| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1006 | Hig | 0.47 | 7.2 | 0.01 | Apr 11, 2022 | The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing Calendars, which could allow high privilege users such as admin to perform SQL injection attacks | ||
| CVE-2022-0989 | Hig | 0.49 | 7.5 | 0.01 | Apr 11, 2022 | An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load images that hide malware for example from passing malicious domains to hide their trace, by making them pass through the vulnerable domain. | ||
| CVE-2022-0920 | Hig | 0.49 | 7.5 | 0.01 | Apr 11, 2022 | The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow customers to access all bookings and other customer's data | ||
| CVE-2022-0828 | Hig | 0.49 | 7.5 | 0.02 | Apr 11, 2022 | The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password… | ||
| CVE-2022-27089 | Hig | 0.51 | 7.8 | 0.00 | Apr 11, 2022 | In Fujitsu PlugFree Network <= 7.3.0.3, an Unquoted service path in PFNService.exe software allows a local attacker to potentially escalate privileges to system level. | ||
| CVE-2022-27088 | Hig | 0.51 | 7.8 | 0.01 | Apr 11, 2022 | Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with elevated privileges. | ||
| CVE-2022-27041 | Hig | 0.49 | 7.5 | 0.01 | Apr 11, 2022 | Due to lack of protection, parameter student_id in OpenSIS Classic 8.0 /modules/eligibility/Student.php can be used to inject SQL queries to extract information from databases. | ||
| CVE-2022-26413 | Hig | 0.52 | 8.0 | 0.01 | Apr 11, 2022 | A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN interface. | ||
| CVE-2022-0556 | Hig | 0.47 | 7.3 | 0.00 | Apr 11, 2022 | A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) version 1.1.4, which could allow an attacker to execute arbitrary code as a local administrator. | ||
| CVE-2022-1252 | Hig | 0.53 | 8.2 | 0.01 | Apr 11, 2022 | Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and including 5.5.5. A vulnerability in gnuboard v5.5.5 and below uses weak encryption algorithms leading to sensitive information exposure. This allows an attacker to derive the… | ||
| CVE-2021-32162 | Hig | 0.57 | 8.8 | 0.03 | Apr 11, 2022 | A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 through the File Manager feature. | ||
| CVE-2021-32159 | Hig | 0.57 | 8.8 | 0.02 | Apr 11, 2022 | A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature. | ||
| CVE-2021-32156 | Hig | 0.57 | 8.8 | 0.02 | Apr 11, 2022 | A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature. | ||
| CVE-2022-28893 | Hig | 0.00 | 7.8 | 0.00 | Apr 11, 2022 | The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state. | ||
| CVE-2022-27295 | Hig | 0.49 | 7.5 | 0.01 | Apr 10, 2022 | D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formAdvanceSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter. | ||
| CVE-2022-27294 | Hig | 0.49 | 7.5 | 0.01 | Apr 10, 2022 | D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formWlanWizardSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter. | ||
| CVE-2022-27293 | Hig | 0.49 | 7.5 | 0.03 | Apr 10, 2022 | D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formWlanSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter. | ||
| CVE-2022-27292 | Hig | 0.49 | 7.5 | 0.01 | Apr 10, 2022 | D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formLanguageChange. This vulnerability allows attackers to cause a Denial of Service (DoS) via the nextPage parameter. | ||
| CVE-2022-27291 | Hig | 0.49 | 7.5 | 0.01 | Apr 10, 2022 | D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formdumpeasysetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the config.save_network_enabled parameter. | ||
| CVE-2022-27290 | Hig | 0.49 | 7.5 | 0.01 | Apr 10, 2022 | D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanDhcpplus. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter. | ||
| CVE-2022-27289 | Hig | 0.49 | 7.5 | 0.01 | Apr 10, 2022 | D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanL2TP. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter. | ||
| CVE-2022-27288 | Hig | 0.49 | 7.5 | 0.01 | Apr 10, 2022 | D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanPPTP. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter. | ||
| CVE-2022-27287 | Hig | 0.49 | 7.5 | 0.01 | Apr 10, 2022 | D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanPPPoE. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter. | ||
| CVE-2022-27286 | Hig | 0.49 | 7.5 | 0.01 | Apr 10, 2022 | D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanNonLogin. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter. | ||
| CVE-2022-27279 | Hig | 0.49 | 7.5 | 0.01 | Apr 10, 2022 | InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain an arbitrary file read via the function sub_177E0. | ||
| CVE-2022-27883 | Hig | 0.48 | 7.3 | 0.01 | Apr 9, 2022 | A link following vulnerability in Trend Micro Antivirus for Mac 11.5 could allow an attacker to create a specially-crafted file as a symlink that can lead to privilege escalation. Please note that an attacker must at least have low-level privileges on the system to attempt to… | ||
| CVE-2022-26180 | Hig | 0.61 | 8.8 | 0.04 | Apr 8, 2022 | qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI. | ||
| CVE-2022-26854 | Hig | 0.53 | 8.1 | 0.01 | Apr 8, 2022 | Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain risky cryptographic algorithms. A remote unprivileged malicious attacker could potentially exploit this vulnerability, leading to full system access | ||
| CVE-2022-26852 | Hig | 0.53 | 8.1 | 0.01 | Apr 8, 2022 | Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a predictable seed in pseudo-random number generator. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to an account compromise. | ||
| CVE-2021-36288 | Hig | 0.56 | 8.6 | 0.01 | Apr 8, 2022 | Dell VNX2 for File version 8.1.21.266 and earlier, contain a path traversal vulnerability which may lead unauthenticated users to read/write restricted files | ||
| CVE-2021-36287 | Hig | 0.48 | 7.3 | 0.02 | Apr 8, 2022 | Dell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerability which may lead unauthenticated users to execute commands on the system. | ||
| CVE-2021-43498 | Hig | 0.49 | 7.5 | 0.02 | Apr 8, 2022 | An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTTP POST parameters are set. | ||
| CVE-2021-43515 | Hig | 0.44 | 7.8 | 0.01 | Apr 8, 2022 | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV file. | ||
| CVE-2022-22339 | Hig | 0.47 | 7.3 | 0.01 | Apr 8, 2022 | IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 219736. | ||
| CVE-2021-43521 | Hig | 0.49 | 7.5 | 0.01 | Apr 8, 2022 | A Buffer Overflow vulnerability exists in zlog 1.2.15 via zlog_conf_build_with_file in src/zlog/src/conf.c. | ||
| CVE-2021-43483 | Hig | 0.52 | 8.0 | 0.01 | Apr 8, 2022 | An Access Control vulnerability exists in CLARO KAON CG3000 1.00.67 in the router configuration, which could allow a malicious user to read or update the configuraiton without authentication. | ||
| CVE-2021-40656 | Hig | 0.50 | 8.8 | 0.01 | Apr 8, 2022 | libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867. | ||
| CVE-2020-4668 | Hig | 0.57 | 8.8 | 0.00 | Apr 8, 2022 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM… | ||
| CVE-2022-27046 | Hig | 0.57 | 8.8 | 0.01 | Apr 8, 2022 | libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388. | ||
| CVE-2022-27044 | Hig | 0.57 | 8.8 | 0.01 | Apr 8, 2022 | libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876. | ||
| CVE-2021-41715 | Hig | 0.57 | 8.8 | 0.01 | Apr 8, 2022 | libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379. | ||
| CVE-2021-46367 | Hig | 0.49 | 7.2 | 0.30 | Apr 8, 2022 | RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated attacker can upload a PHP file and bypass the .htacess configuration to deny execution of .php files in media and files directory by default. | ||
| CVE-2021-46436 | Hig | 0.47 | 7.2 | 0.01 | Apr 8, 2022 | An issue was discovered in ZZCMS 2021. There is a SQL injection vulnerability in ad_manage.php. | ||
| CVE-2022-28002 | Hig | 0.49 | 7.5 | 0.02 | Apr 8, 2022 | Movie Seat Reservation v1 was discovered to contain an unauthenticated file disclosure vulnerability via /index.php?page=home. | ||
| CVE-2022-28000 | Hig | 0.57 | 8.8 | 0.02 | Apr 8, 2022 | Car Rental System v1.0 was discovered to contain a SQL injection vulnerability at /Car_Rental/booking.php via the id parameter. | ||
| CVE-2022-27992 | Hig | 0.57 | 8.8 | 0.02 | Apr 8, 2022 | Zoo Management System v1.0 was discovered to contain a SQL injection vulnerability at /public_html/animals via the class_id parameter. | ||
| CVE-2022-27352 | Hig | 0.57 | 8.8 | 0.03 | Apr 8, 2022 | Simple House Rental System v1 was discovered to contain an arbitrary file upload vulnerability via /app/register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-27349 | Hig | 0.47 | 7.2 | 0.02 | Apr 8, 2022 | Social Codia SMS v1 was discovered to contain an arbitrary file upload vulnerability via addteacher.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-27346 | — | Hig | 0.57 | 8.8 | 0.03 | Apr 8, 2022 | Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| CVE-2022-27064 | Hig | 0.57 | 8.8 | 0.03 | Apr 8, 2022 | Musical World v1 was discovered to contain an arbitrary file upload vulnerability via uploaded_songs.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. |
- risk 0.47cvss 7.2epss 0.01
The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing Calendars, which could allow high privilege users such as admin to perform SQL injection attacks
- risk 0.49cvss 7.5epss 0.01
An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load images that hide malware for example from passing malicious domains to hide their trace, by making them pass through the vulnerable domain.
- risk 0.49cvss 7.5epss 0.01
The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow customers to access all bookings and other customer's data
- risk 0.49cvss 7.5epss 0.02
The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password…
- risk 0.51cvss 7.8epss 0.00
In Fujitsu PlugFree Network <= 7.3.0.3, an Unquoted service path in PFNService.exe software allows a local attacker to potentially escalate privileges to system level.
