Show filters
3,812 Total Results
Displaying 281-290 of 3,812
Sort by:
Attacker Value
Unknown
CVE-2023-6890
Disclosure Date: December 16, 2023 (last updated February 25, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.17.
0
Attacker Value
Unknown
CVE-2023-6889
Disclosure Date: December 16, 2023 (last updated February 25, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.17.
0
Attacker Value
Unknown
CVE-2023-6766
Disclosure Date: December 13, 2023 (last updated February 25, 2025)
A vulnerability classified as problematic has been found in PHPGurukul Teacher Subject Allocation Management System 1.0. Affected is an unknown function of the file /admin/course.php of the component Delete Course Handler. The manipulation of the argument delid leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247896.
0
Attacker Value
Unknown
CVE-2023-6654
Disclosure Date: December 10, 2023 (last updated February 25, 2025)
A vulnerability classified as critical was found in PHPEMS 6.x/7.x/8.x/9.0. Affected by this vulnerability is an unknown functionality in the library lib/session.cls.php of the component Session Data Handler. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247357 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-6653
Disclosure Date: December 10, 2023 (last updated February 25, 2025)
A vulnerability was found in PHPGurukul Teacher Subject Allocation Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/subject.php of the component Create a new Subject. The manipulation of the argument cid leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-247346 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-6649
Disclosure Date: December 10, 2023 (last updated February 25, 2025)
A vulnerability has been found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file index.php. The manipulation of the argument searchdata with the input <script>alert(5)</script> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-247342 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-6648
Disclosure Date: December 10, 2023 (last updated February 23, 2025)
A vulnerability, which was classified as critical, was found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file password-recovery.php. The manipulation of the argument username/contactno leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2023-48841
Disclosure Date: December 07, 2023 (last updated February 25, 2025)
Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
0
Attacker Value
Unknown
CVE-2023-48840
Disclosure Date: December 07, 2023 (last updated February 25, 2025)
A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.
0
Attacker Value
Unknown
CVE-2023-48839
Disclosure Date: December 07, 2023 (last updated February 25, 2025)
Appointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
0