| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Tenda i24 V2.0.0.5 is vulnerable to Buffer Overflow in the addWifiMacFilter function. |
| usb device bluetooth class includes a buffer overflow related to implementation of net_buf_add_mem. |
| WeGIA is a web manager for charitable institutions. Prior to 3.2.8, a critical vulnerability was identified in the /WeGIA/html/socio/sistema/controller/controla_xlsx.php endpoint. The endpoint accepts file uploads without proper validation, allowing the upload of malicious files, such as .phar, which can then be executed by the server. This vulnerability is fixed in 3.2.8. |
| WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /html/funcionario/dependente_listar_um.php endpoint, specifically in the id_dependente parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This vulnerability is fixed in 3.2.8. |
| WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /dao/verificar_recursos_cargo.php endpoint, specifically in the cargo parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This vulnerability is fixed in 3.2.8. |
| Ecto 2.2.0 lacks a certain protection mechanism associated with the interaction between is_nil and raise. |
| An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter |
| An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method |
| An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter |
| An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Some parameters allow SQL injection. Version 2022.1.110.1.02 corrects this issue. |
| Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. |
| Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. |
| Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php. |
| Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php. |
| Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php. |
| Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php. |
| Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php. |
| Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeProduct.php. |
| Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php. |
| Sourcecodester Dynamic Transaction Queuing System v1.0 is vulnerable to SQL Injection via /queuing/index.php?page=display&id=. |