Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In May 2024
An arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a crafted .jsp file.
CVSS Score
9.8
EPSS Score
0.003
Published
2024-05-23
An arbitrary file upload vulnerability in the gok4 method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a crafted .jsp file.
CVSS Score
9.8
EPSS Score
0.003
Published
2024-05-23
There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS
CVSS Score
9.8
EPSS Score
0.001
Published
2024-05-23
An arbitrary file upload vulnerability in the component \controller\ImageUploadController.class of inxedu v2.0.6 allows attackers to execute arbitrary code via uploading a crafted jsp file.
CVSS Score
9.8
EPSS Score
0.017
Published
2024-05-23
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysUreportFileMapper.xml.
CVSS Score
8.2
EPSS Score
0.001
Published
2024-05-23
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysTenantMapper.xml.
CVSS Score
9.8
EPSS Score
0.001
Published
2024-05-23
A SQL injection vulnerability in /model/update_exam.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.
CVSS Score
9.8
EPSS Score
0.001
Published
2024-05-23
A SQL injection vulnerability in /model/update_grade.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the admission_fee parameter.
CVSS Score
6.3
EPSS Score
0.001
Published
2024-05-23
A SQL injection vulnerability in /view/emarks_range_grade_update_form.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id parameter.
CVSS Score
9.8
EPSS Score
0.001
Published
2024-05-23
A SQL injection vulnerability in /view/conversation_history_admin.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id parameter.
CVSS Score
9.8
EPSS Score
0.001
Published
2024-05-23


Contact Us

Shodan ® - All rights reserved