Unknown · CVSS Not scored
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\book-appointment.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Published Jun 22, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter to include/ajax.search.php.
Published Jun 28, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.
Published Jun 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php.
Published Jun 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary code into the name parameter and perform code execution when the crafted file is opened.
Published Jun 21, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_v4l2_m2m_create_context function in v4l2_m2m.c.
Published Jun 1, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in get_block_row at libavfilter/vf_bm3d.c, which might lead to memory corruption and other potential consequences.
Published Jun 1, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php.
Published Jun 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak is affected by: memory leak in the link_filter_inouts function in libavfilter/graphparser.c.
Published Jun 1, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the avpriv_float_dsp_allocl function in libavutil/float_dsp.c.
Published Jun 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Published Jun 22, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsreports.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Published Jun 22, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.
Published Jun 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Published Jun 22, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\registration.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Published Jun 22, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\appointment-history.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Published Jun 22, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Denial of Service vulnerability exists in FFmpeg 4.2 idue to a memory leak in the v_frame_alloc function in frame.c.
Published Jun 1, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.
Published Jun 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\forgot-password.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Published Jun 22, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection in ECShop 3.0 via the id parameter to admin/shophelp.php.
Published Jun 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_buffersrc_add_frame_flags function in buffersrc.
Published Jun 1, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\edit-profile.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Published Jun 22, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_frame_pool_get function in framepool.c.
Published Jun 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Published Jun 22, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection in phpCMS 2008 sp4 via the genre parameter to yp/job.php.
Published Jun 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.
Published Jun 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerability in \hms\admin\appointment-history.php. Remote registered users can exploit the vulnerability to obtain user cookie data.
Published Jun 22, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.
Published Jun 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated users can exploit the vulnerability to obtain user sensitive information.
Published Jun 22, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection in 74cms 3.2.0 via the id parameter to wap/wap-company-show.php.
Published Jun 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection in ECShop 2.7.6 via the goods_number parameter to flow.php. .
Published Jun 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\check_availability.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Published Jun 22, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_dict_set function in dict.c.
Published Jun 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the filter_frame function in vf_tile.c.
Published Jun 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in avcodec_alloc_context3 at options.c.
Published Jun 1, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the url_open_dyn_buf_internal function in libavformat/aviobuf.c.
Published Jun 1, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak at the fifo_alloc_common function in libavutil/fifo.c.
Published Jun 1, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the wtvfile_open_sector function in wtvdec.c.
Published Jun 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Directory Traversal vulnerability in phpCMS 9.1.13 via the q parameter to public_get_suggest_keyword.
Published Jun 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_intra at libavfilter/vf_bwdif.c, which might lead to memory corruption and other potential consequences.
Published Jun 1, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the inavi_add_ientry function.
Published Jun 1, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In IBOS 4.5.4 the email function has a cross site scripting (XSS) vulnerability in emailbody[content] parameter.
Published Jun 24, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.
Published Jun 24, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In IBOS 4.5.4 Open, Arbitrary File Inclusion causes getshell via /system/modules/dashboard/controllers/CronController.php.
Published Jun 24, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.
Published Jun 24, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In CRMEB 3.1.0+ strict domain name filtering leads to SSRF(Server-Side Request Forgery). The vulnerable code is in file /crmeb/app/admin/controller/store/CopyTaobao.php.
Published Jun 24, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability.
Published Jun 24, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename parameter in SystemDatabackup.php.
Published Jun 29, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject arbitrary web script and stolen administrator cookies via the nickname parameter and gain access to the admin panel.
Published Jun 15, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Request Forgery (CSRF) vulnerability in PbootCMS v2.0.3 via /admin.php?p=/User/index.
Published Jun 1, 2022 · Updated Aug 4, 2024