Show filters
294 Total Results
Displaying 141-150 of 294
Sort by:
Attacker Value
Unknown

CVE-2022-31339

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/login.php.
Attacker Value
Unknown

CVE-2022-28944

Disclosure Date: May 23, 2022 (last updated February 23, 2025)
Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan 2.0.8 and Network Inventory for Windows 5.8.22 and Network Software Scanner for Windows 2.0.8 and UnLock IT for Windows 6.1.1. The impact is: execute arbitrary code (remote). The component is: Updater. The attack vector is: To exploit this vulnerability, a user must trigger an update of an affected installation of EMCO Software. ¶¶ Multiple products from EMCO Software are affected by a remote code execution vulnerability during the update process.
Attacker Value
Unknown

CVE-2022-28993

Disclosure Date: May 20, 2022 (last updated February 23, 2025)
Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request.
Attacker Value
Unknown

CVE-2022-28991

Disclosure Date: May 20, 2022 (last updated February 23, 2025)
Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files.
Attacker Value
Unknown

CVE-2022-30407

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Pharmacy Sales And Inventory System v1.0 is vulnerable to SQL Injection via /pharmacy-sales-and-inventory-system/manage_user.php?id=.
Attacker Value
Unknown

CVE-2021-27758

Disclosure Date: April 28, 2022 (last updated February 23, 2025)
There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and system blocked victim's account.
Attacker Value
Unknown

CVE-2021-27759

Disclosure Date: April 28, 2022 (last updated February 23, 2025)
This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application.
Attacker Value
Unknown

CVE-2021-44321

Disclosure Date: March 04, 2022 (last updated February 23, 2025)
Mini-Inventory-and-Sales-Management-System is affected by Cross Site Request Forgery (CSRF), where an attacker can update/delete items in the inventory. The attacker must be logged into the application create a malicious file for updating the inventory details and items.
Attacker Value
Unknown

CVE-2022-23632

Disclosure Date: February 17, 2022 (last updated February 23, 2025)
Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer security (TLS) configuration when the host header is a fully qualified domain name (FQDN). For a request, the TLS configuration choice can be different than the router choice, which implies the use of a wrong TLS configuration. When sending a request using FQDN handled by a router configured with a dedicated TLS configuration, the TLS configuration falls back to the default configuration that might not correspond to the configured one. If the CNAME flattening is enabled, the selected TLS configuration is the SNI one and the routing uses the CNAME value, so this can skip the expected TLS configuration. Version 2.6.1 contains a patch for this issue. As a workaround, one may add the FDQN to the host rule. However, there is no workaround if the CNAME flattening is enabled.
Attacker Value
Unknown

CVE-2021-4106

Disclosure Date: February 16, 2022 (last updated February 23, 2025)
A vulnerability in Snow Inventory Java Scanner allows an attacker to run malicious code at a higher level of privileges. This issue affects: SNOW Snow Inventory Java Scanner 1.0