| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-28423 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/posts.php&action=delete. | ||
| CVE-2022-28422 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/posts.php&action=edit. | ||
| CVE-2022-28421 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=posts&action=display&value=1&postid=. | ||
| CVE-2022-28420 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via BabyCare/admin.php?id=theme&setid=. | ||
| CVE-2022-28417 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase. | ||
| CVE-2022-28416 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase. | ||
| CVE-2022-28415 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_collection. | ||
| CVE-2022-28414 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_member. | ||
| CVE-2022-28413 | Cri | 0.64 | 9.8 | 0.02 | Apr 21, 2022 | Car Driving School Management System v1.0 was discovered to contain a SQL injection vulnerability via /cdsms/classes/Master.php?f=delete_enrollment. | ||
| CVE-2022-28412 | Cri | 0.64 | 9.8 | 0.02 | Apr 21, 2022 | Car Driving School Managment System v1.0 was discovered to contain a SQL injection vulnerability via /cdsms/classes/Master.php?f=delete_package. | ||
| CVE-2022-28411 | Cri | 0.64 | 9.8 | 0.02 | Apr 21, 2022 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/admin/?page=agents/manage_agent. | ||
| CVE-2022-28410 | Cri | 0.64 | 9.8 | 0.02 | Apr 21, 2022 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Users.php?f=delete_agent. | ||
| CVE-2022-28030 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_estate. | ||
| CVE-2022-28029 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_type. | ||
| CVE-2022-28028 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_amenity. | ||
| CVE-2022-28026 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=student_p&id=. | ||
| CVE-2022-28025 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=school_year. | ||
| CVE-2022-28024 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=grade. | ||
| CVE-2022-28023 | Cri | 0.64 | 9.8 | 0.03 | Apr 21, 2022 | Purchase Order Management System v1.0 was discovered to contain a SQL injection vulnerability via /purchase_order/classes/Master.php?f=delete_supplier. | ||
| CVE-2022-28022 | Cri | 0.64 | 9.8 | 0.03 | Apr 21, 2022 | Purchase Order Management System v1.0 was discovered to contain a SQL injection vulnerability via /purchase_order/classes/Master.php?f=delete_item. | ||
| CVE-2022-28021 | Cri | 0.66 | 9.8 | 0.24 | Apr 21, 2022 | Purchase Order Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /purchase_order/admin/?page=user. | ||
| CVE-2022-28743 | Cri | 0.59 | 9.1 | 0.01 | Apr 21, 2022 | Time-of-check Time-of-use (TOCTOU) Race Condition vulerability in Foscam R2C IP camera running System FW <= 1.13.1.6, and Application FW <= 2.91.2.66, allows an authenticated remote attacker with administrator permissions to execute arbitrary remote code via a malicious firmware… | ||
| CVE-2022-0272 | Cri | 0.57 | 9.8 | 0.01 | Apr 21, 2022 | Improper Restriction of XML External Entity Reference in GitHub repository detekt/detekt prior to 1.20.0. | ||
| CVE-2021-41162 | Cri | 0.61 | 9.3 | 0.01 | Apr 21, 2022 | Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?operation=wizard_helper` page did not properly escape the user supplied parameters, allowing for a cross site scripting attack vector. Users are advised to upgrade.… | ||
| CVE-2021-41161 | Cri | 0.61 | 9.3 | 0.01 | Apr 21, 2022 | Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't properly escape the user supplied parameters, allowing for javascript injection into rendered csv files. Users are advised to upgrade. There are no known… | ||
| CVE-2016-20014 | Cri | 0.57 | 9.8 | 0.01 | Apr 21, 2022 | In pam_tacplus.c in pam_tacplus before 1.4.1, pam_sm_acct_mgmt does not zero out the arep data structure. | ||
| CVE-2022-29528 | Cri | 0.64 | 9.8 | 0.02 | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur. | ||
| CVE-2021-43481 | Cri | 0.67 | 9.8 | 0.06 | Apr 20, 2022 | An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php. | ||
| CVE-2022-26133 | Cri | 0.69 | 9.8 | 0.70 | Apr 20, 2022 | SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute… | ||
| CVE-2022-24861 | Cri | 0.00 | 9.9 | 0.03 | Apr 20, 2022 | Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has remote code execution vulnerability. JDBC drivers are not validated prior to use and may be provided by users of the system. This can lead to code execution by any basic user… | ||
| CVE-2022-0540 | Cri | 0.71 | 9.8 | 0.88 | Apr 20, 2022 | A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0… | ||
