5.3

CVSS4.0

CVE-2024-9317 - SourceCodester Online Eyewear Shop Master.php delete_category sql injection

A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerability is the function delete_category of the file /classes/Master.php?f=delete_category. The manipulation of the argument id leads to sql injection. The attack can be launched remote…

📅 Published: Sept. 28, 2024, 9 p.m. 🔄 Last Modified: Oct. 1, 2024, 1:32 p.m.

5.3

CVSS4.0

CVE-2024-9316 - code-projects Blood Bank Management System B+.php sql injection

A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. Affected is an unknown function of the file /admin/blood/update/B+.php. The manipulation of the argument Bloodname leads to sql injection. It is possible to launch the attack remotely. The explo…

📅 Published: Sept. 28, 2024, 8 p.m. 🔄 Last Modified: Oct. 2, 2024, 1:29 p.m.

5.3

CVSS4.0

CVE-2024-9315 - SourceCodester Employee and Visitor Gate Pass Logging System manage_department.php sql injection

A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/maintenance/manage_department.php. The manipulation of the argument id leads to sql injection. The attack may b…

📅 Published: Sept. 28, 2024, 7 p.m. 🔄 Last Modified: Oct. 1, 2024, 1:33 p.m.

6.9

CVSS4.0

CVE-2024-9300 - SourceCodester Online Railway Reservation System Message Us Form contact_us.php cross site scripting

A vulnerability classified as problematic was found in SourceCodester Online Railway Reservation System 1.0. This vulnerability affects unknown code of the file contact_us.php of the component Message Us Form. The manipulation of the argument fullname/email/message leads to cross site scripting. Th…

📅 Published: Sept. 28, 2024, 2:31 p.m. 🔄 Last Modified: Oct. 1, 2024, 1:34 p.m.

5.3

CVSS4.0

CVE-2024-9299 - SourceCodester Online Railway Reservation System ?page=reserve cross site scripting

A vulnerability classified as problematic has been found in SourceCodester Online Railway Reservation System 1.0. This affects an unknown part of the file /?page=reserve. The manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting. It is possible to initiate the …

📅 Published: Sept. 28, 2024, 2 p.m. 🔄 Last Modified: Oct. 1, 2024, 1:36 p.m.

5.3

CVSS4.0

CVE-2024-9298 - SourceCodester Online Railway Reservation System Ticket ?page=tickets access control

A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /?page=tickets of the component Ticket Handler. The manipulation of the argument id leads to improper access controls…

📅 Published: Sept. 28, 2024, 1:31 p.m. 🔄 Last Modified: Oct. 1, 2024, 1:37 p.m.

4.4

CVSS3.1

CVE-2024-8189 - WP MultiTasking - WP Utilities <= 0.1.17 - Authenticated (Administrator+) Stored Cross-Site Scripti…

The WP MultiTasking – WP Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpmt_menu_name’ parameter in all versions up to, and including, 0.1.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with a…

📅 Published: Sept. 28, 2024, 12:31 p.m. 🔄 Last Modified: April 8, 2026, 4:35 p.m.

5.3

CVSS4.0

CVE-2024-9297 - SourceCodester Online Railway Reservation System admin improper authorization

A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/. The manipulation of the argument page with the input trains/schedules/system_info leads to improper au…

📅 Published: Sept. 28, 2024, noon 🔄 Last Modified: Oct. 1, 2024, 1:39 p.m.

6.9

CVSS4.0

CVE-2024-9296 - SourceCodester Advocate Office Management System forgot_pass.php sql injection

A vulnerability was found in SourceCodester Advocate Office Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /control/forgot_pass.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely…

📅 Published: Sept. 28, 2024, 9 a.m. 🔄 Last Modified: Oct. 1, 2024, 11:36 a.m.

6.1

CVSS3.1

CVE-2024-8712 - GTM Server Side <= 2.1.19 - Reflected Cross-Site Scripting

The GTM Server Side plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.1.19. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page…

📅 Published: Sept. 28, 2024, 8:36 a.m. 🔄 Last Modified: April 8, 2026, 4:43 p.m.
Total resulsts: 349182
Page 8442 of 34,919
« previous page » next page
Filters