Show filters
132 Total Results
Displaying 61-70 of 132
Sort by:
Attacker Value
Unknown

CVE-2023-2773

Disclosure Date: May 17, 2023 (last updated February 25, 2025)
A vulnerability has been found in code-projects Bus Dispatch and Information System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file view_admin.php. The manipulation of the argument adminid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229279.
Attacker Value
Unknown

CVE-2023-2425

Disclosure Date: April 29, 2023 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Simple Student Information System 1.0. It has been classified as problematic. This affects an unknown part of the file /classes/Master.php?f=save_course of the component Add New Course. The manipulation of the argument name with the input <script>alert(document.cookie)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227751.
Attacker Value
Unknown

CVE-2022-39989

Disclosure Date: April 26, 2023 (last updated February 24, 2025)
An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor prompt the administrators to change the credentials.
Attacker Value
Unknown

CVE-2023-0320

Disclosure Date: March 20, 2023 (last updated February 24, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Izmir Katip Celebi University UBYS allows Stored XSS.This issue affects UBYS: before 23.03.16.
Attacker Value
Unknown

CVE-2022-48111

Disclosure Date: March 10, 2023 (last updated February 24, 2025)
A cross-site scripting (XSS) vulnerability in the check_login function of SIPE s.r.l WI400 between version 8 and 11 included allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the f parameter.
Attacker Value
Unknown

CVE-2022-43459

Disclosure Date: February 28, 2023 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Forms by CaptainForm – Form Builder for WordPress plugin <= 2.5.3 versions.
Attacker Value
Unknown

CVE-2022-4792

Disclosure Date: January 30, 2023 (last updated October 08, 2023)
The News & Blog Designer Pack WordPress plugin before 3.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
Attacker Value
Unknown

CVE-2022-4749

Disclosure Date: January 30, 2023 (last updated October 08, 2023)
The Posts List Designer by Category WordPress plugin before 3.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Attacker Value
Unknown

CVE-2022-4312

Disclosure Date: December 12, 2022 (last updated February 24, 2025)
A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized user with access the email and short messaging service (SMS) accounts configuration files to discover the associated simple mail transfer protocol (SMTP) account credentials and the SIM card PIN code. Successful exploitation of this vulnerability could allow an unauthorized user access to the underlying email account and SIM card.
Attacker Value
Unknown

CVE-2022-4311

Disclosure Date: December 12, 2022 (last updated February 24, 2025)
An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConnect, which could include credentials. Successful exploitation of this vulnerability could allow other users unauthorized access to the underlying data sources.