Lucene search

K

Yokogawa Rental & Lease Corporation Security Vulnerabilities

nuclei
nuclei

Car Rental Management System 1.0 - SQL Injection

Car Rental Management System 1.0 contains an SQL injection vulnerability via /admin/manage_user.php?id=. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected...

7.2CVSS

7.3AI Score

0.011EPSS

2022-07-31 09:12 PM
2
nuclei
nuclei

Car Rental Management System 1.0 - SQL Injection

Car Rental Management System 1.0 contains an SQL injection vulnerability via /admin/view_car.php?id=. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected...

7.2CVSS

7.3AI Score

0.011EPSS

2022-07-31 09:07 PM
11
nuclei
nuclei

Car Rental Management System 1.0 - SQL Injection

Car Rental Management System 1.0 contains an SQL injection vulnerability via /booking.php?car_id=. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected...

7.2CVSS

7.3AI Score

0.011EPSS

2022-07-31 09:06 PM
2
nuclei
nuclei

Car Rental Management System 1.0 - SQL Injection

Car Rental Management System 1.0 contains an SQL injection vulnerability via /admin/ajax.php?action=login. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected...

7.2CVSS

7.3AI Score

0.012EPSS

2022-07-31 09:05 PM
5
nuclei
nuclei

Car Rental Management System 1.0 - SQL Injection

Car Rental Management System 1.0 contains an SQL injection vulnerability via /admin/manage_booking.php?id=. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected...

7.2CVSS

7.2AI Score

0.011EPSS

2022-07-31 09:11 PM
1
nuclei
nuclei

Car Rental Management System 1.0 - Local File Inclusion

Car Rental Management System 1.0 allows an unauthenticated user to perform a file inclusion attack against the /index.php file with a partial filename in the "page" parameter, leading to code...

9.8CVSS

9.5AI Score

0.012EPSS

2021-07-20 01:08 PM
2
nuclei
nuclei

Sourcecodester Car Rental Management System 1.0 - Stored Cross-Site Scripting

Sourcecodester Car Rental Management System 1.0 is vulnerable to cross-site scripting via the vehicalorcview...

5.4CVSS

5.2AI Score

0.001EPSS

2022-01-29 01:22 PM
cve
cve

CVE-2024-0343

A vulnerability classified as problematic was found in CodeAstro Simple House Rental System 5.6. Affected by this vulnerability is an unknown functionality of the component Login Panel. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been...

6.1CVSS

6AI Score

0.001EPSS

2024-01-09 08:15 PM
13
cve
cve

CVE-2023-3694

A vulnerability, which was classified as critical, has been found in SourceCodester House Rental and Property Listing 1.0. This issue affects some unknown processing of the file index.php. The manipulation of the argument keywords/location leads to sql injection. The attack may be initiated...

9.8CVSS

9.7AI Score

0.001EPSS

2023-07-17 12:15 AM
16
cve
cve

CVE-2023-3806

A vulnerability, which was classified as critical, was found in SourceCodester House Rental and Property Listing System 1.0. Affected is an unknown function of the file btn_functions.php. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has...

9.8CVSS

9.5AI Score

0.001EPSS

2023-07-21 02:15 AM
20
cve
cve

CVE-2023-1559

A vulnerability classified as problematic was found in SourceCodester Storage Unit Rental Management System 1.0. This vulnerability affects unknown code of the file classes/Users.php?f=save. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been...

7.2CVSS

7.1AI Score

0.001EPSS

2023-03-22 12:15 PM
27
osv
osv

CVE-2022-2928

In ISC DHCP 4.4.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1, when the function option_code_hash_lookup() is called from add_option(), it increases the option's refcount field. However, there is not a corresponding call to option_dereference() to decrement the refcount field. The functio...

6.5CVSS

2.6AI Score

0.001EPSS

2022-10-07 05:15 AM
15
cve
cve

CVE-2023-3642

A vulnerability was found in GZ Scripts Vacation Rental Website 1.8 and classified as problematic. Affected by this issue is some unknown functionality of the file /VacationRentalWebsite/property/8/ad-has-principes/ of the component HTTP POST Request Handler. The manipulation of the argument...