- risk 0.51cvss 7.8epss 0.01
Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with elevated privileges.
- risk 0.49cvss 7.5epss 0.01
Due to lack of protection, parameter student_id in OpenSIS Classic 8.0 /modules/eligibility/Student.php can be used to inject SQL queries to extract information from databases.
- risk 0.52cvss 8.0epss 0.01
A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN interface.
- risk 0.47cvss 7.3epss 0.00
A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) version 1.1.4, which could allow an attacker to execute arbitrary code as a local administrator.
- risk 0.53cvss 8.2epss 0.01
Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and including 5.5.5. A vulnerability in gnuboard v5.5.5 and below uses weak encryption algorithms leading to sensitive information exposure. This allows an attacker to derive the…
- risk 0.57cvss 8.8epss 0.03
A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 through the File Manager feature.
- risk 0.57cvss 8.8epss 0.02
A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature.
- risk 0.57cvss 8.8epss 0.02
A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
- risk 0.00cvss 7.8epss 0.00
The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state.
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formAdvanceSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter.
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formWlanWizardSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter.
- risk 0.49cvss 7.5epss 0.03
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formWlanSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter.
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formLanguageChange. This vulnerability allows attackers to cause a Denial of Service (DoS) via the nextPage parameter.
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formdumpeasysetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the config.save_network_enabled parameter.
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanDhcpplus. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanL2TP. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanPPTP. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanPPPoE. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanNonLogin. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.
- risk 0.49cvss 7.5epss 0.01
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain an arbitrary file read via the function sub_177E0.
- risk 0.48cvss 7.3epss 0.01
A link following vulnerability in Trend Micro Antivirus for Mac 11.5 could allow an attacker to create a specially-crafted file as a symlink that can lead to privilege escalation. Please note that an attacker must at least have low-level privileges on the system to attempt to…
- risk 0.61cvss 8.8epss 0.04
qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.
- risk 0.53cvss 8.1epss 0.01
Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain risky cryptographic algorithms. A remote unprivileged malicious attacker could potentially exploit this vulnerability, leading to full system access
- risk 0.53cvss 8.1epss 0.01
Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a predictable seed in pseudo-random number generator. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to an account compromise.
- risk 0.56cvss 8.6epss 0.01
Dell VNX2 for File version 8.1.21.266 and earlier, contain a path traversal vulnerability which may lead unauthenticated users to read/write restricted files
- risk 0.48cvss 7.3epss 0.02
Dell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerability which may lead unauthenticated users to execute commands on the system.
- risk 0.49cvss 7.5epss 0.02
An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTTP POST parameters are set.
- risk 0.44cvss 7.8epss 0.01
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV file.
- risk 0.47cvss 7.3epss 0.01
IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 219736.
- risk 0.49cvss 7.5epss 0.01
A Buffer Overflow vulnerability exists in zlog 1.2.15 via zlog_conf_build_with_file in src/zlog/src/conf.c.
- risk 0.52cvss 8.0epss 0.01
An Access Control vulnerability exists in CLARO KAON CG3000 1.00.67 in the router configuration, which could allow a malicious user to read or update the configuraiton without authentication.
- risk 0.50cvss 8.8epss 0.01
libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867.
- risk 0.57cvss 8.8epss 0.00
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM…
- risk 0.57cvss 8.8epss 0.01
libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388.
- risk 0.57cvss 8.8epss 0.01
libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876.
- risk 0.57cvss 8.8epss 0.01
libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379.
- risk 0.49cvss 7.2epss 0.30
RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated attacker can upload a PHP file and bypass the .htacess configuration to deny execution of .php files in media and files directory by default.
- risk 0.47cvss 7.2epss 0.01
An issue was discovered in ZZCMS 2021. There is a SQL injection vulnerability in ad_manage.php.
- risk 0.49cvss 7.5epss 0.02
Movie Seat Reservation v1 was discovered to contain an unauthenticated file disclosure vulnerability via /index.php?page=home.
- risk 0.57cvss 8.8epss 0.02
Car Rental System v1.0 was discovered to contain a SQL injection vulnerability at /Car_Rental/booking.php via the id parameter.
- risk 0.57cvss 8.8epss 0.02
Zoo Management System v1.0 was discovered to contain a SQL injection vulnerability at /public_html/animals via the class_id parameter.
- risk 0.57cvss 8.8epss 0.03
Simple House Rental System v1 was discovered to contain an arbitrary file upload vulnerability via /app/register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.47cvss 7.2epss 0.02
Social Codia SMS v1 was discovered to contain an arbitrary file upload vulnerability via addteacher.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.57cvss 8.8epss 0.03
Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.57cvss 8.8epss 0.03
Musical World v1 was discovered to contain an arbitrary file upload vulnerability via uploaded_songs.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.