Total CVEs

140,323

Critical Severity

3,747

High Severity

13,514

Last 7 Days

1,775
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,121 - 9,140 of 13,211 CVEs
CVE-2026-4043 HIGH - 8.8

A security vulnerability has been detected in Tenda i12 1.0.0.6(2204). The impacted element is the function formwrlSSIDget of the file /goform/wifiSSIDget. Such manipulation of the argument index leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclose...

Published: Mar 12, 2026
Source: NVD
CVE-2019-25543 HIGH - 8.2

Netartmedia Real Estate Portal 5.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the page parameter. Attackers can submit POST requests to index.php with malicious SQL payloads in the page field to bypass au...

Vendor: Netartmedia
Product: Netartmedia Real Estate Portal
Published: Mar 12, 2026
Source: NVD
CVE-2019-25542 HIGH - 8.2

Netartmedia Real Estate Portal 5.0 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user_email parameter. Attackers can send POST requests to index.php with malicious payloads in the user_email field to bypa...

Vendor: Netartmedia
Product: Netartmedia Real Estate Portal
Published: Mar 12, 2026
Source: NVD
CVE-2019-25541 HIGH - 8.2

Netartmedia PHP Mall 4.1 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through unvalidated parameters. Attackers can inject time-based blind SQL payloads via the 'id' parameter in index.php or the 'Email' param...

Vendor: Netartmedia
Product: Netartmedia PHP Mall
Published: Mar 12, 2026
Source: NVD
CVE-2019-25540 HIGH - 8.2

Netartmedia PHP Mall 4.1 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQL code through various parameters. Attackers can craft malicious requests with SQL payloads to extract sensitive database information including ...

Vendor: Netartmedia
Product: Netartmedia PHP Mall
Published: Mar 12, 2026
Source: NVD
CVE-2019-25539 HIGH - 8.2

202CMS v10 beta contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the log_user parameter. Attackers can send POST requests to index.php with crafted SQL payloads using time-based blind injection techniques ...

Vendor: Sourceforge
Product: 202CMS
Published: Mar 12, 2026
Source: NVD
CVE-2019-25538 HIGH - 8.2

202CMS v10 beta contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the log_user parameter. Attackers can send crafted requests with malicious SQL statements in the log_user field to extract sensitive database inf...

Vendor: Sourceforge
Product: 202CMS
Published: Mar 12, 2026
Source: NVD
CVE-2019-25537 HIGH - 8.2

Netartmedia Event Portal 2.0 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with malicious SQL payloads in the Email fi...

Vendor: Netartmedia
Product: Netartmedia Event Portal
Published: Mar 12, 2026
Source: NVD
CVE-2019-25536 HIGH - 8.2

Netartmedia PHP Real Estate Agency 4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the features[] parameter. Attackers can send POST requests to index.php with crafted SQL payloads in the features[...

Vendor: Netartmedia
Product: Netartmedia PHP Real Estate Agency
Published: Mar 12, 2026
Source: NVD
CVE-2019-25535 HIGH - 8.2

Netartmedia PHP Dating Site contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with time-based SQL injection payloads in the Email field to ...

Vendor: Netartmedia
Product: Netartmedia Php Dating Site
Published: Mar 12, 2026
Source: NVD
CVE-2019-25534 HIGH - 8.2

Netartmedia PHP Car Dealer contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the features[] parameter. Attackers can submit POST requests to index.php with crafted SQL payloads in the features[] paramete...

Vendor: Netartmedia
Product: Netartmedia PHP Car Dealer
Published: Mar 12, 2026
Source: NVD
CVE-2019-25533 HIGH - 8.2

Netartmedia PHP Business Directory 4.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to the loginaction.php endpoint with crafted SQL payloads in the Ema...

Vendor: Phpbusinessdirectory
Product: Netartmedia PHP Business Directory
Published: Mar 12, 2026
Source: NVD
CVE-2019-25532 HIGH - 8.2

Netartmedia Jobs Portal 6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with crafted SQL payloads in the Email field to extract sens...

Vendor: Netartmedia
Product: Netartmedia Jobs Portal
Published: Mar 12, 2026
Source: NVD
CVE-2019-25531 HIGH - 8.2

Netartmedia Deals Portal contains an SQL injection vulnerability in the Email parameter of loginaction.php that allows unauthenticated attackers to manipulate database queries. Attackers can submit crafted SQL payloads through POST requests to extract sensitive information or bypass authentication m...

Vendor: Netartmedia
Product: Netartmedia Deals Portal
Published: Mar 12, 2026
Source: NVD
CVE-2019-25530 HIGH - 8.2

uHotelBooking System contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the system_page GET parameter. Attackers can send crafted requests to index.php with malicious system_page values using time-based blind SQL...

Vendor: Hotel-Booking-Script
Product: uHotelBooking System
Published: Mar 12, 2026
Source: NVD
CVE-2019-25529 HIGH - 7.1

Placeto CMS Alpha rv.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'page' parameter. Attackers can send GET requests to the admin/edit.php endpoint with malicious 'page' values using ...

Vendor: Sourceforge
Product: Placeto CMS
Published: Mar 12, 2026
Source: NVD
CVE-2019-25528 HIGH - 8.2

Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the property1 parameter. Attackers can send POST requests to the search/searchdetailed endpoint with malicious SQL payloads...

Vendor: Inoutscripts
Product: Inout EasyRooms Ultimate Edition
Published: Mar 12, 2026
Source: NVD
CVE-2019-25527 HIGH - 8.2

Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the numguest parameter. Attackers can send POST requests to the search/searchdetailed endpoint with malicious SQL payloads ...

Vendor: Inoutscripts
Product: Inout EasyRooms Ultimate Edition
Published: Mar 12, 2026
Source: NVD
CVE-2019-25526 HIGH - 8.2

Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the location parameter. Attackers can send POST requests to the search/searchdetailed endpoint with malicious SQL payloads ...

Vendor: Inoutscripts
Product: Inout EasyRooms Ultimate Edition
Published: Mar 12, 2026
Source: NVD
CVE-2019-25525 HIGH - 8.2

Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the guests parameter. Attackers can send POST requests to the search/rentals endpoint with malicious SQL payloads to bypass...

Vendor: Inoutscripts
Product: Inout EasyRooms Ultimate Edition
Published: Mar 12, 2026
Source: NVD