ZeroHour

Vulnerabilities

7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-3948
A vulnerability was found in SourceCodester Home Clean Service System 1.0.

A vulnerability was found in SourceCodester Home Clean Service System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file \admin\student.add.php of the component Photo Handler. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-261440.

NVD description · AI analysis pending
9.8<1% PoC
  • library system project library system
CVE-2023-7179
+3 in the same advisory: …7177 …7176 …7178
A vulnerability, which was classified as critical, was found in Campcodes Online College Library System 1.0.

A vulnerability, which was classified as critical, was found in Campcodes Online College Library System 1.0. Affected is an unknown function of the file /admin/category_row.php of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-249366 is the identifier assigned to this vulnerability.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • online college library system project online college library system
CVE-2023-5580
A vulnerability classified as critical has been found in SourceCodester Library System 1.0.

A vulnerability classified as critical has been found in SourceCodester Library System 1.0. This affects an unknown part of the file index.php. The manipulation of the argument category leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-242145 was assigned to this vulnerability.

NVD description · AI analysis pending
9.8<1% PoC
  • library system project library system
CVE-2021-26200
The user area for Library System 1.0 is vulnerable to SQL injection where a user can bypass the authentication and login as the admin user.

The user area for Library System 1.0 is vulnerable to SQL injection where a user can bypass the authentication and login as the admin user.

NVD description · AI analysis pending
9.82% PoC
  • library system project library system