Known vulnerabilities in phpmyadmin (Alpine package)

Software CPE: cpe:2.3:o:alpine:phpmyadmin_alpine_package:*:*:*:*:*:alpine_linux:*:*
Total vulnerabilities: 96
Public exploits: 5
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting phpmyadmin (Alpine package) phpmyadmin (Alpine package) is affected by 96 known vulnerabilities: 12 high, 41 medium, 43 low Critical High Medium Low

Vulnerabilities (96)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU26290 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-10803
CWE-79 Low
No
No
4.9.5-r0, 5.0.2-r0 21.03.2020 SB2020032102
SB2020033001
SB2020033003
and 8 more
#VU26289 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2020-10802
CWE-89 Low
No
No
4.9.5-r0, 5.0.2-r0 21.03.2020 SB2020032102
SB2020033001
SB2020033003
and 8 more
#VU26288 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2020-10804
CWE-89 Low
No
No
4.9.5-r0, 5.0.2-r0 21.03.2020 SB2020032102
SB2020033001
SB2020033003
and 8 more
#VU24075 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-19617
CWE-79 Low
No
No
- 08.01.2020 SB2019112306
SB2020011811
SB2020111916
#VU24074 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2020-5504
CWE-89 Low
Available
No
4.9.5-r0, 5.0.2-r0 08.01.2020 SB2020010802
SB2020011445
SB2020011805
and 1 more
#VU22939 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2019-18622
CWE-89 Low
No
No
- 23.11.2019 SB2019112306
SB2020011445
SB2020031924
and 4 more
#VU21174 - Cross-Site Request Forgery (CSRF)
CVE-2019-12922
CWE-352 Medium
Available
No
4.9.1-r0 18.09.2019 SB2019091805
SB2019092803
SB2019092804
and 5 more
#VU18682 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2019-11768
CWE-89 Low
No
No
4.9.0.1-r0, 4.9.1-r0 05.06.2019 SB2019050613
SB2019070212
SB2019070214
and 5 more
#VU18679 - Cross-Site Request Forgery (CSRF)
CVE-2019-12616
CWE-352 Medium
Available
No
4.9.0.1-r0, 4.9.1-r0 05.06.2019 SB2019060501
SB2019070212
SB2019070214
and 5 more
#VU17236 - Exposure of sensitive information to an unauthorized actor
CVE-2019-6799
CWE-200 Low
No
No
4.8.5-r0 28.01.2019 SB2019012208
SB2019021806
SB2019012708
and 3 more
#VU17232 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2019-6798
CWE-89 Medium
No
No
4.8.5-r0 28.01.2019 SB2019012208
SB2019021806
SB2019012707
and 3 more
#VU16500 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-19970
CWE-79 Low
No
No
4.8.4-r0 12.12.2018 SB2018121208
SB2018121410
SB2018121411
and 3 more
#VU16499 - Cross-Site Request Forgery (CSRF)
CVE-2018-19969
CWE-352 Medium
No
No
4.8.4-r0, 4.8.5-r0 12.12.2018 SB2018121208
SB2018121410
SB2018121411
and 2 more
#VU16498 - Missing release of memory after effective lifetime
CVE-2018-19968
CWE-401 Low
No
No
4.8.4-r0, 4.8.5-r0 12.12.2018 SB2018121208
SB2018121410
SB2018121411
and 3 more
#VU14494 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-15605
CWE-79 Low
No
No
4.8.3-r0 22.08.2018 SB2018082211
SB2018082701
SB2018082702
and 3 more
#VU13417 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-12581
CWE-79 Low
No
No
4.8.2-r0 21.06.2018 SB2018062201
SB2018062502
SB2020042359
and 5 more
#VU13418 - Improper Control of Filename for Include/Require Statement in PHP Program
CVE-2018-12613
CWE-98 High
Available
No
4.8.2-r0 21.06.2018 SB2018062201
SB2018062502
SB2019041504
and 1 more
#VU12284 - Cross-Site Request Forgery (CSRF)
CVE-2018-10188
CWE-352 Low
Available
No
4.8.0-r1 25.04.2018 SB2018042902
SB2018061151
#VU10710 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-7260
CWE-79 Low
No
No
4.7.8-r0 22.02.2018 SB2018022602
SB2018022306
SB2018022723
and 4 more
#VU10026 - Cross-Site Request Forgery (CSRF)
CVE-2017-1000499
CWE-352 Low
No
No
4.7.8-r0 11.01.2018 SB2018010307
SB2018022722


Showing elements 1 - 20 out of 96