Export limit exceeded: 227175 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (227189 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-57436 1 Ruoyi 1 Ruoyi 2025-05-14 7.2 High
RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allow attackers to impersonate Admin users via using a crafted cookie.
CVE-2024-54762 1 Ruoyi 1 Ruoyi 2025-05-14 6.3 Medium
Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter SQL injection keywords, resulting in the risk of SQL injection.
CVE-2024-42900 1 Ruoyi 1 Ruoyi 2025-05-14 6.1 Medium
Ruoyi v4.7.9 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the sql parameter of the createTable() function at /tool/gen/create.
CVE-2025-2170 1 Sonicwall 2 Sma1000, Sma1000 Firmware 2025-05-14 7.2 High
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, which in specific conditions could potentially enable a remote unauthenticated attacker to cause the appliance to make requests to an unintended location.
CVE-2022-3151 1 Wp Custom Cursors Project 1 Wp Custom Cursors 2025-05-14 4.3 Medium
The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when deleting cursors, which could allow attackers to made a logged in admin delete arbitrary cursors via a CSRF attack.
CVE-2022-3150 1 Wp Custom Cursors Project 1 Wp Custom Cursors 2025-05-14 7.2 High
The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privileged users such as admin
CVE-2025-22222 1 Vmware 2 Aria Operations, Cloud Foundation 2025-05-14 7.7 High
VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known.
CVE-2025-22221 1 Vmware 2 Aria Operations For Logs, Cloud Foundation 2025-05-14 5.2 Medium
VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configuration.
CVE-2025-22219 1 Vmware 2 Aria Operations For Logs, Cloud Foundation 2025-05-14 6.8 Medium
VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations as admin user.
CVE-2025-22218 1 Vmware 2 Aria Operations For Logs, Cloud Foundation 2025-05-14 8.5 High
VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs
CVE-2025-2984 1 Fabian 1 Payroll Management System 2025-05-14 6.3 Medium
A vulnerability was found in code-projects Payroll Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /delete.php. The manipulation of the argument emp_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-2985 1 Fabian 1 Payroll Management System 2025-05-14 6.3 Medium
A vulnerability was found in code-projects Payroll Management System 1.0. It has been classified as critical. This affects an unknown part of the file update_account.php. The manipulation of the argument deduction leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
CVE-2025-3038 1 Fabian 1 Payroll Management System 2025-05-14 6.3 Medium
A vulnerability was found in code-projects Payroll Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /view_account.php. The manipulation of the argument salary_rate leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-3039 1 Fabian 1 Payroll Management System 2025-05-14 6.3 Medium
A vulnerability was found in code-projects Payroll Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /add_employee.php. The manipulation of the argument lname/fname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
CVE-2025-3134 1 Fabian 1 Payroll Management System 2025-05-14 6.3 Medium
A vulnerability classified as critical has been found in code-projects Payroll Management System 1.0. This affects an unknown part of the file /add_overtime.php. The manipulation of the argument rate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2022-42070 1 Oretnom23 1 Online Birth Certificate Management System 2025-05-14 8.8 High
Online Birth Certificate Management System version 1.0 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2022-42069 1 Oretnom23 1 Online Birth Certificate Management System 2025-05-14 5.4 Medium
Online Birth Certificate Management System version 1.0 suffers from a persistent Cross Site Scripting (XSS) vulnerability.
CVE-2022-42067 1 Oretnom23 1 Online Birth Certificate Management System 2025-05-14 4.3 Medium
Online Birth Certificate Management System version 1.0 suffers from an Insecure Direct Object Reference (IDOR) vulnerability
CVE-2022-42066 1 Projectworlds 1 Online Examination System 2025-05-14 6.1 Medium
Online Examination System version 1.0 suffers from a cross site scripting vulnerability via index.php.
CVE-2022-42064 1 Online Diagnostic Lab Management System Project 1 Online Diagnostic Lab Management System 2025-05-14 9.8 Critical
Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploads a shell.