| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\users_edit.php. |
| Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\photos_edit.php. |
| Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\package_edit.php. |
| Wedding Management System v1.0 is vulnerable to SQL Injection via admin\client_assign.php. |
| Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\client_edit.php. |
| Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\blog_events_edit.php. |
| In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_profile.php" file. |
| In Wedding Management System v1.0, the editing function of the "Services" module in the background management system has an arbitrary file upload vulnerability in the picture upload point of "package_edit.php" file. |
| In Wedding Management v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_edit.php" file. |
| In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "photos_edit.php" file. |
| Wedding Management System v1.0 is vulnerable to SQL injection via /Wedding-Management/admin/blog_events_edit.php?id=31. |
| Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php. |
| Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php. |
| Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php. |
| Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php. |
| In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected. |
| In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected. |
| Openmoney API through 2020-06-29 uses the JavaScript Math.random function, which does not provide cryptographically secure random numbers. |
| Gitea before 1.16.7 does not escape git fetch remote. |
| Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read_header_more in connections.c has a typo that disrupts use of multiple read operations on large headers. |