CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
Global.py in AIL framework 2.8 allows path traversal.
OX App Suite through 7.10.3 allows SSRF.
OX App Suite through 7.10.3 has Improper Input Validation.
OX App Suite through 7.10.3 allows XSS.
OX App Suite through 7.10.3 allows XXE attacks.
Manageengine_adselfservice_plus, Application_control_plus, Desktop_central, Firewall_analyzer, Log360, Manageengine_access_manager_plus, Manageengine_ad360, Manageengine_adaudit_plus, Manageengine_admanager_plus, Manageengine_analytics_plus
2021-07-21
N/A
9.8 CRITICAL
An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an attacker to inject unauthorized commands, by executing the micomd executable deamon, to trigger unintended functionalities. In addition, this executable may be used by an attacker to inject commands to generate CAN frames that are sent into the M-CAN bus (Multimedia CAN bus) of the vehicle.
SQL injection with start and length parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql
SQL injection in order and column parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql
