Currently trending CVE - Hype Score: 1 - Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoint at /en/9-2radius.php where the radius_address POST parameter is split and interpolated directly into a sed command without sanitization. An unauthenticated ...
Currently trending CVE - Hype Score: 3 - Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in ...
Currently trending CVE - Hype Score: 11 - Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or ...
A vulnerability classified as critical has been found in Miethner-scripting DZ EROTIK Auktionshaus V4rgo. This issue affects some unknown processing of the file news.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is documented as CVE-2010-1094. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability identified as critical has been detected in phpMySite. Affected by this vulnerability is an unknown functionality of the file index.php. This manipulation of the argument action causes sql injection.
This vulnerability is tracked as CVE-2010-1090. The attack is possible to be carried out remotely. Moreover, an exploit is present.
A vulnerability labeled as problematic has been found in phpMySite. Affected by this issue is some unknown functionality of the file contact.php. Such manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2010-1091. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability marked as critical has been reported in ScriptsFeed Business Directory Software. This affects an unknown part of the file login.php of the component Login. Performing a manipulation results in sql injection.
This vulnerability is cataloged as CVE-2010-1092. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as problematic, was found in DeDeCMS 5.5. The impacted element is an unknown function of the file include/userlogin.class.php. Such manipulation of the argument _SESSION[dede_admin_id] leads to improper authentication.
This vulnerability is traded as CVE-2010-1097. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, has been found in ScriptsFeed Dating Software. The affected element is an unknown function of the file searchmatch.php. This manipulation of the argument txtlookgender causes sql injection.
This vulnerability appears as CVE-2010-1096. The attack may be initiated remotely. There is no available exploit.