Show filters
614 Total Results
Displaying 101-110 of 614
Sort by:
Attacker Value
Unknown

CVE-2023-43375

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
Hoteldruid v3.0.5 was discovered to contain multiple SQL injection vulnerabilities at /hoteldruid/clienti.php via the annonascita, annoscaddoc, giornonascita, giornoscaddoc, lingua_cli, mesenascita, and mesescaddoc parameters.
Attacker Value
Unknown

CVE-2023-43374

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the id_utente_log parameter at /hoteldruid/personalizza.php.
Attacker Value
Unknown

CVE-2023-43373

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php.
Attacker Value
Unknown

CVE-2023-43371

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the numcaselle parameter at /hoteldruid/creaprezzi.php.
Attacker Value
Unknown

CVE-2023-4034

Disclosure Date: September 05, 2023 (last updated December 22, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digita Information Technology Smartrise Document Management System allows SQL Injection.This issue affects Smartrise Document Management System: before Hvl-2.0.
Attacker Value
Unknown

CVE-2023-4299

Disclosure Date: August 31, 2023 (last updated October 08, 2023)
Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment.
Attacker Value
Unknown

CVE-2020-27366

Disclosure Date: August 28, 2023 (last updated October 08, 2023)
Cross Site Scripting (XSS) vulnerability in wlscanresults.html in Humax HGB10R-02 BRGCAB version 1.0.03, allows local attackers to execute arbitrary code.
Attacker Value
Unknown

CVE-2023-3653

Disclosure Date: August 08, 2023 (last updated December 22, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital Ant E-Commerce Software allows Stored XSS.This issue affects E-Commerce Software: before 11.
Attacker Value
Unknown

CVE-2023-3652

Disclosure Date: August 08, 2023 (last updated December 22, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital Ant E-Commerce Software allows Reflected XSS.This issue affects E-Commerce Software: before 11.
Attacker Value
Unknown

CVE-2023-3651

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digital Ant E-Commerce Software allows SQL Injection.This issue affects E-Commerce Software: before 11.