VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,947 CVE recordsPage 860 of 1264 · EPSS data 2026.08.10
ReviewHigh
CVE-2019-25704

Kados Kados R10 GreenBee, kados

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the filter_user_mail parameter. Attackers can send crafted requests with malicious SQL statements to extract sensitive database information or modify data.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2019-25702

Kados Kados R10 GreenBee, kados

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_project parameter. Attackers can send crafted requests with malicious SQL statements in the id_project parameter to extract sensitive database information or modify data.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2019-25700

Kados Kados R10 GreenBee, kados

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the sort_direction parameter. Attackers can submit malicious SQL statements in the sort_direction parameter to extract sensitive database information or modify data.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2019-25698

Kados Kados R10 GreenBee, kados

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_to_delete parameter. Attackers can send crafted requests with malicious SQL statements in the id_to_delete field to extract or modify sensitive database information.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2019-25696

Kados Kados R10 GreenBee, kados

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the language_tag parameter. Attackers can submit malicious SQL statements in the language_tag parameter to extract sensitive database information or modify data.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2019-25694

Kados Kados R10 GreenBee, kados

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user2reset parameter. Attackers can send crafted requests with malicious SQL payloads to extract sensitive database information or modify data.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2019-25692

Kados Kados R10 GreenBee, kados

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id_to_modify' parameter. Attackers can send crafted requests with malicious SQL statements in the id_to_modify field to extract sensitive database information or modify data.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2019-25690

Kados Kados R10 GreenBee, kados

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the mng_profile_id parameter. Attackers can send crafted requests with malicious SQL payloads in the mng_profile_id parameter to extract sensitive database information.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2019-25688

Kados Kados GreenBee, kados

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the menu_lev1 parameter. Attackers can send crafted requests with malicious SQL payloads in the menu_lev1 parameter to extract sensitive database information or modify database contents.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2019-25687

wisdom Pegasus CMS, pegasus cms

Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated attackers to execute arbitrary commands by exploiting unsafe eval functionality. Attackers can send POST requests to the submit.php endpoint with malicious PHP code in the action parameter to achieve code execution and obtain an interactive shell.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2019-25686

Coreftp Core FTP, core ftp

Core FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attackers to crash the service by sending a malformed command with an oversized buffer. Attackers can send a PBSZ command with a payload exceeding 211 bytes to trigger an access violation and crash the FTP server process.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2019-25684

opendocman OpenDocMan, opendocman

OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'where' parameter. Attackers can send GET requests to search.php with malicious SQL payloads in the 'where' parameter to extract sensitive database information.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2019-25681

Xlightftpd Xlight, xlight ftp server

Xlight FTP Server 3.9.1 contains a structured exception handler (SEH) overwrite vulnerability that allows local attackers to crash the application and overwrite SEH pointers by supplying a crafted buffer string. Attackers can inject a 428-byte payload through the program execution field in virtual server configuration to trigger a buffer overflow that corrupts the SEH chain and enables potential code execution.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2019-25680

Phpscriptsmall Advance Gift Shop Pro Script, advance gift shop pro script

Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can submit crafted SQL payloads in the 's' parameter of search requests to extract sensitive database information including version details and other data.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2019-25679

Realterm RealTerm: Serial Terminal, realterm

RealTerm Serial Terminal 2.0.0.70 contains a structured exception handling (SEH) buffer overflow vulnerability in the Echo Port tab that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a buffer overflow payload with a POP POP RET gadget chain and shellcode that triggers code execution when pasted into the Port field and the Change button is clicked.

The CVSS severity warrants an early asset and exposure review.