Show filters
1,653 Total Results
Displaying 11-20 of 1,653
Sort by:
Attacker Value
Very High
CVE-2021-42671
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
An incorrect access control vulnerability exists in Sourcecodester Engineers Online Portal in PHP in nia_munoz_monitoring_system/admin/uploads. An attacker can leverage this vulnerability in order to bypass access controls and access all the files uploaded to the web server without the need of authentication or authorization.
2
Attacker Value
Very High
CVE-2021-42665
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of index.php, which can allow an attacker to bypass authentication.
2
Attacker Value
Very High
CVE-2021-42667
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. An attacker can leverage this vulnerability in order to manipulate the sql query performed. As a result he can extract sensitive data from the web server and in some cases he can use this vulnerability in order to get a remote code execution on the remote web server.
2
Attacker Value
Very High
CVE-2021-41646
Disclosure Date: October 29, 2021 (last updated February 23, 2025)
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters..
2
Attacker Value
Very High
CVE-2021-41648
Disclosure Date: October 01, 2021 (last updated February 23, 2025)
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.
2
Attacker Value
Very High
CVE-2021-35458
Disclosure Date: July 30, 2021 (last updated February 23, 2025)
Online Pet Shop We App 1.0 is vulnerable to Union SQL Injection in products.php (aka p=products) via the c or s parameter.
2
Attacker Value
High
CVE-2023-33137
Disclosure Date: June 14, 2023 (last updated January 11, 2025)
Microsoft Excel Remote Code Execution Vulnerability
1
Attacker Value
High
CVE-2022-21840
Disclosure Date: January 11, 2022 (last updated December 21, 2023)
Microsoft Office Remote Code Execution Vulnerability
1
Attacker Value
Very High
CVE-2021-41647
Disclosure Date: October 01, 2021 (last updated February 23, 2025)
An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and retrieve sensitive database information, as well as add an administrative user.
1
Attacker Value
Very High
CVE-2021-36621
Disclosure Date: July 30, 2021 (last updated February 23, 2025)
Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection. The username parameter is vulnerable to time-based SQL injection. Upon successful dumping the admin password hash, an attacker can decrypt and obtain the plain-text password. Hence, the attacker could authenticate as Administrator.
1