Search Results (334265 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-38737 1 Sem-cms 1 Semcms 2025-05-07 9.8 Critical
SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.
CVE-2021-38736 1 Sem-cms 1 Semcms 2025-05-07 9.8 Critical
SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.
CVE-2025-3168 1 Phpgurukul 1 Time Table Generator System 2025-05-07 7.3 High
A vulnerability was found in PHPGurukul Time Table Generator System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit-class.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-3352 1 Phpgurukul 1 Old Age Home Management System 2025-05-07 7.3 High
A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/edit-scdetails.php. The manipulation of the argument contnum leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-20348 1 Cisco 1 Nexus Dashboard Fabric Controller 2025-05-07 7.5 High
A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to read arbitrary files. This vulnerability is due to an unauthenticated provisioning web server. An attacker could exploit this vulnerability through direct web requests to the provisioning server. A successful exploit could allow the attacker to read sensitive files in the PnP container that could facilitate further attacks on the PnP infrastructure.
CVE-2025-3370 1 Phpgurukul 1 Men Salon Management System 2025-05-07 7.3 High
A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unknown part of the file /admin/admin-profile.php. The manipulation of the argument contactnumber leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
CVE-2024-48629 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2025-05-07 8 High
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the IPAddress parameter in the SetGuestZoneRouterSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48630 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2025-05-07 8 High
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the MacAddress parameter in the SetMACFilters2 function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48168 2 D-link, Dlink 3 Dcs 960l, Dcs-960l, Dcs-960l Firmware 2025-05-07 9.8 Critical
A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing an attacker to execute arbitrary code.
CVE-2024-48632 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2025-05-07 8 High
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the LocalIPAddress, TCPPorts, and UDPPorts parameters in the SetPortForwardingSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48631 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2025-05-07 8 High
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SSID parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48633 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2025-05-07 8 High
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the SetVirtualServerSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48634 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2025-05-07 8 High
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the key parameter in the SetWLanRadioSecurity function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48635 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2025-05-07 8 High
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:2/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48637 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2025-05-07 8 High
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:1/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48636 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2025-05-07 8 High
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:0/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-20283 1 Cisco 1 Nexus Dashboard 2025-05-07 4.3 Medium
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to learn cluster deployment information on an affected device. This vulnerability is due to improper access controls on a specific API endpoint. An attacker could exploit this vulnerability by sending queries to the API endpoint. A successful exploit could allow an attacker to access metrics and information about devices in the Nexus Dashboard cluster.
CVE-2024-48271 1 Dlink 3 Dsl-6740c, Dsl-6740c Firmware, Dsl6740c Firmware 2025-05-07 8.8 High
D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly allowing attackers to bypass authentication and escalate privileges on the device via a bruteforce attack.
CVE-2025-3205 1 Codeastro 1 Student Grading System 2025-05-07 6.3 Medium
A vulnerability, which was classified as critical, was found in CodeAstro Student Grading System 1.0. This affects an unknown part of the file studentsubject.php. The manipulation of the argument studentId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2020-5355 1 Dell 1 Emc Isilon Onefs 2025-05-07 4.3 Medium
The Dell Isilon OneFS versions 8.2.2 and earlier SSHD process improperly allows Transmission Control Protocol (TCP) and stream forwarding. This provides the remotesupport user and users with restricted shells more access than is intended.