|
2001
|
8.2 |
HIGH
Network
|
-
|
-
|
Joomla! Component Twitch Tv 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the username and id …
|
CWE-89
SQL Injection
|
CVE-2017-20270
|
2026-06-23 03:35 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2002
|
8.2 |
HIGH
Network
|
-
|
-
|
Joomla! Component PHP-Bridge 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter.…
|
CWE-89
SQL Injection
|
CVE-2017-20275
|
2026-06-23 03:35 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2003
|
8.2 |
HIGH
Network
|
-
|
-
|
Joomla! Component SIMGenealogy 2.1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the type parameter. Att…
|
CWE-89
SQL Injection
|
CVE-2017-20276
|
2026-06-23 03:35 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2004
|
8.2 |
HIGH
Network
|
-
|
-
|
Joomla! Component Extra Search 2.2.8 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the establename paramet…
|
CWE-89
SQL Injection
|
CVE-2017-20281
|
2026-06-23 03:35 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2005
|
8.2 |
HIGH
Network
|
-
|
-
|
Joomla! Component jCart for OpenCart 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the product_id para…
|
CWE-89
SQL Injection
|
CVE-2017-20282
|
2026-06-23 03:35 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2006
|
8.2 |
HIGH
Network
|
-
|
-
|
Joomla! Component VMap 1.9.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the latlngbound parameter.…
|
CWE-89
SQL Injection
|
CVE-2019-25753
|
2026-06-23 03:35 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2007
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller stores the pull_request.statuses_url value from the webhook payload without valida…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-12726
|
2026-06-23 03:33 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2008
|
8.1 |
HIGH
Local
|
-
|
-
|
A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass qSnappers authentication mechanism and operate e.g. as root user.
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-41045
|
2026-06-23 03:32 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2009
|
7.3 |
HIGH
Local
|
-
|
-
|
A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or pot…
|
CWE-23
Relative Path Traversal
|
CVE-2026-41046
|
2026-06-23 03:32 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2010
|
- |
|
-
|
-
|
Lack of authentication when using the "snapshot diff" functions in qSnapper before version 1.3.3 allowed a local attacker to see otherwise read protected information.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-41047
|
2026-06-23 03:32 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|