ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-27909
In Joomla component 'jDownloads 3.9.8.2 Stable' the remote user can change some parameters in the address bar and see the names of other users' files

In Joomla component 'jDownloads 3.9.8.2 Stable' the remote user can change some parameters in the address bar and see the names of other users' files

NVD description · AI analysis pending
4.3<1%
  • jdownloads jdownloads
CVE-2020-19455
+2 in the same advisory: …19451 …19450
SQL injection exists in the jdownloads 3.2.63 component for Joomla! via components/com_jdownloads/helpers/categories.php, order function via the filter_order pa

SQL injection exists in the jdownloads 3.2.63 component for Joomla! via components/com_jdownloads/helpers/categories.php, order function via the filter_order parameter.

NVD description · AI analysis pending
7.51%
  • jdownloads jdownloads
CVE-2020-19447
SQL injection exists in the jdownloads 3.2.63 component for Joomla! com_jdownloads/models/send.php via the f_marked_files_id parameter.

SQL injection exists in the jdownloads 3.2.63 component for Joomla! com_jdownloads/models/send.php via the f_marked_files_id parameter.

NVD description · AI analysis pending
7.51%
  • jdownloads jdownloads
CVE-2018-10068
The jDownloads extension before 3.2.59 for Joomla! has XSS.

The jDownloads extension before 3.2.59 for Joomla! has XSS.

NVD description · AI analysis pending
6.14%
  • jdownloads jdownloads