CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php.
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php.
Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php.
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php.
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeProduct.php.
The Video.js WordPress plugin through 4.5.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php.
i-librarian 4.10 is vulnerable to Arbitrary file upload in ajaxsupplement.php.
TOTOlink A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection Vulnerability in the httpd service. An attacker can obtain a stable root shell through a specially constructed payload.
The Video Sidebar Widgets WordPress plugin through 6.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
