Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,641 - 5,660 of 34,871 CVEs
CVE-2018-25404 HIGH - 8.2

The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the ticket_id parameter. Attackers can send GET requests to add_facnote.php with crafted SQL payloads to extract sensitive da...

Vendor: Open ISES
Product: Open ISES Project
Published: May 29, 2026
Source: NVD
CVE-2018-25403 HIGH - 8.2

The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the p1 parameter. Attackers can send GET requests to city_graph.php with crafted SQL payloads to extract sensitive database i...

Vendor: Open ISES
Product: Open ISES Project
Published: May 29, 2026
Source: NVD
CVE-2018-25402 HIGH - 8.2

The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the p1 parameter. Attackers can send GET requests to inc_types_graph.php with crafted SQL payloads to extract sensitive datab...

Vendor: Open ISES
Product: Open ISES Project
Published: May 29, 2026
Source: NVD
CVE-2018-25401 HIGH - 8.2

The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the p1 parameter. Attackers can send GET requests to sever_graph.php with crafted SQL payloads to extract sensitive database ...

Vendor: Open ISES
Product: Open ISES Project
Published: May 29, 2026
Source: NVD
CVE-2018-25400 HIGH - 8.2

The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to the ajax/form_post.php endpoint with crafted SQL payloads to...

Vendor: Open ISES
Product: Open ISES Project
Published: May 29, 2026
Source: NVD
CVE-2018-25399 HIGH - 8.2

The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the tick_lat and tick_lng parameters. Attackers can send GET requests to nearby.php with crafted SQL payloads to extract sens...

Vendor: Open ISES
Product: Open ISES Project
Published: May 29, 2026
Source: NVD
CVE-2018-25398 HIGH - 8.2

The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the frm_passwd parameter. Attackers can send POST requests to main.php with crafted SQL payloads to extract sensitive databas...

Vendor: Open ISES
Product: Open ISES Project
Published: May 29, 2026
Source: NVD
CVE-2018-25397 MEDIUM - 5.3

PHP-SHOP 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to add administrative users by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form that automatically submits POST requests...

Vendor: joeyrush
Product: PHP-SHOP master
Published: May 29, 2026
Source: NVD
CVE-2018-25396 HIGH - 7.5

Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve administrative credentials by accessing the networkSetup.htm page. Attackers can request the networkSetup.htm endpoint and extract plaintext username and password values fro...

Vendor: Heatmiser
Product: Heatmiser Wifi Thermostat
Published: May 29, 2026
Source: NVD
CVE-2018-25395 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the feature_id parameter of boards_buttons/update_feature.php. The feature_id value is concatenated directly into SQL statements witho...

Vendor: Kados
Product: Kados R10 GreenBee
Published: May 29, 2026
Source: NVD
CVE-2018-25394 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the release_id parameter of boards_buttons/update_release.php. The release_id value is concatenated directly into SQL statements witho...

Vendor: Kados
Product: Kados R10 GreenBee
Published: May 29, 2026
Source: NVD
CVE-2018-25393 MEDIUM - 6.5

Navigate CMS 2.8.5 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by injecting directory traversal sequences in the id parameter. Attackers can send GET requests to navigate_download.php with path traversal payloads ../../../cfg/globals.php to acc...

Vendor: Navigatecms
Product: Navigate CMS
Published: May 29, 2026
Source: NVD
CVE-2018-25392 HIGH - 7.1

MaxOn ERP Software 8.x-9.x contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries through the nomor, user, and jenis parameters in the log_activity function. Attackers can send POST requests to /index.php/user/log_activity with malicious SQL code in ...

Vendor: Talagasoft
Product: MaxOn ERP
Published: May 29, 2026
Source: NVD
CVE-2018-25391 HIGH - 7.5

HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to delete arbitrary records by sending a crafted request that specifies the target record's id. The admin/modul/mod_pengurus/aksi_pengurus.php (module=pengurus&act=hapus) and adm...

Vendor: Sitejo
Product: HaPe PKH
Published: May 29, 2026
Source: NVD
CVE-2018-25390 HIGH - 8.2

HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'desa' POST parameter sent to lap-peserta-perdesa-pdf.php. Attackers can send a crafted request with a time-based blind payload to inf...

Vendor: Sitejo
Product: HaPe PKH
Published: May 29, 2026
Source: NVD
CVE-2018-25389 HIGH - 8.2

HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'nama_kelompok' POST parameter sent to lap-anggota-kelompok-pdf.php. Attackers can send a crafted request with a time-based blind payl...

Vendor: Sitejo
Product: HaPe PKH
Published: May 29, 2026
Source: NVD
CVE-2018-25388 HIGH - 8.8

HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload PHP files through multiple endpoints including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php to execute arbitrary ...

Vendor: Sitejo
Product: HaPe PKH
Published: May 29, 2026
Source: NVD
CVE-2018-25387 MEDIUM - 5.3

HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords by submitting forged requests to the user update endpoint. Attackers can craft malicious forms targeting the aksi_user.php script with parameters like id_user, password, and level...

Vendor: Sitejo
Product: HaPe PKH
Published: May 29, 2026
Source: NVD
CVE-2018-25386 HIGH - 8.2

HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate database queries by injecting SQL code through the 'id' parameter. An unauthenticated attacker can exploit the desa module (module=desa&act=hapus), while authenticated use...

Vendor: Sitejo
Product: HaPe PKH
Published: May 29, 2026
Source: NVD
CVE-2018-25385 HIGH - 8.2

E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id_partai parameter. Attackers can send GET requests to monitor_nilai.php with crafted SQL payloads in the id_partai ...

Vendor: eregistrasi-kejuaraan-silat
Product: Registrasi Pencak Silat
Published: May 29, 2026
Source: NVD