Vulnerabilities (CVE)

Total 306936 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-51668 1 Target-info 1 Mycurator Content Curation 2024-11-18 N/A 4.8 MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mark Tilly MyCurator Content Curation allows Stored XSS.This issue affects MyCurator Content Curation: from n/a through 3.78.
CVE-2024-51586 1 Camilluskillus 1 Elementary Addons 2024-11-18 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BRAFT Elementary Addons allows Stored XSS.This issue affects Elementary Addons: from n/a through 2.0.4.
CVE-2024-51590 1 Hoosoft 1 Hoo Addons For Elementor 2024-11-18 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hoosoft Hoo Addons for Elementor allows DOM-Based XSS.This issue affects Hoo Addons for Elementor: from n/a through 1.0.6.
CVE-2024-50826 1 Lopalopa 1 E-learning Management System 2024-11-18 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/add_content.php in kashipara E-learning Management System Project 1.0 via the title and content parameters.
CVE-2024-50825 1 Lopalopa 1 E-learning Management System 2024-11-18 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/school_year.php in kashipara E-learning Management System Project 1.0 via the school_year parameter.
CVE-2024-50824 1 Lopalopa 1 E-learning Management System 2024-11-18 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.
CVE-2024-50823 1 Lopalopa 1 E-learning Management System 2024-11-18 N/A 9.8 CRITICAL
A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.
CVE-2024-50835 1 Lopalopa 1 E-learning Management System 2024-11-18 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/edit_student.php in KASHIPARA E-learning Management System Project 1.0 via the cys, un, ln, fn, and id parameters.
CVE-2024-50834 1 Lopalopa 1 E-learning Management System 2024-11-18 N/A 7.2 HIGH
A SQL Injection was found in /admin/teachers.php in KASHIPARA E-learning Management System Project 1.0 via the firstname and lastname parameters.
CVE-2024-50833 1 Lopalopa 1 E-learning Management System 2024-11-18 N/A 9.8 CRITICAL
A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the username and password parameters.
CVE-2024-51598 1 Kendysond 1 Selar.co Widget 2024-11-18 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kendysond Selar.Co Widget allows DOM-Based XSS.This issue affects Selar.Co Widget: from n/a through 1.2.
CVE-2024-50832 1 Lopalopa 1 E-learning Management System 2024-11-18 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/edit_class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.
CVE-2024-50831 1 Lopalopa 1 E-learning Management System 2024-11-18 N/A 7.2 HIGH
A SQL Injection was found in /admin/admin_user.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.
CVE-2024-50830 1 Lopalopa 1 E-learning Management System 2024-11-18 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/calendar_of_events.php in kashipara E-learning Management System Project 1.0 via the date_start, date_end, and title parameters.
CVE-2024-50829 1 Lopalopa 1 E-learning Management System 2024-11-18 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/edit_subject.php in kashipara E-learning Management System Project 1.0 via the unit parameter.
CVE-2024-50828 1 Lopalopa 1 E-learning Management System 2024-11-18 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/edit_department.php in kashipara E-learning Management System Project 1.0 via the d parameter.
CVE-2024-50827 1 Lopalopa 1 E-learning Management System 2024-11-18 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/add_subject.php in kashipara E-learning Management System Project 1.0 via the subject_code parameter.
CVE-2024-42499 2024-11-18 N/A 5.3 MEDIUM
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an attacker may be able to know whether a file exists at a specific path, and/or obtain some part of the file contents under specific conditions.
CVE-2024-45087 1 Ibm 1 Websphere Application Server 2024-11-18 N/A 4.8 MEDIUM
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2024-45088 1 Ibm 1 Maximo Asset Management 2024-11-18 N/A 5.4 MEDIUM
IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.