Total
20050 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2019-25516 | 1 Jettweb | 1 Php Stock News Site Script | 2026-06-17 | N/A | 8.2 HIGH |
| Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the gallery_id parameter. Attackers can send GET requests to gallery.php with malicious gallery_id values using UNION-based SQL injection to extract sensitive database information. | |||||
| CVE-2019-25515 | 1 Jettweb | 1 Php Stock News Site Script | 2026-06-17 | N/A | 7.5 HIGH |
| Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an authentication bypass vulnerability in the login.php administration panel that allows unauthenticated attackers to gain administrative access by submitting crafted SQL syntax. Attackers can bypass authentication by submitting equals signs and 'or' operators as username and password parameters to access the administration panel without valid credentials. | |||||
| CVE-2019-25514 | 1 Jettweb | 1 Php Stock News Site Script | 2026-06-17 | N/A | 8.2 HIGH |
| Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows attackers to inject malicious SQL commands through the kelime parameter in POST requests. Attackers can manipulate the kelime parameter with UNION-based SQL injection payloads to extract sensitive data from the database or bypass authentication controls. | |||||
| CVE-2019-25513 | 1 Jettweb | 1 Php Stock News Site Script | 2026-06-17 | N/A | 8.2 HIGH |
| Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'q' parameter. Attackers can send GET requests to datagetir.php with malicious 'q' values using time-based blind SQL injection techniques to extract sensitive database information or bypass authentication. | |||||
| CVE-2019-25512 | 1 Jettweb | 1 Php Stock News Site Script | 2026-06-17 | N/A | 8.2 HIGH |
| Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows attackers to inject malicious SQL commands through the kelime parameter in POST requests. Attackers can manipulate the kelime parameter with UNION-based SQL injection payloads to extract sensitive database information or modify database contents. | |||||
| CVE-2019-25511 | 1 Jettweb | 1 Php Stock News Site Script | 2026-06-17 | N/A | 8.2 HIGH |
| Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the videoid parameter. Attackers can send GET requests to fonksiyonlar.php with malicious videoid values using UNION-based injection to extract sensitive database information. | |||||
| CVE-2019-25510 | 1 Jettweb | 1 Php Stock News Site Script | 2026-06-17 | N/A | 8.2 HIGH |
| Jettweb PHP Hazir Haber Sitesi Scripti V2 contains an authentication bypass vulnerability in the administration panel that allows unauthenticated attackers to gain administrative access by exploiting improper SQL query validation. Attackers can submit SQL injection payloads in the username and password fields of the admingiris.php login form to bypass authentication and access the administrative interface. | |||||
| CVE-2019-25509 | 2026-06-17 | N/A | 8.2 HIGH | ||
| XooDigital Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'p' parameter. Attackers can send GET requests to results.php with malicious 'p' values to extract sensitive database information. | |||||
| CVE-2019-25508 | 1 Jettweb | 1 Php Ready Advertisement Site Script | 2026-06-17 | N/A | 8.2 HIGH |
| Jettweb Php Hazir Ilan Sitesi Scripti V2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'kat' parameter. Attackers can send GET requests to the katgetir.php endpoint with malicious 'kat' values to extract sensitive database information. | |||||
| CVE-2019-25507 | 2026-06-17 | N/A | 8.2 HIGH | ||
| Ashop Shopping Cart Software contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'shop' parameter. Attackers can send GET requests to index.php with malicious 'shop' values using UNION-based SQL injection to extract sensitive database information. | |||||
| CVE-2019-25506 | 1 Freesms Project | 1 Freesms | 2026-06-17 | N/A | 8.2 HIGH |
| FreeSMS 2.1.2 contains a boolean-based blind SQL injection vulnerability in the password parameter that allows unauthenticated attackers to bypass authentication by injecting SQL code through the login endpoint. Attackers can exploit the vulnerable password parameter in requests to /pages/crc_handler.php?method=login to authenticate as any known user and subsequently modify their password via the profile update function. | |||||
| CVE-2019-25505 | 1 Bdtask | 1 Tradebox | 2026-06-17 | N/A | 7.1 HIGH |
| Tradebox 5.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the symbol parameter. Attackers can send POST requests to the monthly_deposit endpoint with malicious symbol values using boolean-based blind, time-based blind, error-based, or union-based SQL injection techniques to extract sensitive database information. | |||||
| CVE-2019-25504 | 2026-06-17 | N/A | 8.2 HIGH | ||
| NCrypted Jobgator contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the experience parameter. Attackers can send POST requests to the agents Find-Jobs endpoint with malicious experience values to extract sensitive database information. | |||||
| CVE-2019-25503 | 1 Blondish | 1 Phpads | 2026-06-17 | N/A | 7.1 HIGH |
| PHPads 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the bannerID parameter in click.php3. Attackers can submit crafted bannerID values using SQL comment syntax and functions like extractvalue to extract sensitive database information such as the current database name. | |||||
| CVE-2019-25501 | 1 Simplejobscript | 1 Simplejobscript | 2026-06-17 | N/A | 8.2 HIGH |
| Simple Job Script contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting malicious SQL code through the app_id parameter. Attackers can send POST requests to delete_application_ajax.php with crafted payloads to extract sensitive data, bypass authentication, or modify database contents. | |||||
| CVE-2019-25500 | 1 Simplejobscript | 1 Simplejobscript | 2026-06-17 | N/A | 8.2 HIGH |
| Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the employerid parameter. Attackers can send POST requests to the register-recruiters endpoint with time-based SQL injection payloads to extract sensitive data or modify database contents. | |||||
| CVE-2019-25499 | 1 Simplejobscript | 1 Simplejobscript | 2026-06-17 | N/A | 8.2 HIGH |
| Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the job_id parameter. Attackers can send POST requests to get_job_applications_ajax.php with malicious job_id values to bypass authentication, extract sensitive data, or modify database contents. | |||||
| CVE-2019-25498 | 1 Simplejobscript | 1 Simplejobscript | 2026-06-17 | N/A | 8.2 HIGH |
| Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the landing_location parameter. Attackers can send POST requests to the searched endpoint with malicious SQL payloads to bypass authentication and extract sensitive database information. | |||||
| CVE-2019-25497 | 1 Oscommerce | 1 Oscommerce | 2026-06-17 | N/A | 8.2 HIGH |
| osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the currency parameter. Attackers can send GET requests to shopping_cart.php with malicious currency values using boolean-based SQL injection payloads to extract sensitive database information. | |||||
| CVE-2019-25496 | 1 Oscommerce | 1 Oscommerce | 2026-06-17 | N/A | 8.2 HIGH |
| osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the products_id parameter. Attackers can modify the products_id value in product_info.php requests and append boolean-based SQL injection payloads to extract sensitive database information. | |||||
