A vulnerability was found in erjemin roll_cms up to 1484fe2c4e0805946a7bcf46218509fcb34883a9. It has been classified as problematic. This affects an unknown part of the file roll_cms/roll_cms/views.py. The manipulation leads to information exposure through error message.
This vulnerability is uniquely identified as CVE-2024-8571. The attack needs to be approached within the local network. There is no exploit available.
This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /inccatadd.php. The manipulation of the argument title leads to sql injection.
This vulnerability is handled as CVE-2024-8570. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability has been found in code-projects Hospital Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file user-login.php. The manipulation of the argument username leads to sql injection.
This vulnerability is known as CVE-2024-8569. The attack can be launched remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, was found in Mini-Tmall up to 20240901. Affected is the function rewardMapper.select of the file tmall/admin/order/1/1. The manipulation of the argument orderBy leads to sql injection.
This vulnerability is traded as CVE-2024-8568. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as critical, has been found in itsourcecode Payroll Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_deductions. The manipulation of the argument id leads to sql injection.
The identification of this vulnerability is CVE-2024-8567. The attack may be initiated remotely. Furthermore, there is an exploit available.
A vulnerability classified as problematic was found in code-projects Online Shop Store 1.0. This vulnerability affects unknown code of the file /settings.php. The manipulation of the argument error leads to cross site scripting.
This vulnerability was named CVE-2024-8566. The attack can be initiated remotely. Furthermore, there is an exploit available.
A vulnerability classified as problematic has been found in Ninja Forms File Uploads Plugin up to 3.3.16 on WordPress. This affects an unknown part of the component File Upload. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-1596. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in Customizer Export Import Plugin up to 0.9.7 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Setting Import Handler. The manipulation leads to unrestricted upload.
This vulnerability is handled as CVE-2024-7620. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in Preloader Plus Plugin up to 2.2.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-6849. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in Pinpoint Booking System Plugin up to 2.9.9.5.0 on WordPress. It has been classified as critical. Affected is an unknown function. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2024-7112. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in Cost Calculator Builder Pro Plugin up to 3.1.96 on WordPress and classified as critical. This issue affects some unknown processing. The manipulation leads to improper authorization.
The identification of this vulnerability is CVE-2024-6010. The attack may be initiated remotely. There is no exploit available.