Export limit exceeded: 374748 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 40271 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (40271 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2019-15565 | 1 Webimpacto | 1 Icommktconnector | 2024-11-21 | N/A |
| The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php. | ||||
| CVE-2019-15564 | 1 Compassionuk | 1 Compassion Switzerland | 2024-11-21 | N/A |
| The Compassion Switzerland addons 10.01.4 for Odoo allow SQL injection in models/partner_compassion.py. | ||||
| CVE-2019-15563 | 1 Ohdsi | 1 Webapi | 2024-11-21 | N/A |
| Observational Health Data Sciences and Informatics (OHDSI) WebAPI before 2.7.2 allows SQL injection in FeatureExtractionService.java. | ||||
| CVE-2019-15562 | 1 Gorm | 1 Gorm | 2024-11-21 | 9.8 Critical |
| GORM before 1.9.10 allows SQL injection via incomplete parentheses. NOTE: Misusing Gorm by passing untrusted user input where Gorm expects trusted SQL fragments is a vulnerability in the application, not in Gorm | ||||
| CVE-2019-15561 | 1 Flashlingo Project | 1 Flashlingo | 2024-11-21 | N/A |
| FlashLingo before 2019-06-12 allows SQL injection, related to flashlingo.js and db.js. | ||||
| CVE-2019-15560 | 1 Reviews Module Project | 1 Reviews Module | 2024-11-21 | N/A |
| The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js. | ||||
| CVE-2019-15559 | 1 Hawn Project | 1 Hawn | 2024-11-21 | N/A |
| DianoxDragon Hawn before 2019-07-10 allows SQL injection. | ||||
| CVE-2019-15558 | 1 Xm-online | 1 Xm\^online 2 - Common Utils And Endpoints | 2024-11-21 | N/A |
| XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, and SchemaChangeResolver.java. | ||||
| CVE-2019-15557 | 1 Xm-online | 1 Xm\^online 2 User Account And Authentication Server | 2024-11-21 | N/A |
| XM^online 2 User Account and Authentication server 1.0.0 allows SQL injection via a tenant key. | ||||
| CVE-2019-15556 | 1 Social Network Project | 1 Social Network | 2024-11-21 | N/A |
| Pvanloon1983 social_network before 2019-07-03 allows SQL injection in includes/form_handlers/register_handler.php. | ||||
| CVE-2019-15555 | 1 Wellness Project | 1 Wellness | 2024-11-21 | N/A |
| FredReinink Wellness-app before 2019-06-19 allows SQL injection, related to dietTrack.php, exerciseGenerator.php, fitnessTrack.php, and server.php. | ||||
| CVE-2019-15541 | 1 Rustls Project | 1 Rustls | 2024-11-21 | N/A |
| rustls-mio/examples/tlsserver.rs in the rustls crate before 0.16.0 for Rust allows attackers to cause a denial of service (loop of conn_event and ready) by arranging for a client to never be writable. | ||||
| CVE-2019-15537 | 1 Cesnet | 1 Proxystatistics | 2024-11-21 | N/A |
| The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php. | ||||
| CVE-2019-15536 | 1 Youracclaim | 1 Acclaim | 2024-11-21 | N/A |
| The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records. | ||||
| CVE-2019-15535 | 1 Hostosm | 1 Tasking Manager | 2024-11-21 | N/A |
| Tasking Manager before 3.4.0 allows SQL Injection via custom SQL. | ||||
| CVE-2019-15534 | 1 Raml-module-builder Project | 1 Raml-module-builder | 2024-11-21 | N/A |
| Raml-Module-Builder 26.4.0 allows SQL Injection in PostgresClient.update. | ||||
| CVE-2019-15533 | 1 Xayr | 1 Xenfcoresharp | 2024-11-21 | N/A |
| XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php. | ||||
| CVE-2019-15498 | 1 Getvera | 2 Vera Edge, Vera Edge Firmware | 2024-11-21 | N/A |
| cgi-bin/cmh/webcam.sh in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via --output argument injection in the username parameter to /cgi-bin/cmh/webcam.sh. | ||||
| CVE-2019-15387 | 1 Archos | 2 Core 101, Core 101 Firmware | 2024-11-21 | 3.3 Low |
| The Archos Core 101 Android device with a build fingerprint of archos/MTKAC101CR3G_ARCHOS/ac101cr3g:7.0/NRD90M/20180611.034442:user/release-keys contains a pre-installed app with a package name of com.roco.autogen app (versionCode=1, versionName=1) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface. | ||||
| CVE-2019-15386 | 1 Lavamobiles | 2 Z60s, Z60s Firmware | 2024-11-21 | 5.5 Medium |
| The Lava Z60s Android device with a build fingerprint of LAVA/Z60s/Z60s:8.1.0/O11019/1530331229:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization. | ||||