Search Results (357321 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-37131 1 Yzncms 1 Yzncms 2024-11-21 6.5 Medium
A Cross-Site Request Forgery (CSRF) in the component /public/admin/profile/update.html of YznCMS v1.1.0 allows attackers to arbitrarily change the Administrator password via a crafted POST request.
CVE-2023-37125 1 Seacms 1 Seacms 2024-11-21 5.4 Medium
A stored cross-site scripting (XSS) vulnerability in the Management Custom label module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2023-37124 1 Seacms 1 Seacms 2024-11-21 5.4 Medium
A stored cross-site scripting (XSS) vulnerability in the Site Setup module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2023-37122 1 Bagesoft 1 Bagecms 2024-11-21 5.4 Medium
A stored cross-site scripting (XSS) vulnerability in Bagecms v3.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Settings module.
CVE-2023-37117 1 Live555 1 Live555 2024-11-21 9.8 Critical
A heap-use-after-free vulnerability was found in live555 version 2023.05.10 while handling the SETUP.
CVE-2023-37070 1 Code-projects 1 Hospital Information System 2024-11-21 4.8 Medium
Code Projects Hospital Information System 1.0 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-37069 1 Online Hospital Management System Project 1 Online Hospital Management System 2024-11-21 9.8 Critical
Code-Projects Online Hospital Management System V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the login id and password fields during the login process, enabling an attacker to inject malicious SQL code.
CVE-2023-37068 1 Sherlock 1 Gym Management System 2024-11-21 9.8 Critical
Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username and password fields, enabling SQL Injection attacks.
CVE-2023-37067 1 Chamilo 1 Chamilo 2024-11-21 4.8 Medium
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the classes/usergroups management section.
CVE-2023-37066 1 Chamilo 1 Chamilo 2024-11-21 4.8 Medium
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the skills wheel.
CVE-2023-37065 1 Chamilo 1 Chamilo 2024-11-21 4.8 Medium
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the session category management section.
CVE-2023-37064 1 Chamilo 1 Chamilo 2024-11-21 4.8 Medium
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the extra fields management section.
CVE-2023-37063 1 Chamilo 1 Chamilo 2024-11-21 4.8 Medium
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the careers & promotions management section.
CVE-2023-37062 1 Chamilo 1 Chamilo 2024-11-21 4.8 Medium
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the course categories' definition.
CVE-2023-37061 1 Chamilo 1 Chamilo 2024-11-21 4.8 Medium
Chamilo 1.11.x up to 1.11.20 allows users with an admin privilege account to insert XSS in the languages management section.
CVE-2023-37049 1 Emlog 1 Emlog 2024-11-21 6.5 Medium
emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php.
CVE-2023-36995 1 Travianz Project 1 Travianz 2024-11-21 6.1 Medium
TravianZ through 8.3.4 allows XSS via the Alliance tag/name, the statistics page, the link preferences, the Admin Logs, or the COOKUSR cookie.
CVE-2023-36994 1 Travianz Project 1 Travianz 2024-11-21 9.8 Critical
In TravianZ 8.3.4 and 8.3.3, Incorrect Access Control in the installation script allows an attacker to overwrite the server configuration and inject PHP code.
CVE-2023-36993 1 Travianz Project 1 Travianz 2024-11-21 9.8 Critical
The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset function allows an attacker to guess the password reset.parameters and to take over accounts.
CVE-2023-36992 1 Travianz Project 1 Travianz 2024-11-21 7.2 High
PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to execute PHP code.