Search Results (42538 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-17429 1 Adhouma Cms Project 1 Adhouma Cms 2024-11-21 9.8 Critical
Adhouma CMS through 2019-10-09 has SQL Injection via the post.php p_id parameter.
CVE-2019-17419 1 Metinfo 1 Metinfo 2024-11-21 7.2 High
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=user&c=admin_user&a=doGetUserInfo id parameter.
CVE-2019-17418 1 Metinfo 1 Metinfo 2024-11-21 7.2 High
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno parameter, a different issue than CVE-2019-16997.
CVE-2019-17400 2 Redhat, Universal Office Converter Project 2 Enterprise Linux, Universal Office Converter 2024-11-21 7.5 High
The unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion.
CVE-2019-17370 1 Otcms 1 Otcms 2024-11-21 7.2 High
OTCMS v3.85 allows arbitrary PHP Code Execution because admin/sysCheckFile_deal.php blocks "into outfile" in a SELECT statement, but does not block the "into/**/outfile" manipulation. Therefore, the attacker can create a .php file.
CVE-2019-17357 1 Cacti 1 Cacti 2024-11-21 6.5 Medium
Cacti through 1.2.7 is affected by a graphs.php?template_id= SQL injection vulnerability affecting how template identifiers are handled when a string and id composite value are used to identify the template type and id. An authenticated attacker can exploit this to extract data from the database, or an unauthenticated remote attacker could exploit this via Cross-Site Request Forgery.
CVE-2019-17350 2 Debian, Xen 2 Debian Linux, Xen 2024-11-21 5.5 Medium
An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a compare-and-exchange operation.
CVE-2019-17349 2 Debian, Xen 2 Debian Linux, Xen 2024-11-21 5.5 Medium
An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a LoadExcl or StoreExcl operation.
CVE-2019-17319 1 Sugarcrm 1 Sugarcrm 2024-11-21 8.8 High
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Emails module by a Regular user.
CVE-2019-17318 1 Sugarcrm 1 Sugarcrm 2024-11-21 8.8 High
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by a Regular user.
CVE-2019-17298 1 Sugarcrm 1 Sugarcrm 2024-11-21 8.8 High
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Administration module by a Developer user.
CVE-2019-17297 1 Sugarcrm 1 Sugarcrm 2024-11-21 8.8 High
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Quotes module by a Regular user.
CVE-2019-17296 1 Sugarcrm 1 Sugarcrm 2024-11-21 8.8 High
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Contacts module by a Regular user.
CVE-2019-17295 1 Sugarcrm 1 Sugarcrm 2024-11-21 8.8 High
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the history function by a Regular user.
CVE-2019-17294 1 Sugarcrm 1 Sugarcrm 2024-11-21 8.8 High
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the export function by a Regular user.
CVE-2019-17293 1 Sugarcrm 1 Sugarcrm 2024-11-21 8.8 High
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Project module by a Regular user.
CVE-2019-17292 1 Sugarcrm 1 Sugarcrm 2024-11-21 7.2 High
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by an Admin user.
CVE-2019-17271 1 Vbulletin 1 Vbulletin 2024-11-21 4.9 Medium
vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter.
CVE-2019-17197 1 Open-emr 1 Openemr 2024-11-21 9.8 Critical
OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc.
CVE-2019-17191 1 Signal 1 Private Messenger 2024-11-21 7.5 High
The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, without callee user interaction, via a connect message. The existence of the call is noticeable to the callee; however, the audio channel may be open before the callee can block eavesdropping.