Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Discuz\! HIGH 8.8
CVE-2018-14729EPSS 11%

The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP code.

Fix: after 3.4
Fix from $1,950 2019-05-22
Discuzx HIGH 8.1
CVE-2018-20422

Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-empty #wechat#common_member_w…

No fix yet
Fix from $1,950 2018-12-24
Discuzx HIGH 8.1
CVE-2018-20423

Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass a "disabled registration" setting by adding a non-existing wxope…

No fix yet
Fix from $1,950 2018-12-24
Discuzx MEDIUM 5.9
CVE-2018-20424

Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the common_member_wechatmp data structure via an ac=unbindmp req…

No fix yet
Fix from $1,600 2018-12-24
Duomicms CRITICAL 9.8
CVE-2018-18083

An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during …

No fix yet
Fix from $2,300 2018-10-09
Duomicms CRITICAL 9.8
CVE-2018-18084

An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter.

No fix yet
Fix from $2,300 2018-10-09
Crazy Star Plugin HIGH 7.5
CVE-2009-3185

SQL injection vulnerability in plugin.php in the Crazy Star plugin 2.0 for Discuz! allows remote authenticated users to execute arbitrary SQL command…

No fix yet
Fix from $1,950 2009-09-15
Crossday Discuz\! Board MEDIUM 6.5
CVE-2008-6958EPSS 6%

wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via the creditsformula parameter.

No fix yet
Fix from $1,600 2009-08-12
Discuz HIGH 7.5
CVE-2008-3554

SQL injection vulnerability in index.php in Discuz! 6.0.1 allows remote attackers to execute arbitrary SQL commands via the searchid parameter in a s…

No fix yet
Fix from $1,950 2008-08-08