Search

Search Results (374295 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-34225 2 Computer Laboratory Management System, Oretnom23 2 Compuer Labatory Management System, Computer Laboratory Management System 2025-04-16 6.1 Medium
Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the name, shortname parameters.
CVE-2024-34224 2 Oretnom23, Sourcecodester 2 Computer Laboratory Management System, Computer Laboratory Management System 2025-04-16 7.3 High
Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the firstname, middlename, lastname parameters.
CVE-2024-34246 1 Wasm3 Project 1 Wasm3 2025-04-16 7.5 High
wasm3 v0.5.0 was discovered to contain an out-of-bound memory read which leads to segmentation fault via the function "main" in wasm3/platforms/app/main.c.
CVE-2024-34252 1 Wasm3 Project 1 Wasm3 2025-04-16 7.5 High
wasm3 v0.5.0 was discovered to contain a global buffer overflow which leads to segmentation fault via the function "PreserveRegisterIfOccupied" in wasm3/source/m3_compile.c.
CVE-2024-34249 1 Wasm3 Project 1 Wasm3 2025-04-16 9.8 Critical
wasm3 v0.5.0 was discovered to contain a heap buffer overflow which leads to segmentation fault via the function "DeallocateSlot" in wasm3/source/m3_compile.c.
CVE-2024-33350 2 Taocms, Taogogo 2 Taocms, Taocms 2025-04-16 9.8 Critical
Directory Traversal vulnerability in TaoCMS v.3.0.2 allows a remote attacker to execute arbitrary code and obtain sensitive information via the include/model/file.php component.
CVE-2024-33443 1 Onethink 1 Onethink 2025-04-16 7.1 High
An issue in onethink v.1.1 allows a remote attacker to execute arbitrary code via a crafted script to the AddonsController.class.php component.
CVE-2024-29865 1 Logpoint 1 Siem 2025-04-16 5.4 Medium
Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form.
CVE-2024-33438 1 Cubecart 1 Cubecart 2025-04-16 8 High
File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file.
CVE-2024-33444 1 Onethink 1 Onethink 2025-04-16 9.8 Critical
SQL injection vulnerability in onethink v.1.1 allows a remote attacker to escalate privileges via a crafted script to the ModelModel.class.php component.
CVE-2024-31615 1 Thinkcmf 1 Thinkcmf 2025-04-16 9.8 Critical
ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php.
CVE-2023-49983 1 Oretnom23 1 School Fees Management System 2025-04-16 6.8 Medium
A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.
CVE-2023-49982 2 Oretnom23, Sourcecodester 2 School Fees Management System, School Fees Management System 2025-04-16 8.8 High
Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and deleting user accounts.
CVE-2023-49986 2 Oretnom23, Sourcecodester 2 School Fees Management System, School Fees Management System 2025-04-16 4.7 Medium
A cross-site scripting (XSS) vulnerability in the component /admin/parent of School Fees Management System 1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.
CVE-2024-27694 1 Flycms Project 1 Flycms 2025-04-16 7.4 High
FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the /system/share/ztree_category_edit.
CVE-2024-25551 1 Oretnom23 1 Simple Student Attendance System 2025-04-16 6.1 Medium
Cross Site Scripting (XSS) vulnerability in sourcecodester Simple Student Attendance System v1.0 allows attackers to execute arbitrary code via crafted GET request to web application URL.
CVE-2024-25434 1 Pkp.sfu 1 Open Journal Systems 2025-04-16 5.4 Medium
A cross-site scripting (XSS) vulnerability in Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Publicname parameter.
CVE-2022-34270 1 Rws 1 Worldserver 2025-04-16 9.8 Critical
An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager.
CVE-2022-23536 1 Linuxfoundation 1 Cortex 2025-04-16 6.5 Medium
Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex versions 1.13.0, 1.13.1 and 1.14.0, where a malicious actor could remotely read local files as a result of parsing maliciously crafted Alertmanager configurations when submitted to the Alertmanager Set Configuration API. Only users of the Alertmanager service where `-experimental.alertmanager.enable-api` or `enable_api: true` is configured are affected. Affected Cortex users are advised to upgrade to patched versions 1.13.2 or 1.14.1. However as a workaround, Cortex administrators may reject Alertmanager configurations containing the `api_key_file` setting in the `opsgenie_configs` section before sending to the Set Alertmanager Configuration API.
CVE-2022-34269 1 Rws 1 Worldserver 2025-04-16 8.8 High
An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF attack to deploy JSP code to the Apache Axis service running on the localhost interface, leading to command execution.