Export limit exceeded: 367326 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (367326 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-51281 | 2 Oretnom23, Sourcecodester | 2 Customer Support System, Customer Support System | 2025-03-28 | 5.4 Medium |
| Cross Site Scripting vulnerability in Customer Support System v.1.0 allows a remote attacker to escalate privileges via a crafted script firstname, "lastname", "middlename", "contact" and address parameters. | ||||
| CVE-2024-27743 | 2 Mayurik, Petroleum Management Software Application Project | 2 Petrol Pump Management, Petroleum Management Software Application | 2025-03-28 | 6.1 Medium |
| Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the Address parameter in the add_invoices.php component. | ||||
| CVE-2024-27744 | 1 Mayurik | 1 Petrol Pump Management | 2025-03-28 | 6.1 Medium |
| Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the image parameter in the profile.php component. | ||||
| CVE-2024-27746 | 1 Mayurik | 1 Petrol Pump Management | 2025-03-28 | 9.8 Critical |
| SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.php component. | ||||
| CVE-2024-27747 | 2 Mayurik, Sourcecodester | 2 Petrol Pump Management, Petrol Pump Management | 2025-03-28 | 9.8 Critical |
| File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Image parameter in the profile.php component. | ||||
| CVE-2023-49545 | 2 Oretnom23, Sourcecodester | 2 Customer Support System, Customer Support System | 2025-03-28 | 7.5 High |
| A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization. | ||||
| CVE-2023-49546 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | 8.8 High |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php. | ||||
| CVE-2023-49547 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | 9.8 Critical |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login. | ||||
| CVE-2023-49548 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | 8.8 High |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user. | ||||
| CVE-2023-49968 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | 7.3 High |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/manage_department.php. | ||||
| CVE-2023-49969 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | 4.3 Medium |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer. | ||||
| CVE-2023-49970 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | 9.8 Critical |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/ajax.php?action=save_ticket. | ||||
| CVE-2025-0190 | 1 Aimstack | 1 Aim | 2025-03-28 | 7.5 High |
| In version 3.25.0 of aimhubio/aim, a denial of service vulnerability exists. By tracking a large number of `Text` objects and then querying them simultaneously through the web API, the Aim web server becomes unresponsive to other requests for an extended period while processing and returning these objects. This vulnerability can be exploited repeatedly, leading to a complete denial of service. | ||||
| CVE-2023-49544 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | 4.9 Medium |
| A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php. | ||||
| CVE-2024-27559 | 1 Codelyfe | 1 Stupid Simple Cms | 2025-03-28 | 6.3 Medium |
| Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /save_settings.php | ||||
| CVE-2024-27689 | 2 Codelyfe, Stupid Simple | 2 Stupid Simple Cms, Cms | 2025-03-28 | 8.8 High |
| Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via /update-article.php. | ||||
| CVE-2025-0281 | 1 Lunary | 1 Lunary | 2025-03-28 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability exists in lunary-ai/lunary versions 1.6.7 and earlier. An attacker can inject malicious JavaScript into the SAML IdP XML metadata, which is used to generate the SAML login redirect URL. This URL is then set as the value of `window.location.href` without proper validation or sanitization. This vulnerability allows the attacker to execute arbitrary JavaScript in the context of the user's browser, potentially leading to session hijacking, data theft, or other malicious actions. The issue is fixed in version 1.7.10. | ||||
| CVE-2022-4654 | 1 Fatcatapps | 1 Pricing Tables | 2025-03-28 | 5.4 Medium |
| The Pricing Tables WordPress Plugin WordPress plugin before 3.2.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. | ||||
| CVE-2022-4649 | 1 Wp Extended Search Project | 1 Wp Extended Search | 2025-03-28 | 5.4 Medium |
| The WP Extended Search WordPress plugin before 2.1.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. | ||||
| CVE-2022-4496 | 1 Miniorange | 1 Saml Sp Single Sign On | 2025-03-28 | 6.1 Medium |
| The SAML SSO Standard WordPress plugin version 16.0.0 before 16.0.8, SAML SSO Premium WordPress plugin version 12.0.0 before 12.1.0 and SAML SSO Premium Multisite WordPress plugin version 20.0.0 before 20.0.7 does not validate that the redirect parameter to its SSO login endpoint points to an internal site URL, making it vulnerable to an Open Redirect issue when the user is already logged in. | ||||