Search

Search Results (47067 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-38733 1 Sem-cms 1 Semcms 2025-05-07 9.8 Critical
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.
CVE-2021-38732 1 Sem-cms 1 Semcms 2025-05-07 9.8 Critical
SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.
CVE-2021-38731 1 Sem-cms 1 Semcms 2025-05-07 9.8 Critical
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.
CVE-2021-38730 1 Sem-cms 1 Semcms 2025-05-07 9.8 Critical
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.
CVE-2021-38729 1 Sem-cms 1 Semcms 2025-05-07 9.8 Critical
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.
CVE-2021-37781 1 Phpgurukul 1 Employee Record Management System 2025-05-07 5.4 Medium
Employee Record Management System v 1.2 is vulnerable to Cross Site Scripting (XSS) via editempprofile.php.
CVE-2021-35388 1 Phpgurukul 1 Hospital Management System 2025-05-07 5.4 Medium
Hospital Management System v 4.0 is vulnerable to Cross Site Scripting (XSS) via /hospital/hms/admin/patient-search.php.
CVE-2021-35387 1 Phpgurukul 1 Hospital Management System 2025-05-07 8.8 High
Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php.
CVE-2025-47201 1 Intrexx 1 Intrexx 2025-05-07 4.4 Medium
In Intrexx Portal Server before 12.0.4, multiple Velocity-Scripts are susceptible to the execution of unrequested JavaScript code in HTML, aka XSS.
CVE-2025-3709 1 Flowring 1 Agentflow 2025-05-07 9.8 Critical
Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to perform password brute force attack.
CVE-2025-3708 1 Le-show 1 Le-yan 2025-05-07 9.8 Critical
Le-show medical practice management system from Le-yan has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
CVE-2025-3707 1 Sun.net 1 Ehrd Ctms 2025-05-07 6.5 Medium
The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL command to read database contents.
CVE-2025-3312 1 Phpgurukul 1 Men Salon Management System 2025-05-07 7.3 High
A vulnerability, which was classified as critical, has been found in PHPGurukul Men Salon Management System 1.0. This issue affects some unknown processing of the file /admin/add-customer-services.php. The manipulation of the argument sids[] leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-57235 1 Netgear 2 Rax50, Rax50 Firmware 2025-05-07 6.5 Medium
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable function.
CVE-2024-57234 1 Netgear 2 Rax50, Rax50 Firmware 2025-05-07 6.5 Medium
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.
CVE-2024-57233 1 Netgear 2 Rax50, Rax50 Firmware 2025-05-07 6.5 Medium
NETGEAR RAX5 (AX1600 WiFi Router) v1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.
CVE-2024-57232 1 Netgear 2 Rax50, Rax50 Firmware 2025-05-07 6.5 Medium
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.
CVE-2024-57231 1 Netgear 2 Rax50, Rax50 Firmware 2025-05-07 6.5 Medium
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.
CVE-2024-57230 1 Netgear 2 Rax50, Rax50 Firmware 2025-05-07 6.5 Medium
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.
CVE-2024-57229 1 Netgear 2 Rax50, Rax50 Firmware 2025-05-07 6.5 Medium
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.