Vulnerability index

Browse CVEs

53 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-50741 Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sen… Revive Adserver 6.0.8+ Fix from $1,9502026-06-26 MEDIUM 6.1 CVE-2026-50745 A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follo… Revive Adserver 6.0.8+ Fix from $1,6002026-06-26 MEDIUM 5.4 CVE-2026-50740 A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user … Revive Adserver 6.0.8+ Fix from $1,6002026-06-26 MEDIUM 5.4 CVE-2026-50742 A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue … Revive Adserver 6.0.8+ Fix from $1,6002026-06-26 MEDIUM 6.1 CVE-2023-53931 Revive Adserver 5.4.1 contains a cross-site scripting vulnerability in the banner advanced configuration page that allows attackers to inject malicio… Revive Adserver No fix yet Fix from $1,6002025-12-17 MEDIUM 6.5 CVE-2025-52670 Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accou… Revive Adserver after 6.0.1 Fix from $1,6002025-11-20 MEDIUM 6.1 CVE-2025-55124 Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script. Revive Adserver after 6.0.1 Fix from $1,6002025-11-20 MEDIUM 5.4 CVE-2025-55123 Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to t… Revive Adserver No fix yet Fix from $1,6002025-11-20 HIGH 8.8 CVE-2025-48986 Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and po… Revive Adserver after 6.0.1 Fix from $1,9502025-11-20 MEDIUM 6.1 CVE-2025-48987 Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XSS attack. Revive Adserver after 6.0.1 Fix from $1,6002025-11-20 MEDIUM 5.4 CVE-2025-52667 Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS attack to be possible for a … Revive Adserver after 6.0.1 Fix from $1,6002025-11-20 MEDIUM 5.4 CVE-2025-52668 Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential informatio… Revive Adserver after 6.0.1 Fix from $1,6002025-11-20 HIGH 8.8 CVE-2025-52664 SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in use… Revive Adserver Patch available Fix from $1,9502025-10-31 MEDIUM 6.1 CVE-2025-27208 A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker could trick a user with access… Revive Adserver 6.0.0+ Fix from $1,6002025-10-31 MEDIUM 6.1 CVE-2023-38040 A reflected XSS vulnerability exists in Revive Adserver 5.4.1 and earlier versions.. Revive Adserver after 5.4.1 Fix from $1,6002023-09-17 HIGH 7.1 CVE-2021-22948 Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some … Revive Adserver 5.3.0+ Fix from $1,9502021-09-23 MEDIUM 6.1 CVE-2021-22888EPSS 20% Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `status` parameter of campaign-zone-zones.php. An attacker could … Revive Adserver 5.2.0+ Fix from $1,6002021-03-25 MEDIUM 6.1 CVE-2021-22889EPSS 36% Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `statsBreakdown` parameter of stats.php (and possibly other scrip… Revive Adserver 5.2.0+ Fix from $1,6002021-03-25 MEDIUM 6.1 CVE-2021-22874EPSS 18% Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in userlog-index.php via the `period_preset` parameter. Revive Adserver 5.1.1+ Fix from $1,6002021-01-28 MEDIUM 6.1 CVE-2021-22875EPSS 18% Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in stats.php via the `setPerPage` parameter. Revive Adserver 5.1.1+ Fix from $1,6002021-01-28 MEDIUM 6.1 CVE-2021-22872 Revive Adserver before 5.1.0 is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the publicly accessible afr.php delivery scrip… Revive Adserver 5.1.0+ Fix from $1,6002021-01-26 MEDIUM 6.1 CVE-2021-22873EPSS 70% Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delivery scri… Revive Adserver 5.1.0+ Fix from $1,6002021-01-26 MEDIUM 6.8 CVE-2020-8142 A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoangn144. Revive Adserver, like… Revive Adserver 5.0.5+ Fix from $1,6002020-04-03 MEDIUM 6.1 CVE-2020-8143EPSS 70% An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144. A remote attacker could tr… Revive Adserver 5.0.5+ Fix from $1,6002020-04-03 MEDIUM 6.1 CVE-2020-8115EPSS 7% A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo Tediosi. T… Revive Adserver after 5.0.3 Fix from $1,6002020-02-04 HIGH 8.1 CVE-2019-5440 Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potential authentication bypass att… Revive Adserver 4.2.1+ Fix from $1,9502019-05-28 MEDIUM 5.4 CVE-2019-5433 A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL th… Revive Adserver 4.2.0+ Fix from $1,6002019-05-06 CRITICAL 9.0 CVE-2016-9470 Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. `www/delivery/asyncspc.php` was vulnerable to the fairly new Reflected F… Revive Adserver after 3.2.4 Fix from $2,3002017-03-28 MEDIUM 5.4 CVE-2016-9472 Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS. The Revive Adserver web installer scripts were vulnerable to a reflected XSS attac… Revive Adserver after 3.2.4 Fix from $1,6002017-03-28 CRITICAL 9.8 CVE-2016-9124 Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts. The login page of Revive Adserver is vulnerable … Revive Adserver after 3.2.2 Fix from $2,3002017-03-28