361,222
Total CVEs
26,155
Critical
85,582
High
1,625
CISA KEV
1,975
This Week
290 results · Page 2/12
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.856 through 0.9.8.864 allows an attacker to get a victim's session file name from the /tmp directory, and the victim's token value from /usr/local/cwpsrv/logs/access_log, then use them to make a request to extract the victim's password (for the OS and phpMyAdmin) via an attacker account.
control-webpanel
phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php.
phpmyadmin · debian
An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.
phpmyadmin · opensuse · fedoraproject
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
phpmyadmin · fedoraproject