Total
277614 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2024-43252 | 1 Crewhrm | 1 Crewhrm | 2024-08-21 | 9 Critical |
Deserialization of Untrusted Data vulnerability in Crew HRM allows Object Injection.This issue affects Crew HRM: from n/a through 1.1.1. | ||||
CVE-2024-43232 | 1 Wponlinesupport | 1 Timeline And History Slider | 2024-08-21 | 8.5 High |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP OnlineSupport, Essential Plugin Timeline and History slider allows PHP Local File Inclusion.This issue affects Timeline and History slider: from n/a through 2.3. | ||||
CVE-2024-42612 | 1 Pigg | 1 Cms | 2024-08-21 | 8.8 High |
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?whitelist_add | ||||
CVE-2024-42577 | 1 Siamonhasan | 1 Warehouse Inventory System | 2024-08-21 | 8.8 High |
A Cross-Site Request Forgery (CSRF) in the component add_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | ||||
CVE-2024-35539 | 1 Typecho | 1 Cms | 2024-08-21 | 6.5 Medium |
Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post several comments before the spam protection checks if the comments are posted too frequently. | ||||
CVE-2024-43401 | 1 Xwiki | 2 Xwiki, Xwiki-platform | 2024-08-21 | 9.1 Critical |
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor. The user with elevated rights is not warned beforehand that they are going to edit possibly dangerous content. The payload is executed at edit time. This vulnerability has been patched in XWiki 15.10RC1. | ||||
CVE-2024-7842 | 2 Sourcecodester, Tamparongj 03 | 2 Online Graduate Tracer System, Online Graduate Tracer System | 2024-08-21 | 5.3 Medium |
A vulnerability, which was classified as problematic, has been found in SourceCodester Online Graduate Tracer System 1.0. This issue affects some unknown processing of the file /tracking/admin/export_it.php. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
CVE-2024-7843 | 2 Sourcecodester, Tamparongj 03 | 2 Online Graduate Tracer System, Online Graduate Tracer System | 2024-08-21 | 5.3 Medium |
A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function of the file /tracking/admin/exportcs.php. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | ||||
CVE-2024-7844 | 1 Tamparongj 03 | 1 Online Graduate Tracer System | 2024-08-21 | 3.5 Low |
A vulnerability has been found in SourceCodester Online Graduate Tracer System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /tracking/admin/add_acc.php. The manipulation of the argument name/user/position leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | ||||
CVE-2024-7841 | 2 Oretnom23, Sourcecodester | 2 Clinics Patient Management System, Clinics Patient Management System | 2024-08-21 | 6.3 Medium |
A vulnerability classified as critical was found in SourceCodester Clinics Patient Management System 1.0. This vulnerability affects unknown code of the file /pms/ajax/check_user_name.php. The manipulation of the argument user_name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
CVE-2024-7929 | 2 Oretnom23, Sourcecodester | 2 Simple Forum Website, Simple Forum Website | 2024-08-21 | 5.3 Medium |
A vulnerability, which was classified as problematic, was found in SourceCodester Simple Forum Website 1.0. This affects an unknown part of the file /registration.php of the component Signup Page. The manipulation of the argument username leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | ||||
CVE-2024-7931 | 2 Sourcecodester, Tamparongj 03 | 2 Online Graduate Tracer System, Online Graduate Tracer System | 2024-08-21 | 6.3 Medium |
A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. This issue affects some unknown processing of the file /tracking/admin/view_csprofile.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
CVE-2024-7947 | 2 Janobe, Sourcecodester | 2 Point Of Sales And Inventory Management System, Point Of Sales And Inventory Management System | 2024-08-21 | 7.3 High |
A vulnerability classified as critical has been found in SourceCodester Point of Sales and Inventory Management System 1.0. This affects an unknown part of the file login.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | ||||
CVE-2024-42335 | 1 7-twenty | 1 Bot | 2024-08-21 | 5.4 Medium |
7Twenty - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||||
CVE-2024-42566 | 2 Arajajyothibabu, School Management System Project | 2 School Management System, School Management System | 2024-08-21 | 8.8 High |
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the password parameter at login.php | ||||
CVE-2024-42567 | 2 Arajajyothibabu, School Management System Project | 2 School Management System, School Management System | 2024-08-21 | 9.8 Critical |
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the sid parameter at /search.php?action=2. | ||||
CVE-2024-42570 | 1 Arajajyothibabu | 1 School Management System | 2024-08-21 | 9.8 Critical |
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at admininsert.php. | ||||
CVE-2024-42574 | 1 Arajajyothibabu | 1 School Management System | 2024-08-21 | 9.8 Critical |
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at attendance.php. | ||||
CVE-2024-42575 | 1 Arajajyothibabu | 1 School Management System | 2024-08-21 | 9.8 Critical |
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at substaff.php. | ||||
CVE-2024-8023 | 1 Springblade Project | 1 Springblade | 2024-08-21 | 6.3 Medium |
A vulnerability classified as critical has been found in chillzhuang SpringBlade 4.1.0. Affected is an unknown function of the file /api/blade-system/menu/list?updatexml. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. |