Search Results (359807 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-37689 1 Phpgurukul 1 Maid Hiring Management System 2024-11-21 4.8 Medium
Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Booking Request page.
CVE-2023-37688 1 Phpgurukul 1 Maid Hiring Management System 2024-11-21 4.8 Medium
Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Admin page.
CVE-2023-37687 1 Phpgurukul 1 Online Nurse Hiring System 2024-11-21 7.2 High
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the View Request of Nurse Page in the Admin portal.
CVE-2023-37686 1 Phpgurukul 1 Online Nurse Hiring System 2024-11-21 4.8 Medium
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Nurse Page in the Admin portal.
CVE-2023-37685 1 Phpgurukul 1 Online Nurse Hiring System 2024-11-21 4.8 Medium
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Page of the Admin portal.
CVE-2023-37684 1 Phpgurukul 1 Online Nurse Hiring System 2024-11-21 4.8 Medium
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Details of the Admin portal.
CVE-2023-37683 1 Phpgurukul 1 Online Nurse Hiring System 2024-11-21 4.8 Medium
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Profile Page of the Admin.
CVE-2023-37682 1 Judging Management System Project 1 Judging Management System 2024-11-21 9.8 Critical
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-jms/deductScores.php.
CVE-2023-37679 1 Nextgen 1 Mirth Connect 2024-11-21 9.8 Critical
A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.
CVE-2023-37677 1 Pligg 1 Pligg Cms 2024-11-21 9.8 Critical
Pligg CMS v2.0.2 (also known as Kliqqi) was discovered to contain a remote code execution (RCE) vulnerability in the component admin_editor.php.
CVE-2023-37659 1 Xalpha Project 1 Xalpha 2024-11-21 9.8 Critical
xalpha v0.11.4 is vulnerable to Remote Command Execution (RCE).
CVE-2023-37658 1 Fastposter 1 Fast-poster 2024-11-21 5.4 Medium
fast-poster v2.15.0 is vulnerable to Cross Site Scripting (XSS). File upload check binary of img, but without strictly check file suffix at /server/fast.py -> ApiUploadHandler.post causes stored XSS
CVE-2023-37657 1 Lm21 1 Twonav 2024-11-21 5.4 Medium
TwoNav v2.0.28-20230624 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-37656 1 Websiteguide Project 1 Websiteguide 2024-11-21 9.8 Critical
WebsiteGuide v0.2 is vulnerable to Remote Command Execution (RCE) via image upload.
CVE-2023-37650 1 Agentejo 1 Cockpit 2024-11-21 8.8 High
A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands.
CVE-2023-37649 1 Agentejo 1 Cockpit 2024-11-21 7.5 High
Incorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized attackers to access sensitive data.
CVE-2023-37647 1 Sem-cms 1 Semcms 2024-11-21 9.8 Critical
SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.
CVE-2023-37646 1 Bitberry 1 File Opener 2024-11-21 7.8 High
An issue in the CAB file extraction function of Bitberry File Opener v23.0 allows attackers to execute a directory traversal.
CVE-2023-37645 1 Eyoucms 1 Eyoucms 2024-11-21 5.3 Medium
eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.
CVE-2023-37636 1 Webkul 1 Uvdesk 2024-11-21 5.4 Medium
A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field when creating a ticket.