Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2020-29653
Froxlor through 0.10.22 does not perform validation on user input passed in the customermail GET parameter. The value of this parameter is reflected …
Froxlor
after 0.10.22
MEDIUM 5.4
CVE-2020-28957
Multiple cross-site scripting (XSS) vulnerabilities in the Customer Add module of Foxlor v0.10.16 allows attackers to execute arbitrary web scripts o…
Froxlor
No fix yet
CRITICAL 9.8
CVE-2021-42325EPSS 12%
Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.
Froxlor
0.10.30+
HIGH 8.8
CVE-2020-10235
An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary code via th…
Froxlor
0.10.14+
MEDIUM 6.1
CVE-2020-10236
An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the installation directory was n…
Froxlor
0.10.14+
MEDIUM 5.5
CVE-2020-10237
An issue was discovered in Froxlor through 0.10.15. The installer wrote configuration parameters including passwords into files in /tmp, setting prop…
Froxlor
after 0.10.15
HIGH 7.2
CVE-2018-1000527
Froxlor version <= 0.9.39.5 contains a PHP Object Injection vulnerability in Domain name form that can result in Possible information disclosure and …
Froxlor
after 0.9.39.5
HIGH 7.5
CVE-2018-12642
Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.
Froxlor
after 0.9.39.5
CRITICAL 9.8
CVE-2015-5959
Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/sql-error.…
Froxlor
after 0.9.33.1
CRITICAL 9.8
CVE-2016-5100
Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the password reset…
Froxlor
after 0.9.34.2