Show filters
79 Total Results
Displaying 21-30 of 79
Sort by:
Attacker Value
Unknown

CVE-2022-45025

Disclosure Date: December 07, 2022 (last updated October 08, 2023)
Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerability via the PDF file import function.
Attacker Value
Unknown

CVE-2022-3426

Disclosure Date: December 05, 2022 (last updated October 08, 2023)
The Advanced WP Columns WordPress plugin through 2.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Attacker Value
Unknown

CVE-2022-42109

Disclosure Date: November 29, 2022 (last updated October 08, 2023)
Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php.
Attacker Value
Unknown

CVE-2022-34580

Disclosure Date: July 28, 2022 (last updated February 24, 2025)
Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the address parameter at ip/school/index.php.
Attacker Value
Unknown

CVE-2022-34594

Disclosure Date: July 27, 2022 (last updated February 24, 2025)
Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component ip/school/moudel/update_subject.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit Subject text field.
Attacker Value
Unknown

CVE-2022-34588

Disclosure Date: July 20, 2022 (last updated February 24, 2025)
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/view/timetable_insert_form.php.
Attacker Value
Unknown

CVE-2022-34586

Disclosure Date: July 20, 2022 (last updated February 24, 2025)
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/view/student_grade_wise.php.
Attacker Value
Unknown

CVE-2022-32372

Disclosure Date: June 15, 2022 (last updated February 23, 2025)
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_subject.php?id=.
Attacker Value
Unknown

CVE-2022-32371

Disclosure Date: June 15, 2022 (last updated February 23, 2025)
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_teacher.php?id=.
Attacker Value
Unknown

CVE-2022-32370

Disclosure Date: June 15, 2022 (last updated February 23, 2025)
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_classroom.php?id=.