Show filters
501 Total Results
Displaying 141-150 of 501
Sort by:
Attacker Value
Unknown

CVE-2022-33880

Disclosure Date: September 29, 2022 (last updated February 24, 2025)
hms-staff.php in Projectworlds Hospital Management System Mini-Project through 2018-06-17 allows SQL injection via the type parameter.
Attacker Value
Unknown

CVE-2022-3333

Disclosure Date: September 28, 2022 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, was found in Zephyr Project Manager up to 3.2.4. Affected is an unknown function of the file /v1/tasks/create/ of the component REST Call Handler. The manipulation of the argument onanimationstart leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 3.2.5 is able to address this issue. It is recommended to upgrade the affected component. VDB-209370 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-2840

Disclosure Date: September 19, 2022 (last updated February 24, 2025)
The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections
Attacker Value
Unknown

CVE-2022-3130

Disclosure Date: September 07, 2022 (last updated February 24, 2025)
A vulnerability classified as critical has been found in codeprojects Online Driving School. This affects an unknown part of the file /login.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-207873 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-3129

Disclosure Date: September 07, 2022 (last updated February 24, 2025)
A vulnerability was found in codeprojects Online Driving School. It has been rated as critical. Affected by this issue is some unknown functionality of the file /registration.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-207872.
Attacker Value
Unknown

CVE-2022-3118

Disclosure Date: September 04, 2022 (last updated February 24, 2025)
A vulnerability was found in Sourcecodehero ERP System Project. It has been rated as critical. This issue affects some unknown processing of the file /pages/processlogin.php. The manipulation of the argument user leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-207845 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-36030

Disclosure Date: August 20, 2022 (last updated February 24, 2025)
Project-nexus is a general-purpose blog website framework. Affected versions are subject to SQL injection due to a lack of sensitization of user input. This issue has not yet been patched. Users are advised to restrict user input and to upgrade when a new release becomes available.
Attacker Value
Unknown

CVE-2022-34857

Disclosure Date: August 10, 2022 (last updated February 24, 2025)
Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPress
Attacker Value
Unknown

CVE-2022-1585

Disclosure Date: August 01, 2022 (last updated February 24, 2025)
The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensitive files like wp-config.php.
Attacker Value
Unknown

CVE-2022-1551

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.