6.1CVSS

6AI Score

0.001EPSS

2023-07-12 05:15 PM
12
cve
cve

CVE-2023-4117

A vulnerability, which was classified as problematic, has been found in PHP Jabbers Rental Property Booking 2.0. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack may be launched remotely....

6.1CVSS

6AI Score

0.001EPSS

2023-08-03 08:15 AM
29
cve
cve

CVE-2024-0501

A vulnerability has been found in SourceCodester House Rental Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Manage Invoice Details. The manipulation of the argument Invoice leads to cross site scripting. The attack.....

4.8CVSS

4.9AI Score

0.001EPSS

2024-01-13 08:15 PM
13
cve
cve

CVE-2023-3555

A vulnerability was found in GZ Scripts PHP Vacation Rental Script 1.8. It has been classified as problematic. This affects an unknown part of the file /preview.php. The manipulation of the argument page/layout/sort_by/property_id leads to cross site scripting. It is possible to initiate the...

6.1CVSS

6AI Score

0.0005EPSS

2023-07-10 04:15 PM
16
cve
cve

CVE-2024-0499

A vulnerability, which was classified as problematic, has been found in SourceCodester House Rental Management System 1.0. This issue affects some unknown processing of the file index.php. The manipulation of the argument page leads to cross site scripting. The attack may be initiated remotely....

4.8CVSS

4.9AI Score

0.001EPSS

2024-01-13 07:15 PM
16
cve
cve

CVE-2024-0500

A vulnerability, which was classified as problematic, was found in SourceCodester House Rental Management System 1.0. Affected is an unknown function of the component Manage Tenant Details. The manipulation of the argument Name leads to cross site scripting. It is possible to launch the attack...

4.8CVSS

4.9AI Score

0.001EPSS

2024-01-13 07:15 PM
9
cve
cve

CVE-2023-5585

A vulnerability was found in SourceCodester Online Motorcycle Rental System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/?page=bike of the component Bike List. The manipulation of the argument Model with the input ">confirm (document.cookie...

6.1CVSS

6AI Score

0.0005EPSS

2023-10-15 12:15 AM
30
cve
cve

CVE-2024-23847

Incorrect default permissions issue exists in Unifier and Unifier Cast Version.5.0 or later, and the patch "20240527" not applied. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be modified.....

7.2AI Score

0.0004EPSS

2024-05-31 06:15 AM
27
cve
cve

CVE-2023-3757

A vulnerability classified as problematic has been found in GZ Scripts Car Rental Script 1.8. Affected is an unknown function of the file /EventBookingCalendar/load.php?controller=GzFront/action=checkout/cid=1/layout=calendar/show_header=T/local=3. The manipulation of the argument...

6.1CVSS

6AI Score

0.001EPSS

2023-07-19 05:15 AM
12
cve
cve

CVE-2024-0502

A vulnerability was found in SourceCodester House Rental Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file manage_user.php of the component Edit User. The manipulation of the argument id/name/username leads to sql injection. The...

7.2CVSS

7.2AI Score

0.001EPSS

2024-01-13 08:15 PM
15
cve
cve

CVE-2024-36246

Missing authorization vulnerability exists in Unifier and Unifier Cast Version.5.0 or later, and the patch "20240527" not applied. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be modified.....

7.2AI Score

0.0004EPSS

2024-05-31 06:15 AM
43
nuclei
nuclei

WordPress eaSYNC Booking <1.1.16 - Arbitrary File Upload

WordPress eaSync Booking plugin bundle for hotel, restaurant and car rental before 1.1.16 is susceptible to arbitrary file upload. The plugin contains insufficient input validation of an AJAX action. An allowlist of valid file extensions is defined but is not used during the validation steps. An...

9.8CVSS

9.7AI Score

0.731EPSS

2022-10-29 11:20 AM
8
osv
osv

CVE-2023-32082

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when Keys parameter is true, even a user doesn't have read permission to the keys. The impact is...

