Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2023-43267
A cross-site scripting (XSS) vulnerability in the publish article function of emlog pro v2.1.14 allows attackers to execute arbitrary web scripts or …
Emlog
Mitigation only
HIGH 7.2
CVE-2023-39121
emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.
Emlog
No fix yet
MEDIUM 6.5
CVE-2023-37049
emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php.
Emlog
No fix yet
HIGH 7.5
CVE-2020-19028
*File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/plugin.php…
Emlog
No fix yet
HIGH 7.2
CVE-2022-42189
Emlog Pro 1.6.0 plugins upload suffers from a remote code execution (RCE) vulnerability.
Emlog
No fix yet
CRITICAL 9.8
CVE-2022-23379
Emlog v6.0 was discovered to contain a SQL injection vulnerability via the $TagID parameter of getblogidsfromtagid().
Emlog
No fix yet
CRITICAL 9.8
CVE-2021-40883
A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins.
Emlog
No fix yet
HIGH 7.2
CVE-2020-21654
emlog v6.0 contains a vulnerability in the component admin\template.php, which allows attackers to getshell via a crafted Zip file.
Emlog
No fix yet
HIGH 7.2
CVE-2020-21013
emlog v6.0.0 contains a SQL injection via /admin/comment.php.
Emlog
No fix yet
MEDIUM 6.5
CVE-2020-21014
emlog v6.0.0 contains an arbitrary file deletion vulnerability in admin/plugin.php.
Emlog
No fix yet
HIGH 8.8
CVE-2021-30081
An issue was discovered in emlog 6.0.0stable. There is a SQL Injection vulnerability that can execute any SQL statement and query server sensitive da…
Emlog
No fix yet
MEDIUM 6.1
CVE-2020-18194
Cross Site Scripting (XSS) in emlog v6.0.0 allows remote attackers to execute arbitrary code by adding a crafted script as a link to a new blog post.
Emlog
No fix yet
CRITICAL 9.8
CVE-2021-31737
emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php.
Emlog
No fix yet
MEDIUM 6.1
CVE-2021-30227
Cross Site Scripting (XSS) vulnerability in the article comments feature in emlog 6.0.
Emlog
No fix yet
CRITICAL 9.8
CVE-2020-21585
Vulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module.
Emlog
No fix yet
MEDIUM 5.3
CVE-2021-3293EPSS 21%
emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webroot/file.
Emlog
No fix yet
HIGH 8.8
CVE-2018-18316
emlog v6.0.0 has CSRF via the admin/user.php?action=new URI.
Emlog
No fix yet