Show filters
753 Total Results
Displaying 131-140 of 753
Sort by:
Attacker Value
Unknown
CVE-2024-24140
Disclosure Date: January 29, 2024 (last updated February 26, 2025)
Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'
0
Attacker Value
Unknown
CVE-2024-24139
Disclosure Date: January 29, 2024 (last updated February 26, 2025)
Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.
0
Attacker Value
Unknown
CVE-2024-24136
Disclosure Date: January 29, 2024 (last updated February 26, 2025)
The 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cross-Site Scripting (XSS) attacks.
0
Attacker Value
Unknown
CVE-2024-24135
Disclosure Date: January 29, 2024 (last updated February 26, 2025)
Product Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSS attacks.
0
Attacker Value
Unknown
CVE-2024-24134
Disclosure Date: January 29, 2024 (last updated February 26, 2025)
Sourcecodester Online Food Menu 1.0 is vulnerable to Cross Site Scripting (XSS) via the 'Menu Name' and 'Description' fields in the Update Menu section.
0
Attacker Value
Unknown
CVE-2023-2655
Disclosure Date: January 16, 2024 (last updated February 26, 2025)
The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
0
Attacker Value
Unknown
CVE-2023-49238
Disclosure Date: January 09, 2024 (last updated February 25, 2025)
In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password. Although this password must be changed upon the first login, it is possible that an attacker logs in before the legitimate administrator logs in.
0
Attacker Value
Unknown
CVE-2023-51449
Disclosure Date: December 22, 2023 (last updated February 25, 2025)
Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine learning model, API, or any arbitary Python function. Versions of `gradio` prior to 4.11.0 contained a vulnerability in the `/file` route which made them susceptible to file traversal attacks in which an attacker could access arbitrary files on a machine running a Gradio app with a public URL (e.g. if the demo was created with `share=True`, or on Hugging Face Spaces) if they knew the path of files to look for. This issue has been patched in version 4.11.0.
0
Attacker Value
Unknown
CVE-2023-7059
Disclosure Date: December 22, 2023 (last updated February 25, 2025)
A vulnerability was found in SourceCodester School Visitor Log e-Book 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file log-book.php. The manipulation of the argument Full Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248750 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-6572
Disclosure Date: December 14, 2023 (last updated February 25, 2025)
Command Injection in GitHub repository gradio-app/gradio prior to main.
0