CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2022-46890 MEDIUM

Weak access control in NexusPHP before 1.7.33 allows a remote authenticated user to edit any post in the forum (this is caused by a lack of checks performed by…

CVSS 4.3 EPSS 0.64% Jan 19, 2023
CVE-2022-46889 MEDIUM

A persistent cross-site scripting (XSS) vulnerability in NexusPHP before 1.7.33 allows remote authenticated attackers to permanently inject arbitrary web scrip…

CVSS 5.4 EPSS 60.11% Jan 19, 2023
CVE-2022-46888 MEDIUM

Multiple reflective cross-site scripting (XSS) vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to inject arbitrary web script or HTML via the…

CVSS 6.1 EPSS 1.54% Jan 19, 2023
CVE-2022-46887 CRITICAL

Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[] parameter in takeco…

CVSS 9.8 EPSS 19.37% Jan 19, 2023
CVE-2020-24769 CRITICAL

SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the classes parameter.

CVSS 9.8 EPSS 1.98% Mar 30, 2022
CVE-2020-24770 CRITICAL

SQL injection vulnerability in modrules.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 9.8 EPSS 2.43% Mar 30, 2022
CVE-2020-24771 HIGH

Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content.

CVSS 7.5 EPSS 2.05% Mar 30, 2022
CVE-2017-15305 MEDIUM

XSS exists in NexusPHP 1.5 via the keyword parameter to messages.php.

CVSS 6.1 EPSS 0.89% Oct 15, 2017
CVE-2017-12792 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authentication of administrators for requests t…

CVSS 6.1 EPSS 1.21% Oct 2, 2017
CVE-2017-14534 MEDIUM

Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF.

CVSS 6.1 EPSS 0.67% Sep 18, 2017
CVE-2017-14512 CRITICAL

NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an editforum action, a different vulnerability than CVE-2017-12981.

CVSS 9.8 EPSS 1.10% Sep 17, 2017
CVE-2017-14347 MEDIUM

NexusPHP 1.5.beta5.20120707 has XSS in the returnto parameter to fun.php in a delete action.

CVSS 6.1 EPSS 0.68% Sep 12, 2017
CVE-2017-12906 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in NexusPHP allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) cheaters…

CVSS 6.1 EPSS 0.82% Sep 7, 2017
CVE-2017-12838 HIGH

Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users for requests that (1) send manas…

CVSS 8.8 EPSS 0.56% Sep 7, 2017
CVE-2017-14076 CRITICAL

SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the id parameter to linksmanage.php in an editlink action.

CVSS 9.8 EPSS 1.14% Aug 31, 2017
CVE-2017-14070 MEDIUM

Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to ipsearch.php, related to PHP_SELF.

CVSS 6.1 EPSS 0.65% Aug 31, 2017
CVE-2017-14069 CRITICAL

SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the usernw array parameter to nowarn.php.

CVSS 9.8 EPSS 1.19% Aug 31, 2017
CVE-2017-13669 CRITICAL

SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the setanswered parameter to staffbox.php.

CVSS 9.8 EPSS 1.50% Aug 24, 2017
CVE-2017-12679 CRITICAL

SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the delcheater parameter to cheaterbox.php.

CVSS 9.8 EPSS 1.50% Aug 24, 2017
CVE-2017-12981 CRITICAL

NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an addforum action.

CVSS 9.8 EPSS 1.16% Aug 21, 2017
CVE-2017-12776 CRITICAL

SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the delreport parameter.

CVSS 9.8 EPSS 1.43% Aug 18, 2017
CVE-2017-12680 MEDIUM

Cross-Site Scripting (XSS) exists in NexusPHP 1.5 via the type parameter to shoutbox.php.

CVSS 6.1 EPSS 0.68% Aug 18, 2017
CVE-2017-12910 CRITICAL

SQL injection vulnerability in massmail.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the or parameter.

CVSS 9.8 EPSS 1.34% Aug 17, 2017
CVE-2017-12909 CRITICAL

SQL injection vulnerability in modtask.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the userid parameter.

CVSS 9.8 EPSS 1.36% Aug 17, 2017
CVE-2017-12908 CRITICAL

SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the conusr parameter.

CVSS 9.8 EPSS 1.29% Aug 17, 2017

Showing 1 to 25 CVEs · page 1 (more available)