• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2022-25403
2022-03-03
N/A
9.8 CRITICAL
HMS v1.0 was discovered to contain a SQL injection vulnerability via the component admin.php.
CVE-2022-25402
2022-03-03
N/A
9.1 CRITICAL
An incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify all PHP files.
CVE-2022-25401
2022-03-03
N/A
7.5 HIGH
The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting attackers read access to arbitrary files.
CVE-2022-2540
2022-09-13
N/A
8.8 HIGH
The Link Optimizer Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 1.4.5. This is due to missing nonce validation on the admin_page function found in the ~/admin.php file. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-2022-25399
2022-03-14
N/A
9.8 CRITICAL
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
CVE-2022-25398
2022-03-14
N/A
9.8 CRITICAL
Auto Spare Parts Management v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.
CVE-2022-25396
2022-03-14
N/A
9.8 CRITICAL
Cosmetics and Beauty Product Online Store v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.
CVE-2022-25395
2022-03-14
N/A
9.6 CRITICAL
Cosmetics and Beauty Product Online Store v1.0 was discovered to contain multiple reflected cross-site scripting (XSS) attacks via the search parameter under the /cbpos/ app.
CVE-2022-25394
2022-03-14
N/A
9.8 CRITICAL
Medical Store Management System v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter under customer-add.php.
CVE-2022-25393
2022-03-14
N/A
7.5 HIGH
Simple Bakery Shop Management v1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
« Previous 1 … 10,421 10,422 10,423 10,424 10,425 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE