BigTiger2020
Products
9- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
10| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-38730 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php. | ||
| CVE-2021-37782 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php. | ||
| CVE-2021-25210 | Cri | 0.64 | 9.8 | 0.01 | Jul 22, 2021 | Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to manage_event.php. | ||
| CVE-2020-29283 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2020 | An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php. | ||
| CVE-2020-29282 | Cri | 0.64 | 9.8 | 0.03 | Dec 2, 2020 | SQL injection vulnerability in BloodX 1.0 allows attackers to bypass authentication. | ||
| CVE-2020-25537 | Cri | 0.64 | 9.8 | 0.02 | Nov 30, 2020 | File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission. | ||
| CVE-2020-36002 | Hig | 0.49 | 7.5 | 0.02 | Feb 17, 2021 | Seat-Reservation-System 1.0 has a SQL injection vulnerability in index.php in the id parameter where attackers can obtain sensitive database information. | ||
| CVE-2021-27545 | Med | 0.42 | 6.5 | 0.02 | Apr 15, 2021 | SQL Injection in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to obtain sensitive database information by injecting SQL commands into the "sername" parameter. | ||
| CVE-2020-26609 | Med | 0.35 | 5.4 | 0.01 | Feb 23, 2021 | fastadmin V1.0.0.20200506_beta contains a cross-site scripting (XSS) vulnerability which may allow an attacker to obtain administrator credentials to log in to the background. | ||
| CVE-2021-27544 | Med | 0.31 | 4.8 | 0.01 | Apr 15, 2021 | Cross Site Scripting (XSS) in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "sername" parameter. |
- risk 0.64cvss 9.8epss 0.01
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.
- risk 0.64cvss 9.8epss 0.01
Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php.
- risk 0.64cvss 9.8epss 0.01
Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to manage_event.php.
- risk 0.64cvss 9.8epss 0.01
An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php.
- risk 0.64cvss 9.8epss 0.03
SQL injection vulnerability in BloodX 1.0 allows attackers to bypass authentication.
- risk 0.64cvss 9.8epss 0.02
File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission.
- risk 0.49cvss 7.5epss 0.02
Seat-Reservation-System 1.0 has a SQL injection vulnerability in index.php in the id parameter where attackers can obtain sensitive database information.
- risk 0.42cvss 6.5epss 0.02
SQL Injection in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to obtain sensitive database information by injecting SQL commands into the "sername" parameter.
- risk 0.35cvss 5.4epss 0.01
fastadmin V1.0.0.20200506_beta contains a cross-site scripting (XSS) vulnerability which may allow an attacker to obtain administrator credentials to log in to the background.
- risk 0.31cvss 4.8epss 0.01
Cross Site Scripting (XSS) in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "sername" parameter.