CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Wl-wn575a3_firmware, Wl-wn575a3, Wl-wn530hg4_firmware, Wl-wn530hg4, Wl-wn579g3_firmware, Wl-wn579g3, Wn530hg4_firmware, Wn530hg4, Wn531g3_firmware, Wn531g3
2022-07-15
N/A
9.8 CRITICAL
Wavlink WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability via the function obtw. This vulnerability allows attackers to execute arbitrary commands via a crafted POST request.
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/admin.php.
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/view/timetable_insert_form.php.
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/view/student_grade_wise.php.
Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the address parameter at ip/school/index.php.
A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /employeeview.php of the component Image File Handler. The manipulation leads to unrestricted upload. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-210559.
Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.
Wl-wn575a3_firmware, Wl-wn575a3, Wl-wn530hg4_firmware, Wl-wn530hg4, Wl-wn579g3_firmware, Wl-wn579g3, Wn530hg4_firmware, Wn530hg4, Wn531g3_firmware, Wn531g3
2022-08-03
N/A
9.8 CRITICAL
A vulnerability in adm.cgi of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.
Wl-wn575a3_firmware, Wl-wn575a3, Wl-wn530hg4_firmware, Wl-wn530hg4, Wl-wn579g3_firmware, Wl-wn579g3, Wn530hg4_firmware, Wn530hg4, Wn531g3_firmware, Wn531g3
2022-08-03
N/A
7.5 HIGH
A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via accessing fctest.shtml.
