Show filters
1,653 Total Results
Displaying 171-180 of 1,653
Sort by:
Attacker Value
Unknown

CVE-2024-43465

Disclosure Date: September 10, 2024 (last updated February 26, 2025)
Microsoft Excel Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2024-8604

Disclosure Date: September 09, 2024 (last updated February 26, 2025)
A vulnerability classified as problematic has been found in SourceCodester Online Food Ordering System 2.0. This affects an unknown part of the file index.php of the component Create an Account Page. The manipulation of the argument First Name/Last Name leads to cross site scripting. It is possible to initiate the attack remotely.
Attacker Value
Unknown

CVE-2024-8583

Disclosure Date: September 08, 2024 (last updated February 26, 2025)
A vulnerability was found in SourceCodester Online Bank Management System and Online Bank Management System - 1.0. It has been classified as problematic. This affects an unknown part of the file /mfeedback.php of the component Feedback Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-8566

Disclosure Date: September 08, 2024 (last updated February 26, 2025)
A vulnerability classified as problematic was found in code-projects Online Shop Store 1.0. This vulnerability affects unknown code of the file /settings.php. The manipulation of the argument error leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-8559

Disclosure Date: September 07, 2024 (last updated February 26, 2025)
A vulnerability, which was classified as critical, has been found in SourceCodester Online Food Menu 1.0. This issue affects some unknown processing of the file /endpoint/delete-menu.php. The manipulation of the argument menu leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-8417

Disclosure Date: September 04, 2024 (last updated February 26, 2025)
A vulnerability was found in 云课网络科技有限公司 Yunke Online School System up to 1.5.5. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/educloud/videobind.html. The manipulation leads to inclusion of sensitive information in source code. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.6 is able to address this issue. It is recommended to upgrade the affected component.
Attacker Value
Unknown

CVE-2024-1621

Disclosure Date: September 02, 2024 (last updated February 26, 2025)
The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the tenant. Those tenants utilising email login in combination with Microsoft Safe Links or similar are impacted. This vulnerability may allow the attacker to register themselves against a genuine user in the system and allow malicious users with similar access and capabilities via the app to the existing genuine user.
Attacker Value
Unknown

CVE-2024-7871

Disclosure Date: September 02, 2024 (last updated February 26, 2025)
SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the word parameter.
Attacker Value
Unknown

CVE-2024-43776

Disclosure Date: September 02, 2024 (last updated February 26, 2025)
SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the qlevel parameter.
Attacker Value
Unknown

CVE-2024-43775

Disclosure Date: September 02, 2024 (last updated February 26, 2025)
SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the search parameter.