Show filters
11,864 Total Results
Displaying 21-30 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Very High
CVE-2021-40578
Disclosure Date: December 07, 2021 (last updated February 23, 2025)
Authenticated Blind & Error-based SQL injection vulnerability was discovered in Online Enrollment Management System in PHP and PayPal Free Source Code 1.0, that allows attackers to obtain sensitive information and execute arbitrary SQL commands via IDNO parameter.
3
Attacker Value
Very High
CVE-2021-38833
Disclosure Date: September 13, 2021 (last updated February 23, 2025)
SQL injection vulnerability in PHPGurukul Apartment Visitors Management System (AVMS) v. 1.0 allows attackers to execute arbitrary SQL statements and to gain RCE.
3
Attacker Value
High
CVE-2020-35846
Disclosure Date: December 30, 2020 (last updated February 22, 2025)
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
3
Attacker Value
Very High
CVE-2020-7356
Disclosure Date: April 06, 2020 (last updated October 07, 2023)
CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and execute SYSTEM commands.
3
Attacker Value
Very High
CVE-2025-0282
Disclosure Date: January 08, 2025 (last updated February 27, 2025)
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.
2
Attacker Value
Very High
CVE-2024-29824
Disclosure Date: May 31, 2024 (last updated February 26, 2025)
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
2
Attacker Value
High
CVE-2023-41724
Disclosure Date: March 31, 2024 (last updated February 26, 2025)
A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlying operating system of the appliance within the same physical or logical network.
2
Attacker Value
Low
CVE-2023-41474
Disclosure Date: January 25, 2024 (last updated February 26, 2025)
Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component.
2
Attacker Value
High
CVE-2023-5360
Disclosure Date: October 31, 2023 (last updated February 25, 2025)
The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.
2
Attacker Value
Moderate
CVE-2023-28128
Disclosure Date: May 09, 2023 (last updated February 24, 2025)
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution.
2