Show filters
16,414 Total Results
Displaying 51-60 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
High
CVE-2023-33131
Disclosure Date: June 14, 2023 (last updated January 11, 2025)
Microsoft Outlook Remote Code Execution Vulnerability
2
Attacker Value
Low
CVE-2023-28303
Disclosure Date: June 13, 2023 (last updated January 11, 2025)
Windows Snipping Tool Information Disclosure Vulnerability
2
Attacker Value
High
CVE-2023-28285
Disclosure Date: April 11, 2023 (last updated January 11, 2025)
Microsoft Office Remote Code Execution Vulnerability
2
Attacker Value
Very High
CVE-2021-42580
Disclosure Date: November 15, 2021 (last updated February 23, 2025)
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) file , we can craft these two vunlerablities to get unauthenticated remote command execution.
2
Attacker Value
Very High
CVE-2021-42667
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. An attacker can leverage this vulnerability in order to manipulate the sql query performed. As a result he can extract sensitive data from the web server and in some cases he can use this vulnerability in order to get a remote code execution on the remote web server.
2
Attacker Value
Very High
CVE-2021-41492
Disclosure Date: November 03, 2021 (last updated February 23, 2025)
Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Code in the pos page in cashiering. (2) id parameter in manage_products and the (3) t paramater in actions.php.
2
Attacker Value
Very High
CVE-2021-37806
Disclosure Date: October 27, 2021 (last updated February 23, 2025)
An SQL Injection vulnerability exists in https://phpgurukul.com Vehicle Parking Management System affected version 1.0. The system is vulnerable to time-based SQL injection on multiple endpoints. Based on the SLEEP(N) function payload that will sleep for a number of seconds used on the (1) editid , (2) viewid, and (3) catename parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind (Time Based). An attacker can use sqlmap to further the exploitation for extracting sensitive information from the database.
2
Attacker Value
Very High
CVE-2021-41511
Disclosure Date: October 04, 2021 (last updated February 23, 2025)
The username and password field of login in Lodging Reservation Management System V1 can give access to any user by using SQL injection to bypass authentication.
2
Attacker Value
Very High
CVE-2021-41648
Disclosure Date: October 01, 2021 (last updated February 23, 2025)
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.
2
Attacker Value
Unknown
CVE-2021-36260
Disclosure Date: September 22, 2021 (last updated February 23, 2025)
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
3