.0

CVE-2019-25492 - Homey BNB V4 SQL Injection via getcmsdata.php

Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'pt' parameter. Attackers can send GET requests to the admin/getcmsdata.php endpoint with malicious 'pt' values to extract sensitive database i…

πŸ“… Published: Feb. 27, 2026, 5:23 p.m. πŸ”„ Last Modified: April 7, 2026, 2:04 p.m.

8.8

CVSS4.0

CVE-2019-25491 - Homey BNB V4 SQL Injection via cms_getpagetitle.php

Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the catid parameter. Attackers can send GET requests to the admin/cms_getpagetitle.php endpoint with malicious catid values to extract sensitive da…

πŸ“… Published: Feb. 27, 2026, 5:23 p.m. πŸ”„ Last Modified: April 7, 2026, 2:04 p.m.

8.8

CVSS4.0

CVE-2019-25490 - Homey BNB V4 SQL Injection via admin edit.php

Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'id' parameter. Attackers can send GET requests to the admin/edit.php endpoint with time-based SQL injection payloads to extract sensitive datab…

πŸ“… Published: Feb. 27, 2026, 5:23 p.m. πŸ”„ Last Modified: April 7, 2026, 2:04 p.m.

8.8

CVSS4.0

CVE-2019-25489 - Homey BNB V4 SQL Injection via ajax_refresh_subtotal

Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the hosting_id parameter. Attackers can send GET requests to the rooms/ajax_refresh_subtotal endpoint with malicious hosting_id values to extract se…

πŸ“… Published: Feb. 27, 2026, 5:23 p.m. πŸ”„ Last Modified: April 7, 2026, 2:04 p.m.

7.1

CVSS3.1

CVE-2026-25147 - OpenEMR's Portal Payment Endpoint Trusts User-Controlled pid

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, in `portal/portal_payment.php`, the patient id used for the page is taken from the request (`$pid = $_REQUEST['pid'] ?? $pid` and `$pid = ($_REQUEST['hidden_patient_code'…

πŸ“… Published: Feb. 27, 2026, 4:44 p.m. πŸ”„ Last Modified: April 16, 2026, 3:30 p.m.

6.5

CVSS3.1

CVE-2026-24488 - OpenEMR Vulnerable to Arbitrary File Exfiltration via Fax Endpoint

OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, an arbitrary file exfiltration vulnerability in the fax sending endpoint allows any authenticated user to read and transmit any file on the server (includi…

πŸ“… Published: Feb. 27, 2026, 4:41 p.m. πŸ”„ Last Modified: April 16, 2026, 3:30 p.m.

8.2

CVSS4.0

CVE-2026-2293 - NestJS 11.1.13 - Lack of data validation allowing authentication/authorization bypass

A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled. This issue affects nest.Js: 11.1.13.

πŸ“… Published: Feb. 27, 2026, 4:15 p.m. πŸ”„ Last Modified: April 18, 2026, 10:15 a.m.

8.7

CVSS4.0

CVE-2026-3304 - Multer vulnerable to Denial of Service via incomplete cleanup

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion. Users should upgrade to version 2.1.0 to receive a patc…

πŸ“… Published: Feb. 27, 2026, 3:44 p.m. πŸ”„ Last Modified: April 16, 2026, 3:30 p.m.
Total resulsts: 348147
Page 1300 of 34,815
Β« previous page Β» next page
Filters