CVE Database

Search and browse vulnerability records from NVD

Showing 50 of 11490 CVEs

CVE ID Severity Description EPSS Published
9.8 CRITICAL

EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15, EMC VASA Virtual Appliance versions prior to 8.4.0.512, and EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier) contain an authentication bypass vulnerability that may potentially be exploited by malicious users to compromise the affected system.

4.8% 2017-11-01
9.1 CRITICAL

An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would pass on that (non-existing) data with a pointer and the size (zero) to the deliver-data function. libcurl's deliver-data function treats zero as a magic number and invokes strlen() on the data to figure out the length. The strlen() is called on a heap based buffer that might not be zero terminated so libcurl might read beyond the end of it into whatever memory lies after (or just crash) and then deliver that to the application as if it was actually downloaded.

6.2% 2017-10-31
9.8 CRITICAL

An SQL Injection vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow SQL injection.

1.8% 2017-10-31
9.8 CRITICAL

Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter.

2.7% 2017-10-31
9.8 CRITICAL

Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php.

2.7% 2017-10-31
9.8 CRITICAL

Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type, city, or posted_by parameter, or searchResidential.php via the property_type, city, or bedroom parameter, a different vulnerability than CVE-2008-3951, CVE-2009-3497, and CVE-2012-0982.

2.7% 2017-10-31
9.8 CRITICAL

Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.

7.7% 2017-10-31
9.8 CRITICAL

Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action.

2.7% 2017-10-31
9.8 CRITICAL

Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008-6525.

2.7% 2017-10-31
9.8 CRITICAL

Fake Magazine Cover Script allows SQL Injection via the rate.php value parameter or the content.php id parameter.

2.0% 2017-10-31
9.8 CRITICAL

CPA Lead Reward Script allows SQL Injection via the username parameter.

2.7% 2017-10-31
9.8 CRITICAL

Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter.

2.7% 2017-10-31
9.8 CRITICAL

Creative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php.

2.7% 2017-10-31
9.8 CRITICAL

MyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.

2.7% 2017-10-31
9.8 CRITICAL

Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.

2.6% 2017-10-31
9.8 CRITICAL

Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.

2.6% 2017-10-31
9.8 CRITICAL

US Zip Codes Database Script 1.0 allows SQL Injection via the state parameter.

2.7% 2017-10-31
9.8 CRITICAL

Shareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter.

2.7% 2017-10-31
9.8 CRITICAL

AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.

2.7% 2017-10-31
9.8 CRITICAL

Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter.

2.7% 2017-10-31
9.8 CRITICAL

Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from which to load and execute malicious Java classes via port 20931.

1.9% 2017-10-31
10.0 CRITICAL

Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Default Account). Supported versions that are affected are 11.1.1.7, 11.1.2.3 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

3.9% 2017-10-30
9.8 CRITICAL

The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 through 2.9.0 does not properly validate callback identifiers, which allows remote attackers to execute arbitrary JavaScript in the host page and consequently gain privileges via a crafted gap-iab: URI.

8.1% 2017-10-30
9.8 CRITICAL

http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.

2.2% 2017-10-30
9.8 CRITICAL

Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security features are enabled, which makes it easier for context-dependent attackers to crack secret keys via a brute-force attack.

1.2% 2017-10-30
9.1 CRITICAL

An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not match up with that assumption. When such a grant copy operation is being done on a grant of a dying domain, the assumption turns out wrong. A malicious guest administrator can cause hypervisor memory corruption, most likely resulting in host crash and a Denial of Service. Privilege escalation and information leaks cannot be ruled out.

2.8% 2017-10-30
9.8 CRITICAL

The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds access and daemon crash) or possibly execute arbitrary code via vectors related to the (1) frame_handlers array or (2) set_dynamic_table_size function.

5.4% 2017-10-30
9.8 CRITICAL

Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.

3.8% 2017-10-30
9.8 CRITICAL

The XSLTCompiledTransform function in Ektron Content Management System (CMS) before 8.02 SP5 configures the XSL with enableDocumentFunction set to true, which allows remote attackers to read arbitrary files and consequently bypass authentication, modify viewstate, cause a denial of service, or possibly have unspecified other impact via crafted XSL data.

1.9% 2017-10-30
9.8 CRITICAL

Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attackers to execute arbitrary code with NETWORK SERVICE privileges via crafted XSL data.

67.8% 2017-10-30
9.8 CRITICAL

Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-1000116, and CVE-2017-1000117.

3.4% 2017-10-29
9.8 CRITICAL

In the "NQ Contacts Backup & Restore" application 1.1 for Android, no HTTPS is used for transmitting login and synced user data. When logging in, the username is transmitted in cleartext along with an SHA-1 hash of the password. The attacker can either crack this hash or use it for further attacks where only the hash value is required.

0.7% 2017-10-29
9.8 CRITICAL

rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions. NOTE: the rsync development branch has significant use beyond the rsync developers, e.g., the code has been copied for use in various GitHub projects.

1.0% 2017-10-29
9.8 CRITICAL

ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-2008-3604.

3.0% 2017-10-29
9.8 CRITICAL

Vastal I-Tech Dating Zone 0.9.9 allows SQL Injection via the 'product_id' to add_to_cart.php, a different vulnerability than CVE-2008-4461.

3.0% 2017-10-29
9.8 CRITICAL

tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.

3.7% 2017-10-29
9.8 CRITICAL

Sokial Social Network Script 1.0 allows SQL Injection via the id parameter to admin/members_view.php.

2.9% 2017-10-29
9.8 CRITICAL

SoftDatepro Dating Social Network 1.3 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15971.

2.9% 2017-10-29
9.8 CRITICAL

Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15972.

2.0% 2017-10-29
9.8 CRITICAL

PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter.

2.2% 2017-10-29
9.8 CRITICAL

PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_catalog/category.

2.1% 2017-10-29
9.8 CRITICAL

MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter.

2.1% 2017-10-29
9.8 CRITICAL

Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the edit parameter to admin/template.

2.1% 2017-10-29
9.8 CRITICAL

The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parameter to index.php.

3.4% 2017-10-29
9.8 CRITICAL

The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action.

3.4% 2017-10-29
9.8 CRITICAL

Job Board Script Software allows SQL Injection via the PATH_INFO to a /job-details URI.

2.1% 2017-10-29
9.8 CRITICAL

iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser parameter.

2.1% 2017-10-29
9.8 CRITICAL

iStock Management System 1.0 allows Arbitrary File Upload via user/profile.

4.9% 2017-10-29
9.8 CRITICAL

iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php.

2.1% 2017-10-29
9.8 CRITICAL

Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php.

2.1% 2017-10-29