Show filters
123 Total Results
Displaying 1-10 of 123
Sort by:
Attacker Value
Unknown
CVE-2025-0683
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text
patient data to a hard-coded public IP address when a patient is hooked
up to the monitor. This could lead to a leakage of confidential patient
data to any device with that IP address or an attacker in a
machine-in-the-middle scenario.
0
Attacker Value
Unknown
CVE-2025-0626
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
Contec Health CMS8000 Patient Monitor sends out remote access requests to a hard-coded IP address, bypassing existing device network settings to do so. This could serve as a backdoor and lead to a malicious actor being able to upload and overwrite files on the device.
0
Attacker Value
Unknown
CVE-2024-12248
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to write arbitrary data. This could result in remote code execution.
0
Attacker Value
Unknown
CVE-2024-12209
Disclosure Date: December 08, 2024 (last updated December 21, 2024)
The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the 'filename' parameter of the 'umbrella-restore' action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
0
Attacker Value
Unknown
CVE-2024-8080
Disclosure Date: August 22, 2024 (last updated October 18, 2024)
A vulnerability classified as critical has been found in SourceCodester Online Health Care System 1.0. Affected is an unknown function of the file search.php. The manipulation of the argument f_name with the input 1%' or 1=1 ) UNION SELECT 1,2,3,4,5,database(),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23# as part of string leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-38348
Disclosure Date: June 18, 2024 (last updated October 10, 2024)
CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Staff Info module via the searvalu parameter.
0
Attacker Value
Unknown
CVE-2024-38347
Disclosure Date: June 18, 2024 (last updated July 11, 2024)
CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Room Information module via the id parameter.
0
Attacker Value
Unknown
CVE-2024-37803
Disclosure Date: June 18, 2024 (last updated July 16, 2024)
Multiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname and lname parameters under the Staff Info page.
0
Attacker Value
Unknown
CVE-2024-37802
Disclosure Date: June 18, 2024 (last updated July 20, 2024)
CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Patient Info module via the searvalu parameter.
0
Attacker Value
Unknown
CVE-2024-37800
Disclosure Date: June 18, 2024 (last updated July 06, 2024)
CodeProjects Restaurant Reservation System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Date parameter at index.php.
0