Vulnerability index

Browse CVEs

39 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2023-29962 S-CMS v5.0 was discovered to contain an arbitrary file read vulnerability. S Cms No fix yet Fix from $1,6002024-01-04 HIGH 8.8 CVE-2023-7190 A vulnerability, which was classified as critical, has been found in S-CMS up to 2.0_build20220529-20231006. Affected by this issue is some unknown f… S Cms Mitigation only Fix from $1,9502023-12-31 HIGH 8.8 CVE-2023-7191 A vulnerability, which was classified as critical, was found in S-CMS up to 2.0_build20220529-20231006. This affects an unknown part of the file memb… S Cms Mitigation only Fix from $1,9502023-12-31 HIGH 8.8 CVE-2023-7189 A vulnerability classified as critical was found in S-CMS up to 2.0_build20220529-20231006. Affected by this vulnerability is an unknown functionalit… S Cms Mitigation only Fix from $1,9502023-12-31 CRITICAL 9.8 CVE-2023-51050 S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_productauth parameter at /admin/ajax.php. S Cms Mitigation only Fix from $2,3002023-12-21 CRITICAL 9.8 CVE-2023-51051 S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_textauth parameter at /admin/ajax.php. S Cms Mitigation only Fix from $2,3002023-12-21 CRITICAL 9.8 CVE-2023-51052 S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_formauth parameter at /admin/ajax.php. S Cms Mitigation only Fix from $2,3002023-12-21 CRITICAL 9.8 CVE-2023-51048 S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_newsauth parameter at /admin/ajax.php. S Cms Mitigation only Fix from $2,3002023-12-21 CRITICAL 9.8 CVE-2023-51049 S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_bbsauth parameter at /admin/ajax.php. S Cms Mitigation only Fix from $2,3002023-12-21 HIGH 7.2 CVE-2023-29963 S-CMS v5.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /admin/ajax.php. S Cms No fix yet Fix from $1,9502023-05-05 MEDIUM 5.4 CVE-2022-4377 A vulnerability was found in S-CMS 5.0 Build 20220328. It has been declared as problematic. Affected by this vulnerability is an unknown functionalit… S Cms Mitigation only Fix from $1,6002022-12-09 CRITICAL 9.8 CVE-2022-23336 S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter. S Cms No fix yet Fix from $2,3002022-02-14 MEDIUM 6.1 CVE-2020-20425 S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in the search function. S Cms No fix yet Fix from $1,6002021-12-22 MEDIUM 6.1 CVE-2020-20426 S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in /function/booksave.php. S Cms No fix yet Fix from $1,6002021-12-22 HIGH 7.5 CVE-2020-19954 An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files. S Cms No fix yet Fix from $1,9502021-10-14 CRITICAL 9.8 CVE-2021-37270 There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0. Attackers can use this vulnerability to directly… Cms Enterprise Website Construction System Mitigation only Fix from $2,3002021-09-27 MEDIUM 5.4 CVE-2020-19158 Cross Site Scripting (XSS) in S-CMS build 20191014 and earlier allows remote attackers to execute arbitrary code via the 'Site Title' parameter of th… S Cms Mitigation only Fix from $1,6002021-09-15 HIGH 7.5 CVE-2020-20340 A SQL injection vulnerability in the 4.edu.php\conn\function.php component of S-CMS v1.0 allows attackers to access sensitive database information. S Cms No fix yet Fix from $1,9502021-09-01 MEDIUM 5.4 CVE-2020-19046 Cross Site Scripting (XSS) in S-CMS v1.0 allows remote attackers to execute arbitrary code via the component '/admin/tpl.php?page='. S Cms No fix yet Fix from $1,6002021-08-31 HIGH 7.2 CVE-2020-20698 A remote code execution (RCE) vulnerability in /1.com.php of S-CMS PHP v3.0 allows attackers to getshell via modification of a PHP file. S Cms No fix yet Fix from $1,9502021-07-30 MEDIUM 6.1 CVE-2019-17368 S-CMS v1.5 has XSS in tpl.php via the member/member_login.php from parameter. S Cms No fix yet Fix from $1,6002019-10-09 MEDIUM 6.1 CVE-2019-16312 s-cms V3.0 has XSS in index.php?type=text via the S_id parameter. S Cms No fix yet Fix from $1,6002019-09-14 CRITICAL 9.8 CVE-2019-10708 S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter. S Cms No fix yet Fix from $2,3002019-04-02 HIGH 8.8 CVE-2019-10237 S-CMS PHP v1.0 has a CSRF vulnerability to add a new admin user via the 4.edu.php/admin/ajax.php?type=admin&action=add&lang=0 URI, a related issue to… S Cms No fix yet Fix from $1,9502019-03-27 MEDIUM 6.1 CVE-2019-9925 S-CMS PHP v1.0 has XSS in 4.edu.php via the S_id parameter. S Cms No fix yet Fix from $1,6002019-03-22 HIGH 8.8 CVE-2019-9040 S-CMS PHP v3.0 has a CSRF vulnerability to add a new admin user via the admin/ajax.php?type=admin&action=add URI, a related issue to CVE-2018-19332. S Cms Mitigation only Fix from $1,9502019-02-23 CRITICAL 9.8 CVE-2019-6805 SQL Injection was found in S-CMS version V3.0 via the alipay/alipayapi.php O_id parameter. S Cms No fix yet Fix from $2,3002019-01-25 CRITICAL 9.8 CVE-2018-20477 An issue was discovered in S-CMS 3.0. It allows SQL Injection via the bank/callback1.php P_no field. S Cms No fix yet Fix from $2,3002018-12-26 CRITICAL 9.8 CVE-2018-20479 An issue was discovered in S-CMS 1.0. It allows SQL Injection via the wap_index.php?type=newsinfo S_id parameter. S Cms No fix yet Fix from $2,3002018-12-26 CRITICAL 9.8 CVE-2018-20480 An issue was discovered in S-CMS 1.0. It allows SQL Injection via the js/pic.php P_id parameter. S Cms No fix yet Fix from $2,3002018-12-26