| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-40053 | Cri | 0.59 | 9.1 | 0.01 | Mar 10, 2022 | There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity. | ||
| CVE-2021-40050 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2022 | There is an out-of-bounds read vulnerability in the IFAA module. Successful exploitation of this vulnerability may cause stack overflow. | ||
| CVE-2021-33293 | Cri | 0.59 | 9.1 | 0.02 | Mar 10, 2022 | Panorama Tools libpano13 v2.9.20 was discovered to contain an out-of-bounds read in the function panoParserFindOLine() in parser.c. | ||
| CVE-2020-14115 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2022 | A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code. | ||
| CVE-2022-0895 | Cri | 0.57 | 9.8 | 0.02 | Mar 10, 2022 | Static Code Injection in GitHub repository microweber/microweber prior to 1.3. | ||
| CVE-2022-22806 | Cri | 0.65 | 9.8 | 0.12 | Mar 9, 2022 | A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malformed connection is sent. Affected Product: SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and prior), SMC Series (SMC… | ||
| CVE-2022-22805 | Cri | 0.65 | 9.8 | 0.12 | Mar 9, 2022 | A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause remote code execution when an improperly handled TLS packet is reassembled. Affected Product: SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and… | ||
| CVE-2022-0715 | Cri | 0.60 | 9.1 | 0.06 | Mar 9, 2022 | A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Series (SMT Series ID=18: UPS 09.8 and prior… | ||
| CVE-2022-0482 | — | Cri | 0.58 | 9.1 | 0.38 | Mar 9, 2022 | Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3. | |
| CVE-2022-26314 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2022 | A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix Forgot Password Appstore module (Mendix 7 compatible) (All versions < V3.2.2). Initial passwords are generated in an insecure manner. This could allow an… | ||
| CVE-2022-26313 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2022 | A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1). In certain configurations of the affected product, a threat actor could use the sign up flow to hijack arbitrary user accounts. | ||
| CVE-2021-37208 | Cri | 0.62 | 9.6 | 0.01 | Mar 8, 2022 | A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2100NC, RUGGEDCOM M2200, RUGGEDCOM M2200F, RUGGEDCOM… | ||
| CVE-2022-0441 | Cri | 0.67 | 9.8 | 0.85 | Mar 7, 2022 | The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin | ||
| CVE-2022-0434 | Cri | 0.65 | 9.8 | 0.15 | Mar 7, 2022 | The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL… | ||
| CVE-2022-0349 | Cri | 0.66 | 9.8 | 0.34 | Mar 7, 2022 | The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection | ||
| CVE-2022-0767 | Cri | 0.57 | 9.9 | 0.01 | Mar 7, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17. | ||
| CVE-2022-0766 | Cri | 0.57 | 9.8 | 0.01 | Mar 7, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17. | ||
| CVE-2021-46704 | Cri | 0.58 | 9.8 | 0.22 | Mar 6, 2022 | In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts and lib/ping.ts). The vulnerability arises from insufficient input validation combined with a missing authorization check. | ||
| CVE-2022-26496 | Cri | 0.64 | 9.8 | 0.03 | Mar 6, 2022 | In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by sending a crafted NBD_OPT_INFO or NBD_OPT_GO message with an large value as the length of the name. | ||
| CVE-2022-26495 | Cri | 0.64 | 9.8 | 0.03 | Mar 6, 2022 | In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length field will cause a zero-sized buffer to be allocated for the name, resulting in a write to a dangling pointer. This issue exists… | ||
| CVE-2021-46703 | — | Cri | 0.64 | 9.8 | 0.02 | Mar 6, 2022 | In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a sandboxed environment (if users can externally control template contents). NOTE: This vulnerability only affects products that are no longer… | |
| CVE-2022-0845 | Cri | 0.57 | 9.8 | 0.01 | Mar 5, 2022 | Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0. | ||
| CVE-2022-25069 | Cri | 0.00 | 9.6 | 0.02 | Mar 5, 2022 | Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote code execution (RCE) via injecting a crafted payload into /lib/contentState/pasteCtrl.js. | ||
| CVE-2022-25312 | Cri | 0.59 | 9.1 | 0.03 | Mar 5, 2022 | An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions < 2.7. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with… | ||
| CVE-2021-46384 | — | Cri | 0.64 | 9.8 | 0.02 | Mar 4, 2022 | https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE vulnerability through which allows unauthenticated… | |
| CVE-2021-32008 | Cri | 0.64 | 9.9 | 0.01 | Mar 4, 2022 | This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories. | ||
| CVE-2022-26318 | Cri | 0.85 | 9.8 | 0.78 | KEV | Mar 4, 2022 | On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2. | |
| CVE-2022-0839 | Cri | 0.57 | 9.8 | 0.03 | Mar 4, 2022 | Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0. | ||
| CVE-2022-26201 | Cri | 0.64 | 9.8 | 0.01 | Mar 4, 2022 | Victor CMS v1.0 was discovered to contain a SQL injection vulnerability. | ||
| CVE-2021-46394 | Cri | 0.64 | 9.8 | 0.03 | Mar 4, 2022 | There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v13 variable is directly retrieved from the http request parameter startIp. Then v13 will be splice to stack by function sscanf without any security check,… | ||
| CVE-2021-46393 | Cri | 0.65 | 9.8 | 0.16 | Mar 4, 2022 | There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v10 variable is directly retrieved from the http request parameter startIp. Then v10 will be splice to stack by function sscanf without any security… | ||
| CVE-2022-0848 | Cri | 0.06 | 9.8 | 0.35 | Mar 4, 2022 | OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11. | ||
| CVE-2022-0730 | Cri | 0.64 | 9.8 | 0.03 | Mar 3, 2022 | Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types. | ||
| CVE-2022-22947 | Cri | 0.81 | 10.0 | 0.98 | KEV | Mar 3, 2022 | In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote… | |
| CVE-2022-0265 | Cri | 0.57 | 9.8 | 0.03 | Mar 3, 2022 | Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1. | ||
| CVE-2021-3762 | — | Cri | 0.57 | 9.8 | 0.05 | Mar 3, 2022 | A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution. | |
| CVE-2022-25125 | Cri | 0.64 | 9.8 | 0.07 | Mar 3, 2022 | MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp. | ||
| CVE-2022-23899 | — | Cri | 0.64 | 9.8 | 0.01 | Mar 3, 2022 | MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java. | |
| CVE-2022-23898 | — | Cri | 0.64 | 9.8 | 0.08 | Mar 3, 2022 | MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml. | |
| CVE-2022-0841 | — | Cri | 0.57 | 9.8 | 0.03 | Mar 3, 2022 | OS Command Injection in GitHub repository ljharb/npm-lockfile in v2.0.3 and v2.0.4. | |
| CVE-2022-25089 | Cri | 0.68 | 9.8 | 0.18 | Mar 3, 2022 | Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.PersistentRegistryData. | ||
| CVE-2022-26171 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2022 | Bank Management System v1.o was discovered to contain a SQL injection vulnerability via the email parameter. | ||
| CVE-2022-26170 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2022 | Simple Mobile Comparison Website v1.0 was discovered to contain a SQL injection vulnerability via the search parameter. | ||
| CVE-2022-26169 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2022 | Air Cargo Management System v1.0 was discovered to contain a SQL injection vulnerability via the ref_code parameter. | ||
| CVE-2022-25399 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2022 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter. | ||
| CVE-2022-25398 | — | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2022 | Auto Spare Parts Management v1.0 was discovered to contain a SQL injection vulnerability via the user parameter. | |
| CVE-2022-25396 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2022 | Cosmetics and Beauty Product Online Store v1.0 was discovered to contain a SQL injection vulnerability via the search parameter. | ||
| CVE-2022-25395 | Cri | 0.62 | 9.6 | 0.01 | Mar 2, 2022 | Cosmetics and Beauty Product Online Store v1.0 was discovered to contain multiple reflected cross-site scripting (XSS) attacks via the search parameter under the /cbpos/ app. | ||
| CVE-2022-25394 | — | Cri | 0.64 | 9.8 | 0.02 | Mar 2, 2022 | Medical Store Management System v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter under customer-add.php. | |
| CVE-2022-25045 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2022 | Home Owners Collection Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel. |
- risk 0.59cvss 9.1epss 0.01
There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity.
- risk 0.64cvss 9.8epss 0.01
There is an out-of-bounds read vulnerability in the IFAA module. Successful exploitation of this vulnerability may cause stack overflow.
- risk 0.59cvss 9.1epss 0.02
Panorama Tools libpano13 v2.9.20 was discovered to contain an out-of-bounds read in the function panoParserFindOLine() in parser.c.
- risk 0.64cvss 9.8epss 0.01
A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code.
- risk 0.57cvss 9.8epss 0.02
Static Code Injection in GitHub repository microweber/microweber prior to 1.3.
- risk 0.65cvss 9.8epss 0.12
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malformed connection is sent. Affected Product: SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and prior), SMC Series (SMC…
- risk 0.65cvss 9.8epss 0.12
A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause remote code execution when an improperly handled TLS packet is reassembled. Affected Product: SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and…
- risk 0.60cvss 9.1epss 0.06
A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Series (SMT Series ID=18: UPS 09.8 and prior…
- risk 0.58cvss 9.1epss 0.38
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix Forgot Password Appstore module (Mendix 7 compatible) (All versions < V3.2.2). Initial passwords are generated in an insecure manner. This could allow an…
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1). In certain configurations of the affected product, a threat actor could use the sign up flow to hijack arbitrary user accounts.
- risk 0.62cvss 9.6epss 0.01
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2100NC, RUGGEDCOM M2200, RUGGEDCOM M2200F, RUGGEDCOM…
- risk 0.67cvss 9.8epss 0.85
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
- risk 0.65cvss 9.8epss 0.15
The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL…
- risk 0.66cvss 9.8epss 0.34
The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection
- risk 0.57cvss 9.9epss 0.01
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.
- risk 0.57cvss 9.8epss 0.01
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.
- risk 0.58cvss 9.8epss 0.22
In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts and lib/ping.ts). The vulnerability arises from insufficient input validation combined with a missing authorization check.
- risk 0.64cvss 9.8epss 0.03
In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by sending a crafted NBD_OPT_INFO or NBD_OPT_GO message with an large value as the length of the name.
- risk 0.64cvss 9.8epss 0.03
In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length field will cause a zero-sized buffer to be allocated for the name, resulting in a write to a dangling pointer. This issue exists…
- risk 0.64cvss 9.8epss 0.02
In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a sandboxed environment (if users can externally control template contents). NOTE: This vulnerability only affects products that are no longer…
- risk 0.57cvss 9.8epss 0.01
Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.
- risk 0.00cvss 9.6epss 0.02
Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote code execution (RCE) via injecting a crafted payload into /lib/contentState/pasteCtrl.js.
- risk 0.59cvss 9.1epss 0.03
An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions < 2.7. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with…
- risk 0.64cvss 9.8epss 0.02
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE vulnerability through which allows unauthenticated…
- risk 0.64cvss 9.9epss 0.01
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories.
- risk 0.85cvss 9.8epss 0.78
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.
- risk 0.57cvss 9.8epss 0.03
Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.
- risk 0.64cvss 9.8epss 0.01
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability.
- risk 0.64cvss 9.8epss 0.03
There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v13 variable is directly retrieved from the http request parameter startIp. Then v13 will be splice to stack by function sscanf without any security check,…
- risk 0.65cvss 9.8epss 0.16
There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v10 variable is directly retrieved from the http request parameter startIp. Then v10 will be splice to stack by function sscanf without any security…
- risk 0.06cvss 9.8epss 0.35
OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11.
- risk 0.64cvss 9.8epss 0.03
Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.
- risk 0.81cvss 10.0epss 0.98
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote…
- risk 0.57cvss 9.8epss 0.03
Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1.
- risk 0.57cvss 9.8epss 0.05
A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.
- risk 0.64cvss 9.8epss 0.07
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
- risk 0.64cvss 9.8epss 0.01
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java.
- risk 0.64cvss 9.8epss 0.08
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.
- risk 0.57cvss 9.8epss 0.03
OS Command Injection in GitHub repository ljharb/npm-lockfile in v2.0.3 and v2.0.4.
- risk 0.68cvss 9.8epss 0.18
Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.PersistentRegistryData.
- risk 0.64cvss 9.8epss 0.01
Bank Management System v1.o was discovered to contain a SQL injection vulnerability via the email parameter.
- risk 0.64cvss 9.8epss 0.01
Simple Mobile Comparison Website v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.
- risk 0.64cvss 9.8epss 0.01
Air Cargo Management System v1.0 was discovered to contain a SQL injection vulnerability via the ref_code parameter.
- risk 0.64cvss 9.8epss 0.01
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
- risk 0.64cvss 9.8epss 0.01
Auto Spare Parts Management v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.
- risk 0.64cvss 9.8epss 0.01
Cosmetics and Beauty Product Online Store v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.
- risk 0.62cvss 9.6epss 0.01
Cosmetics and Beauty Product Online Store v1.0 was discovered to contain multiple reflected cross-site scripting (XSS) attacks via the search parameter under the /cbpos/ app.
- risk 0.64cvss 9.8epss 0.02
Medical Store Management System v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter under customer-add.php.
- risk 0.64cvss 9.8epss 0.01
Home Owners Collection Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.