CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2017-17593

    Last Modified: 20 Apr 2025

    Simple Chatting System 1.0 allows Arbitrary File Upload via view/my_profile.php, which places files under uploads/.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17594

    Last Modified: 20 Apr 2025

    DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17596

    Last Modified: 20 Apr 2025

    Entrepreneur Job Portal Script 2.0.6 has SQL Injection via the jobsearch_all.php rid1 parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17602

    Last Modified: 20 Apr 2025

    Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17603

    Last Modified: 20 Apr 2025

    Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17610

    Last Modified: 20 Apr 2025

    E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17618

    Last Modified: 20 Apr 2025

    Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17574

    Last Modified: 20 Apr 2025

    FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17582

    Last Modified: 20 Apr 2025

    FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter.

    Published: 13 Dec 2017
    7.5
    High

    CVE-2017-17538

    Last Modified: 20 Apr 2025

    MikroTik v6.40.5 devices allow remote attackers to cause a denial of service via a flood of ICMP packets.

    Published: 13 Dec 2017
    6.1
    Medium

    CVE-2017-17569

    Last Modified: 20 Apr 2025

    Scubez Posty Readymade Classifieds has XSS via the admin/user_activate_submit.php ID parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17572

    Last Modified: 20 Apr 2025

    FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17573

    Last Modified: 20 Apr 2025

    FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17577

    Last Modified: 20 Apr 2025

    FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17578

    Last Modified: 20 Apr 2025

    FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17579

    Last Modified: 20 Apr 2025

    FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17580

    Last Modified: 20 Apr 2025

    FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.php id parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17581

    Last Modified: 20 Apr 2025

    FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17586

    Last Modified: 20 Apr 2025

    FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17588

    Last Modified: 20 Apr 2025

    FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17589

    Last Modified: 20 Apr 2025

    FS Thumbtack Clone 1.0 has SQL Injection via the browse-category.php cat parameter or the browse-scategory.php sc parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17590

    Last Modified: 20 Apr 2025

    FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17597

    Last Modified: 20 Apr 2025

    Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17598

    Last Modified: 20 Apr 2025

    Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17599

    Last Modified: 20 Apr 2025

    Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17600

    Last Modified: 20 Apr 2025

    Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17601

    Last Modified: 20 Apr 2025

    Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17604

    Last Modified: 20 Apr 2025

    Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17605

    Last Modified: 20 Apr 2025

    Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17606

    Last Modified: 20 Apr 2025

    Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17607

    Last Modified: 20 Apr 2025

    CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17608

    Last Modified: 20 Apr 2025

    Child Care Script 1.0 has SQL Injection via the /list city parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17609

    Last Modified: 20 Apr 2025

    Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17611

    Last Modified: 20 Apr 2025

    Doctor Search Script 1.0 has SQL Injection via the /list city parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17612

    Last Modified: 20 Apr 2025

    Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17613

    Last Modified: 20 Apr 2025

    Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17614

    Last Modified: 20 Apr 2025

    Food Order Script 1.0 has SQL Injection via the /list city parameter.

    Published: 13 Dec 2017
    8.8
    High

    CVE-2017-17615

    Last Modified: 20 Apr 2025

    Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17616

    Last Modified: 20 Apr 2025

    Event Search Script 1.0 has SQL Injection via the /event-list city parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17619

    Last Modified: 20 Apr 2025

    Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17620

    Last Modified: 20 Apr 2025

    Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17621

    Last Modified: 20 Apr 2025

    Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17622

    Last Modified: 20 Apr 2025

    Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17623

    Last Modified: 20 Apr 2025

    Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17626

    Last Modified: 20 Apr 2025

    Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17627

    Last Modified: 20 Apr 2025

    Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17628

    Last Modified: 20 Apr 2025

    Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17629

    Last Modified: 20 Apr 2025

    Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17630

    Last Modified: 20 Apr 2025

    Yoga Class Script 1.0 has SQL Injection via the /list city parameter.

    Published: 13 Dec 2017
    9.8
    Critical

    CVE-2017-17631

    Last Modified: 20 Apr 2025

    Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.

    Published: 13 Dec 2017