Search Results (378430 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-37831 1 Itsourcecode 1 Payroll Management System 2024-11-21 9.1 Critical
Itsourcecode Payroll Management System 1.0 is vulnerable to SQL Injection in payroll_items.php via the ID parameter.
CVE-2024-37830 1 Getoutline 1 Outline 2024-11-21 4.3 Medium
An issue in Outline <= v0.76.1 allows attackers to redirect a victim user to a malicious site via intercepting and changing the state cookie.
CVE-2024-37802 2 Codeprojects, Health Care Hospital Management System Project 2 Health Care Hospital Management System, Health Care Hospital Management System 2024-11-21 9.4 Critical
CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Patient Info module via the searvalu parameter.
CVE-2024-37769 1 B1ackc4t 1 14finger 2024-11-21 8.8 High
Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request.
CVE-2024-37741 1 Openplcproject 2 Openplc V3, Openplc V3 Firmware 2024-11-21 5.4 Medium
OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture.
CVE-2024-37732 1 Anchorcms 2 Anchor, Anchor Cms 2024-11-21 8.8 High
Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a crafted .pdf file.
CVE-2024-37679 2 Finesoft Project, Hangzhou Meisoft Information Technology 2 Finesoft, Finesoft 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp parameter.
CVE-2024-37677 2 Access Management Specialist Project, Shenzhenweitillage 2 Access Management Specialist, Access Management Specialist 2024-11-21 7.5 High
An issue in Shenzhen Weitillage Industrial Co., Ltd the access management specialist V6.62.51215 allows a remote attacker to obtain sensitive information.
CVE-2024-37673 1 Tessi 2 Docubase, Docubase Document Management 2024-11-21 5.4 Medium
Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the filename parameter.
CVE-2024-37672 1 Tessi 1 Docubase 2024-11-21 5.4 Medium
Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the idactivity parameter.
CVE-2024-37635 1 Totolink 2 A3700r, A3700r Firmware 2024-11-21 9.8 Critical
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfg
CVE-2024-37625 1 Zhimengzhel 1 Ibarn 2024-11-21 6.1 Medium
zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /index.php.
CVE-2024-37619 1 Strongshop 1 Strongshop 2024-11-21 7.6 High
StrongShop v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the spec_group_id parameter at /spec/index.blade.php.
CVE-2024-37570 1 Mitel 4 6869i Sip, 6869i Sip Firmware, Rev00 6868i and 1 more 2024-11-21 8.8 High
On Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform sanitization on the username and path parameters (sent by an authenticated user) before appending flags to the busybox ftpget command. This leads to $() command execution.
CVE-2024-37569 1 Mitel 3 6869i Firmware, 6869i Sip, 6869i Sip Firmware 2024-11-21 8.3 High
An issue was discovered on Mitel 6869i through 4.5.0.41 and 5.x through 5.0.0.1018 devices. A command injection vulnerability exists in the hostname parameter taken in by the provis.html endpoint. The provis.html endpoint performs no sanitization on the hostname parameter (sent by an authenticated user), which is subsequently written to disk. During boot, the hostname parameter is executed as part of a series of shell commands. Attackers can achieve remote code execution in the root context by placing shell metacharacters in the hostname parameter.
CVE-2024-37559 1 Henleyedition 1 Counterpoint 2024-11-21 7.1 High
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Echenley Counterpoint allows Reflected XSS.This issue affects Counterpoint: from n/a through 1.8.1.
CVE-2024-37558 1 Nihal 1 Wpfavicon 2024-11-21 5.9 Medium
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nazmul Hossain Nihal WPFavicon allows Stored XSS.This issue affects WPFavicon: from n/a through 2.1.1.
CVE-2024-37557 1 Sohamsolution 1 Wp Cookie Law Info 2024-11-21 5.9 Medium
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Soham Web Solution WP Cookie Law Info allows Stored XSS.This issue affects WP Cookie Law Info: from n/a through 1.1.
CVE-2024-37556 1 Seedprod 1 Wordpress Notification Bar 2024-11-21 5.9 Medium
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SeedProd WordPress Notification Bar allows Stored XSS.This issue affects WordPress Notification Bar: from n/a through 1.3.10.
CVE-2024-37553 1 Axelerant 1 Testimonials Widget 2024-11-21 6.5 Medium
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Axelerant Testimonials Widget allows Stored XSS.This issue affects Testimonials Widget: from n/a through 4.0.4.