Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
adminer vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2018-7667
Adminer up to and including 4.3.1 has SSRF via the server parameter.
Adminer Adminer
4.3
CVSSv2
CVE-2021-29625
Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4.8.0 affects users of MySQL, MariaDB, PgSQL and SQLite. XSS is in most cases prevented by strict CSP in all modern browsers. The only exception is when Adminer ...
Adminer Adminer
4.3
CVSSv2
CVE-2020-35572
Adminer up to and including 4.7.8 allows XSS via the history parameter to the default URI.
Adminer Adminer
4.6
CVSSv2
CVE-2017-20066
A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public an...
Adminer Login Project Adminer Login 1.4.4
5
CVSSv2
CVE-2021-43008
Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an malicious user to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database.
Adminer Adminer
Debian Debian Linux 9.0
1 Github repository
6.4
CVSSv2
CVE-2021-21311
Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and prior to 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4....
Adminer Adminer
Debian Debian Linux 9.0
3 Github repositories
10
CVSSv2
CVE-2020-35186
The official adminer docker images prior to 4.7.0-fastcgi contain a blank password for a root user. System using the adminer docker container deployed by affected versions of the docker image may allow a remote malicious user to achieve root access with a blank password.
Docker Adminer
3.5
CVSSv2
CVE-2020-19156
Cross Site Scripting (XSS) in Ari Adminer v1 allows remote malicious users to execute arbitrary code via the 'Title' parameter of the 'Add New Connections' component when the 'save()' function is called.
Ari-soft Ari Adminer 1.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3400
CVE-2023-7252
CVE-2024-21111
denial of service
CVE-2024-29661
CVE-2024-22856
remote attackers
encryption
CVE-2023-38299
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started