Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
nu11secur1ty vulnerabilities and exploits
(subscribe to this query)
7.8
CVSSv3
CVE-2023-28311
Microsoft Word Remote Code Execution Vulnerability
Microsoft Office 2019
Microsoft 365 Apps -
Microsoft Office Long Term Servicing Channel 2021
9.8
CVSSv3
CVE-2022-24263
Hospital Management System v4.0 exists to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.
Phpgurukul Hospital Management System 4.0
9.8
CVSSv3
CVE-2021-33470
COVID19 Testing Management System 1.0 is vulnerable to SQL Injection via the admin panel.
Phpgurukul Covid19 Testing Management System 1.0
4.9
CVSSv3
CVE-2021-31777
The dce (aka Dynamic Content Element) extension 2.2.0 up to and including 2.6.x prior to 2.6.2, and 2.7.x prior to 2.7.1, for TYPO3 allows SQL Injection via a backend user account.
Dynamic Content Elements Project Dynamic Content Elements
4.8
CVSSv3
CVE-2021-38603
PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field.
Pluxml Pluxml 5.8.7
1 Github repository
5.4
CVSSv3
CVE-2021-38699
TastyIgniter 3.0.7 allows XSS via /account, /reservation, /admin/dashboard, and /admin/system_logs.
Tastyigniter Tastyigniter 3.0.7
4 Github repositories
6.1
CVSSv3
CVE-2021-38757
Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php.
Hospital Management System Project Hospital Management System -
9.8
CVSSv3
CVE-2021-26201
The Login Panel of CASAP Automated Enrollment System 1.0 is vulnerable to SQL injection authentication bypass. An attacker can obtain access to the admin panel by injecting a SQL query in the username field of the login page.
Casap Automated Enrollment System Project Casap Automated Enrollment System 1.0
8.8
CVSSv3
CVE-2020-0022
In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitatio...
Google Android 8.0
Google Android 8.1
Google Android 9.0
Google Android 10.0
Huawei Mate 20 Firmware
Huawei Mate 20 Pro Firmware
Huawei Mate 20 X Firmware
Huawei P Smart Firmware
Huawei P Smart 2019 Firmware
Huawei P20 Firmware
Huawei P20 Pro Firmware
Huawei P30 Firmware
Huawei P30 Pro Firmware
Huawei Y6 2019 Firmware
Huawei Y6 Pro 2019 Firmware
Huawei Y9 2019 Firmware
Huawei Nova 3 Firmware
Huawei Nova Lite 3 Firmware
Huawei Honor 8a Firmware
Huawei Honor 8x Firmware
Huawei Honor View 20 Firmware
Huawei Mate 30 Pro Firmware
10 Github repositories
1 Article
9.8
CVSSv3
CVE-2022-24571
Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access.
Car Driving School Management System Project Car Driving School Management System 1.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30051
remote
CVE-2024-27954
CVE-2023-51483
CVE-2023-47782
SSRF
CVE-2024-24715
CVE-2023-52424
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »