CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
A vulnerability classified as problematic was found in SourceCodester Online Medicine Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /omos/admin/?page=user/list. The manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-212347.
Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.
RuoYi v3.8.3 has a Weak password vulnerability in the management system.
RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.
An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.login.php.
An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob" parameter in "/classes/Users.php?f=save_client"
There is an unauthorized access vulnerability in Online Diagnostic Lab Management System 1.0.
An issue was discovered in Online Diagnostic Lab Management System 1.0. There is a stored XSS vulnerability via firstname, address, middlename, lastname , gender, email, contact parameters.
2023-02-24
N/A
7.8 HIGH
A flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems.
Wl-wn575a3_firmware, Wl-wn575a3, Wl-wn530hg4_firmware, Wl-wn530hg4, Wl-wn579g3_firmware, Wl-wn579g3, Wn530hg4_firmware, Wn530hg4, Wn531g3_firmware, Wn531g3
2022-09-07
N/A
9.8 CRITICAL
WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi. This vulnerability allows attackers to execute arbitrary commands via the username parameter.
