Search Results (323565 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-42552 1 Vaibhavverma9999 1 Hotel Management System 2025-06-05 8.6 High
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_room_history.php.
CVE-2024-42553 1 Vaibhavverma9999 1 Hotel Management System 2025-06-05 8.8 High
A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
CVE-2024-42554 2 Hotel Management System Project, Vaibhavverma9999 2 Hotel Management System, Hotel Management System 2025-06-05 8.8 High
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_added.php.
CVE-2024-42555 1 Vaibhavverma9999 1 Hotel Management System 2025-06-05 8.8 High
A Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
CVE-2024-42556 1 Vaibhavverma9999 1 Hotel Management System 2025-06-05 9.8 Critical
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php.
CVE-2024-42557 1 Vaibhavverma9999 1 Hotel Management System 2025-06-05 8.8 High
A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
CVE-2024-42558 1 Vaibhavverma9999 1 Hotel Management System 2025-06-05 9.8 Critical
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_modify_room.php.
CVE-2024-42560 1 Varunsardana004 1 Blood Bank And Donation Management System 2025-06-05 6.1 Medium
A cross-site scripting (XSS) vulnerability in the component update_page_details.php of Blood Bank And Donation Management System commit dc9e039 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Details parameter.
CVE-2024-42561 2 Krishna9772, Pharmacy Management System Project 2 Pharmacy Management System, Pharmacy Management System 2025-06-05 8.8 High
Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at sales_report.php.
CVE-2024-42562 1 Krishna9772 1 Pharmacy Management System 2025-06-05 9.8 Critical
Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php.
CVE-2024-42563 1 Jerryhanjj 1 Erp 2025-06-05 9.8 Critical
An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file.
CVE-2024-42569 1 Arajajyothibabu 1 School Management System 2025-06-05 9.8 Critical
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at paidclass.php.
CVE-2024-42571 2 Arajajyothibabu, School Management System Project 2 School Management System, School Management System 2025-06-05 9.8 Critical
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at insertattendance.php.
CVE-2024-20697 1 Microsoft 3 Windows 11 22h2, Windows 11 23h2, Windows Server 2022 23h2 2025-06-05 7.3 High
Windows libarchive Remote Code Execution Vulnerability
CVE-2024-22705 1 Linux 1 Linux Kernel 2025-06-05 7.8 High
An issue was discovered in ksmbd in the Linux kernel before 6.6.10. smb2_get_data_area_len in fs/smb/server/smb2misc.c can cause an smb_strndup_from_utf16 out-of-bounds access because the relationship between Name data and CreateContexts data is mishandled.
CVE-2024-22099 2 Linux, Redhat 2 Linux Kernel, Enterprise Linux 2025-06-05 6.3 Medium
NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows Overflow Buffers. This vulnerability is associated with program files /net/bluetooth/rfcomm/core.C. This issue affects Linux kernel: v2.6.12-rc2.
CVE-2025-5074 1 Freefloat 1 Ftp Server 2025-06-05 7.3 High
A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown function of the component PROMPT Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-5073 1 Freefloat 1 Ftp Server 2025-06-05 7.3 High
A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. This issue affects some unknown processing of the component MKDIR Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-21727 1 Digital-peak 2 Dp Calendar For Joomla, Dpcalendar 2025-06-05 6.1 Medium
XSS vulnerability in DP Calendar component for Joomla.
CVE-2025-49466 2025-06-05 5.8 Medium
aerc before 93bec0d allows directory traversal in commands/msgview/open.go because of direct path concatenation of the name of an attachment part,