Search Results (323533 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-40068 1 Oretnom23 1 Online Id Generator System 2025-04-22 5.9 Medium
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=templates/manage_template&id=1.
CVE-2024-40069 1 Oretnom23 1 Online Id Generator System 2025-04-22 5.4 Medium
Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/Users.php?f=save, and the point of vulnerability is in the POST parameter 'firstname' and 'lastname'.
CVE-2024-40070 1 Oretnom23 1 Online Id Generator System 2025-04-22 5.1 Medium
Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/Users.php?f=save. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2024-40071 1 Oretnom23 1 Online Id Generator System 2025-04-22 9.8 Critical
Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2024-40072 1 Oretnom23 1 Online Id Generator System 2025-04-22 9.8 Critical
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1.
CVE-2024-40073 1 Oretnom23 1 Online Id Generator System 2025-04-22 9.8 Critical
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4.
CVE-2024-40074 1 Oretnom23 1 Online Id Generator System 2025-04-22 4.8 Medium
Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/SystemSettings.php?f=update_settings, and the point of vulnerability is in the POST parameter 'short_name'.
CVE-2024-28276 1 Rems 1 School Task Manager 2025-04-22 6.1 Medium
Sourcecodester School Task Manager 1.0 is vulnerable to Cross Site Scripting (XSS) via add-task.php?task_name=.
CVE-2024-34226 1 Oretnom23 1 Visitor Management System 2025-04-22 9.4 Critical
SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&id=1 in SourceCodester Visitor Management System 1.0 allow attackers to execute arbitrary SQL commands via the id parameters.
CVE-2025-22903 1 Totolink 2 N600r, N600r Firmware 2025-04-22 4.6 Medium
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the pin parameter in the function setWiFiWpsConfig.
CVE-2025-22900 1 Totolink 2 N600r, N600r Firmware 2025-04-22 9.8 Critical
Totolink N600R v4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macCloneMac parameter in the setWanConfig function.
CVE-2025-3665 1 Totolink 2 A3700r, A3700r Firmware 2025-04-22 5.3 Medium
A vulnerability has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this vulnerability is the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-3664 1 Totolink 2 A3700r, A3700r Firmware 2025-04-22 5.3 Medium
A vulnerability, which was classified as critical, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-34230 1 Sourcecodester 1 Laboratory Management System 2025-04-22 6.1 Medium
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the System Information parameter.
CVE-2025-3674 1 Totolink 2 A3700r, A3700r Firmware 2025-04-22 5.3 Medium
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. Affected by this vulnerability is the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-34231 1 Sourcecodester 1 Laboratory Management System 2025-04-22 7.1 High
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the System Short Name parameter.
CVE-2025-32375 1 Bentoml 1 Bentoml 2025-04-22 9.8 Critical
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.8, there was an insecure deserialization in BentoML's runner server. By setting specific headers and parameters in the POST request, it is possible to execute any unauthorized arbitrary code on the server, which will grant the attackers to have the initial access and information disclosure on the server. This vulnerability is fixed in 1.4.8.
CVE-2024-33304 2 Oretnom23, Sourcecodester 2 Product Show Room Site, Product Show Room 2025-04-22 6.1 Medium
SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" under Add Users.
CVE-2024-33306 1 Sourcecodester 1 Laboratory Management System 2025-04-22 7.4 High
SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" parameter in Create User.
CVE-2025-25457 1 Tenda 2 Ac10, Ac10 Firmware 2025-04-22 7.5 High
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via cloneType2.