Search Results (360672 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-4966 1 Sinamjackson 1 Schoolwebtech 2025-02-10 7.3 High
A vulnerability was found in SourceCodester SchoolWebTech 1.0. It has been classified as critical. Affected is an unknown function of the file /improve/home.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-264534 is the identifier assigned to this vulnerability.
CVE-2024-4946 1 Donbermoy 1 Online Art Gallery Management System 2025-02-10 6.3 Medium
A vulnerability was found in SourceCodester Online Art Gallery Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file admin/adminHome.php. The manipulation of the argument sliderpic leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264481 was assigned to this vulnerability.
CVE-2024-4945 1 Mayurik 1 Best Courier Management System 2025-02-10 4.3 Medium
A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file view_parcel.php. The manipulation of the argument id leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264480.
CVE-2024-5378 1 Oretnom23 1 School Intramurals - Student Attendance Management System 2025-02-10 6.3 Medium
A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /manage_sy.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-266290 is the identifier assigned to this vulnerability.
CVE-2024-4926 1 Oretnom23 1 School Intramurals - Student Attendance Management System 2025-02-10 6.3 Medium
A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /intrams_sams/manage_student.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-264462 is the identifier assigned to this vulnerability.
CVE-2024-4925 2 Oretnom23, Sourcecodester 2 School Intramurals - Student Attendance Management System, School Instramurals 2025-02-10 6.3 Medium
A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /intrams_sams/manage_course.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264461 was assigned to this vulnerability.
CVE-2024-4922 1 Oretnom23 1 Simple Image Stack Website 2025-02-10 3.5 Low
A vulnerability, which was classified as problematic, was found in SourceCodester Simple Image Stack Website 1.0. This affects an unknown part. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264459.
CVE-2024-4921 2 Oretnom23, Sourcecodester 2 Employee And Visitor Gate Pass Logging System, Employee Visitor Gatepass Logging System 2025-02-10 6.3 Medium
A vulnerability classified as critical has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is an unknown function of the file /employee_gatepass/classes/Users.php?f=ssave. The manipulation of the argument img leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264456.
CVE-2024-4920 1 Razormist 1 Online Discussion Forum Site 2025-02-10 7.3 High
A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file registerH.php. The manipulation of the argument ima leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264455.
CVE-2025-0517 2025-02-08 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-8377 2025-02-08 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-6909 2025-02-08 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-5183 2025-02-08 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-4927 2025-02-08 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-29580 1 Yasm Project 1 Yasm 2025-02-08 5.5 Medium
yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the component yasm_expr_create at /libyasm/expr.c.
CVE-2023-29574 1 Axiosys 1 Bento4 2025-02-08 5.5 Medium
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42avc component.
CVE-2023-29571 1 Cesanta 1 Mjs 2025-02-08 5.5 Medium
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via gc_sweep at src/mjs_gc.c. This vulnerability can lead to a Denial of Service (DoS).
CVE-2023-28488 1 Intel 1 Connman 2025-02-08 6.5 Medium
client.c in gdhcp in ConnMan through 1.41 could be used by network-adjacent attackers (operating a crafted DHCP server) to cause a stack-based buffer overflow and denial of service, terminating the connman process.
CVE-2023-27830 1 Tightvnc 1 Tightvnc 2025-02-08 9 Critical
TightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate files with crafted files when executing a file transfer. This is due to the fact that TightVNC runs in the backend as a high-privileges account.
CVE-2023-27826 1 Seowonintech 2 Swc-5100w, Swc-5100w Firmware 2025-02-08 8.8 High
SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Injection. which allows attackers to take over the system with root privilege by abusing doSystem() function.