Show filters
1,460 Total Results
Displaying 111-120 of 1,460
Sort by:
Attacker Value
Unknown

CVE-2024-7101

Disclosure Date: July 25, 2024 (last updated February 26, 2025)
A vulnerability, which was classified as critical, has been found in ForIP Tecnologia Administração PABX 1.x. This issue affects some unknown processing of the file /login of the component Authentication Form. The manipulation of the argument usuario leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272423. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown

CVE-2024-38728

Disclosure Date: July 22, 2024 (last updated February 26, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Seraphinite Solutions Seraphinite Post .DOCX Source.This issue affects Seraphinite Post .DOCX Source: from n/a through 2.16.9.
Attacker Value
Unknown

CVE-2024-6969

Disclosure Date: July 22, 2024 (last updated February 26, 2025)
A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /ajax/get_patient_history.php. The manipulation of the argument patient_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272123.
Attacker Value
Unknown

CVE-2024-6968

Disclosure Date: July 22, 2024 (last updated February 26, 2025)
A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /print_patients_visits.php. The manipulation of the argument from/to leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-272122 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2024-5625

Disclosure Date: July 18, 2024 (last updated February 26, 2025)
Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console allows Data Serialization External Entities Blowup.This issue affects Apinizer Management Console: before 2024.05.1.
0
Attacker Value
Unknown

CVE-2024-5620

Disclosure Date: July 18, 2024 (last updated February 26, 2025)
Authentication Bypass Using an Alternate Path or Channel vulnerability in PruvaSoft Informatics Apinizer Management Console allows Authentication Bypass.This issue affects Apinizer Management Console: before 2024.05.1.
0
Attacker Value
Unknown

CVE-2024-5619

Disclosure Date: July 18, 2024 (last updated February 26, 2025)
Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Apinizer Management Console: before 2024.05.1.
0
Attacker Value
Unknown

CVE-2024-5618

Disclosure Date: July 18, 2024 (last updated February 26, 2025)
Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Apinizer Management Console: before 2024.05.1.
0
Attacker Value
Unknown

CVE-2020-25836

Disclosure Date: July 16, 2024 (last updated February 26, 2025)
Exposure of Sensitive Information to an Unauthorized Access vulnerability in OpenText NetIQ Directory and Resource Administrator. This issue affects NetIQ Directory and Resource Administrator versions prior to 10.0.2 and prior to 9.2.1 Patch 10.
0
Attacker Value
Unknown

CVE-2024-40393

Disclosure Date: July 16, 2024 (last updated February 26, 2025)
Online Clinic Management System In PHP With Free Source code v1.0 was discovered to contain a SQL injection vulnerability via the user parameter at login.php.