Search Results (328655 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-43362 1 Slims 1 Senayan Library Management System 2025-05-05 7.2 High
Senayan Library Management System v9.4.2 was discovered to contain a SQL injection vulnerability via the collType parameter at loan_by_class.php.
CVE-2022-43361 1 Slims 1 Senayan Library Management System 2025-05-05 4.8 Medium
Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component pop_chart.php.
CVE-2022-43241 2 Debian, Struktur 2 Debian Linux, Libde265 2025-05-05 6.5 Medium
Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_v_3_8_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
CVE-2022-43240 2 Debian, Struktur 2 Debian Linux, Libde265 2025-05-05 6.5 Medium
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_hevc_qpel_h_2_v_1_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
CVE-2022-43127 1 Online Diagnostic Lab Management System Project 1 Online Diagnostic Lab Management System 2025-05-05 7.2 High
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/update_status.php.
CVE-2022-43083 1 Vehicle Booking System Project 1 Vehicle Booking System 2025-05-05 7.2 High
An arbitrary file upload vulnerability in admin-add-vehicle.php of Vehicle Booking System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-43082 1 Fast Food Ordering System Project 1 Fast Food Ordering System 2025-05-05 6.1 Medium
A cross-site scripting (XSS) vulnerability in /fastfood/purchase.php of Fast Food Ordering System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the customer parameter.
CVE-2022-43081 1 Fast Food Ordering System Project 1 Fast Food Ordering System 2025-05-05 7.5 High
Fast Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /fastfood/purchase.php.
CVE-2022-3499 1 Tenable 1 Nessus 2025-05-05 6.5 Medium
An authenticated attacker could utilize the identical agent and cluster node linking keys to potentially allow for a scenario where unauthorized disclosure of agent logs and data is present.
CVE-2022-32888 2 Apple, Redhat 7 Ipados, Iphone Os, Macos and 4 more 2025-05-05 8.8 High
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, watchOS 9, macOS Monterey 12.6, tvOS 16. Processing maliciously crafted web content may lead to arbitrary code execution.
CVE-2024-38882 1 Horizoncloud 1 Caterease 2025-05-05 9.8 Critical
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform command line execution through SQL Injection due to improper neutralization of special elements used in an OS command.
CVE-2024-25849 2 Presta Tool Kit, Prestatoolkit 2 Make An Offer For Prestashop, Make An Offer\/offer Your Price 2025-05-05 9.8 Critical
In the module "Make an offer" (makeanoffer) <= 1.7.1 from PrestaToolKit for PrestaShop, a guest can perform SQL injection via MakeOffers::checkUserExistingOffer()` and `MakeOffers::addUserOffer()` .
CVE-2024-25848 1 Team-ever 1 Seo 2025-05-05 5.9 Medium
In the module "Ever Ultimate SEO" (everpsseo) <= 8.1.2 from Team Ever for PrestaShop, a guest can perform SQL injection in affected versions.
CVE-2024-25845 1 Cleanpresta 1 Cd Custom Fields 4 Orders 2025-05-05 9.8 Critical
In the module "CD Custom Fields 4 Orders" (cdcustomfields4orders) <= 1.0.0 from Cleanpresta.com for PrestaShop, a guest can perform SQL injection in affected versions.
CVE-2024-25847 1 Myprestamodules 2 Product Catalog \(csv\, Excel\) Import, Product Catalog Import For Prestashop 2025-05-05 9.8 Critical
SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::__construct() and importProducts::_addDataToDb methods.
CVE-2024-27515 1 Mindstellar 1 Osclass 2025-05-05 7.2 High
Osclass 5.1.2 is vulnerable to SQL Injection.
CVE-2021-34645 1 Wpeasycart 1 Shopping Cart \& Ecommerce Store 2025-05-05 8.8 High
The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_settings function found in the ~/admin/inc/wp_easycart_admin_initial_setup.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 5.1.0.
CVE-2021-34668 1 Devowl 1 Wordpress Real Media Library 2025-05-05 6.4 Medium
The WordPress Real Media Library WordPress plugin is vulnerable to Stored Cross-Site Scripting via the name parameter in the ~/inc/overrides/lite/rest/Folder.php file which allows author-level attackers to inject arbitrary web scripts in folder names, in versions up to and including 4.14.1.
CVE-2021-34646 1 Booster 1 Booster For Woocommerce 2025-05-05 9.8 Critical
Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a random token generation weakness in the reset_and_mail_activation_link function found in the ~/includes/class-wcj-emails-verification.php file. This allows attackers to impersonate users and trigger an email address verification for arbitrary accounts, including administrative accounts, and automatically be logged in as that user, including any site administrators. This requires the Email Verification module to be active in the plugin and the Login User After Successful Verification setting to be enabled, which it is by default.
CVE-2021-39316 1 Digitalzoomstudio 1 Zoomsounds 2025-05-05 7.5 High
The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the `dzsap_download` action using directory traversal in the `link` parameter.