CVE Database

CVE-2025-11476CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability was identified in SourceCodester Simple E-Commerce Bookstore 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument login_username leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.

CVE-2018-7124CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11944CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-11945CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2025-11475CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability was determined in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /view_member.php. Executing a manipulation of the argument user_id can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

CVE-2025-11474CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability was found in SourceCodester Hotel and Lodge Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_booking.php. Performing manipulation of the argument Name results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.

CVE-2025-11473CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability has been found in SourceCodester Hotel and Lodge Management System 1.0. Affected is an unknown function of the file /edit_curr.php. Such manipulation of the argument currsymbol leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2019-5347CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

A remote authentication bypass vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5352CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-917

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5356CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5358CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-917

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5367CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1188

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5387CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-917

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5390CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

A remote command injection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2018-17842CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.

CVE-2019-5391CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A stack buffer overflow vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2025-11472CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A flaw has been found in SourceCodester Hotel and Lodge Management System 1.0. This impacts an unknown function of the file /edit_room.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.

CVE-2019-11949CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-917

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-12553CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the StrCat function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution.

CVE-2019-9642CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possible to evaluate malicious PHP code by placing it on the fourth line of a .php file, as demonstrated by a PoC.php created by the guest account, with execution via a proxy.php?hash=../../../../../var/lib/pydio/data/personal/guest/PoC.php request. This is related to plugins/action.share/src/Store/ShareStore.php.

CVE-2019-11988CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

A Remote Unauthorized Access vulnerability was identified in HPE Smart Update Manager (SUM) earlier than version 8.3.5.

CVE-2019-12196CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute arbitrary SQL commands via the DeviceID parameter.

CVE-2025-11471CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability was detected in SourceCodester Hotel and Lodge Management System 1.0. This affects an unknown function of the file /edit_customer.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.

CVE-2025-11469CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A weakness has been identified in SourceCodester Hotel and Lodge Management System 1.0. The affected element is an unknown function of the file /pages/save_customer.php. Executing manipulation of the argument Contact can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.

CVE-2025-11434CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A weakness has been identified in itsourcecode Student Transcript Processing System 1.0. Affected is an unknown function of the file /login.php. Executing a manipulation of the argument uname can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

CVE-2018-10171CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-732

Kromtech MacKeeper 3.20.4 suffers from a root privilege escalation vulnerability through its `com.mackeeper.AdwareAnalyzer.AdwareAnalyzerPrivilegedHelper` component. The AdwareAnalzyerPrivilegedHelper tool implements an XPC service that allows an unprivileged application to connect and execute shell scripts as the root user.

CVE-2019-12135CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An unspecified vulnerability in the application server in PaperCut MF and NG versions 18.3.8 and earlier and versions 19.0.3 and earlier allows remote attackers to execute arbitrary code via an unspecified vector.

CVE-2019-11523CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for example, send the "open door" command, download the users list (which includes RFID codes and passcodes in cleartext), or update/create users. The same attack can be executed on a local network and over the internet (if the device is exposed on a public IP address).

CVE-2019-12771CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Command injection is possible in ThinStation through 6.1.1 via shell metacharacters after the cgi-bin/CdControl.cgi action= substring, or after the cgi-bin/VolControl.cgi OK= substring.

CVE-2019-12776CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They include a hard-coded SSH backdoor for remote SSH and SCP access as the root user. A command in the relocate and relocate_revB scripts copies the hardcoded key to the root user's authorized_keys file, enabling anyone with the associated private key to gain remote root access to all affected products.

CVE-2018-19800CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

aubio v0.4.0 to v0.4.8 has a Buffer Overflow in new_aubio_tempo.

CVE-2019-10160CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-172

A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application.

CVE-2019-12598CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 1 of 3).

CVE-2019-12599CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SuiteCRM 7.10.x before 7.10.17 and 7.11.x before 7.11.5 allows SQL Injection.

CVE-2019-12600CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 2 of 3).

CVE-2019-12601CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 3 of 3).

CVE-2018-10698CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-311

An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET service by default. This allows an attacker who has been able to gain an MITM position to easily sniff the traffic between the device and the user. Also an attacker can easily connect to the TELNET daemon using the default credentials if they have not been changed by the user.

CVE-2019-2097CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

In HAliasAnalyzer.Query of hydrogen-alias-analysis.h, there is possible memory corruption due to type confusion. This could lead to remote code execution from a malicious proxy configuration, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-117606285.

CVE-2019-9086CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

HotelDruid before v2.3.1 has SQL Injection via the /visualizza_tabelle.php anno parameter.

CVE-2019-9087CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

HotelDruid before v2.3.1 has SQL Injection via the /tab_tariffe.php numtariffa1 parameter.

CVE-2019-12780CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple POST request to /upnp/control/basicevent1 can allow an attacker to execute commands without authentication.

CVE-2018-20353CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

An invalid read of 8 bytes due to a use-after-free vulnerability during a "NULL test" in the mg_http_get_proto_data function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.

CVE-2018-20354CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the mg_http_get_proto_data function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.

CVE-2018-20355CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.

CVE-2018-20356CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.

CVE-2025-11432CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /reset.php. Such manipulation of the argument employid leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.

CVE-2019-11027CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw. This library is used by Rails web applications to integrate with OpenID Providers. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk.

CVE-2019-11232CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information (Password) without being authenticated, by sending an EMP_NO element to the kws_login/asp/query_user.asp URI, and then reading the PWD element.

CVE-2019-3412CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability. Due to some interfaces do not adequately verify parameters, an attacker can execute arbitrary commands through specific interfaces.

CVE-2018-11800CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts related table.

← PreviousPage 308 / 7034Next →