Lucene search

K

Free Security Vulnerabilities

cve
cve

CVE-2007-2626

SQL injection vulnerability in admin.php in SchoolBoard allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. NOTE: CVE disputes this issue, because 'username' does not exist, and the password is not used in any...

8.5AI Score

0.006EPSS

2007-05-11 05:19 PM
20
cve
cve

CVE-2023-4442

A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been rated as critical. This issue affects some unknown processing of the file \vm\patient\booking-complete.php. The manipulation of the argument userid/apponum/scheduleid leads to sql...

9.8CVSS

9.7AI Score

0.001EPSS

2023-08-21 12:15 AM
16
cve
cve

CVE-2023-5587

A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /vm/admin/doctors.php of the component Parameter Handler. The manipulation of the argument search leads...

9.8CVSS

9.7AI Score

0.001EPSS

2023-10-15 10:15 PM
35
cve
cve

CVE-2023-4443

A vulnerability classified as critical has been found in SourceCodester Free Hospital Management System for Small Practices 1.0/5.0.12. Affected is an unknown function of the file vm\doctor\edit-doc.php. The manipulation of the argument id00/nic/oldemail/email/spec/Tele leads to sql injection. It.....

9.8CVSS

9.7AI Score

0.001EPSS

2023-08-21 01:15 AM
100
cve
cve

CVE-2023-4440

A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been classified as critical. This affects an unknown part of the file appointment.php. The manipulation of the argument sheduledate leads to sql injection. It is possible to initiate the...

9.8CVSS

9.7AI Score

0.002EPSS

2023-08-20 11:15 PM
113
cve
cve

CVE-2023-4444

A vulnerability classified as critical was found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected by this vulnerability is an unknown functionality of the file vm\patient\edit-user.php. The manipulation of the argument id00/nic/oldemail/email/spec/Tele leads to...

9.8CVSS

9.7AI Score

0.001EPSS

2023-08-21 01:15 AM
101
cve
cve

CVE-2023-4441

A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /patient/appointment.php. The manipulation of the argument sheduledate leads to sql injection. The attack can...

9.8CVSS

9.7AI Score

0.001EPSS

2023-08-21 12:15 AM
13
cve
cve

CVE-2023-51813

Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary code via the staff_list parameter in the index.php...

6.5CVSS

7AI Score

0.001EPSS

2024-01-30 01:15 AM
10
cve
cve

CVE-2023-4949

An attacker with local access to a system (either through a disk or external drive) can present a modified XFS partition to grub-legacy in such a way to exploit a memory corruption in grub’s XFS file system...

8.1CVSS

6.7AI Score

0.0004EPSS

2023-11-10 05:15 PM
37
cve
cve

CVE-2023-39712

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Put...

6.1CVSS

6AI Score

0.001EPSS

2023-09-08 06:15 PM
12
cve
cve

CVE-2023-39711

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Subtotal and Paidbill parameters under the Add New Put...

6.1CVSS

6AI Score

0.001EPSS

2023-09-07 03:15 PM
15
cve
cve

CVE-2023-39710

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Customer...

6.1CVSS

6AI Score

0.001EPSS

2023-09-01 02:15 PM
11
cve
cve

CVE-2023-39714

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Member...

6.1CVSS

6AI Score

0.001EPSS

2023-09-01 06:15 PM
16
cve
cve

CVE-2023-39709

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Member...

6.1CVSS

6AI Score

0.001EPSS

2023-08-28 07:15 PM
13
cve
cve

CVE-2023-39708

A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Add New parameter under the New Buy...

6.1CVSS

5.8AI Score

0.001EPSS

2023-08-28 02:15 PM
18
cve
cve

CVE-2023-39707

A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Add Expense parameter under the Expense...

5.4CVSS

5.3AI Score

0.001EPSS

2023-08-25 08:15 PM
25
cve
cve

CVE-2020-24377

A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before...