4.3CVSS

6.8AI Score

0.001EPSS

2023-05-11 08:15 PM
9
cvelist
cvelist

CVE-2024-6015 itsourcecode Online House Rental System manage_user.php sql injection

A vulnerability classified as critical was found in itsourcecode Online House Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file manage_user.php. The manipulation of the argument month_of leads to sql injection. The attack can be launched remotely. The...

6.3CVSS

0.0004EPSS

2024-06-15 05:00 PM
3
cvelist
cvelist

CVE-2024-5981 itsourcecode Online House Rental System manage_user.php sql injection

A vulnerability was found in itsourcecode Online House Rental System 1.0. It has been classified as critical. Affected is an unknown function of the file manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been.....

6.3CVSS

0.0004EPSS

2024-06-14 01:00 AM
2
openbugbounty
openbugbounty

tomesode-rental-kikuzuru.jp Cross Site Scripting vulnerability OBB-3865147

Following the coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. notified the website operator about its existence. Technical details of the vulnerability are currently...

6.2AI Score

2024-03-05 01:09 PM
3
vulnrichment
vulnrichment

CVE-2024-6015 itsourcecode Online House Rental System manage_user.php sql injection

A vulnerability classified as critical was found in itsourcecode Online House Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file manage_user.php. The manipulation of the argument month_of leads to sql injection. The attack can be launched remotely. The...

6.3CVSS

7.4AI Score

0.0004EPSS

2024-06-15 05:00 PM
3
vulnrichment
vulnrichment

CVE-2024-5981 itsourcecode Online House Rental System manage_user.php sql injection

A vulnerability was found in itsourcecode Online House Rental System 1.0. It has been classified as critical. Affected is an unknown function of the file manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been.....

6.3CVSS

7.4AI Score

0.0004EPSS

2024-06-14 01:00 AM
3
vulnrichment
vulnrichment

CVE-2024-6066 SourceCodester Best House Rental Management System payment_report.php sql injection

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. Affected is an unknown function of the file payment_report.php. The manipulation of the argument month_of leads to sql injection. It is possible to launch the attack remotely. The...

6.3CVSS

7.7AI Score

0.0004EPSS

2024-06-17 09:00 PM
1
wpvulndb
wpvulndb

VikRentCar Car Rental Management System < 1.3.3 - Information Exposure

Description The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.2 due to publicly accessible PDF files. This makes it possible for unauthenticated attackers to extract potentially sensitive...

5.9CVSS

6.7AI Score

0.0004EPSS

2024-04-30 12:00 AM
7
cvelist
cvelist

CVE-2024-6066 SourceCodester Best House Rental Management System payment_report.php sql injection

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. Affected is an unknown function of the file payment_report.php. The manipulation of the argument month_of leads to sql injection. It is possible to launch the attack remotely. The...

6.3CVSS

0.0004EPSS

2024-06-17 09:00 PM
1
githubexploit
githubexploit

Exploit for Improper Input Validation in Microsoft

Pachine Python implementation for CVE-2021-42278 (Active...

8.7AI Score

2021-12-13 11:15 PM
336
vulnrichment
vulnrichment

CVE-2024-6043 SourceCodester Best House Rental Management System admin_class.php login sql injection

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This affects the function login of the file admin_class.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The...

7.3CVSS

7.5AI Score

0.0004EPSS

2024-06-17 12:00 AM
cvelist
cvelist

CVE-2024-6043 SourceCodester Best House Rental Management System admin_class.php login sql injection

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This affects the function login of the file admin_class.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The...

7.3CVSS

0.0004EPSS

2024-06-17 12:00 AM
3
cvelist
cvelist

CVE-2024-3719 Campcodes House Rental Management System ajax.php sql injection

A vulnerability, which was classified as critical, was found in Campcodes House Rental Management System 1.0. This affects an unknown part of the file ajax.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been...

6.3CVSS

7AI Score

0.0004EPSS

2024-04-13 11:00 AM
2
cvelist
cvelist

CVE-2024-3697 Campcodes House Rental Management System manage_tenant.php sql injection

A vulnerability was found in Campcodes House Rental Management System 1.0. It has been classified as critical. Affected is an unknown function of the file manage_tenant.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has...

