Search Results (86693 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-40969 1 Siretta 2 Quartz-gold, Quartz-gold Firmware 2025-03-27 8.8 High
An os command injection vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.
CVE-2024-36735 1 Oneflow 1 Oneflow 2025-03-27 5.3 Medium
OneFlow-Inc. Oneflow v0.9.1 does not display an error or warning when the oneflow.eye parameter is floating.
CVE-2022-47698 1 Comfast Project 2 Cf-wr623n, Cf-wr623n Firmware 2025-03-27 6.1 Medium
COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 is vulnerable to Cross Site Scripting (XSS) via the URL filtering feature in the router.
CVE-2022-45598 1 Joplin Project 1 Joplin 2025-03-27 6.1 Medium
Cross Site Scripting vulnerability in Joplin Desktop App before v2.9.17 allows attacker to execute arbitrary code via improper santization.
CVE-2022-45494 1 Json.h Project 1 Json.h 2025-03-27 7.8 High
Buffer overflow vulnerability in function json_parse_object in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc81fdadf41 (November 14, 2022) allows attackers to code arbitrary code and gain escalated privileges.
CVE-2025-2674 1 Phpgurukul 1 Bank Locker Management System 2025-03-27 7.3 High
A vulnerability classified as critical was found in PHPGurukul Bank Locker Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /aboutus.php. The manipulation of the argument pagetitle leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2022-25979 1 Jsuites 1 Jsuites 2025-03-27 5.4 Medium
Versions of the package jsuites before 5.0.1 are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization in the Editor() function.
CVE-2022-21129 1 Paypal 1 Nemo-appium 2025-03-27 7.4 High
Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup' function. **Note:** In order to exploit this vulnerability appium-running 0.1.3 has to be installed as one of nemo-appium dependencies.
CVE-2025-2383 1 Phpgurukul 1 Doctor Appointment Management System 2025-03-27 7.3 High
A vulnerability, which was classified as critical, has been found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this issue is some unknown functionality of the file /doctor/search.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-2386 1 Phpgurukul 1 Local Services Search Engine Management System 2025-03-27 7.3 High
A vulnerability was found in PHPGurukul Local Services Search Engine Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /serviceman-search.php. The manipulation of the argument location leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-2681 1 Phpgurukul 1 Bank Locker Management System 2025-03-27 7.3 High
A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /edit-locker.php?ltid=6. The manipulation of the argument lockersize leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-2682 1 Phpgurukul 1 Bank Locker Management System 2025-03-27 7.3 High
A vulnerability classified as critical has been found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown part of the file /edit-subadmin.php?said=3. The manipulation of the argument mobilenumber leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-2683 1 Phpgurukul 1 Bank Locker Management System 2025-03-27 7.3 High
A vulnerability classified as critical was found in PHPGurukul Bank Locker Management System 1.0. This vulnerability affects unknown code of the file /profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2023-38920 1 Phpgurukul 1 Cyber Cafe Management System 2025-03-27 4.8 Medium
Cross Site Scripting vulnerability in Cyber Cafe Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the adminname parameter.
CVE-2024-53365 1 Phpgurukul 1 Vehicle Parking Management System 2025-03-27 6.1 Medium
A stored cross-site scripting (XSS) vulnerability was identified in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/profile.php. This vulnerability allows authenticated users to inject malicious XSS scripts into the profile name field.
CVE-2024-51054 1 Phpgurukul 1 Online Marriage Registration System 2025-03-27 4.8 Medium
A Cross Site Scriptng (XSS) vulnerability was found in /omrs/admin/search.php in PHPGurukul Online Marriage Registration System 1.0, which allows remote attackers to execute arbitrary code via the "searchdata" POST request parameter.
CVE-2024-50990 1 Phpgurukul 1 Online Marriage Registration System 2025-03-27 6.1 Medium
A Reflected Cross Site Scriptng (XSS) vulnerability was found in /omrs/user/search.php in PHPGurukul Online Marriage Registration System v1.0, which allows remote attackers to execute arbitrary code via the "searchdata" POST request parameter.
CVE-2022-31902 1 Notepad-plus-plus 1 Notepad\+\+ 2025-03-27 5.5 Medium
Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().
CVE-2025-2650 1 Phpgurukul 1 Medical Card Generation System 2025-03-27 3.5 Low
A vulnerability, which was classified as problematic, has been found in PHPGurukul Medical Card Generation System 1.0. This issue affects some unknown processing of the file /download-medical-cards.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-2649 1 Phpgurukul 1 Doctor Appointment Management System 2025-03-27 7.3 High
A vulnerability classified as critical was found in PHPGurukul Doctor Appointment Management System 1.0. This vulnerability affects unknown code of the file /check-appointment.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.