Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
adminer adminer vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2020-35572
Adminer up to and including 4.7.8 allows XSS via the history parameter to the default URI.
Adminer Adminer
9.8
CVSSv3
CVE-2018-7667
Adminer up to and including 4.3.1 has SSRF via the server parameter.
Adminer Adminer
6.1
CVSSv3
CVE-2021-29625
Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4.8.0 affects users of MySQL, MariaDB, PgSQL and SQLite. XSS is in most cases prevented by strict CSP in all modern browsers. The only exception is when Adminer ...
Adminer Adminer
7.8
CVSSv3
CVE-2017-20066
A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public an...
Adminer Login Project Adminer Login 1.4.4
7.2
CVSSv3
CVE-2021-21311
Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and prior to 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4....
Adminer Adminer
Debian Debian Linux 9.0
4 Github repositories
7.5
CVSSv3
CVE-2021-43008
Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an malicious user to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database.
Adminer Adminer
Debian Debian Linux 9.0
2 Github repositories
9.8
CVSSv3
CVE-2020-35186
The official adminer docker images prior to 4.7.0-fastcgi contain a blank password for a root user. System using the adminer docker container deployed by affected versions of the docker image may allow a remote malicious user to achieve root access with a blank password.
Docker Adminer
5.4
CVSSv3
CVE-2020-19156
Cross Site Scripting (XSS) in Ari Adminer v1 allows remote malicious users to execute arbitrary code via the 'Title' parameter of the 'Add New Connections' component when the 'save()' function is called.
Ari-soft Ari Adminer 1.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started