| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Buffer overflow vulnerability in function NumberToPrecisionCmd in jsish before 3.0.7, allows remote attackers to execute arbitrary code. |
| A remote code execution (RCE) vulnerability in the \Playsong.php component of cscms v4.1 allows attackers to execute arbitrary commands. |
| An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature. |
| A remote command execution vulnerability exists in add_server_service of PPTP_SERVER in Mercury Router MER1200 v1.0.1 and Mercury Router MER1200G v1.0.1. |
| Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and xmlXPathFreeContext. |
| Installer RCE on settings file write in MyBB before 1.8.22. |
| An issue was discovered in pdfcrack 0.17 thru 0.18, allows attackers to execute arbitrary code via a stack overflow in the MD5 function. |
| WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry. |
| JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile. |
| Xiongmai Technology Co devices AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, and HI3518E_50H10L_S39 were all discovered to have port 9530 open which allows unauthenticated attackers to make arbitrary Telnet connections with the victim device. |
| Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a malicious plugin which contains the php files with extensions like PHP,phtml,php7 will be copied to the plugins directory which would lead to the remote code execution |
| Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionSetAmount function. |
| Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function. |
| Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoad function. |
| SQL Injection in 74cms 3.2.0 via the id parameter to wap/wap-company-show.php. |
| SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php. |
| SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php. |
| SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php. |
| SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php. |
| SQL Injection in ECShop 3.0 via the aid parameter to admin/affiliate_ck.php. |