Total CVEs

140,356

Critical Severity

3,747

High Severity

13,524

Last 7 Days

1,771
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,641 - 9,660 of 13,221 CVEs
CVE-2018-25196 HIGH - 8.2

ServerZilla 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter. Attackers can send POST requests to reset.php with malicious email values containing SQL operators to bypass authentication ...

Vendor: Serverzilla
Product: ServerZilla
Published: Mar 06, 2026
Source: NVD
CVE-2018-25194 HIGH - 8.2

Nominas 0.27 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the username parameter. Attackers can send POST requests to the login/checklogin.php endpoint with crafted UNION-based SQL injection payload...

Vendor: Arixolab
Product: Nominas
Published: Mar 06, 2026
Source: NVD
CVE-2018-25193 HIGH - 7.5

Mongoose Web Server 6.9 contains a denial of service vulnerability that allows remote attackers to crash the service by establishing multiple socket connections. Attackers can repeatedly create connections to the default port and send malformed data to exhaust server resources and cause service unav...

Vendor: Cesanta
Product: Mongoose Web Server
Published: Mar 06, 2026
Source: NVD
CVE-2018-25192 HIGH - 8.2

GPS Tracking System 2.12 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can submit crafted POST requests to the login.php endpoint with SQL injection payloads in the username field...

Vendor: Sourceforge
Product: GPS Tracking System
Published: Mar 06, 2026
Source: NVD
CVE-2018-25191 HIGH - 7.1

Facturation System 1.0 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'mod_id' parameter. Attackers can send POST requests to the editar_producto.php endpoint with crafted SQL payloads in ...

Vendor: Obedalvarado
Product: Facturation System
Published: Mar 06, 2026
Source: NVD
CVE-2018-25189 HIGH - 8.2

Data Center Audit 2.6.2 contains an SQL injection vulnerability in the username parameter of dca_login.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted SQL payloads through POST requests to extract sensitive database information including usern...

Vendor: Sourceforge
Product: Data Center Audit
Published: Mar 06, 2026
Source: NVD
CVE-2018-25188 HIGH - 8.2

Webiness Inventory 2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the order parameter. Attackers can send POST requests to the WsModelGrid.php endpoint with crafted SQL payloads to extract sensiti...

Vendor: Github
Product: Webiness Inventory
Published: Mar 06, 2026
Source: NVD
CVE-2018-25187 HIGH - 8.2

Tina4 Stack 1.0.3 contains multiple vulnerabilities allowing unauthenticated attackers to access sensitive database files and execute SQL injection attacks. Attackers can directly request the kim.db database file to retrieve user credentials and password hashes, or inject SQL code through the menu e...

Vendor: Tina4
Product: Tina4 Stack
Published: Mar 06, 2026
Source: NVD
CVE-2018-25182 HIGH - 8.2

Silurus Classifieds Script 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the ID parameter. Attackers can send GET requests to wcategory.php with crafted SQL payloads in the ID parameter to extrac...

Vendor: Snowhall
Product: Silurus Classifieds Script
Published: Mar 06, 2026
Source: NVD
CVE-2018-25181 HIGH - 7.5

Musicco 2.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary directories by manipulating the parent parameter. Attackers can supply directory traversal sequences in the parent parameter of the getAlbum endpoint to access sensitive system directori...

Vendor: Musicco
Product: Musicco
Published: Mar 06, 2026
Source: NVD
CVE-2018-25180 HIGH - 7.1

Maitra 1.7.2 contains an sql injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the mailid parameter in outmail and inmail modules. Attackers can also download the SQLite database file directly from the application directo...

Vendor: Salzertechnologies
Product: Maitra
Published: Mar 06, 2026
Source: NVD
CVE-2018-25179 HIGH - 8.2

Gumbo CMS 0.99 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the language parameter. Attackers can send POST requests to the settings endpoint with crafted SQL payloads in the language parameter to e...

Vendor: Gumbo-Cms
Product: Gumbo CMS
Published: Mar 06, 2026
Source: NVD
CVE-2018-25178 HIGH - 7.5

Easyndexer 1.0 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the file parameter. Attackers can send POST requests to showtif.php with arbitrary file paths in the file parameter to retrieve system files like configu...

Vendor: Sourceforge
Product: Easyndexer
Published: Mar 06, 2026
Source: NVD
CVE-2018-25176 HIGH - 8.2

Alive Parish 2.0.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the key parameter in the search endpoint. Attackers can also upload arbitrary files via the person photo upload functionality to the i...

Vendor: Demo
Product: Alive Parish
Published: Mar 06, 2026
Source: NVD
CVE-2018-25175 HIGH - 8.2

Alienor Web Libre 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the identifiant parameter. Attackers can submit crafted POST requests to index.php with SQL injection payloads in the identifiant f...

Vendor: Alienor
Product: Alienor Web Libre
Published: Mar 06, 2026
Source: NVD
CVE-2018-25173 HIGH - 8.2

Rmedia SMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the gid parameter. Attackers can send GET requests to editgrp.php with malicious gid values using EXTRACTVALUE and CONCAT functions to retrieve s...

Vendor: Sms
Product: Rmedia SMS
Published: Mar 06, 2026
Source: NVD
CVE-2018-25172 HIGH - 8.2

Pedidos 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'q' parameter. Attackers can send GET requests to the ajax/load_proveedores.php endpoint with crafted SQL payloads to extract s...

Vendor: Obedalvarado
Product: Pedidos
Published: Mar 06, 2026
Source: NVD
CVE-2018-25171 HIGH - 8.2

EdTv 2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to the admin/edit_source endpoint with crafted SQL UNION statements to extract datab...

Vendor: Edtv
Product: EdTv
Published: Mar 06, 2026
Source: NVD
CVE-2018-25170 HIGH - 8.2

DoceboLMS 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id, idC, and idU parameters. Attackers can send GET requests to the lesson.php endpoint with malicious SQL payloads to extract sensitive databa...

Vendor: Spaghettilearning
Product: DoceboLMS
Published: Mar 06, 2026
Source: NVD
CVE-2018-25169 HIGH - 7.5

AMPPS 2.7 contains a denial of service vulnerability that allows remote attackers to crash the service by sending malformed data to the default HTTP port. Attackers can establish multiple socket connections and transmit invalid payloads to exhaust server resources and cause service unavailability.

Vendor: Ampps
Product: AMPPS
Published: Mar 06, 2026
Source: NVD