Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2024-36528 nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /admin/exten… Egovernment after 4.5.05 Fix from $1,9502024-06-10 MEDIUM 5.7 CVE-2024-36531 nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.php compo… Egovernment after 4.5.05 Fix from $1,6002024-06-10 MEDIUM 6.1 CVE-2022-3975 A vulnerability, which was classified as problematic, has been found in NukeViet CMS. Affected by this issue is the function filterAttr of the file v… Nukeviet 4.5+ Fix from $1,6002022-11-13 MEDIUM 5.4 CVE-2022-30874 There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02. Nukeviet 4.5.02+ Fix from $1,6002022-06-21 CRITICAL 9.8 CVE-2020-21808 SQL Injection vulnerability in NukeViet CMS 4.0.10 - 4.3.07 via:the topicsid parameter in modules/news/admin/addtotopics.php. Nukeviet after 4.3.07 Fix from $2,3002021-07-30 CRITICAL 9.8 CVE-2020-21809 SQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and the (2) group_price or groupid… Nukeviet after 4.3 Fix from $2,3002021-07-30 MEDIUM 6.1 CVE-2020-22765 Cross Site Scripting (XSS) vulnerability in NukeViet cms 4.4.0 via the editor in the News module. Nukeviet Mitigation only Fix from $1,6002021-07-30 CRITICAL 9.8 CVE-2019-7725 includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization forma… Nukeviet 4.3.04+ Fix from $2,3002020-12-31 CRITICAL 9.8 CVE-2019-7726 modules/banners/funcs/click.php in NukeViet before 4.3.04 has a SQL INSERT statement with raw header data from an HTTP request (e.g., Referer and Use… Nukeviet 4.3.04+ Fix from $2,3002020-12-31 HIGH 8.8 CVE-2020-13155 clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=clearsystem… Nukeviet No fix yet Fix from $1,9502020-06-23 MEDIUM 6.5 CVE-2020-13156 modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI. Nukeviet No fix yet Fix from $1,6002020-06-23 MEDIUM 6.5 CVE-2020-13157 modules\users\admin\edit.php in NukeViet 4.4 allows CSRF to change a user's password via an admin/index.php?nv=users&op=edit&userid= URI. The old pas… Nukeviet No fix yet Fix from $1,6002020-06-23