Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2019-6127
An issue was discovered in XiaoCms 20141229. It allows admin/index.php?c=database table[] SQL injection. This can be used for PHP code execution via …
Xiaocms
No fix yet
CRITICAL 9.8
CVE-2018-19196
An issue was discovered in XiaoCms 20141229. It allows remote attackers to execute arbitrary code by using the type parameter to bypass the standard …
Xiaocms
No fix yet
HIGH 8.8
CVE-2018-19192
An issue was discovered in XiaoCms 20141229. admin/index.php?c=content&a=add&catid=3 has CSRF, as demonstrated by entering news via the data[content]…
Xiaocms
No fix yet
MEDIUM 6.1
CVE-2018-19193
An issue was discovered in XiaoCms 20141229. There is XSS via the largest input box on the "New news" screen.
Xiaocms
No fix yet
MEDIUM 6.1
CVE-2018-19195
An issue was discovered in XiaoCms 20141229. There is XSS related to the template\default\show_product.html file.
Xiaocms
No fix yet
MEDIUM 5.3
CVE-2018-19194
An issue was discovered in XiaoCms 20141229. /admin/index.php?c=database allows full path disclosure in a "failed to open stream" error message.
Xiaocms
No fix yet
HIGH 8.8
CVE-2018-14331
An issue was discovered in XiaoCms X1 v20140305. There is a CSRF vulnerability to change the administrator account password via admin/index.php?c=ind…
Xiaocms X1
No fix yet