Search Results (361498 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-36692 1 Ingredients Stock Management System Project 1 Ingredients Stock Management System 2024-11-21 9.8 Critical
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.
CVE-2022-36690 1 Ingredient Stock Management System Project 1 Ingredient Stock Management System 2024-11-21 8.8 High
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user&id=.
CVE-2022-36689 1 Ingredient Stock Management System Project 1 Ingredient Stock Management System 2024-11-21 8.8 High
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /admin/?page=reports/waste&month=.
CVE-2022-36688 1 Ingredient Stock Management System Project 1 Ingredient Stock Management System 2024-11-21 8.8 High
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /admin/?page=reports/stockout&month=.
CVE-2022-36687 1 Ingredient Stock Management System Project 1 Ingredient Stock Management System 2024-11-21 6.5 Medium
Ingredients Stock Management System v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /classes/Master.php?f=delete_img.
CVE-2022-36686 1 Ingredient Stock Management System Project 1 Ingredient Stock Management System 2024-11-21 8.8 High
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /admin/?page=reports/stockin&month=.
CVE-2022-36683 1 Simple Task Scheduling System Project 1 Simple Task Scheduling System 2024-11-21 9.8 Critical
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_payment.
CVE-2022-36682 1 Simple Task Scheduling System Project 1 Simple Task Scheduling System 2024-11-21 9.8 Critical
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_student.
CVE-2022-36681 1 Simple Task Scheduling System Project 1 Simple Task Scheduling System 2024-11-21 9.8 Critical
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_account.
CVE-2022-36680 1 Simple Task Scheduling System Project 1 Simple Task Scheduling System 2024-11-21 9.8 Critical
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule.
CVE-2022-36679 1 Simple Task Scheduling System Project 1 Simple Task Scheduling System 2024-11-21 9.8 Critical
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user.
CVE-2022-36678 1 Simple Task Scheduling System Project 1 Simple Task Scheduling System 2024-11-21 9.8 Critical
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.
CVE-2022-36676 1 Simple Task Scheduling System Project 1 Simple Task Scheduling System 2024-11-21 7.2 High
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /categories/view_category.php.
CVE-2022-36675 1 Simple Task Scheduling System Project 1 Simple Task Scheduling System 2024-11-21 7.2 High
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /schedules/manage_schedule.php.
CVE-2022-36674 1 Simple Task Scheduling System Project 1 Simple Task Scheduling System 2024-11-21 7.2 High
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /schedules/view_schedule.php.
CVE-2022-36672 1 Xxyopen 1 Novel-plus 2024-11-21 9.8 Critical
Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a custom user session.
CVE-2022-36671 1 Xxyopen 1 Novel-plus 2024-11-21 7.5 High
Novel-Plus v3.6.2 was discovered to contain an arbitrary file download vulnerability via the background file download API.
CVE-2022-36670 1 Pcprotect 1 Endpoint 2024-11-21 6.7 Medium
PCProtect Endpoint prior to v5.17.470 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator privileges to modify processes within the application and escalate privileges to SYSTEM via a crafted executable.
CVE-2022-36669 1 Hospital Information System Project 1 Hospital Information System 2024-11-21 9.8 Critical
Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
CVE-2022-36668 1 Garage Management System Project 1 Garage Management System 2024-11-21 5.4 Medium
Garage Management System 1.0 is vulnerable to Stored Cross Site Scripting (XSS) on several parameters. The vulnerabilities exist during creating or editing the parts under parameters. Using the XSS payload, the Stored XSS triggered and can be used for further attack vector.