Show filters
318 Total Results
Displaying 31-40 of 318
Sort by:
Attacker Value
Unknown

CVE-2024-8080

Disclosure Date: August 22, 2024 (last updated October 18, 2024)
A vulnerability classified as critical has been found in SourceCodester Online Health Care System 1.0. Affected is an unknown function of the file search.php. The manipulation of the argument f_name with the input 1%' or 1=1 ) UNION SELECT 1,2,3,4,5,database(),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23# as part of string leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-23562

Disclosure Date: July 08, 2024 (last updated October 23, 2024)
A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthenticated attacker could exploit this vulnerability to obtain information to launch further attacks against the affected system.
Attacker Value
Unknown

CVE-2024-23588

Disclosure Date: July 05, 2024 (last updated July 09, 2024)
HCL Nomad server on Domino fails to properly handle users configured with limited Domino access resulting in a possible denial of service vulnerability.
Attacker Value
Unknown

CVE-2024-38348

Disclosure Date: June 18, 2024 (last updated October 10, 2024)
CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Staff Info module via the searvalu parameter.
Attacker Value
Unknown

CVE-2024-38347

Disclosure Date: June 18, 2024 (last updated July 11, 2024)
CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Room Information module via the id parameter.
Attacker Value
Unknown

CVE-2024-37803

Disclosure Date: June 18, 2024 (last updated July 16, 2024)
Multiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname and lname parameters under the Staff Info page.
Attacker Value
Unknown

CVE-2024-37802

Disclosure Date: June 18, 2024 (last updated July 20, 2024)
CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Patient Info module via the searvalu parameter.
Attacker Value
Unknown

CVE-2024-37800

Disclosure Date: June 18, 2024 (last updated July 06, 2024)
CodeProjects Restaurant Reservation System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Date parameter at index.php.
Attacker Value
Unknown

CVE-2023-37539

Disclosure Date: June 06, 2024 (last updated July 17, 2024)
The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in the catalog application/database created from this template can embed a cross site scripting attack. The attack would be activated by an end user clicking it.
Attacker Value
Unknown

CVE-2024-34714

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
The Hoppscotch Browser Extension is a browser extension for Hoppscotch, a community-driven end-to-end open-source API development ecosystem. Due to an oversight during a change made to the extension in the commit d4e8e4830326f46ba17acd1307977ecd32a85b58, a critical check for the origin list was missed and allowed for messages to be sent to the extension which the extension gladly processed and responded back with the results of, while this wasn't supposed to happen and be blocked by the origin not being present in the origin list. This vulnerability exposes Hoppscotch Extension users to sites which call into Hoppscotch Extension APIs internally. This fundamentally allows any site running on the browser with the extension installed to bypass CORS restrictions if the user is running extensions with the given version. This security hole was patched in the commit 7e364b928ab722dc682d0fcad713a96cc38477d6 which was released along with the extension version `0.35`. As a workaround, Chrome u…
0