Search Results (36147 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-11100 1 1000projects 1 Beauty Parlour Management System 2024-11-18 7.3 High
A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-10990 2 Oretnom23, Sourcecodester 2 Online Veterinary Appointment System, Online Veterinary Appointment System 2024-11-18 6.3 Medium
A vulnerability classified as critical was found in SourceCodester Online Veterinary Appointment System 1.0. This vulnerability affects unknown code of the file /admin/services/view_service.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-10991 1 Codezips 1 Hospital Appointment System 2024-11-18 7.3 High
A vulnerability, which was classified as critical, has been found in Codezips Hospital Appointment System 1.0. This issue affects some unknown processing of the file /editBranchResult.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-44761 2 Gzequan, Yiquan Information 2 Eq Enterprise Management System, Eq Enterprise Management System 2024-11-18 9.9 Critical
An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted requests.
CVE-2024-8049 1 Progress 1 Telerik Document Processing Libraries 2024-11-18 6.5 Medium
In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with unsupported features can lead to excessive processing, leading to excessive use of computing resources leaving the application process unavailable.
CVE-2024-52300 2 Xwiki, Xwikisas 2 Pdf Viewer Macro, Macro Pdfviewer 2024-11-18 9.1 Critical
macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't properly escaped, allowing XSS for any user who can edit a page. XSS can impact the confidentiality, integrity and availability of the whole XWiki installation when an admin visits the page with the malicious code. This is fixed in 2.5.6.
CVE-2024-50826 2 Kashipara, Lopalopa 2 E Learning Management System Project, E-learning Management System 2024-11-18 3.5 Low
A SQL Injection vulnerability was found in /admin/add_content.php in kashipara E-learning Management System Project 1.0 via the title and content parameters.
CVE-2024-50825 2 Kashipara, Lopalopa 2 E Learning Management System Project, E-learning Management System 2024-11-18 3.5 Low
A SQL Injection vulnerability was found in /admin/school_year.php in kashipara E-learning Management System Project 1.0 via the school_year parameter.
CVE-2024-50824 2 Kashipara, Lopalopa 2 E Learning Management System Project, E-learning Management System 2024-11-18 3.5 Low
A SQL Injection vulnerability was found in /admin/class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.
CVE-2024-50823 2 Kashipara, Lopalopa 2 E Learning Management System Project, E-learning Management System 2024-11-18 3.5 Low
A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.
CVE-2024-50835 2 Kashipara, Lopalopa 2 E Learning Management System Project, E-learning Management System 2024-11-18 3.5 Low
A SQL Injection vulnerability was found in /admin/edit_student.php in KASHIPARA E-learning Management System Project 1.0 via the cys, un, ln, fn, and id parameters.
CVE-2024-50834 2 Kashipara, Lopalopa 2 E Learning Management System Project, E-learning Management System 2024-11-18 3.5 Low
A SQL Injection was found in /admin/teachers.php in KASHIPARA E-learning Management System Project 1.0 via the firstname and lastname parameters.
CVE-2024-50833 2 Kashipara, Lopalopa 2 E Learning Management System Project, E-learning Management System 2024-11-18 3.5 Low
A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the username and password parameters.
CVE-2024-50832 2 Kashipara, Lopalopa 2 E Learning Management System Project, E-learning Management System 2024-11-18 3.5 Low
A SQL Injection vulnerability was found in /admin/edit_class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.
CVE-2024-50831 2 Kashipara, Lopalopa 2 E Learning Management System Project, E-learning Management System 2024-11-18 3.5 Low
A SQL Injection was found in /admin/admin_user.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.
CVE-2024-50830 2 Kashipara, Lopalopa 2 E Learning Management System Project, E-learning Management System 2024-11-18 3.5 Low
A SQL Injection vulnerability was found in /admin/calendar_of_events.php in kashipara E-learning Management System Project 1.0 via the date_start, date_end, and title parameters.
CVE-2024-50829 2 Kashipara, Lopalopa 2 E Learning Management System Project, E-learning Management System 2024-11-18 3.5 Low
A SQL Injection vulnerability was found in /admin/edit_subject.php in kashipara E-learning Management System Project 1.0 via the unit parameter.
CVE-2024-50828 2 Kashipara, Lopalopa 2 E Learning Management System Project, E-learning Management System 2024-11-18 3.5 Low
A SQL Injection vulnerability was found in /admin/edit_department.php in kashipara E-learning Management System Project 1.0 via the d parameter.
CVE-2024-50827 2 Kashipara, Lopalopa 2 E Learning Management System Project, E-learning Management System 2024-11-18 3.5 Low
A SQL Injection vulnerability was found in /admin/add_subject.php in kashipara E-learning Management System Project 1.0 via the subject_code parameter.
CVE-2024-50321 1 Ivanti 1 Avalanche 2024-11-18 7.5 High
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.