CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2019-25535

    Last Modified: 15 Apr 2026

    Netartmedia PHP Dating Site contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with time-based SQL injection payloads in the Email field to extract sensitive database information.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25534

    Last Modified: 15 Apr 2026

    Netartmedia PHP Car Dealer contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the features[] parameter. Attackers can submit POST requests to index.php with crafted SQL payloads in the features[] parameter to extract sensitive database information or manipulate database queries.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25533

    Last Modified: 15 Apr 2026

    Netartmedia PHP Business Directory 4.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to the loginaction.php endpoint with crafted SQL payloads in the Email field to extract sensitive database information or bypass authentication.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25532

    Last Modified: 15 Apr 2026

    Netartmedia Jobs Portal 6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with crafted SQL payloads in the Email field to extract sensitive database information or bypass authentication.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25531

    Last Modified: 15 Apr 2026

    Netartmedia Deals Portal contains an SQL injection vulnerability in the Email parameter of loginaction.php that allows unauthenticated attackers to manipulate database queries. Attackers can submit crafted SQL payloads through POST requests to extract sensitive information or bypass authentication mechanisms.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25530

    Last Modified: 15 Apr 2026

    uHotelBooking System contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the system_page GET parameter. Attackers can send crafted requests to index.php with malicious system_page values using time-based blind SQL injection techniques to extract sensitive database information.

    Published: 12 Mar 2026
    7.1
    High

    CVE-2019-25529

    Last Modified: 15 Apr 2026

    Placeto CMS Alpha rv.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'page' parameter. Attackers can send GET requests to the admin/edit.php endpoint with malicious 'page' values using boolean-based blind, time-based blind, or union-based techniques to extract sensitive database information.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25528

    Last Modified: 20 Mar 2026

    Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the property1 parameter. Attackers can send POST requests to the search/searchdetailed endpoint with malicious SQL payloads to extract sensitive data or modify database contents.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25527

    Last Modified: 20 Mar 2026

    Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the numguest parameter. Attackers can send POST requests to the search/searchdetailed endpoint with malicious SQL payloads to bypass authentication, extract sensitive data, or modify database contents.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25526

    Last Modified: 20 Mar 2026

    Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the location parameter. Attackers can send POST requests to the search/searchdetailed endpoint with malicious SQL payloads in the location field to extract sensitive data or modify database contents.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25525

    Last Modified: 20 Mar 2026

    Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the guests parameter. Attackers can send POST requests to the search/rentals endpoint with malicious SQL payloads to bypass authentication, extract sensitive data, or modify database contents.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25524

    Last Modified: 24 Mar 2026

    XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'p' parameter. Attackers can send GET requests to results.php with malicious 'p' values to bypass authentication, extract sensitive data, or modify database contents.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25523

    Last Modified: 24 Mar 2026

    XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cat_id parameter. Attackers can send GET requests to cat.php with malicious cat_id values to bypass authentication, extract sensitive data, or modify database contents.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25522

    Last Modified: 24 Mar 2026

    XooGallery Latest contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQL code through the photo_id parameter. Attackers can send GET requests to photo.php with malicious photo_id values to extract sensitive data, bypass authentication, or modify database contents.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25521

    Last Modified: 24 Mar 2026

    XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the gal_id parameter. Attackers can send GET requests to gal.php with malicious gal_id values to extract sensitive database information or modify database contents.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25520

    Last Modified: 20 Mar 2026

    Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an authentication bypass vulnerability in the administration panel that allows unauthenticated attackers to gain administrative access by exploiting improper SQL query validation. Attackers can submit SQL injection payloads in the username and password fields of the admingiris.php login form to bypass authentication and access the administrative interface.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25519

    Last Modified: 20 Mar 2026

    Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting malicious SQL code through the option parameter. Attackers can send POST requests to uyelik.php with crafted payloads in the option parameter to execute time-based SQL injection attacks and extract sensitive database information.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25518

    Last Modified: 20 Mar 2026

    Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the poll parameter. Attackers can send POST requests to arama.php with malicious SQL payloads in the poll parameter to extract sensitive data or modify database contents.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25517

    Last Modified: 20 Mar 2026

    Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cid parameter. Attackers can send requests to haberarsiv.php with malicious cid values using UNION-based injection to extract sensitive database information or modify database contents.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25516

    Last Modified: 20 Mar 2026

    Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the gallery_id parameter. Attackers can send GET requests to gallery.php with malicious gallery_id values using UNION-based SQL injection to extract sensitive database information.

