Search Results (360295 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-28467 1 Online Student Admission Project 1 Online Student Admission 2024-11-21 9.8 Critical
Online Student Admission v1.0 was discovered to contain a SQL injection vulnerability via the txtapplicationID parameter.
CVE-2022-28464 1 Apifox 1 Apifox 2024-11-21 9.0 Critical
Apifox through 2.1.6 is vulnerable to Cross Site Scripting (XSS) which can lead to remote code execution.
CVE-2022-28462 1 Xxyopen 1 Novel-plus 2024-11-21 7.5 High
novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.
CVE-2022-28461 1 Mingyuefusu Project 1 Mingyuefusu 2024-11-21 9.8 Critical
mingyuefusu Library Management System all versions as of 03-27-2022 is vulnerable to SQL Injection.
CVE-2022-28454 1 Limbas 1 Limbas 2024-11-21 6.1 Medium
Limbas 4.3.36.1319 is vulnerable to Cross Site Scripting (XSS).
CVE-2022-28452 1 Redplanetcomputers 1 Laundry Management System 2024-11-21 9.8 Critical
Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.
CVE-2022-28451 1 Nopcommerce 1 Nopcommerce 2024-11-21 7.5 High
nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature.
CVE-2022-28450 1 Nopcommerce 1 Nopcommerce 2024-11-21 5.4 Medium
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new post, which allows a remote attacker to execute arbitrary JavaScript code at client browser.
CVE-2022-28449 1 Nopcommerce 1 Nopcommerce 2024-11-21 6.1 Medium
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upload an arbitrary file to the system.
CVE-2022-28448 1 Nopcommerce 1 Nopcommerce 2024-11-21 5.4 Medium
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info.
CVE-2022-28445 1 Kitesky 1 Kitecms 2024-11-21 6.5 Medium
KiteCMS v1.1.1 was discovered to contain an arbitrary file read vulnerability via the background management module.
CVE-2022-28444 1 Ucms Project 1 Ucms 2024-11-21 7.5 High
UCMS v1.6 was discovered to contain an arbitrary file read vulnerability.
CVE-2022-28443 1 Ucms Project 1 Ucms 2024-11-21 9.1 Critical
UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability.
CVE-2022-28440 1 Ucms Project 1 Ucms 2024-11-21 8.8 High
An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-28417 1 Home Owners Collection Management System Project 1 Home Owners Collection Management System 2024-11-21 9.8 Critical
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase.
CVE-2022-28416 1 Home Owners Collection Management System Project 1 Home Owners Collection Management System 2024-11-21 9.8 Critical
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase.
CVE-2022-28415 1 Home Owners Collection Management System Project 1 Home Owners Collection Management System 2024-11-21 9.8 Critical
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_collection.
CVE-2022-28414 1 Home Owners Collection Management System Project 1 Home Owners Collection Management System 2024-11-21 9.8 Critical
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_member.
CVE-2022-28413 1 Car Driving School Management System Project 1 Car Driving School Management System 2024-11-21 9.8 Critical
Car Driving School Management System v1.0 was discovered to contain a SQL injection vulnerability via /cdsms/classes/Master.php?f=delete_enrollment.
CVE-2022-28412 1 Car Driving School Management System Project 1 Car Driving School Management System 2024-11-21 9.8 Critical
Car Driving School Managment System v1.0 was discovered to contain a SQL injection vulnerability via /cdsms/classes/Master.php?f=delete_package.