Vulnerabilities
20 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-7937 +1 in the same advisory: …7936 | A vulnerability classified as critical was found in itsourcecode Project Expense Monitoring System 1.0. A vulnerability classified as critical was found in itsourcecode Project Expense Monitoring System 1.0. This vulnerability affects unknown code of the file printtransfer.php. The manipulation of the argument transfer_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2024-7933 | A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been classified as critical. Affected is an unknown function of the file login1.php of the component Backend Login. The manipulation of the argument user leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 6.9 group max | <1% | PoC |
| — | |
| CVE-2023-5827 | A vulnerability was found in Shanghai CTI Navigation CTI Monitoring and Early Warning System 2.2. A vulnerability was found in Shanghai CTI Navigation CTI Monitoring and Early Warning System 2.2. It has been classified as critical. This affects an unknown part of the file /Web/SysManage/UserEdit.aspx. The manipulation of the argument ID leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-243717 was assigned to this vulnerability. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2023-1480 +1 in the same advisory: …1481 | A vulnerability classified as critical was found in SourceCodester Monitoring of Students Cyber Accounts System 1.0. A vulnerability classified as critical was found in SourceCodester Monitoring of Students Cyber Accounts System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php of the component POST Parameter Handler. The manipulation of the argument un leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223363. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2022-37298 | Shinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control. Shinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control. The SafeUnpickler class found in shinken/safepickle.py implements a weak authentication scheme when unserializing objects passed from monitoring nodes to the Shinken monitoring server. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2022-31202 +1 in the same advisory: …31201 | The export function in SoftGuard Web (SGW) before 5.1.5 allows directory traversal to read an arbitrary local file via export or man.tcl. The export function in SoftGuard Web (SGW) before 5.1.5 allows directory traversal to read an arbitrary local file via export or man.tcl. NVD description · AI analysis pending | 6.5 group max | 1% | PoC |
| — | |
| CVE-2021-4035 | A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of tinymce editor. A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of tinymce editor. In order to exploit this vulnerability, the attackers needs an account with enough privileges to view and edit reports. NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2021-45043 | HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter. HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter. NVD description · AI analysis pending | 7.5 | 33% | PoC ×2 |
| — | |
| CVE-2020-5623 | NITORI App for Android versions 6.0.4 and earlier and NITORI App for iOS versions 6.0.2 and earlier allow remote attackers to lead a user to access an arbitrary NITORI App for Android versions 6.0.4 and earlier and NITORI App for iOS versions 6.0.2 and earlier allow remote attackers to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2020-13118 | An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter community. NVD description · AI analysis pending | 9.8 | 4% | PoC ×2 |
| — | |
| CVE-2018-18798 | Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and user/index.php?view=vie Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and user/index.php?view=view. NVD description · AI analysis pending | 9.8 | 3% | PoC ×2 |
| — | |
| CVE-2018-18806 | School Equipment Monitoring System 1.0 allows SQL injection via the login screen, related to include/user.vb. School Equipment Monitoring System 1.0 allows SQL injection via the login screen, related to include/user.vb. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2018-18799 +1 in the same advisory: …18797 | School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos. School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos. NVD description · AI analysis pending | 8.8 | 2% | PoC ×2 |
| — | |
| CVE-2017-6188 | Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user. NVD description · AI analysis pending | 5.5 | <1% |
| — |