| CVE-2022-24799 | Cri | 0.00 | 9.6 | 0.01 | Apr 20, 2022 | wire-webapp is the web application interface for the wire messaging service. Insufficient escaping in markdown “code highlighting” in the wire-webapp resulted in the possibility of injecting and executing arbitrary HTML code and thus also JavaScript. If a user receives and… | ||
| CVE-2022-1039 | Cri | 0.62 | 9.6 | 0.01 | Apr 20, 2022 | The weak password on the web user interface can be exploited via HTTP or HTTPS. Once such access has been obtained, the other passwords can be changed. The weak password on Linux accounts can be accessed via SSH or Telnet, the former of which is by default enabled on trusted… | ||
| CVE-2022-0567 | Cri | 0.59 | 9.1 | 0.01 | Apr 20, 2022 | A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bypasses existing ingress policies of other pods in a cluster, allowing network traffic to access pods that should not be reachable. This… | ||
| CVE-2022-24826 | Cri | 0.64 | 9.8 | 0.02 | Apr 20, 2022 | On Windows, if Git LFS operates on a malicious repository with a `..exe` file as well as a file named `git.exe`, and `git.exe` is not found in `PATH`, the `..exe` program will be executed, permitting the attacker to execute arbitrary code. This does not affect Unix systems.… | ||
| CVE-2022-27862 | Cri | 0.64 | 9.8 | 0.02 | Apr 19, 2022 | Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form. | ||
| CVE-2022-21445 | Cri | 0.81 | 9.8 | 0.62 | KEV | Apr 19, 2022 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| CVE-2022-21431 | Cri | 0.65 | 10.0 | 0.02 | Apr 19, 2022 | Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4 and 12.0.0.5. Easily exploitable vulnerability allows unauthenticated… | ||
| CVE-2022-21420 | Cri | 0.64 | 9.8 | 0.01 | Apr 19, 2022 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise… | ||
| CVE-2022-0992 | Cri | 0.64 | 9.8 | 0.03 | Apr 19, 2022 | The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on initial 2FA set-up that allows unauthenticated and unauthorized users to configure 2FA… | ||
| CVE-2022-27104 | Cri | 0.64 | 9.8 | 0.01 | Apr 19, 2022 | An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3. | ||
| CVE-2022-27927 | Cri | 0.65 | 9.8 | 0.14 | Apr 19, 2022 | A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter. | ||
| CVE-2022-29464 | — | Cri | 0.93 | 9.8 | 1.00 | KEV | Apr 18, 2022 | Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a… |
| CVE-2022-1020 | Cri | 0.66 | 9.8 | 0.26 | Apr 18, 2022 | The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback… | ||
| CVE-2022-0785 | Cri | 0.64 | 9.8 | 0.09 | Apr 18, 2022 | The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection | ||
| CVE-2022-25226 | Cri | 0.66 | 10.0 | 0.11 | Apr 18, 2022 | ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?cmd=connect' by obtaining a valid SID without any kind of authentication. It is possible to achieve code execution on the server by sending keyboard or mouse… | ||
| CVE-2020-13567 | Cri | 0.64 | 9.8 | 0.02 | Apr 18, 2022 | Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability. | ||
| CVE-2022-26631 | Cri | 0.64 | 9.8 | 0.01 | Apr 18, 2022 | Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter. | ||
| CVE-2022-27423 | Cri | 0.64 | 9.8 | 0.01 | Apr 15, 2022 | Chamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php. | ||
| CVE-2022-26809 | Cri | 0.71 | 9.8 | 0.91 | Apr 15, 2022 | Remote Procedure Call Runtime Remote Code Execution Vulnerability |
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/posts.php&action=delete.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/posts.php&action=edit.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=posts&action=display&value=1&postid=.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via BabyCare/admin.php?id=theme&setid=.
- risk 0.64cvss 9.8epss 0.01
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase.
- risk 0.64cvss 9.8epss 0.01
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase.
- risk 0.64cvss 9.8epss 0.01
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_collection.
- risk 0.64cvss 9.8epss 0.01
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_member.
- risk 0.64cvss 9.8epss 0.02
Car Driving School Management System v1.0 was discovered to contain a SQL injection vulnerability via /cdsms/classes/Master.php?f=delete_enrollment.
- risk 0.64cvss 9.8epss 0.02
Car Driving School Managment System v1.0 was discovered to contain a SQL injection vulnerability via /cdsms/classes/Master.php?f=delete_package.
- risk 0.64cvss 9.8epss 0.02
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/admin/?page=agents/manage_agent.
- risk 0.64cvss 9.8epss 0.02
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Users.php?f=delete_agent.
- risk 0.64cvss 9.8epss 0.01
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_estate.
- risk 0.64cvss 9.8epss 0.01
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_type.
- risk 0.64cvss 9.8epss 0.01
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_amenity.
- risk 0.64cvss 9.8epss 0.01
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=student_p&id=.
- risk 0.64cvss 9.8epss 0.01
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=school_year.
- risk 0.64cvss 9.8epss 0.01
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=grade.
- risk 0.64cvss 9.8epss 0.03
Purchase Order Management System v1.0 was discovered to contain a SQL injection vulnerability via /purchase_order/classes/Master.php?f=delete_supplier.
- risk 0.64cvss 9.8epss 0.03
Purchase Order Management System v1.0 was discovered to contain a SQL injection vulnerability via /purchase_order/classes/Master.php?f=delete_item.
- risk 0.66cvss 9.8epss 0.24
Purchase Order Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /purchase_order/admin/?page=user.
- risk 0.59cvss 9.1epss 0.01
Time-of-check Time-of-use (TOCTOU) Race Condition vulerability in Foscam R2C IP camera running System FW <= 1.13.1.6, and Application FW <= 2.91.2.66, allows an authenticated remote attacker with administrator permissions to execute arbitrary remote code via a malicious firmware…
- risk 0.57cvss 9.8epss 0.01
Improper Restriction of XML External Entity Reference in GitHub repository detekt/detekt prior to 1.20.0.
- risk 0.61cvss 9.3epss 0.01
Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?operation=wizard_helper` page did not properly escape the user supplied parameters, allowing for a cross site scripting attack vector. Users are advised to upgrade.…
- risk 0.61cvss 9.3epss 0.01
Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't properly escape the user supplied parameters, allowing for javascript injection into rendered csv files. Users are advised to upgrade. There are no known…
- risk 0.57cvss 9.8epss 0.01
In pam_tacplus.c in pam_tacplus before 1.4.1, pam_sm_acct_mgmt does not zero out the arep data structure.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.
- risk 0.67cvss 9.8epss 0.06
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.
- risk 0.69cvss 9.8epss 0.70
SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute…
- risk 0.00cvss 9.9epss 0.03
Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has remote code execution vulnerability. JDBC drivers are not validated prior to use and may be provided by users of the system. This can lead to code execution by any basic user…
- risk 0.71cvss 9.8epss 0.88
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0…
- risk 0.00cvss 9.6epss 0.01
wire-webapp is the web application interface for the wire messaging service. Insufficient escaping in markdown “code highlighting” in the wire-webapp resulted in the possibility of injecting and executing arbitrary HTML code and thus also JavaScript. If a user receives and…
- risk 0.62cvss 9.6epss 0.01
The weak password on the web user interface can be exploited via HTTP or HTTPS. Once such access has been obtained, the other passwords can be changed. The weak password on Linux accounts can be accessed via SSH or Telnet, the former of which is by default enabled on trusted…
- risk 0.59cvss 9.1epss 0.01
A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bypasses existing ingress policies of other pods in a cluster, allowing network traffic to access pods that should not be reachable. This…
- risk 0.64cvss 9.8epss 0.02
On Windows, if Git LFS operates on a malicious repository with a `..exe` file as well as a file named `git.exe`, and `git.exe` is not found in `PATH`, the `..exe` program will be executed, permitting the attacker to execute arbitrary code. This does not affect Unix systems.…
- risk 0.64cvss 9.8epss 0.02
Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form.
- risk 0.81cvss 9.8epss 0.62
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network…
- risk 0.65cvss 10.0epss 0.02
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4 and 12.0.0.5. Easily exploitable vulnerability allows unauthenticated…
- risk 0.64cvss 9.8epss 0.01
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise…
- risk 0.64cvss 9.8epss 0.03
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on initial 2FA set-up that allows unauthenticated and unauthorized users to configure 2FA…
- risk 0.64cvss 9.8epss 0.01
An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3.
- risk 0.65cvss 9.8epss 0.14
A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter.
- risk 0.93cvss 9.8epss 1.00
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a…
- risk 0.66cvss 9.8epss 0.26
The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback…
- risk 0.64cvss 9.8epss 0.09
The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection
- risk 0.66cvss 10.0epss 0.11
ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?cmd=connect' by obtaining a valid SID without any kind of authentication. It is possible to achieve code execution on the server by sending keyboard or mouse…
- risk 0.64cvss 9.8epss 0.02
Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.
- risk 0.64cvss 9.8epss 0.01
Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter.
- risk 0.64cvss 9.8epss 0.01
Chamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php.
- risk 0.71cvss 9.8epss 0.91
Remote Procedure Call Runtime Remote Code Execution Vulnerability