Search Results (101117 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-30829 1 Wedding Management System Project 1 Wedding Management System 2024-11-21 7.2 High
Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\users_edit.php.
CVE-2022-30828 1 Wedding Management System Project 1 Wedding Management System 2024-11-21 7.2 High
Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\photos_edit.php.
CVE-2022-30827 1 Wedding Management System Project 1 Wedding Management System 2024-11-21 7.2 High
Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\package_edit.php.
CVE-2022-30826 1 Wedding Management System Project 1 Wedding Management System 2024-11-21 7.2 High
Wedding Management System v1.0 is vulnerable to SQL Injection via admin\client_assign.php.
CVE-2022-30825 1 Wedding Management System Project 1 Wedding Management System 2024-11-21 7.2 High
Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\client_edit.php.
CVE-2022-30823 1 Wedding Management System Project 1 Wedding Management System 2024-11-21 7.2 High
Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\blog_events_edit.php.
CVE-2022-30822 1 Wedding Management System Project 1 Wedding Management System 2024-11-21 8.8 High
In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_profile.php" file.
CVE-2022-30821 1 Wedding Management System Project 1 Wedding Management System 2024-11-21 8.8 High
In Wedding Management System v1.0, the editing function of the "Services" module in the background management system has an arbitrary file upload vulnerability in the picture upload point of "package_edit.php" file.
CVE-2022-30820 1 Wedding Management System Project 1 Wedding Management System 2024-11-21 8.8 High
In Wedding Management v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_edit.php" file.
CVE-2022-30819 1 Wedding Management System Project 1 Wedding Management System 2024-11-21 8.8 High
In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "photos_edit.php" file.
CVE-2022-30818 1 Wedding Management System Project 1 Wedding Management System 2024-11-21 7.2 High
Wedding Management System v1.0 is vulnerable to SQL injection via /Wedding-Management/admin/blog_events_edit.php?id=31.
CVE-2022-30799 1 Online Ordering System Project 1 Online Ordering System 2024-11-21 7.2 High
Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php.
CVE-2022-30798 1 Online Ordering System Project 1 Online Ordering System 2024-11-21 7.2 High
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php.
CVE-2022-30795 1 Online Ordering System Project 1 Online Ordering System 2024-11-21 7.2 High
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php.
CVE-2022-30794 1 Online Ordering System Project 1 Online Ordering System 2024-11-21 7.2 High
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php.
CVE-2022-30792 1 Codesys 19 Control For Beaglebone, Control For Empc-a\/imx6, Control For Iot2000 Sl and 16 more 2024-11-21 7.5 High
In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected.
CVE-2022-30791 1 Codesys 19 Control For Beaglebone, Control For Empc-a\/imx6, Control For Iot2000 Sl and 16 more 2024-11-21 7.5 High
In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected.
CVE-2022-30782 1 Openmoney Api Project 1 Openmoney Api 2024-11-21 7.5 High
Openmoney API through 2020-06-29 uses the JavaScript Math.random function, which does not provide cryptographically secure random numbers.
CVE-2022-30781 1 Gitea 1 Gitea 2024-11-21 7.5 High
Gitea before 1.16.7 does not escape git fetch remote.
CVE-2022-30780 1 Lighttpd 1 Lighttpd 2024-11-21 7.5 High
Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read_header_more in connections.c has a typo that disrupts use of multiple read operations on large headers.