Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In May 2024
Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.
CVSS Score
8.8
EPSS Score
0.002
Published
2024-05-14
Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.
CVSS Score
5.9
EPSS Score
0.0
Published
2024-05-14
Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow attackers to approve or reject leave ticket.
CVSS Score
4.3
EPSS Score
0.002
Published
2024-05-14
Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the firstname, middlename, lastname parameters.
CVSS Score
7.3
EPSS Score
0.008
Published
2024-05-14
Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the name, shortname parameters.
CVSS Score
6.1
EPSS Score
0.003
Published
2024-05-14
SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&id=1 in SourceCodester Visitor Management System 1.0 allow attackers to execute arbitrary SQL commands via the id parameters.
CVSS Score
9.4
EPSS Score
0.002
Published
2024-05-14
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the CloudACMunualUpdate function.
CVSS Score
7.3
EPSS Score
0.004
Published
2024-05-14
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the SetPortForwardRules function.
CVSS Score
9.8
EPSS Score
0.005
Published
2024-05-14
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setUrlFilterRules function.
CVSS Score
7.3
EPSS Score
0.004
Published
2024-05-14
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the addWlProfileClientMode function.
CVSS Score
7.7
EPSS Score
0.005
Published
2024-05-14


Contact Us

Shodan ® - All rights reserved