    Published: 12 Mar 2026
    8.7
    High

    CVE-2019-25515

    Last Modified: 20 Mar 2026

    Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an authentication bypass vulnerability in the login.php administration panel that allows unauthenticated attackers to gain administrative access by submitting crafted SQL syntax. Attackers can bypass authentication by submitting equals signs and 'or' operators as username and password parameters to access the administration panel without valid credentials.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25514

    Last Modified: 20 Mar 2026

    Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows attackers to inject malicious SQL commands through the kelime parameter in POST requests. Attackers can manipulate the kelime parameter with UNION-based SQL injection payloads to extract sensitive data from the database or bypass authentication controls.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25513

    Last Modified: 20 Mar 2026

    Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'q' parameter. Attackers can send GET requests to datagetir.php with malicious 'q' values using time-based blind SQL injection techniques to extract sensitive database information or bypass authentication.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25512

    Last Modified: 20 Mar 2026

    Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows attackers to inject malicious SQL commands through the kelime parameter in POST requests. Attackers can manipulate the kelime parameter with UNION-based SQL injection payloads to extract sensitive database information or modify database contents.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25511

    Last Modified: 23 Mar 2026

    Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the videoid parameter. Attackers can send GET requests to fonksiyonlar.php with malicious videoid values using UNION-based injection to extract sensitive database information.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25510

    Last Modified: 20 Mar 2026

    Jettweb PHP Hazir Haber Sitesi Scripti V2 contains an authentication bypass vulnerability in the administration panel that allows unauthenticated attackers to gain administrative access by exploiting improper SQL query validation. Attackers can submit SQL injection payloads in the username and password fields of the admingiris.php login form to bypass authentication and access the administrative interface.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25509

    Last Modified: 15 Apr 2026

    XooDigital Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'p' parameter. Attackers can send GET requests to results.php with malicious 'p' values to extract sensitive database information.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25508

    Last Modified: 20 Mar 2026

    Jettweb Php Hazir Ilan Sitesi Scripti V2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'kat' parameter. Attackers can send GET requests to the katgetir.php endpoint with malicious 'kat' values to extract sensitive database information.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25488

    Last Modified: 20 Mar 2026

    Jettweb Hazir Rent A Car Scripti V4 contains multiple SQL injection vulnerabilities in the admin panel that allow unauthenticated attackers to manipulate database queries through GET parameters. Attackers can inject SQL code into the 'tur', 'id', and 'ozellikdil' parameters of the admin/index.php endpoint to extract sensitive database information or cause denial of service.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25482

    Last Modified: 20 Mar 2026

    Jettweb PHP Hazir Rent A Car Sitesi Scripti V2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the arac_kategori_id parameter. Attackers can send POST requests to the endpoint with malicious SQL payloads to extract sensitive database information.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25481

    Last Modified: 15 Apr 2026

    iScripts ReserveLogic contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the jqSearchDestination parameter. Attackers can send POST requests to the search endpoint with crafted SQL payloads to extract sensitive database information.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2019-25479

    Last Modified: 28 Jul 2026

    Inout RealEstate contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the city parameter. Attackers can send POST requests to the agents/agentlistdetails endpoint with malicious SQL payloads in the city parameter to extract sensitive database information.

    Published: 12 Mar 2026
    7.1
    High

    CVE-2019-25473

    Last Modified: 15 Apr 2026

    Clinic Pro contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the month parameter. Attackers can send POST requests to the monthly_expense_overview endpoint with crafted month values using boolean-based blind, time-based blind, or error-based SQL injection techniques to extract sensitive database information.

