| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 15.03.2.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload |
| There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arbitrary command execution |
| Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php. |
| Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtusername (aka Username) field. |
| Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory. |
| ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php. |
| ZCMS v20170206 was discovered to contain a file inclusion vulnerability via index.php?m=home&c=home&a=sp_set_config. |
| A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantasticblog/single.php" via the "id=5" parameters. |
| CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection. |
| ALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe. |
| marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor. |
| Payroll Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter. |
| Online Student Admission v1.0 was discovered to contain a SQL injection vulnerability via the txtapplicationID parameter. |
| Apifox through 2.1.6 is vulnerable to Cross Site Scripting (XSS) which can lead to remote code execution. |
| mingyuefusu Library Management System all versions as of 03-27-2022 is vulnerable to SQL Injection. |
| Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection. |
| UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability. |
| Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase. |
| Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase. |
| Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_collection. |