Show filters
45 Total Results
Displaying 31-40 of 45
Sort by:
Attacker Value
Unknown

CVE-2024-25211

Disclosure Date: February 14, 2024 (last updated October 24, 2024)
Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpoint/delete_category.php.
Attacker Value
Unknown

CVE-2024-25210

Disclosure Date: February 14, 2024 (last updated October 24, 2024)
Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoint/delete_expense.php.
Attacker Value
Unknown

CVE-2024-25209

Disclosure Date: February 14, 2024 (last updated October 24, 2024)
Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at /endpoint/delete-resident.php.
Attacker Value
Unknown

CVE-2024-24142

Disclosure Date: February 13, 2024 (last updated October 05, 2024)
Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.
Attacker Value
Unknown

CVE-2024-1111

Disclosure Date: January 31, 2024 (last updated April 30, 2024)
A vulnerability, which was classified as problematic, has been found in SourceCodester QR Code Login System 1.0. Affected by this issue is some unknown functionality of the file add-user.php. The manipulation of the argument qr-code leads to cross site scripting. The attack may be launched remotely. VDB-252470 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2019-14476

Disclosure Date: December 16, 2020 (last updated February 22, 2025)
AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server. Every user can trick the server into performing SMB requests to other systems.
Attacker Value
Unknown

CVE-2019-14478

Disclosure Date: December 16, 2020 (last updated February 22, 2025)
AdRem NetCrunch 10.6.0.4587 has a stored Cross-Site Scripting (XSS) vulnerability in the NetCrunch web client. The user's input data is not properly encoded when being echoed back to the user. This data can be interpreted as executable code by the browser and allows an attacker to execute JavaScript code in the context of the user's browser if the victim opens or searches for a node whose "Display Name" contains an XSS payload.
Attacker Value
Unknown

CVE-2019-14479

Disclosure Date: December 16, 2020 (last updated February 22, 2025)
AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution. In the NetCrunch web client, a read-only administrator can execute arbitrary code on the server running the NetCrunch server software.
Attacker Value
Unknown

CVE-2019-14481

Disclosure Date: December 16, 2020 (last updated February 22, 2025)
AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client. Successful exploitation requires a logged-in user to open a malicious page and leads to account takeover.
Attacker Value
Unknown

CVE-2019-14482

Disclosure Date: December 16, 2020 (last updated February 22, 2025)
AdRem NetCrunch 10.6.0.4587 has a hardcoded SSL private key vulnerability in the NetCrunch web client. The same hardcoded SSL private key is used across different customers' installations when no other SSL certificate is installed, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.