Search Results (76070 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-33991 2024-08-06 7.1 High
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/eventwinner/index.php'.
CVE-2024-33993 2024-08-06 7.1 High
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in /candidate/index.php'.
CVE-2024-33982 2024-08-06 7.1 High
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'StudentID' parameter in '/AttendanceMonitoring/student/controller.php'.
CVE-2024-33981 2024-08-06 7.1 High
Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'start' parameter in '/admin/mod_reports/index.php'.
CVE-2024-33978 2024-08-06 7.1 High
Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session cookie details via 'category' parameter in '/index.php'.
CVE-2024-41959 2024-08-06 7.6 High
mailcow: dockerized is an open source groupware/email suite based on docker. An unauthenticated attacker can inject a JavaScript payload into the API logs. This payload is executed whenever the API logs page is viewed, potentially allowing an attacker to run malicious scripts in the context of the user's browser. This could lead to unauthorized actions, data theft, or further exploitation of the affected system. This issue has been addressed in the `2024-07` release. All users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2024-6886 1 Gitea 1 Gitea 2024-08-06 8.8 High
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.
CVE-2024-23382 1 Qualcomm 99 Fastconnect 6200 Firmware, Fastconnect 6700 Firmware, Fastconnect 6900 Firmware and 96 more 2024-08-06 8.4 High
Memory corruption while processing graphics kernel driver request to create DMA fence.
CVE-2024-23356 1 Qualcomm 188 Aqt1000 Firmware, Ar8031 Firmware, Ar8035 Firmware and 185 more 2024-08-06 7.8 High
Memory corruption during session sign renewal request calls in HLOS.
CVE-2024-23353 1 Qualcomm 212 315 5g Iot Modem Firmware, 9205 Lte Modem Firmware, 9206 Lte Modem Firmware and 209 more 2024-08-06 7.5 High
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
CVE-2024-33010 1 Qualcomm 239 Ar8035 Firmware, Ar9380 Firmware, Csr8811 Firmware and 236 more 2024-08-06 7.5 High
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
CVE-2024-33980 2024-08-06 7.1 High
Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'start' parameter in '/admin/mod_reports/printreport.php'.
CVE-2024-33986 2024-08-06 7.1 High
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter in '/department/index.php'.
CVE-2024-33990 2024-08-06 7.1 High
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via the 'id' and 'view' parameters in '/user/index.php'.
CVE-2024-33994 2024-08-06 7.1 High
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in '/event/index.php'.
CVE-2024-33989 2024-08-06 7.1 High
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via the 'eventdate' and 'events' parameters in 'port/event_print.php'.
CVE-2024-7498 1 Itsourcecode 1 Airline Reservation System 2024-08-06 7.3 High
A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been classified as critical. Affected is the function login/login2 of the file /admin/login.php of the component Admin Login Page. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273624.
CVE-2024-33979 2024-08-06 7.1 High
Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'q', 'arrival', 'departure' and 'accomodation' parameters in '/index.php'.
CVE-2024-41376 1 Dzzoffice 1 Dzzoffice 2024-08-06 8.8 High
dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.
CVE-2024-33014 1 Qualcomm 304 315 5g Iot Modem Firmware, Apq8064au Firmware, Aqt1000 Firmware and 301 more 2024-08-06 7.5 High
Transient DOS while parsing ESP IE from beacon/probe response frame.