Search Results (339825 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-1747 2 Vanquish, Woocommerce 2 Woocommerce Customers Manager, Woocommerce Customers Manager 2025-05-29 6.5 Medium
The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX actions, allowing any authenticated users, such as subscriber, to call them and update/delete/create customer metadata, also leading to Stored Cross-Site Scripting due to the lack of escaping of said metadata values.
CVE-2024-2843 2 Vanquish, Woocommerce 2 Woocommerce Customers Manager, Woocommerce Customers Manager 2025-05-29 6.5 Medium
The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin users delete users via CSRF attacks
CVE-2024-3983 2 Vanquish, Woocommerce 2 Woocommerce Customers Manager, Woocommerce Customers Manager 2025-05-29 8.1 High
The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting customers via CSRF attacks
CVE-2024-46328 1 Vonets 2 Vap11g-300, Vap11g-300 Firmware 2025-05-29 8 High
VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain hardcoded credentials for several different privileged accounts, including root.
CVE-2024-46329 1 Vonets 2 Vap11g-300, Vap11g-300 Firmware 2025-05-29 8 High
VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the SystemCommand object.
CVE-2023-47189 1 Wpmudev 1 Defender 2025-05-29 5.3 Medium
Improper Authentication vulnerability in WPMU DEV Defender Security allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Defender Security: from n/a through 4.2.0.
CVE-2024-32792 1 Incsub 1 Hummingbird 2025-05-29 4.3 Medium
Missing Authorization vulnerability in WPMU DEV Hummingbird.This issue affects Hummingbird: from n/a through 3.7.3.
CVE-2023-37226 1 Loftware 1 Spectrum 2025-05-29 9.8 Critical
Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.
CVE-2023-37227 1 Loftware 1 Spectrum 2025-05-29 9.8 Critical
Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.
CVE-2023-37231 1 Loftware 1 Spectrum 2025-05-29 9.8 Critical
Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password.
CVE-2023-43953 1 Sscms 1 Sscms 2025-05-29 5.4 Medium
SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.
CVE-2024-51360 1 Phpgurukul 1 Hospital Management System 2025-05-29 9.8 Critical
An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor/edit-profile.php file
CVE-2024-51108 1 Anujk305 1 Medical Card Generation System 2025-05-29 5.4 Medium
Multiple stored cross-site scripting (XSS) vulnerabilities in the component /admin/card-bwdates-report.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the fromdate and todate parameters.
CVE-2024-51107 1 Anujk305 1 Medical Card Generation System 2025-05-29 4.8 Medium
Multiple stored cross-site scripting (XSS) vulnerabilities in the component /mcgs/admin/contactus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the pagetitle, pagedes, and email parameters.
CVE-2024-51101 1 Phpgurukul 1 Restaurant Table Booking System 2025-05-29 9.8 Critical
PHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /rtbs/check-status.php.
CVE-2024-48702 1 Phpgurukul 1 Old Age Home Management System 2025-05-29 5.4 Medium
PHPGurukul Old Age Home Management System v1.0 is vulnerable to HTML Injection via the searchdata parameter.
CVE-2024-24140 1 Remyandrade 1 Daily Habit Tracker 2025-05-29 7.2 High
Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'
CVE-2024-24134 1 Remyandrade 1 Online Food Menu 2025-05-29 4.8 Medium
Sourcecodester Online Food Menu 1.0 is vulnerable to Cross Site Scripting (XSS) via the 'Menu Name' and 'Description' fields in the Update Menu section.
CVE-2024-23739 2 Apple, Discord 2 Macos, Discord 2025-05-29 9.8 Critical
An issue in Discord for macOS version 0.0.291 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.
CVE-2024-22639 1 Igalerie 1 Igalerie 2025-05-29 6.1 Medium
iGalerie v3.0.22 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Titre (Title) field in the editing interface.