9.6CVSS

9.1AI Score

0.003EPSS

2020-09-16 08:15 PM
30
cve
cve

CVE-2020-24373

A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before...

8.8CVSS

8.6AI Score

0.001EPSS

2020-09-16 08:15 PM
35
2
cve
cve

CVE-2020-24374

A DNS rebinding vulnerability in Freebox v5 before...

9.6CVSS

9.1AI Score

0.003EPSS

2020-09-16 08:15 PM
35
2
cve
cve

CVE-2014-1943

Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a...

5.5AI Score

0.058EPSS

2014-02-18 07:55 PM
64
cve
cve

CVE-2002-2144

Directory traversal vulnerability in BearShare 4.0.5 and 4.0.6 allows remote attackers to read files outside of the web root by hex-encoding the "/" (forward slash) or "." (dot)...

7.1AI Score

0.002EPSS

2022-10-03 04:23 PM
23
cve
cve

CVE-2022-0826

The WP Video Gallery WordPress plugin through 1.7.1 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated...

9.8CVSS

9.8AI Score

0.04EPSS

2022-05-09 05:15 PM
62
6
cve
cve

CVE-2022-0784

The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL...

9.8CVSS

9.8AI Score

0.04EPSS

2022-03-28 06:15 PM
78
cve
cve

CVE-2021-46013

An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can leverage this vulnerability to enable remote code execution on the affected web server. Once a php webshell containing "" gets uploaded it is saved into /uploads/exam_question/...

9.8CVSS

9.6AI Score

0.02EPSS

2022-01-18 06:15 PM
21
cve
cve

CVE-2020-24375

A DNS rebinding vulnerability in the UPnP MediaServer implementation in Freebox Server before...

6.5CVSS

6.4AI Score

0.002EPSS

2020-10-19 07:15 PM
25
cve
cve

CVE-2020-24376

A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before...

9.6CVSS

9.2AI Score

0.002EPSS

2020-09-16 08:15 PM
37
cve
cve

CVE-2020-5561

Keijiban Tsumiki v1.15 allows remote attackers to execute arbitrary OS commands via unspecified...

9.8CVSS

9.7AI Score

0.011EPSS

2020-03-25 02:15 AM
23
cve
cve

CVE-2014-9382

Freebox OS Web interface 3.0.2 has CSRF which can allow VPN user account...

6.5CVSS

6.5AI Score

0.002EPSS

2020-01-13 02:15 PM
33
cve
cve

CVE-2014-9405

A Cross-Site Scripting (XSS) vulnerability exists in the description field of an Download RSS item or Contacts in Freebox OS Web interface 3.0.2, which allows malicious users to execute arbitrary...

5.4CVSS

5.4AI Score

0.006EPSS

2020-01-06 10:15 PM
115
cve
cve

CVE-2015-4084

Cross-site scripting (XSS) vulnerability in the Free Counter plugin 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the value_ parameter in a check_stat action to...

5.8AI Score

0.002EPSS

2015-05-28 02:59 PM
26
cve
cve

CVE-2014-7788

The Best Free Giveaways (aka com.wIphone5GiveAways) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...

6AI Score

0.0005EPSS

2014-10-21 10:55 AM
15
cve
cve

CVE-2014-6826

The Tic-Tac To The MAX FREE (aka com.tothemax) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...

6AI Score

0.0005EPSS

2014-09-30 10:55 AM
22
cve
cve

CVE-2014-5935

The Daily Free App @ Amazon (aka com.kattanweb.android.dfaa) application 1.5.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...

6AI Score

0.0005EPSS

2014-09-18 10:55 AM
19
cve
cve

CVE-2014-5745

The FREE Pageplus Activation (aka com.wFREEPageplusActivations) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...

6AI Score

0.0005EPSS

2014-09-09 10:55 AM
17
cve
cve

CVE-2014-5588

The Free eBooks (aka com.bmfapps.freekindlebooks) application 14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...

