Total
277619 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2024-42567 | 2 Arajajyothibabu, School Management System Project | 2 School Management System, School Management System | 2024-08-21 | 9.8 Critical |
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the sid parameter at /search.php?action=2. | ||||
CVE-2024-42570 | 1 Arajajyothibabu | 1 School Management System | 2024-08-21 | 9.8 Critical |
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at admininsert.php. | ||||
CVE-2024-42574 | 1 Arajajyothibabu | 1 School Management System | 2024-08-21 | 9.8 Critical |
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at attendance.php. | ||||
CVE-2024-42575 | 1 Arajajyothibabu | 1 School Management System | 2024-08-21 | 9.8 Critical |
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at substaff.php. | ||||
CVE-2024-8023 | 1 Springblade Project | 1 Springblade | 2024-08-21 | 6.3 Medium |
A vulnerability classified as critical has been found in chillzhuang SpringBlade 4.1.0. Affected is an unknown function of the file /api/blade-system/menu/list?updatexml. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
CVE-2024-42580 | 2 Oswapp, Siamonhasan | 2 Warehouse Inventory System, Warehouse Inventory System | 2024-08-21 | 5.7 Medium |
A Cross-Site Request Forgery (CSRF) in the component edit_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | ||||
CVE-2024-42581 | 2 Oswapp, Siamonhasan | 2 Warehouse Inventory System, Warehouse Inventory System | 2024-08-21 | 9.6 Critical |
A Cross-Site Request Forgery (CSRF) in the component delete_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | ||||
CVE-2024-42582 | 1 Siamonhasan | 1 Warehouse Inventory System | 2024-08-21 | 8.8 High |
A Cross-Site Request Forgery (CSRF) in the component delete_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | ||||
CVE-2024-42583 | 2 Siamonhasan, Warehouse Inventory System | 2 Warehouse Inventory System, Warehouse Inventory System | 2024-08-21 | 8.8 High |
A Cross-Site Request Forgery (CSRF) in the component delete_user.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges. | ||||
CVE-2024-6767 | 2024-08-21 | 5.5 Medium | ||
The WordSurvey plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sounding_title’ parameter in all versions up to, and including, 3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. | ||||
CVE-2024-7013 | 1 Panasonic | 1 Control Fpwin Pro | 2024-08-21 | 7.8 High |
Stack-based buffer overflow in Control FPWIN Pro version 7.7.2.0 and all previous versions may allow attackers to execute arbitrary code via a specially crafted project file. | ||||
CVE-2024-34458 | 1 Keyfactor | 1 Command | 2024-08-21 | 7.5 High |
Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information disclosure. | ||||
CVE-2024-42006 | 1 Keyfactor | 1 Aws Orchestrator | 2024-08-21 | 7.5 High |
Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure. | ||||
CVE-2024-7090 | 2024-08-21 | 6.1 Medium | ||
The LH Add Media From Url plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘lh_add_media_from_url-file_url’ parameter in all versions up to, and including, 1.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. | ||||
CVE-2024-42603 | 1 Pligg | 1 Pligg Cms | 2024-08-21 | 5.7 Medium |
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=clearall | ||||
CVE-2024-6883 | 2024-08-21 | 4.3 Medium | ||
The Event Espresso 4 Decaf – Event Registration Event Ticketing plugin for WordPress is vulnerable to limited unauthorized plugin settings modification due to a missing capability check on the saveTimezoneString and some other functions in all versions up to, and including, 5.0.22.decaf. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify some of the plugin settings. | ||||
CVE-2024-42605 | 1 Pligg | 1 Pligg Cms | 2024-08-21 | 7.1 High |
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/edit_page.php?link_id=1 | ||||
CVE-2024-42606 | 1 Pligg | 1 Pligg Cms | 2024-08-21 | 5.7 Medium |
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_log.php?clear=1 | ||||
CVE-2024-42607 | 1 Pligg | 1 Pligg Cms | 2024-08-21 | 8.8 High |
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=database | ||||
CVE-2024-42609 | 1 Pligg | 1 Pligg Cms | 2024-08-21 | 7.1 High |
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=avatars |