CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Payroll Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
Online Student Admission v1.0 was discovered to contain a SQL injection vulnerability via the txtapplicationID parameter.
Apifox through 2.1.6 is vulnerable to Cross Site Scripting (XSS) which can lead to remote code execution.
ImageMagick 7.1.0-27 is vulnerable to Buffer Overflow.
novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.
mingyuefusu Library Management System all versions as of 03-27-2022 is vulnerable to SQL Injection.
The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields. This could allow unauthenticated attackers to create arbitrary events and put Cross-Site Scripting payloads in it.
Limbas 4.3.36.1319 is vulnerable to Cross Site Scripting (XSS).
Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.
nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature.
