5.1

CVSS4.0

CVE-2019-25301 - thrsrossi Millhouse-Project 1.414 - 'content' Persistent Cross-Site Scripting

Millhouse-Project 1.414 contains a persistent cross-site scripting vulnerability in the comment submission functionality that allows attackers to inject malicious scripts. Attackers can post comments with embedded JavaScript through the 'content' parameter in add_comment_sql.php to execute arbitrar…

πŸ“… Published: Feb. 6, 2026, 4:41 p.m. πŸ”„ Last Modified: Feb. 9, 2026, 10:50 a.m.

7.1

CVSS4.0

CVE-2019-25300 - thejshen Globitek CMS 1.4 - 'id' SQL Injection

thejshen Globitek CMS 1.4 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'id' GET parameter. Attackers can exploit boolean-based, time-based, and UNION-based SQL injection techniques to potentially extract or modify database information.

πŸ“… Published: Feb. 6, 2026, 4:41 p.m. πŸ”„ Last Modified: Feb. 9, 2026, 10:50 a.m.

7.1

CVSS4.0

CVE-2019-25299 - rimbalinux AhadPOS 1.11 - 'alamatCustomer' SQL Injection

RimbaLinux AhadPOS 1.11 contains a SQL injection vulnerability in the 'alamatCustomer' parameter that allows attackers to manipulate database queries through crafted POST requests. Attackers can exploit time-based and boolean-based blind SQL injection techniques to extract information or potentiall…

πŸ“… Published: Feb. 6, 2026, 4:41 p.m. πŸ”„ Last Modified: Feb. 9, 2026, 10:50 a.m.

7.1

CVSS4.0

CVE-2019-25298 - html5_snmp 1.11 - 'Router_ID' SQL Injection

html5_snmp 1.11 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries through Router_ID and Router_IP parameters. Attackers can exploit error-based, time-based, and union-based injection techniques to potentially extract or modify database information b…

πŸ“… Published: Feb. 6, 2026, 4:41 p.m. πŸ”„ Last Modified: March 2, 2026, 3:16 p.m.

5.1

CVSS4.0

CVE-2019-25294 - html5_snmp 1.11 - 'Remark' Persistent Cross-Site Scripting

html5_snmp 1.11 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through the 'Remark' parameter in add_router_operation.php. Attackers can craft a POST request with a script payload in the Remark field to execute arbitrary JavaScript in vict…

πŸ“… Published: Feb. 6, 2026, 4:41 p.m. πŸ”„ Last Modified: March 2, 2026, 3:16 p.m.

8.5

CVSS4.0

CVE-2019-25292 - Alps HID Monitor Service 8.1.0.10 - 'ApHidMonitorService' Unquote Service Path

Alps HID Monitor Service 8.1.0.10 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files\Apoint2K\HidMonitorSvc.exe to inject malicious executables and ga…

πŸ“… Published: Feb. 6, 2026, 4:41 p.m. πŸ”„ Last Modified: Feb. 9, 2026, 10:50 a.m.

8.5

CVSS4.0

CVE-2019-25266 - Wondershare Application Framework Service 2.4.3.231 - 'WsAppService' Unquote Service Path

Wondershare Application Framework Service 2.4.3.231 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted service path by placing malicious executables in specific directory loca…

πŸ“… Published: Feb. 6, 2026, 4:41 p.m. πŸ”„ Last Modified: Feb. 9, 2026, 10:50 a.m.

6.9

CVSS4.0

CVE-2026-2058 - mathurvishal CloudClassroom-PHP-Project Post Query Details postquerypublic.php sql injection

A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file /postquerypublic.php of the component Post Query Details Page. This manipulation of the argument gnamex causes sql injection. The attack is p…

πŸ“… Published: Feb. 6, 2026, 4:32 p.m. πŸ”„ Last Modified: April 17, 2026, 10:45 p.m.

7.1

CVSS3.1

CVE-2026-2103 - Use of Hard-Coded Cryptographic Key for Password Storage

Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, and API keys. The encryption keys are identical across all installations. An attacker with access to the application binary and database can decrypt all…

πŸ“… Published: Feb. 6, 2026, 4:22 p.m. πŸ”„ Last Modified: April 17, 2026, 10:45 p.m.

5.9

CVSS4.0

CVE-2026-25556 - MuPDF <= 1.27.0 Barcode Decoding Double Free

MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer but incorrectly drops the pixmap in its error handling path before rethrowing …

πŸ“… Published: Feb. 6, 2026, 4:11 p.m. πŸ”„ Last Modified: April 16, 2026, 5:30 p.m.
Total resulsts: 349182
Page 1772 of 34,919
Β« previous page Β» next page
Filters