Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In May 2024
An arbitrary file upload vulnerability in the component \controller\ImageUploadController.class of inxedu v2.0.6 allows attackers to execute arbitrary code via uploading a crafted jsp file.
CVSS Score
9.8
EPSS Score
0.016
Published
2024-05-23
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysUreportFileMapper.xml.
CVSS Score
8.2
EPSS Score
0.002
Published
2024-05-23
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysTenantMapper.xml.
CVSS Score
9.8
EPSS Score
0.002
Published
2024-05-23
A SQL injection vulnerability in /model/update_exam.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.
CVSS Score
9.8
EPSS Score
0.002
Published
2024-05-23
A SQL injection vulnerability in /model/update_grade.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the admission_fee parameter.
CVSS Score
6.3
EPSS Score
0.001
Published
2024-05-23
A SQL injection vulnerability in /view/emarks_range_grade_update_form.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id parameter.
CVSS Score
9.8
EPSS Score
0.002
Published
2024-05-23
A SQL injection vulnerability in /view/conversation_history_admin.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id parameter.
CVSS Score
9.8
EPSS Score
0.002
Published
2024-05-23
A SQL injection vulnerability in /view/event1.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the month parameter.
CVSS Score
8.6
EPSS Score
0.001
Published
2024-05-23
LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter in the fileDownload method.
CVSS Score
7.5
EPSS Score
0.003
Published
2024-05-23
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysOperLogMapper.xml.
CVSS Score
6.3
EPSS Score
0.001
Published
2024-05-23


Contact Us

Shodan ® - All rights reserved