|
1161
|
8.1 |
HIGH
Network
|
-
|
-
|
OpenCATS from version 0.9.1a contains an SQL injection vulnerability in DataGrid filter handling that allows authenticated attackers to inject SQL through crafted filters targeting the non-filterable…
New
|
CWE-89
SQL Injection
|
CVE-2026-49490
|
2026-06-2 01:55 |
2026-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1162
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by embedding malicious HTML in media file metad…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-48559
|
2026-06-2 01:55 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1163
|
7.5 |
HIGH
Network
|
-
|
-
|
Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulnerability in the Command ID 30 UDP packet handler that allows remote attackers t…
Update
|
CWE-125 CWE-754
Out-of-bounds Read Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-39929
|
2026-06-2 01:52 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1164
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted multipart form…
Update
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2018-25412
|
2026-06-2 01:52 |
2026-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1165
|
8.2 |
HIGH
Network
|
-
|
-
|
eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. A…
Update
|
CWE-89
SQL Injection
|
CVE-2018-25405
|
2026-06-2 01:51 |
2026-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1166
|
8.2 |
HIGH
Network
|
-
|
-
|
eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. A…
Update
|
CWE-89
SQL Injection
|
CVE-2018-25406
|
2026-06-2 01:51 |
2026-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1167
|
8.2 |
HIGH
Network
|
-
|
-
|
eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. A…
Update
|
CWE-89
SQL Injection
|
CVE-2018-25407
|
2026-06-2 01:51 |
2026-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1168
|
7.5 |
HIGH
Network
|
-
|
-
|
The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php endpoint that allows unauthenticated attackers to download arbitrary files by manipulating the filename pa…
Update
|
CWE-22
Path Traversal
|
CVE-2018-25408
|
2026-06-2 01:51 |
2026-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1169
|
8.8 |
HIGH
Network
|
-
|
-
|
SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by submitting PHP code through the fupload parameter. Attackers can upload …
Update
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-25409
|
2026-06-2 01:51 |
2026-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1170
|
7.1 |
HIGH
Network
|
-
|
-
|
SIM-PKH 2.4.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send G…
Update
|
CWE-89
SQL Injection
|
CVE-2018-25410
|
2026-06-2 01:51 |
2026-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|