VYPR

CVEs

8,984 total · page 117 of 180

  • CVE-2017-17699CriDec 15, 2017
    risk 0.64cvss 9.8epss 0.00

    K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025ac DeviceIoControl request.

  • CVE-2017-14101CriDec 15, 2017
    risk 0.64cvss 9.8epss 0.01

    A security researcher found an XML External Entity (XXE) vulnerability on the Conserus Image Repository archive solution version 2.1.1.105 by McKesson Medical Imaging Company, which is now a Change Healthcare company. An unauthenticated user supplying a modified HTTP SOAP…

  • CVE-2017-17672CriDec 14, 2017
    risk 0.68cvss 9.8epss 0.15

    In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circumstances, code execution, because of unsafe usage of PHP's unserialize() in vB_Library_Template's cacheTemplates() function, which…

  • CVE-2017-17671CriDec 14, 2017
    risk 0.64cvss 9.8epss 0.05

    vBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an unauthenticated request that can include directory traversal sequences to specify an arbitrary pathname, and because ../ traversal is blocked but ..\ traversal is…

  • CVE-2017-17648CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.01

    Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter.

  • CVE-2017-14590CriDec 13, 2017
    risk 0.59cvss 9.1epss 0.00

    Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan that has a non-linked Mercurialrepository, create or edit a plan when there is at least…

  • CVE-2017-14589CriDec 13, 2017
    risk 0.62cvss 9.6epss 0.00

    It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration rights to Bamboo or who hosts a website that a Bamboo administrator visits, is able to exploit this vulnerability to execute…

  • CVE-2017-17642CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.

  • CVE-2017-17641CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.

  • CVE-2017-17640CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter.

  • CVE-2017-17639CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.

  • CVE-2017-17638CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.

  • CVE-2017-17637CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.

  • CVE-2017-17636CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.

  • CVE-2017-17635CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eventid parameter.

  • CVE-2017-17634CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.

  • CVE-2017-17633CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detail.php eid parameter.

  • CVE-2017-17632CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.

  • CVE-2017-17631CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.

  • CVE-2017-17630CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Yoga Class Script 1.0 has SQL Injection via the /list city parameter.

  • CVE-2017-17629CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter.

  • CVE-2017-17628CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.

  • CVE-2017-17627CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.

  • CVE-2017-17626CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.

  • CVE-2017-17625CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.02

    Professional Service Script 1.0 has SQL Injection via the service-list city parameter.

  • CVE-2017-17624CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.

  • CVE-2017-17623CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.

  • CVE-2017-17622CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.04

    Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.

  • CVE-2017-17621CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.04

    Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.

  • CVE-2017-17620CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.

  • CVE-2017-17619CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.04

    Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.

  • CVE-2017-17618CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.

  • CVE-2017-17617CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.

  • CVE-2017-17616CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Event Search Script 1.0 has SQL Injection via the /event-list city parameter.

  • CVE-2017-17614CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Food Order Script 1.0 has SQL Injection via the /list city parameter.

  • CVE-2017-17613CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter.

  • CVE-2017-17612CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.04

    Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.

  • CVE-2017-17611CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Doctor Search Script 1.0 has SQL Injection via the /list city parameter.

  • CVE-2017-17610CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid parameter.

  • CVE-2017-17609CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.

  • CVE-2017-17608CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Child Care Script 1.0 has SQL Injection via the /list city parameter.

  • CVE-2017-17607CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail.

  • CVE-2017-17606CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.

  • CVE-2017-17605CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.

  • CVE-2017-17604CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.

  • CVE-2017-17603CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter.

  • CVE-2017-17602CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter.

  • CVE-2017-17601CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter.

  • CVE-2017-17600CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter.

  • CVE-2017-17599CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter.