Export limit exceeded: 357917 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (357917 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-6902 | 1 Jkev | 1 Record Management System | 2024-11-21 | 6.3 Medium |
| A vulnerability classified as critical was found in SourceCodester Record Management System 1.0. Affected by this vulnerability is an unknown functionality of the file sort_user.php. The manipulation of the argument sort leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-271927. | ||||
| CVE-2024-6901 | 1 Jkev | 1 Record Management System | 2024-11-21 | 6.3 Medium |
| A vulnerability classified as critical has been found in SourceCodester Record Management System 1.0. Affected is an unknown function of the file entry.php. The manipulation of the argument school leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-271926 is the identifier assigned to this vulnerability. | ||||
| CVE-2024-6900 | 1 Jkev | 1 Record Management System | 2024-11-21 | 6.3 Medium |
| A vulnerability was found in SourceCodester Record Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file edit_emp.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-271925 was assigned to this vulnerability. | ||||
| CVE-2024-6899 | 1 Jkev | 1 Record Management System | 2024-11-21 | 6.3 Medium |
| A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file view_info.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-271924. | ||||
| CVE-2024-6898 | 1 Jkev | 1 Record Management System | 2024-11-21 | 7.3 High |
| A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as critical. This affects an unknown part of the file index.php. The manipulation of the argument UserName leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-271923. | ||||
| CVE-2024-6893 | 1 Journyx | 1 Journyx | 2024-11-21 | 7.5 High |
| The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform server-side request forgery, and overwhelm the web server resources. | ||||
| CVE-2024-6892 | 1 Journyx | 1 Journyx | 2024-11-21 | 6.1 Medium |
| Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application. | ||||
| CVE-2024-6891 | 1 Journyx | 1 Journyx | 2024-11-21 | 8.8 High |
| Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow. | ||||
| CVE-2024-6890 | 1 Journyx | 1 Journyx | 2024-11-21 | 8.8 High |
| Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password. | ||||
| CVE-2024-6830 | 1 Oretnom23 | 1 Simple Inventory Management System | 2024-11-21 | 6.3 Medium |
| A vulnerability, which was classified as critical, was found in SourceCodester Simple Inventory Management System 1.0. Affected is an unknown function of the file action.php of the component Order Handler. The manipulation of the argument order_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-271812. | ||||
| CVE-2024-6808 | 1 Code-projects | 1 Simple Task List | 2024-11-21 | 7.3 High |
| A vulnerability was found in itsourcecode Simple Task List 1.0. It has been classified as critical. This affects the function insertUserRecord of the file signUp.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-271707. | ||||
| CVE-2024-6806 | 1 Ni | 1 Veristand | 2024-11-21 | 9.8 Critical |
| The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These missing checks may result in remote code execution. This affects NI VeriStand 2024 Q2 and prior versions. | ||||
| CVE-2024-6805 | 1 Ni | 1 Veristand | 2024-11-21 | 7.5 High |
| The NI VeriStand Gateway is missing authorization checks when an actor attempts to access File Transfer resources. These missing checks may result in information disclosure or remote code execution. This affects NI VeriStand 2024 Q2 and prior versions. | ||||
| CVE-2024-6803 | 1 Document Management System Project | 1 Document Management System | 2024-11-21 | 5.5 Medium |
| A vulnerability has been found in itsourcecode Document Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file insert.php. The manipulation of the argument anothercont leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-271705 was assigned to this vulnerability. | ||||
| CVE-2024-6802 | 1 Computer Laboratory Management System Project | 1 Computer Laboratory Management System | 2024-11-21 | 6.3 Medium |
| A vulnerability, which was classified as critical, was found in SourceCodester Computer Laboratory Management System 1.0. Affected is an unknown function of the file /lms/classes/Master.php?f=save_record. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2024-6801 | 1 Online Student Management System Project | 1 Online Student Management System | 2024-11-21 | 6.3 Medium |
| A vulnerability, which was classified as critical, has been found in SourceCodester Online Student Management System 1.0. This issue affects some unknown processing of the file /add-students.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-271703. | ||||
| CVE-2024-6794 | 1 Ni | 1 Veristand | 2024-11-21 | 9.8 Critical |
| A deserialization of untrusted data vulnerability exists in NI VeriStand Waveform Streaming Server that may result in remote code execution. Successful exploitation requires an attacker to send a specially crafted message. These vulnerabilities affect NI VeriStand 2024 Q2 and prior versions. | ||||
| CVE-2024-6793 | 1 Ni | 1 Veristand | 2024-11-21 | 9.8 Critical |
| A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote code execution. Successful exploitation requires an attacker to send a specially crafted message. These vulnerabilities affect NI VeriStand 2024 Q2 and prior versions. | ||||
| CVE-2024-6791 | 1 Ni | 1 Veristand | 2024-11-21 | 7.8 High |
| A directory path traversal vulnerability exists when loading a vsmodel file in NI VeriStand that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .vsmodel file. This vulnerability affects VeriStand 2024 Q2 and prior versions. | ||||
| CVE-2024-6760 | 1 Freebsd | 1 Freebsd | 2024-11-21 | 7.5 High |
| A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivileged users to trace and inspect the behavior of setuid programs. The bug may be used by an unprivileged user to read the contents of files to which they would not otherwise have access, such as the local password database. | ||||