    Published: 12 Mar 2026
    2
    Low

    CVE-2026-4044

    Last Modified: 22 Apr 2026

    A vulnerability was detected in projectsend up to r1945. This affects the function realpath of the file /import-orphans.php of the component Delete Handler. Performing a manipulation of the argument files[] results in path traversal. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 12 Mar 2026
    7.4
    High

    CVE-2026-4043

    Last Modified: 3 Apr 2026

    A security vulnerability has been detected in Tenda i12 1.0.0.6(2204). The impacted element is the function formwrlSSIDget of the file /goform/wifiSSIDget. Such manipulation of the argument index leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

    Published: 12 Mar 2026
    8.8
    High

    CVE-2026-21668

    Last Modified: 10 May 2026

    A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.

    Published: 12 Mar 2026
    9.9
    Critical

    CVE-2026-21669

    Last Modified: 10 May 2026

    A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

    Published: 12 Mar 2026
    9.1
    Critical

    CVE-2026-21671

    Last Modified: 18 Jun 2026

    A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.

    Published: 12 Mar 2026
    7.7
    High

    CVE-2026-21670

    Last Modified: 2 Apr 2026

    A vulnerability allowing a low-privileged user to extract saved SSH credentials.

    Published: 12 Mar 2026
    9.9
    Critical

    CVE-2026-21666

    Last Modified: 31 Mar 2026

    A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

    Published: 12 Mar 2026
    9.9
    Critical

    CVE-2026-21667

    Last Modified: 31 Mar 2026

    A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

    Published: 12 Mar 2026
    7.4
    High

    CVE-2026-4042

    Last Modified: 3 Apr 2026

    A weakness has been identified in Tenda i12 1.0.0.6(2204). The affected element is the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet. This manipulation of the argument index causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.

    Published: 12 Mar 2026
    7.4
    High

    CVE-2026-4041

    Last Modified: 3 Apr 2026

    A security flaw has been discovered in Tenda i12 1.0.0.6(2204). Impacted is the function vos_strcpy of the file /goform/exeCommand. The manipulation of the argument cmdinput results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

    Published: 12 Mar 2026
    9.4
    Critical

    CVE-2026-28384

    Last Modified: 11 Sept 2026

    An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. This issue affected LXD from 4.12 through 6.6 and was fixed in the snap versions 5.0.6-e49d9f4 (channel 5.0/stable), 5.21.4-1374f39 (channel 5.21/stable), and 6.7-1f11451 (channel 6.0 stable). The channel 4.0/stable is not affected as it contains version 4.0.10.

    Published: 12 Mar 2026
    Unknown

    CVE-2026-4049

    Last Modified: 22 Apr 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 12 Mar 2026
    6.3
    Medium

    CVE-2026-0809

    Last Modified: 20 Mar 2026

    Use of a custom token encoding algorithm in Streamsoft Prestiż software allows the value of the KSeF (Krajowy System e-Faktur) token to be guessed after analyzing how tokens with know values are encoded. This issue was fixed in version 20.0.380.92.

    Published: 12 Mar 2026
    8.6
    High

    CVE-2026-2514

    Last Modified: 3 Sept 2026

    In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed by Flowmon ADS and viewed by an authenticated user, could result in unintended actions being executed in the user's browser context.

    Published: 12 Mar 2026
    8.6
    High

    CVE-2026-2513

    Last Modified: 3 Sept 2026

    A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session.

    Published: 12 Mar 2026
    6.1
    Medium

    CVE-2026-2987

    Last Modified: 22 Apr 2026

    The Simple Ajax Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'c' parameter in versions up to, and including, 20260217 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 12 Mar 2026
    4.8
    Medium

    CVE-2026-4040

    Last Modified: 20 Mar 2026

    A vulnerability was identified in OpenClaw up to 2026.2.17. This issue affects the function tools.exec.safeBins of the component File Existence Handler. The manipulation leads to information exposure through discrepancy. The attack needs to be performed locally. Upgrading to version 2026.2.19-beta.1 is capable of addressing this issue. The identifier of the patch is bafdbb6f112409a65decd3d4e7350fbd637c7754. Upgrading the affected component is advised.

    Published: 12 Mar 2026