Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
nu11secur1ty vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2021-30044
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the First Name or Last Name field on staff/register.php.
Remoteclinic Remote Clinic 2.0
9.8
CVSSv3
CVE-2022-23366
HMS v1.0 exists to contain a SQL injection vulnerability via patientlogin.php.
Hms Project Hms 1.0
9.8
CVSSv3
CVE-2021-42224
SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.
Phpgurukul Ifsc Code Finder 1.0
9.8
CVSSv3
CVE-2021-33470
COVID19 Testing Management System 1.0 is vulnerable to SQL Injection via the admin panel.
Phpgurukul Covid19 Testing Management System 1.0
8.8
CVSSv3
CVE-2020-0022
In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitatio...
Google Android 8.0
Google Android 8.1
Google Android 9.0
Google Android 10.0
Huawei Mate 20 Firmware
Huawei Mate 20 Pro Firmware
Huawei Mate 20 X Firmware
Huawei P Smart Firmware
Huawei P Smart 2019 Firmware
Huawei P20 Firmware
Huawei P20 Pro Firmware
Huawei P30 Firmware
Huawei P30 Pro Firmware
Huawei Y6 2019 Firmware
Huawei Y6 Pro 2019 Firmware
Huawei Y9 2019 Firmware
Huawei Nova 3 Firmware
Huawei Nova Lite 3 Firmware
Huawei Honor 8a Firmware
Huawei Honor 8x Firmware
Huawei Honor View 20 Firmware
Huawei Mate 30 Pro Firmware
10 Github repositories
1 Article
9.8
CVSSv3
CVE-2022-24571
Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access.
Car Driving School Management System Project Car Driving School Management System 1.0
5.4
CVSSv3
CVE-2021-35501
PandoraFMS <=7.54 allows Stored XSS by placing a payload in the name field of a visual console. When a user or an administrator visits the console, the XSS payload will be executed.
Pandorafms Pandora Fms
7.8
CVSSv3
CVE-2023-28285
Microsoft Office Remote Code Execution Vulnerability
Microsoft Office 2019
Microsoft 365 Apps -
Microsoft Office Long Term Servicing Channel 2021
7.8
CVSSv3
CVE-2023-28311
Microsoft Word Remote Code Execution Vulnerability
Microsoft Office 2019
Microsoft 365 Apps -
Microsoft Office Long Term Servicing Channel 2021
4.9
CVSSv3
CVE-2021-31777
The dce (aka Dynamic Content Element) extension 2.2.0 up to and including 2.6.x prior to 2.6.2, and 2.7.x prior to 2.7.1, for TYPO3 allows SQL Injection via a backend user account.
Dynamic Content Elements Project Dynamic Content Elements
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-3400
deserialization
CVE-2024-21788
CVE-2023-42433
CVE-2024-21841
CVE-2024-22095
local file inclusion
memory leak
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »