SugarCRM versions prior to 7.9.4.0 and 7.11.0.0 suffer from a PHP code injection vulnerability in the WorkFlow module. User input passed through the $_POST[‘base_module’] parameter to the “Save” action of…
Oracle Application Express versions prior to 5.1.4.00.08 suffer from a cross site scripting vulnerability. The vulnerability is located in the OracleAnyChart.swf file. User input passed through the “__externalobjid” GET parameter…
SugarCRM versions prior to 7.9.5.0, 8.0.2, and 8.2.0 suffer from a PHP code injection vulnerability. User input passed through key values of the ‘labels_’ parameters is not properly sanitized before…
SugarCRM versions prior to 7.9.5.0, 8.0.2, and 8.2.0 suffer from a PHP code injection vulnerability. User input passed through the “trigger_event” parameter is not properly sanitized before being used to…
SugarCRM versions prior to 7.9.5.0, 8.0.2, and 8.2.0 suffer from a path traversal vulnerability. User input passed through the “webhook_target_module” parameter is not properly sanitized before being used to save…
Typo3 CMS pw_highslide_gallery extension version 0.3.1 suffers from a database disclosure vulnerability.
Typo3 CMS Static Info Tables extension version 6.7.3 suffers from a database disclosure vulnerability.
aria2 version 1.33.1 suffers from a password disclosure vulnerability when logging URLs with secrets in them.
Frog CMS version 0.9.5 suffers from a cross site scripting vulnerability.
Typo3 CMS twwc_pages extension version 8.7.x suffers from a database disclosure vulnerability.