6AI Score

0.0005EPSS

2014-09-09 01:55 AM
19
cve
cve

CVE-2009-0183

Stack-based buffer overflow in Remote Control Server in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allows remote attackers to execute arbitrary code via a long Authorization header in an HTTP...

8AI Score

0.78EPSS

2009-02-03 07:30 PM
38
cve
cve

CVE-2009-0184

Multiple buffer overflows in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote attackers to execute arbitrary code via (1) a long file name within a torrent file, (2) a long tracker URL in a torrent file, or (3) a long comment in a...

7.6AI Score

0.672EPSS

2009-02-03 07:30 PM
24
cve
cve

CVE-2008-5521

Avira AntiVir 7.9.0.36 and possibly 7.8.1.28, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or...

6.3AI Score

0.972EPSS

2008-12-12 06:30 PM
25
cve
cve

CVE-2007-2652

Multiple unspecified vulnerabilities in Free-SA before 1.2.2 allow remote attackers to execute arbitrary code via unspecified vectors involving certain (1) sprintf and (2) vsprintf calls in (a) r_index.c, (b) r_reports.c, (c) r_topsites.c, (d) r_topuser.c, (e) r_typical.c, (f) r_userdatetime.c,...

8AI Score

0.066EPSS

2007-05-14 09:19 PM
22
cve
cve

CVE-2007-1715

PHP remote file inclusion vulnerability in frontpage.php in Free Image Hosting 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. NOTE: the forgot_pass.php vector is already covered by CVE-2006-5670, and the login.php vector overlaps...

7.5AI Score

0.159EPSS

2007-03-27 09:19 PM
20
cve
cve

CVE-2007-0696

Cross-site scripting (XSS) vulnerability in error messages in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC3 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, different vectors than...

5.6AI Score

0.005EPSS

2007-02-03 10:28 PM
35
cve
cve

CVE-2007-0695

Multiple SQL injection vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: some sources mention the escape_sqlData, implode_sql, and implode_sqlIn functions, but these are protection...

8.5AI Score

0.004EPSS

2007-02-03 10:28 PM
39
cve
cve

CVE-2007-0611

Multiple cross-site scripting (XSS) vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in (1) inc.page.php and (2)...

5.7AI Score

0.005EPSS

2007-01-31 01:28 AM
27
cve
cve

CVE-2006-5762

PHP remote file inclusion vulnerability in forgot_pass.php in Free File Hosting 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. NOTE: this issue was later reported for the "File Upload System" which is a component of Free File...

7.6AI Score

0.684EPSS

2006-11-06 11:07 PM
90
cve
cve

CVE-2006-5763

Multiple PHP remote file inclusion vulnerabilities in Free File Hosting 1.1, and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter to (1) login.php, (2) register.php, or (3) send.php. NOTE: the original.....

7.5AI Score

0.159EPSS

2006-11-06 11:07 PM
21
cve
cve

CVE-2006-5764

PHP remote file inclusion vulnerability in contact.php in Free File Hosting 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party...

7.8AI Score

0.037EPSS

2006-11-06 11:07 PM
24
cve
cve

CVE-2006-5670

PHP remote file inclusion vulnerability in forgot_pass.php in Free Image Hosting 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP...

7.6AI Score

0.153EPSS

2006-11-03 01:07 AM
23
cve
cve

CVE-2006-5671

PHP remote file inclusion vulnerability in contact.php in Free Image Hosting 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party...

7.7AI Score

0.006EPSS

2006-11-03 01:07 AM
15
cve
cve

CVE-2006-3475

Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the qb_path parameter to (1) index.php, (2) about.php, (3) contact.php, (4) delete.php, (5) faq.php, (6) features.php or (7) history.php, a different set of...

7.6AI Score

0.599EPSS

2006-07-10 08:05 PM
25
cve
cve

CVE-2006-3165

SQL injection vulnerability in propview.php in Free Realty 2.9-0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the sort...

8.8AI Score

0.013EPSS

2006-06-22 10:06 PM
24
Total number of security vulnerabilities58