Show filters
1,937 Total Results
Displaying 11-20 of 1,937
Sort by:
Attacker Value
Very High
CVE-2021-38757
Disclosure Date: August 16, 2021 (last updated February 23, 2025)
Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php.
1
Attacker Value
Very High
CVE-2021-36624
Disclosure Date: July 30, 2021 (last updated February 23, 2025)
Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
1
Attacker Value
Very Low
CVE-2020-28054
Disclosure Date: November 19, 2020 (last updated November 28, 2024)
JamoDat TSMManager Collector version up to 6.5.0.21 is vulnerable to an Authorization Bypass because the Collector component is not properly validating an authenticated session with the Viewer. If the Viewer has been modified (binary patched) and the Bypass Login functionality is being used, an attacker can request every Collector's functionality as if they were a properly logged-in user: administrating connected instances, reviewing logs, editing configurations, accessing the instances' consoles, accessing hardware configurations, etc.Exploiting this vulnerability won't grant an attacker access nor control on remote ISP servers as no credentials is sent with the request.
1
Attacker Value
Very Low
CVE-2019-15043
Disclosure Date: September 03, 2019 (last updated November 08, 2023)
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
1
Attacker Value
Unknown
CVE-2025-23843
Disclosure Date: March 03, 2025 (last updated March 04, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphrmanager WP-HR Manager: The Human Resources Plugin for WordPress allows Reflected XSS. This issue affects WP-HR Manager: The Human Resources Plugin for WordPress: from n/a through 3.1.0.
0
Attacker Value
Unknown
CVE-2025-1723
Disclosure Date: March 03, 2025 (last updated March 03, 2025)
Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug.
0
Attacker Value
Unknown
CVE-2024-12820
Disclosure Date: February 28, 2025 (last updated February 28, 2025)
The MK Google Directions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MKGD' shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2025-26876
Disclosure Date: February 25, 2025 (last updated February 26, 2025)
Path Traversal vulnerability in CodeManas Search with Typesense allows Path Traversal. This issue affects Search with Typesense: from n/a through 2.0.8.
0
Attacker Value
Unknown
CVE-2024-11778
Disclosure Date: February 19, 2025 (last updated February 27, 2025)
The CanadaHelps Embedded Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embedcdn' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-13508
Disclosure Date: February 19, 2025 (last updated February 27, 2025)
The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the locale parameter in all versions up to, and including, 1.6.72 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0