Total
803 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-3584 | 1 Canteen Management System Project | 1 Canteen Management System | 2022-10-18 | N/A | 8.8 HIGH |
A vulnerability was found in SourceCodester Canteen Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file edituser.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-211193 was assigned to this vulnerability. | |||||
CVE-2022-3581 | 1 Cashier Queuing System Project | 1 Cashier Queuing System | 2022-10-18 | N/A | 6.1 MEDIUM |
A vulnerability, which was classified as problematic, was found in SourceCodester Cashier Queuing System 1.0. Affected is an unknown function of the component Cashiers Tab. The manipulation of the argument Name leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-211188. | |||||
CVE-2022-3580 | 1 Cashier Queuing System Project | 1 Cashier Queuing System | 2022-10-18 | N/A | 6.1 MEDIUM |
A vulnerability, which was classified as problematic, has been found in SourceCodester Cashier Queuing System 1.0.1. This issue affects some unknown processing of the component User Creation Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-211187. | |||||
CVE-2022-3579 | 1 Cashier Queuing System Project | 1 Cashier Queuing System | 2022-10-18 | N/A | 8.8 HIGH |
A vulnerability classified as critical was found in SourceCodester Cashier Queuing System 1.0. This vulnerability affects unknown code of the file /queuing/login.php of the component Login Page. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-211186 is the identifier assigned to this vulnerability. | |||||
CVE-2022-3502 | 1 Human Resource Management System Project | 1 Human Resource Management System | 2022-10-14 | N/A | 5.4 MEDIUM |
A vulnerability was found in Human Resource Management System 1.0. It has been classified as problematic. This affects an unknown part of the component Leave Handler. The manipulation of the argument Reason leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-210831. | |||||
CVE-2022-3503 | 1 Purchase Order Management System Project | 1 Purchase Order Management System | 2022-10-14 | N/A | 5.4 MEDIUM |
A vulnerability was found in SourceCodester Purchase Order Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the component Supplier Handler. The manipulation of the argument Supplier Name/Address/Contact person/Contact leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-210832. | |||||
CVE-2022-3467 | 1 Jiusi | 1 Jiusi Oa | 2022-10-14 | N/A | 9.8 CRITICAL |
A vulnerability classified as critical was found in Jiusi OA. Affected by this vulnerability is an unknown functionality of the file /jsoa/hntdCustomDesktopActionContent. The manipulation of the argument inforid leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-210709 was assigned to this vulnerability. | |||||
CVE-2022-3473 | 1 Human Resource Management System Project | 1 Human Resource Management System | 2022-10-14 | N/A | 6.5 MEDIUM |
A vulnerability classified as critical has been found in SourceCodester Human Resource Management System. This affects an unknown part of the file getstatecity.php. The manipulation of the argument ci leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-210717 was assigned to this vulnerability. | |||||
CVE-2022-3493 | 1 Human Resource Management System Project | 1 Human Resource Management System | 2022-10-14 | N/A | 5.4 MEDIUM |
A vulnerability, which was classified as problematic, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the component Add Employee Handler. The manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-210773 was assigned to this vulnerability. | |||||
CVE-2022-3492 | 1 Human Resource Management System Project | 1 Human Resource Management System | 2022-10-14 | N/A | 8.8 HIGH |
A vulnerability classified as critical was found in SourceCodester Human Resource Management System 1.0. This vulnerability affects unknown code of the component Profile Photo Handler. The manipulation of the argument parameter leads to os command injection. The attack can be initiated remotely. The identifier of this vulnerability is VDB-210772. | |||||
CVE-2022-3471 | 1 Human Resource Management System Project | 1 Human Resource Management System | 2022-10-13 | N/A | 4.9 MEDIUM |
A vulnerability was found in SourceCodester Human Resource Management System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file city.php. The manipulation of the argument searccity leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-210715. | |||||
CVE-2022-3472 | 1 Human Resource Management System Project | 1 Human Resource Management System | 2022-10-13 | N/A | 4.9 MEDIUM |
A vulnerability was found in SourceCodester Human Resource Management System. It has been rated as critical. Affected by this issue is some unknown functionality of the file city.php. The manipulation of the argument cityedit leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-210716. | |||||
CVE-2022-3470 | 1 Human Resource Management System Project | 1 Human Resource Management System | 2022-10-13 | N/A | 6.5 MEDIUM |
A vulnerability was found in SourceCodester Human Resource Management System. It has been classified as critical. Affected is an unknown function of the file getstatecity.php. The manipulation of the argument sc leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-210714 is the identifier assigned to this vulnerability. | |||||
CVE-2021-36913 | 1 Redirection-for-contact-form7 | 1 Redirection For Contact Form 7 | 2022-10-13 | N/A | 7.5 HIGH |
Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows attackers to change options and inject scripts into the footer HTML. Requires an additional extension (plugin) AccessiBe. | |||||
CVE-2022-3452 | 1 Book Store Management System Project | 1 Book Store Management System | 2022-10-11 | N/A | 5.4 MEDIUM |
A vulnerability was found in SourceCodester Book Store Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /category.php. The manipulation of the argument category_name leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-210436. | |||||
CVE-2022-3453 | 1 Book Store Management System Project | 1 Book Store Management System | 2022-10-11 | N/A | 5.4 MEDIUM |
A vulnerability was found in SourceCodester Book Store Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /transcation.php. The manipulation of the argument buyer_name leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-210437 was assigned to this vulnerability. | |||||
CVE-2022-3414 | 1 Web-based Student Clearance System Project | 1 Web-based Student Clearance System | 2022-10-07 | N/A | 9.8 CRITICAL |
A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been classified as critical. Affected is an unknown function of the file /Admin/login.php of the component POST Parameter Handler. The manipulation of the argument txtusername leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-210246 is the identifier assigned to this vulnerability. | |||||
CVE-2020-26298 | 2 Debian, Redcarpet Project | 2 Debian Linux, Redcarpet | 2022-10-06 | 3.5 LOW | 5.4 MEDIUM |
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the `:escape_html` option was being used. This is fixed in version 3.5.1 by the referenced commit. | |||||
CVE-2022-24039 | 1 Siemens | 4 Desigo Pxc4, Desigo Pxc4 Firmware, Desigo Pxc5 and 1 more | 2022-10-05 | 8.5 HIGH | 9.0 CRITICAL |
A vulnerability has been identified in Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The “addCell” JavaScript function fails to properly sanitize user-controllable input before including it into the generated XML body of the XLS report document, such that it is possible to inject arbitrary content (e.g., XML tags) into the generated file. An attacker with restricted privileges, by poisoning any of the content used to generate XLS reports, could be able to leverage the application to deliver malicious files against higher-privileged users and obtain Remote Code Execution (RCE) against the administrator’s workstation. | |||||
CVE-2020-27602 | 1 Bigbluebutton | 1 Bigbluebutton | 2022-10-03 | N/A | 9.8 CRITICAL |
BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken. |