14,642 vulnerabilities published in 2017
Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.
Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.
CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail.
Child Care Script 1.0 has SQL Injection via the /list city parameter.
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid paramet
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
Food Order Script 1.0 has SQL Injection via the /list city parameter.
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat o
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_d
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eve
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country pa
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid para
vBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an una
In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file delet
A security researcher found an XML External Entity (XXE) vulnerability on the Conserus Image Repository archive solution
K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025ac DeviceIoControl request
K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025a4 DeviceIoControl request
K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025c8 DeviceIoControl request
Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC fail to properly restrict ac
ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that
ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC use non-random default crede
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the re
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credent
Scan for 2017 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started