Vulnerabilities (CVE)

Total 291487 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-57523 1 Oretnom23 1 Packers And Movers Management System 2025-04-22 N/A 4.5 MEDIUM
Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests sent to an authenticated admin user.
CVE-2023-51297 1 Phpjabbers 1 Hotel Booking System 2025-04-22 N/A 6.5 MEDIUM
A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
CVE-2023-51298 1 Phpjabbers 1 Event Booking Calendar 2025-04-22 N/A 4.7 MEDIUM
PHPJabbers Event Booking Calendar v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.
CVE-2023-51299 1 Phpjabbers 1 Hotel Booking System 2025-04-22 N/A 6.1 MEDIUM
PHPJabbers Hotel Booking System v4.0 is vulnerable to HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.
CVE-2023-51300 1 Phpjabbers 1 Hotel Booking System 2025-04-22 N/A 6.1 MEDIUM
PHPJabbers Hotel Booking System v4.0 is vulnerable to Cross-Site Scripting (XSS) vulnerabilities in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters.
CVE-2024-20030 2 Google, Mediatek 20 Android, Mt6739, Mt6757 and 17 more 2025-04-22 N/A 4.4 MEDIUM
In da, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541632; Issue ID: ALPS08541741.
CVE-2025-0532 1 Codezips 1 Gym Management System 2025-04-22 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /dashboard/admin/new_submit.php. The manipulation of the argument m_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-20029 2 Google, Mediatek 5 Android, Mt6985, Mt6989 and 2 more 2025-04-22 N/A 8.4 HIGH
In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08477406; Issue ID: MSV-1010.
CVE-2025-0535 1 Codezips 1 Gym Management System 2025-04-22 6.5 MEDIUM 6.3 MEDIUM
A vulnerability classified as critical has been found in Codezips Gym Management System 1.0. This affects an unknown part of the file /dashboard/admin/edit_mem_submit.php. The manipulation of the argument uid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-57252 1 Otcms 1 Otcms 2025-04-22 N/A 4.3 MEDIUM
OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (SSRF) in /admin/read.php, which can Read system files arbitrarily.
CVE-2025-0565 1 Zzcms 1 Zzcms 2025-04-22 7.5 HIGH 7.3 HIGH
A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-50766 1 Oretnom23 1 Survey Application System 2025-04-22 N/A 9.8 CRITICAL
SourceCodester Survey Application System 1.0 is vulnerable to SQL Injection in takeSurvey.php via the id parameter.
CVE-2025-3402 1 Seeyon 1 Fe Collaborative Office Platform 2025-04-22 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in Seeyon Zhiyuan Interconnect FE Collaborative Office Platform 5.5.2 and classified as critical. This issue affects some unknown processing of the file /sysform/042/check.js%70. The manipulation of the argument Name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2022-46904 1 Websoft 1 Websoft Hcm 2025-04-22 N/A 5.4 MEDIUM
Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Self-XSS.
CVE-2022-46903 1 Websoft 1 Websoft Hcm 2025-04-22 N/A 5.4 MEDIUM
Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Stored XSS.
CVE-2022-45997 1 Tenda 2 W15e, W20e Firmware 2025-04-22 N/A 7.2 HIGH
Tenda W20E V16.01.0.6(3392) is vulnerable to Buffer Overflow.
CVE-2022-45996 1 Tenda 2 W15e, W20e Firmware 2025-04-22 N/A 7.2 HIGH
Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output.
CVE-2022-45980 1 Tenda 2 Ax12, Ax12 Firmware 2025-04-22 N/A 8.8 HIGH
Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via /goform/SysToolRestoreSet .
CVE-2022-45979 1 Tenda 2 Ax12, Ax12 Firmware 2025-04-22 N/A 7.5 HIGH
Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the ssid parameter at /goform/fast_setting_wifi_set .
CVE-2022-45977 1 Tenda 2 Ax12, Ax12 Firmware 2025-04-22 N/A 8.8 HIGH
Tenda AX12 V22.03.01.21_CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function.