Export limit exceeded: 40006 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (40006 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-13356 1 Terra-master 1 Terramaster Operating System 2024-11-21 N/A
Incorrect access control on ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to elevate user permissions.
CVE-2018-13350 1 Terra-master 1 Terramaster Operating System 2024-11-21 N/A
SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter.
CVE-2018-13324 1 Buffalo 2 Ts5600d1206, Ts5600d1206 Firmware 2024-11-21 N/A
Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by sending a modified HTTP Host header.
CVE-2018-13116 1 Zzcms 1 Zzcms 2024-11-21 N/A
/user/del.php in zzcms 8.3 allows SQL injection via the tablename parameter after leveraging use of the zzcms_ask table.
CVE-2018-13109 1 Adbglobal 8 Dv2210, Dv2210 Firmware, Prg Av4202n and 5 more 2024-11-21 N/A
All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerability where attackers are able to access and manipulate settings within the web interface that are forbidden to end users (e.g., by the ISP). An attacker would be able to enable the TELNET server or other settings as well.
CVE-2018-13063 1 Easyappointments 1 Easy\!appointments 2024-11-21 7.5 High
Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.
CVE-2018-13050 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 N/A
A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_username parameter in a /j_security_check POST request.
CVE-2018-13049 1 Glpi-project 1 Glpi 2024-11-21 N/A
The constructSQL function in inc/search.class.php in GLPI 9.2.x through 9.3.0 allows SQL Injection, as demonstrated by triggering a crafted LIMIT clause to front/computer.php.
CVE-2018-13045 1 Yeswiki 1 Cercopitheque 2024-11-21 N/A
SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to execute arbitrary SQL commands via the "id" parameter.
CVE-2018-12977 1 Softexpert 1 Excellence Suite 2024-11-21 N/A
A SQL injection vulnerability in the SoftExpert (SE) Excellence Suite 2.0 allows remote authenticated users to perform SQL heuristics by pulling information from the database with the "cddocument" parameter in the "Downloading Electronic Documents" section.
CVE-2018-12942 1 Seeddms 1 Seeddms 2024-11-21 N/A
SQL injection vulnerability in the "Users management" functionality in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows authenticated attackers to manipulate an SQL query within the application by sending additional SQL commands to the application server. An attacker can use this vulnerability to perform malicious tasks such as to extract, change, or delete sensitive information within the database supporting the application, and potentially run system commands on the underlying operating system.
CVE-2018-12913 1 Miniz Project 1 Miniz 2024-11-21 N/A
In Miniz 2.0.7, tinfl_decompress in miniz_tinfl.c has an infinite loop because sym2 and counter can both remain equal to zero.
CVE-2018-12912 1 Hongcms Project 1 Hongcms 2024-11-21 N/A
An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via an admin/index.php/database/operate?dbaction=emptytable&tablename= URI.
CVE-2018-12636 1 Ithemes 1 Security 2024-11-21 N/A
The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.
CVE-2018-12630 1 Nmark 1 Nmcms 2024-11-21 N/A
NEWMARK (aka New Mark) NMCMS 2.1 allows SQL Injection via the sect_id parameter to the /catalog URI.
CVE-2018-12548 1 Eclipse 1 Openj9 2024-11-21 N/A
In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which accept pointer values that are dereferenced in the native code.
CVE-2018-12534 1 Quick Chat Project 1 Quick Chat 2024-11-21 N/A
A SQL injection issue was discovered in the Quick Chat plugin before 4.00 for WordPress.
CVE-2018-12498 1 Icmsdev 1 Icms 2024-11-21 N/A
spider.admincp.php in iCMS v7.0.8 has SQL Injection via the id parameter in an app=spider&do=batch request to admincp.php.
CVE-2018-12482 1 Ocsinventory-ng 1 Ocsinventory Ng 2024-11-21 N/A
OCS Inventory 2.4.1 contains multiple SQL injections in the search engine. Authentication is needed in order to exploit the issues.
CVE-2018-12470 1 Suse 1 Subscription Management Tool 2024-11-21 N/A
A SQL Injection in the RegistrationSharing module of SUSE Linux SMT allows remote attackers to cause execute arbitrary SQL statements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.