Search Results (323571 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-17403 1 Phonepe 1 Phonepe 2024-11-21 N/A
The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to impersonate a user and set up their account without their knowledge. NOTE: the vendor says that, to exploit this, the user has to explicitly install a malicious app and provide accessibility permission to the malicious app, that the Android platform provides fair warnings to the users before turning on accessibility for any application, and that it believes it is similar to installing malicious keyboards, or malicious apps taking screenshots
CVE-2018-17402 1 Phonepe 1 Phonepe 2024-11-21 N/A
The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to discover the Credit/Debit card number, expiration date, and CVV number. NOTE: the vendor says that, to exploit this, the user has to explicitly install a malicious app and provide accessibility permission to the malicious app, that the Android platform provides fair warnings to the users before turning on accessibility for any application, and that it believes it is similar to installing malicious keyboards, or malicious apps taking screenshots
CVE-2018-17401 1 Phonepe 1 Phonepe 2024-11-21 N/A
The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to perform Account Takeover attacks by exploiting its Forgot Password feature. NOTE: the vendor says that, to exploit this, the user has to explicitly install a malicious app and provide accessibility permission to the malicious app, that the Android platform provides fair warnings to the users before turning on accessibility for any application, and that it believes it is similar to installing malicious keyboards, or malicious apps taking screenshots
CVE-2018-17400 1 Phonepe 1 Phonepe 2024-11-21 N/A
The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to perform Account Takeover attacks by intercepting the user name and PIN during the initial configuration of the application. NOTE: the vendor says that, to exploit this, the user has to explicitly install a malicious app and provide accessibility permission to the malicious app, that the Android platform provides fair warnings to the users before turning on accessibility for any application, and that it believes it is similar to installing malicious keyboards, or malicious apps taking screenshots
CVE-2018-17399 1 Jimtawl Project 1 Jimtawl 2024-11-21 N/A
SQL Injection exists in the Jimtawl 2.2.7 component for Joomla! via the id parameter.
CVE-2018-17398 1 Arenam 1 Amgallery 2024-11-21 N/A
SQL Injection exists in the AMGallery 1.2.3 component for Joomla! via the filter_category_id parameter.
CVE-2018-17397 1 Multiplanet 1 Alphaindex Dictionaries 2024-11-21 N/A
SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter.
CVE-2018-17394 1 Osthemeclub 1 Timetable Schedule 2024-11-21 N/A
SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter.
CVE-2018-17393 1 Healthnode Hospital Management System Project 1 Healthnode Hospital Management System 2024-11-21 N/A
SQL Injection exists in HealthNode Hospital Management System 1.0 via the id parameter to dashboard/Patient/info.php or dashboard/Patient/patientdetails.php.
CVE-2018-17391 1 Super Cms Blog Pro Project 1 Super Cms Blog Pro 2024-11-21 N/A
SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter.
CVE-2018-17389 1 Ranksol 1 Live Call Support 2024-11-21 N/A
CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account.
CVE-2018-17388 1 Ranksol 1 Twilio Web To Fax Machine System 2024-11-21 N/A
SQL Injection exists in Twilio WEB To Fax Machine System 1.0 via the email or password parameter to login_check.php, or the id parameter to add_email.php or edit_content.php.
CVE-2018-17387 1 Ranksol 1 Nimble Professional 2024-11-21 N/A
CSRF exists in Nimble Messaging Bulk SMS Marketing Application 1.0 for adding an admin account.
CVE-2018-17386 1 Thephpfactory 1 Micro Deal Factory 2024-11-21 N/A
SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.
CVE-2018-17385 1 Thephpfactory 1 Social Factory 2024-11-21 N/A
SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter.
CVE-2018-17384 1 Thephpfactory 1 Swap Factory 2024-11-21 N/A
SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.
CVE-2018-17383 1 Thephpfactory 1 Collection Factory 2024-11-21 N/A
SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter.
CVE-2018-17382 1 Thephpfactory 1 Jobs Factory 2024-11-21 N/A
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
CVE-2018-17381 1 Thephpfactory 1 Dutch Auction Factory 2024-11-21 N/A
SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
CVE-2018-17380 1 Thephpfactory 1 Article Factory Manager 2024-11-21 N/A
SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter.