Search Results (30648 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-34927 1 Campcodes 1 Complete Web-based School Management System 2025-03-25 9.8 Critical
A SQL injection vulnerability in /model/update_classroom.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.
CVE-2024-34929 1 Campcodes 1 Complete Web-based School Management System 2025-03-25 9.8 Critical
A SQL injection vulnerability in /view/find_friends.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the my_index parameter.
CVE-2024-34931 1 Campcodes 1 Complete Web-based School Management System 2025-03-25 9.8 Critical
A SQL injection vulnerability in /model/update_subject.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.
CVE-2024-34932 1 Campcodes 1 Complete Web-based School Management System 2025-03-25 9.8 Critical
A SQL injection vulnerability in /model/update_exam.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.
CVE-2024-34934 1 Campcodes 1 Complete Web-based School Management System 2025-03-25 9.8 Critical
A SQL injection vulnerability in /view/emarks_range_grade_update_form.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id parameter.
CVE-2024-34935 1 Campcodes 1 Complete Web-based School Management System 2025-03-25 9.8 Critical
A SQL injection vulnerability in /view/conversation_history_admin.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id parameter.
CVE-2024-33799 1 Campcodes 1 Complete Web-based School Management System 2025-03-25 9.8 Critical
A SQL injection vulnerability in /model/get_teacher.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
CVE-2024-33800 1 Campcodes 1 Complete Web-based School Management System 2025-03-25 9.8 Critical
A SQL injection vulnerability in /model/get_student1.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the index parameter.
CVE-2024-33801 1 Campcodes 1 Complete Web-based School Management System 2025-03-25 9.8 Critical
A SQL injection vulnerability in /model/get_subject_routing.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
CVE-2024-33805 1 Campcodes 1 Complete Web-based School Management System 2025-03-25 9.8 Critical
A SQL injection vulnerability in /model/get_student.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
CVE-2024-33806 1 Campcodes 1 Complete Web-based School Management System 2025-03-25 9.8 Critical
A SQL injection vulnerability in /model/get_grade.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
CVE-2024-42978 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-03-25 9.8 Critical
An issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary commands via a crafted HTTP request.
CVE-2024-36736 1 Oneflow 1 Oneflow 2025-03-25 9.8 Critical
An issue in the oneflow.permute component of OneFlow-Inc. Oneflow v0.9.1 causes an incorrect calculation when the same dimension operation is performed.
CVE-2024-32608 2 Hdfgroup, Redhat 2 Hdf5, Enterprise Linux Ai 2025-03-25 9.8 Critical
HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
CVE-2024-22441 1 Hpe 1 Cray Parallel Application Launch Service 2025-03-25 9.8 Critical
HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.
CVE-2024-33808 1 Campcodes 1 Complete Web-based School Management System 2025-03-25 9.8 Critical
A SQL injection vulnerability in /model/get_timetable.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
CVE-2025-25977 1 Canvg 1 Canvg 2025-03-25 9.8 Critical
An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code via the Constructor of the class StyleElement.
CVE-2023-52153 2 Pmb Project, Sigb 2 Pmb, Pmb 2025-03-25 9.8 Critical
A SQL Injection vulnerability in /pmb/opac_css/includes/sessions.inc.php in PMB 7.4.7 and earlier allows remote unauthenticated attackers to inject arbitrary SQL commands via the PmbOpac-LOGIN cookie value.
CVE-2023-51828 2 Pmb Project, Sigb 2 Pmb, Pmb 2025-03-25 9.8 Critical
A SQL Injection vulnerability in /admin/convert/export.class.php in PMB 7.4.7 and earlier versions allows remote unauthenticated attackers to execute arbitrary SQL commands via the query parameter in get_next_notice function.
CVE-2023-37177 1 Sigb 1 Pmb 2025-03-25 9.8 Critical
SQL Injection vulnerability in PMB Services PMB v.7.4.7 and before allows a remote unauthenticated attacker to execute arbitrary code via the query parameter in the /admin/convert/export_z3950.php endpoint.