6.3CVSS

7.1AI Score

0.0004EPSS

2024-04-12 04:31 PM
vulnrichment
vulnrichment

CVE-2024-3697 Campcodes House Rental Management System manage_tenant.php sql injection

A vulnerability was found in Campcodes House Rental Management System 1.0. It has been classified as critical. Affected is an unknown function of the file manage_tenant.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has...

6.3CVSS

7.4AI Score

0.0004EPSS

2024-04-12 04:31 PM
1
githubexploit
githubexploit

Exploit for CVE-2021-1675

PrintNightmare Python implementation for PrintNightmare...

8.6AI Score

2021-09-26 01:53 PM
226
nuclei
nuclei

IceWarp Email Client - Cross Site Scripting

Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitrary code via a crafted payload to the mid...

6.1CVSS

6.4AI Score

0.088EPSS

2023-09-09 08:25 PM
2
vulnrichment
vulnrichment

CVE-2024-5363 SourceCodester Best House Rental Management System manage_user.php sql injection

A vulnerability classified as critical was found in SourceCodester Best House Rental Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely.....

6.3CVSS

7.5AI Score

0.0004EPSS

2024-05-26 12:00 PM
cvelist
cvelist

CVE-2024-5365 SourceCodester Best House Rental Management System manage_payment.php sql injection

A vulnerability, which was classified as critical, was found in SourceCodester Best House Rental Management System up to 1.0. This affects an unknown part of the file manage_payment.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The....

6.3CVSS

6.8AI Score

0.0004EPSS

2024-05-26 01:00 PM
2
vulnrichment
vulnrichment

CVE-2024-5365 SourceCodester Best House Rental Management System manage_payment.php sql injection

A vulnerability, which was classified as critical, was found in SourceCodester Best House Rental Management System up to 1.0. This affects an unknown part of the file manage_payment.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The....

6.3CVSS

7.3AI Score

0.0004EPSS

2024-05-26 01:00 PM
cvelist
cvelist

CVE-2024-5363 SourceCodester Best House Rental Management System manage_user.php sql injection

A vulnerability classified as critical was found in SourceCodester Best House Rental Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely.....

6.3CVSS

6.9AI Score

0.0004EPSS

2024-05-26 12:00 PM
cvelist
cvelist

CVE-2024-5094 SourceCodester Best House Rental Management System view_payment.php sql injection

A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as critical. This issue affects some unknown processing of the file view_payment.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has....

7.3CVSS

7.5AI Score

0.0004EPSS

2024-05-18 08:00 PM
cvelist
cvelist

CVE-2024-5364 SourceCodester Best House Rental Management System manage_tenant.php sql injection

A vulnerability, which was classified as critical, has been found in SourceCodester Best House Rental Management System up to 1.0. Affected by this issue is some unknown functionality of the file manage_tenant.php. The manipulation of the argument id leads to sql injection. The attack may be...

6.3CVSS

6.8AI Score

0.0004EPSS

2024-05-26 12:31 PM
cvelist
cvelist

CVE-2024-5093 SourceCodester Best House Rental Management System login.php sql injection

A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The...

7.3CVSS

7.5AI Score

0.0004EPSS

2024-05-18 06:31 PM
vulnrichment
vulnrichment

CVE-2024-5094 SourceCodester Best House Rental Management System view_payment.php sql injection

A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as critical. This issue affects some unknown processing of the file view_payment.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has....

7.3CVSS

7.4AI Score

0.0004EPSS

2024-05-18 08:00 PM
vulnrichment
vulnrichment

CVE-2024-5364 SourceCodester Best House Rental Management System manage_tenant.php sql injection

A vulnerability, which was classified as critical, has been found in SourceCodester Best House Rental Management System up to 1.0. Affected by this issue is some unknown functionality of the file manage_tenant.php. The manipulation of the argument id leads to sql injection. The attack may be...

6.3CVSS

7.3AI Score

0.0004EPSS

2024-05-26 12:31 PM
2
Total number of security vulnerabilities21755