Search Results (348912 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-3758 1 Gitlab 1 Gitlab 2025-02-28 5.4 Medium
An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Due to improper permissions checks an unauthorised user was able to read, add or edit a users private snippet.
CVE-2022-4317 1 Gitlab 1 Dynamic Application Security Testing Analyzer 2025-02-28 5 Medium
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 1.47 before 3.0.51, which sends custom request headers in redirects.
CVE-2023-27204 1 Best Pos Management System Project 1 Best Pos Management System 2025-02-28 9.8 Critical
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.
CVE-2023-27205 1 Best Pos Management System Project 1 Best Pos Management System 2025-02-28 9.8 Critical
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php.
CVE-2023-27206 1 Best Pos Management System Project 1 Best Pos Management System 2025-02-28 6.1 Medium
A cross-site scripting (XSS) vulnerability in /kruxton/navbar.php of Best POS Management System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter.
CVE-2023-27207 1 Online Pizza Ordering System Project 1 Online Pizza Ordering System 2025-02-28 9.8 Critical
Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php.
CVE-2023-27208 1 Online Pizza Ordering System Project 1 Online Pizza Ordering System 2025-02-28 6.1 Medium
A cross-site scripting (XSS) vulnerability in /php-opos/login.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the redirect parameter.
CVE-2023-27210 1 Online Pizza Ordering System Project 1 Online Pizza Ordering System 2025-02-28 9.8 Critical
Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/view_order.php.
CVE-2023-27211 1 Online Pizza Ordering System Project 1 Online Pizza Ordering System 2025-02-28 6.1 Medium
A cross-site scripting (XSS) vulnerability in /admin/navbar.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter.
CVE-2023-27212 1 Online Pizza Ordering System Project 1 Online Pizza Ordering System 2025-02-28 6.1 Medium
A cross-site scripting (XSS) vulnerability in /php-opos/signup.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the redirect parameter.
CVE-2023-27213 1 Online Student Management System Project 1 Online Student Management System 2025-02-28 9.8 Critical
Online Student Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /eduauth/student/search.php.
CVE-2023-27850 1 Netgear 2 Rax30, Rax30 Firmware 2025-02-28 6.8 Medium
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that allows users with access to this feature to access arbitrary files on the device.
CVE-2023-27115 1 Webassembly 1 Webassembly 2025-02-28 5.5 Medium
WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::cat_compute_size.
CVE-2023-27114 1 Radare 1 Radare2 2025-02-28 5.5 Medium
radare2 v5.8.3 was discovered to contain a segmentation fault via the component wasm_dis at p/wasm/wasm.c.
CVE-2023-26948 1 Onekeyadmin 1 Onekeyadmin 2025-02-28 7.5 High
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/file/download.
CVE-2023-1205 1 Netgear 2 Rax30, Rax30 Firmware 2025-02-28 8.8 High
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 is vulnerable to cross-site request forgery attacks on all endpoints due to improperly implemented CSRF protections.
CVE-2023-27214 1 Online Student Management System Project 1 Online Student Management System 2025-02-28 9.8 Critical
Online Student Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the fromdate and todate parameters at /eduauth/student/between-date-reprtsdetails.php.
CVE-2023-1251 1 Akinsoft 1 Wolvox 2025-02-28 9.8 Critical
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akinsoft Wolvox. This issue affects Wolvox: before 8.02.03.
CVE-2023-1291 1 Sales Tracker Management System Project 1 Sales Tracker Management System 2025-02-28 6.3 Medium
A vulnerability, which was classified as critical, was found in SourceCodester Sales Tracker Management System 1.0. This affects an unknown part of the file admin/clients/manage_client.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-222645 was assigned to this vulnerability.
CVE-2023-1287 1 3ds 1 Enovia Live Collaboration 2025-02-28 9 Critical
An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution.