Export limit exceeded: 296804 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (296816 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-28584 | 1 Freeimage Project | 1 Freeimage | 2025-03-28 | 3.3 Low |
| Null Pointer Dereference vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the J2KImageToFIBITMAP() function when reading images in J2K format. | ||||
| CVE-2024-28562 | 1 Freeimage Project | 1 Freeimage | 2025-03-28 | 6.8 Medium |
| Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::copyIntoFrameBuffer() component when reading images in EXR format. | ||||
| CVE-2023-49977 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | 5.4 Medium |
| A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the address parameter at /customer_support/index.php?page=new_customer. | ||||
| CVE-2023-49976 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | 5.4 Medium |
| A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the subject parameter at /customer_support/index.php?page=new_ticket. | ||||
| CVE-2023-49974 | 2 Oretnom23, Sourcecodester | 2 Customer Support System, Customer Support System | 2025-03-28 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the contact parameter at /customer_support/index.php?page=customer_list. | ||||
| CVE-2023-51281 | 2 Oretnom23, Sourcecodester | 2 Customer Support System, Customer Support System | 2025-03-28 | 5.4 Medium |
| Cross Site Scripting vulnerability in Customer Support System v.1.0 allows a remote attacker to escalate privileges via a crafted script firstname, "lastname", "middlename", "contact" and address parameters. | ||||
| CVE-2024-27743 | 2 Mayurik, Petroleum Management Software Application Project | 2 Petrol Pump Management, Petroleum Management Software Application | 2025-03-28 | 6.1 Medium |
| Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the Address parameter in the add_invoices.php component. | ||||
| CVE-2024-27744 | 1 Mayurik | 1 Petrol Pump Management | 2025-03-28 | 6.1 Medium |
| Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the image parameter in the profile.php component. | ||||
| CVE-2024-27746 | 1 Mayurik | 1 Petrol Pump Management | 2025-03-28 | 9.8 Critical |
| SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.php component. | ||||
| CVE-2024-27747 | 2 Mayurik, Sourcecodester | 2 Petrol Pump Management, Petrol Pump Management | 2025-03-28 | 9.8 Critical |
| File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Image parameter in the profile.php component. | ||||
| CVE-2023-49545 | 2 Oretnom23, Sourcecodester | 2 Customer Support System, Customer Support System | 2025-03-28 | 7.5 High |
| A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization. | ||||
| CVE-2023-49546 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | 8.8 High |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php. | ||||
| CVE-2023-49547 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | 9.8 Critical |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login. | ||||
| CVE-2023-49548 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | 8.8 High |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user. | ||||
| CVE-2023-49968 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | 7.3 High |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/manage_department.php. | ||||
| CVE-2023-49969 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | 4.3 Medium |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer. | ||||
| CVE-2023-49970 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | 9.8 Critical |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/ajax.php?action=save_ticket. | ||||
| CVE-2023-49544 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | 4.9 Medium |
| A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php. | ||||
| CVE-2024-27559 | 1 Codelyfe | 1 Stupid Simple Cms | 2025-03-28 | 6.3 Medium |
| Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /save_settings.php | ||||
| CVE-2024-27689 | 2 Codelyfe, Stupid Simple | 2 Stupid Simple Cms, Cms | 2025-03-28 | 8.8 High |
| Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via /update-article.php. | ||||