Vulnerabilities (CVE)

Total 395814 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-42582 1 Siamonhasan 1 Warehouse Inventory System 2026-06-17 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in the component delete_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
CVE-2024-42581 1 Siamonhasan 1 Warehouse Inventory System 2026-06-17 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in the component delete_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
CVE-2024-42580 1 Siamonhasan 1 Warehouse Inventory System 2026-06-17 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in the component edit_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
CVE-2024-42579 1 Siamonhasan 1 Warehouse Inventory System 2026-06-17 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in the component add_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
CVE-2024-42578 1 Siamonhasan 1 Warehouse Inventory System 2026-06-17 N/A 8.0 HIGH
A Cross-Site Request Forgery (CSRF) in the component edit_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
CVE-2024-42577 1 Siamonhasan 1 Warehouse Inventory System 2026-06-17 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in the component add_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
CVE-2024-42576 1 Siamonhasan 1 Warehouse Inventory System 2026-06-17 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in the component edit_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
CVE-2024-42575 1 Arajajyothibabu 1 School Management System 2026-06-17 N/A 9.8 CRITICAL
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at substaff.php.
CVE-2024-42574 1 Arajajyothibabu 1 School Management System 2026-06-17 N/A 9.8 CRITICAL
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at attendance.php.
CVE-2024-42573 1 Arajajyothibabu 1 School Management System 2026-06-17 N/A 9.8 CRITICAL
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at dtmarks.php.
CVE-2024-42572 1 Arajajyothibabu 1 School Management System 2026-06-17 N/A 9.8 CRITICAL
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at unitmarks.php.
CVE-2024-42571 1 Arajajyothibabu 1 School Management System 2026-06-17 N/A 9.8 CRITICAL
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at insertattendance.php.
CVE-2024-42570 1 Arajajyothibabu 1 School Management System 2026-06-17 N/A 9.8 CRITICAL
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at admininsert.php.
CVE-2024-42569 1 Arajajyothibabu 1 School Management System 2026-06-17 N/A 9.8 CRITICAL
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at paidclass.php.
CVE-2024-42568 1 Arajajyothibabu 1 School Management System 2026-06-17 N/A 9.8 CRITICAL
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the transport parameter at vehicle.php.
CVE-2024-42567 1 Arajajyothibabu 1 School Management System 2026-06-17 N/A 9.8 CRITICAL
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the sid parameter at /search.php?action=2.
CVE-2024-42566 1 Arajajyothibabu 1 School Management System 2026-06-17 N/A 9.8 CRITICAL
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the password parameter at login.php
CVE-2024-42565 1 Jerryhanjj 1 Erp 2026-06-17 N/A 9.8 CRITICAL
ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/contact/delete?action=delete.
CVE-2024-42564 1 Jerryhanjj 1 Erp 2026-06-17 N/A 7.6 HIGH
ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/inventory/delete?action=delete.
CVE-2024-42563 1 Jerryhanjj 1 Erp 2026-06-17 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file.