Vulnerabilities (CVE)

Total 396574 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-34936 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 8.6 HIGH
A SQL injection vulnerability in /view/event1.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the month parameter.
CVE-2024-34935 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /view/conversation_history_admin.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id parameter.
CVE-2024-34934 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /view/emarks_range_grade_update_form.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id parameter.
CVE-2024-34933 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 6.3 MEDIUM
A SQL injection vulnerability in /model/update_grade.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the admission_fee parameter.
CVE-2024-34932 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /model/update_exam.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.
CVE-2024-34931 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /model/update_subject.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.
CVE-2024-34930 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 5.3 MEDIUM
A SQL injection vulnerability in /model/all_events1.php in Campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the month parameter.
CVE-2024-34929 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /view/find_friends.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the my_index parameter.
CVE-2024-34928 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 7.3 HIGH
A SQL injection vulnerability in /model/update_subject_routing.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the grade parameter.
CVE-2024-34927 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /model/update_classroom.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.
CVE-2024-34923 2026-06-17 N/A 6.1 MEDIUM
In Avocent DSR2030 Appliance firmware 03.04.00.07 before 03.07.01.23, and SVIP1020 Appliance firmware 01.06.00.03 before 01.07.00.00, there is reflected cross-site scripting (XSS).
CVE-2024-34921 1 Totolink 2 X5000r, X5000r Firmware 2026-06-17 N/A 8.8 HIGH
TOTOLINK X5000R v9.1.0cu.2350_B20230313 was discovered to contain a command injection via the disconnectVPN function.
CVE-2024-34919 2026-06-17 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the component \modstudent\controller.php of Pisay Online E-Learning System using PHP/MySQL v1.0 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-34914 2026-06-17 N/A 5.3 MEDIUM
php-censor v2.1.4 and fixed in v.2.1.5 was discovered to utilize a weak hashing algorithm for its remember_key value. This allows attackers to bruteforce to bruteforce the remember_key value to gain access to accounts that have checked "remember me" when logging in.
CVE-2024-34913 1 Technocking 1 R-pan-scaffolding 2026-06-17 N/A 5.4 MEDIUM
An arbitrary file upload vulnerability in r-pan-scaffolding v5.0 and below allows attackers to execute arbitrary code via uploading a crafted PDF file.
CVE-2024-34909 1 Kykms 1 Kykms 2026-06-17 N/A 5.4 MEDIUM
An arbitrary file upload vulnerability in KYKMS v1.0.1 and below allows attackers to execute arbitrary code via uploading a crafted PDF file.
CVE-2024-34906 1 Dootask 1 Dootask 2026-06-17 N/A 5.4 MEDIUM
An arbitrary file upload vulnerability in dootask v0.30.13 allows attackers to execute arbitrary code via uploading a crafted PDF file.
CVE-2024-34905 1 Cloudwise 1 Flyfish 2026-06-17 N/A 7.5 HIGH
FlyFish v3.0.0 was discovered to contain a buffer overflow via the password parameter on the login page. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2024-34899 1 Wwbn 1 Avideo 2026-06-17 N/A 5.4 MEDIUM
WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS).
CVE-2024-34854 1 F-logic 2 Datacube3, Datacube3 Firmware 2026-06-17 N/A 9.8 CRITICAL
F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.`