Vulnerabilities (CVE)

Total 396574 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2010-4925 1 Nuked-klan 2 Nuked-klan, Partenaires Module 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in clic.php in the Partenaires module 1.5 for Nuked-Klan allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2010-4924 1 Clearbudget 1 Clearbudget 2026-06-16 7.5 HIGH N/A
PHP remote file inclusion vulnerability in logic/controller.class.php in clearBudget 0.9.8 allows remote attackers to execute arbitrary PHP code via a URL in the actionPath parameter. NOTE: this issue has been disputed by a reliable third party
CVE-2010-4923 1 Virtuenetz 1 Virtue Book Store 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in book/detail.php in Virtue Netz Virtue Book Store allows remote attackers to execute arbitrary SQL commands via the bid parameter.
CVE-2010-4922 1 Allinta 1 Allinta Cms 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Allinta CMS 22.07.2010 allow remote attackers to execute arbitrary SQL commands via the i parameter in an edit action to (1) contentAE.asp or (2) templatesAE.asp.
CVE-2010-4921 1 Dmxready 1 Polling Booth Manager 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in inc_pollingboothmanager.asp in DMXReady Polling Booth Manager allows remote attackers to execute arbitrary SQL commands via the QuestionID parameter in a results action.
CVE-2010-4920 1 Micronetsoft 1 Rental Property Website 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in detail.asp in Micronetsoft Rental Property Management Website 1.0 allows remote attackers to execute arbitrary SQL commands via the ad_ID parameter.
CVE-2010-4919 1 Micronetsoft 1 Rv Dealer Website 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in detail.asp in Micronetsoft RV Dealer Website 1.0 allows remote attackers to execute arbitrary SQL commands via the vehicletypeID parameter.
CVE-2010-4918 2 Ijoomla, Joomla 2 Com Magazine, Joomla\! 2026-06-16 7.5 HIGH N/A
PHP remote file inclusion vulnerability in iJoomla Magazine (com_magazine) component 3.0.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the config parameter to magazine.functions.php.
CVE-2010-4917 1 A-blog 1 A-blog 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in sources/search.php in A-Blog 2.0 allows remote attackers to execute arbitrary SQL commands via the words parameter.
CVE-2010-4916 1 Coldgen 1 Coldusergroup 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in index.cfm in ColdGen ColdUserGroup 1.06 allow remote attackers to execute arbitrary SQL commands via the (1) ArticleID or (2) LibraryID parameter.
CVE-2010-4915 1 Coldgen 1 Coldbookmarks 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.cfm in ColdGen ColdBookmarks 1.22 allows remote attackers to execute arbitrary SQL commands via the BookmarkID parameter in an EditBookmark action.
CVE-2010-4914 1 Deltascripts 1 Php Classifieds 2026-06-16 7.5 HIGH N/A
PHP remote file inclusion vulnerability in tools/phpmailer/class.phpmailer.php in PHP Classifieds 7.3 allows remote attackers to execute arbitrary PHP code via a URL in the lang_path parameter.
CVE-2010-4913 1 Coldgen 1 Coldusergroup 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the search feature in ColdGen ColdUserGroup 1.06 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter. NOTE: some of these details are obtained from third party information.
CVE-2010-4912 1 Discuz 1 Ucenter Home 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in shop.php in UCenter Home 2.0 allows remote attackers to execute arbitrary SQL commands via the shopid parameter in a view action.
CVE-2010-4911 1 Sellatsite 1 Php Classifieds Ads 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in classi/detail.php in PHP Classifieds Ads allows remote attackers to execute arbitrary SQL commands via the sid parameter.
CVE-2010-4910 1 Coldgen 1 Coldcalendar 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.cfm in ColdGen ColdCalendar 2.06 allows remote attackers to execute arbitrary SQL commands via the EventID parameter in a ViewEventDetails action.
CVE-2010-4909 1 Mechbunny 1 Paysitereviewcms 2026-06-16 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in PaysiteReviewCMS 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to search.php or the (2) image parameter to image.php.
CVE-2010-4908 1 Virtuenetz 1 Virtue Shopping Mall 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in detail.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL commands via the prodid parameter.
CVE-2010-4907 1 Zenphoto 1 Zenphoto 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.3 allows remote attackers to inject arbitrary web script or HTML via the user parameter. NOTE: the from parameter is already covered by CVE-2009-4562.
CVE-2010-4906 1 Zenphoto 1 Zenphoto 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in zp-core/full-image.php in Zenphoto 1.3 and 1.3.1.2 allows remote attackers to execute arbitrary SQL commands via the a parameter. NOTE: some of these details are obtained from third party information.