Show filters
294 Total Results
Displaying 61-70 of 294
Sort by:
Attacker Value
Unknown

CVE-2024-2067

Disclosure Date: March 01, 2024 (last updated December 18, 2024)
A vulnerability was found in SourceCodester Computer Inventory System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-computer.php. The manipulation of the argument computer leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-255382 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2024-2066

Disclosure Date: March 01, 2024 (last updated December 18, 2024)
A vulnerability was found in SourceCodester Computer Inventory System 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/add-computer.php. The manipulation of the argument model leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-255381 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2024-1926

Disclosure Date: February 27, 2024 (last updated December 19, 2024)
A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /app/ajax/search_sales_report.php. The manipulation of the argument customer leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-254861 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2024-1150

Disclosure Date: February 08, 2024 (last updated February 16, 2024)
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 7.3.1.
Attacker Value
Unknown

CVE-2024-1149

Disclosure Date: February 08, 2024 (last updated February 16, 2024)
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, Snow Software Inventory Agent on Linux allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 6.12.0; Inventory Agent: through 6.14.5; Inventory Agent: through 6.7.2.
Attacker Value
Unknown

CVE-2023-7169

Disclosure Date: February 08, 2024 (last updated February 15, 2024)
Authentication Bypass by Spoofing vulnerability in Snow Software Snow Inventory Agent on Windows allows Signature Spoof.This issue affects Snow Inventory Agent: through 6.14.5. Customers advised to upgrade to version 7.0
Attacker Value
Unknown

CVE-2023-51813

Disclosure Date: January 30, 2024 (last updated February 06, 2024)
Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary code via the staff_list parameter in the index.php component.
Attacker Value
Unknown

CVE-2024-24135

Disclosure Date: January 29, 2024 (last updated February 22, 2024)
Product Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSS attacks.
Attacker Value
Unknown

CVE-2023-52221

Disclosure Date: January 24, 2024 (last updated January 31, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in UkrSolution Barcode Scanner and Inventory manager.This issue affects Barcode Scanner and Inventory manager: from n/a through 1.5.1.
Attacker Value
Unknown

CVE-2024-0422

Disclosure Date: January 11, 2024 (last updated January 19, 2024)
A vulnerability was found in CodeAstro POS and Inventory Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /new_item of the component New Item Creation Page. The manipulation of the argument new_item leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250441 was assigned to this vulnerability.