A vulnerability classified as problematic was found in Icon Time Systems RTC-1000 up to 2.5.7458. Affected by this vulnerability is an unknown functionality of the file /employee.html. The manipulation leads to cross site scripting (Reflected).
This vulnerability is known as CVE-2017-16819. The attack can be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in XD Forum 3.9.17. It has been rated as critical. Affected by this issue is some unknown functionality of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is handled as CVE-2014-6740. The attack needs to be initiated within the local network. There is no exploit available.
A vulnerability was found in healthways Well-Being Connect Mobile 2.9. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is known as CVE-2014-6739. The attack needs to be done within the local network. There is no exploit available.
A vulnerability, which was classified as critical, has been found in TutorialCMS. This issue affects some unknown processing of the file topFrame.php. The manipulation of the argument id leads to sql injection.
The identification of this vulnerability is CVE-2007-2599. The attack may be initiated remotely. Furthermore, there is an exploit available.
A vulnerability was found in Joungouapps Maccabi Tel Aviv 1. It has been classified as critical. Affected is an unknown function of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is traded as CVE-2014-6738. The attack can only be initiated within the local network. There is no exploit available.
A vulnerability has been found in D-LINK DKVM-IP8 2282 Dlinka4 P8 20071213 and classified as problematic. This vulnerability affects unknown code of the file auth.asp. The manipulation of the argument nickname leads to cross site scripting.
This vulnerability was named CVE-2010-0936. The attack can be initiated remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical has been found in TOTOLINK A720R 4.1.5. Affected is the function exportOvpn. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2024-8869. It is possible to launch the attack remotely. There is no exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Ultimate Target-Armored Sniper 1.0.1 and classified as critical. This issue affects some unknown processing of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
The identification of this vulnerability is CVE-2014-6737. The attack can only be done within the local network. There is no exploit available.
A vulnerability has been found in 9jacompass EPL Hat Trick 1 and classified as critical. This vulnerability affects unknown code of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability was named CVE-2014-6736. The attack needs to be approached within the local network. There is no exploit available.
A vulnerability was found in JFinalCMS up to 1.0. It has been rated as critical. This issue affects the function delete of the file /admin/template/edit. The manipulation of the argument name leads to path traversal.
The identification of this vulnerability is CVE-2024-8782. The attack may be initiated remotely. Furthermore, there is an exploit available.
A vulnerability was found in FOX Plugin up to 1.4.2.1 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality of the component Shortcode Handler. The manipulation leads to code injection.
This vulnerability is handled as CVE-2024-8271. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as critical has been found in WooCommerce Multiple Free Gift Plugin up to 1.2.3 on WordPress. This affects an unknown part. The manipulation leads to improper authorization.
This vulnerability is uniquely identified as CVE-2022-3459. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in Simple Spoiler Plugin 1.2/1.3 on WordPress. It has been rated as critical. This issue affects some unknown processing of the component Shortcode Handler. The manipulation leads to code injection.
The identification of this vulnerability is CVE-2024-8479. The attack may be initiated remotely. There is no exploit available.
A vulnerability classified as critical was found in Backuply Plugin up to 1.3.4 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection.
This vulnerability is known as CVE-2024-8669. The attack can be launched remotely. There is no exploit available.
A vulnerability classified as critical has been found in Login with Phone Number Plugin up to 1.7.49 on WordPress. This affects an unknown part. The manipulation leads to authorization bypass.
This vulnerability is uniquely identified as CVE-2024-6482. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as critical was found in QDocs Smart School Management System 7.0.0. Affected by this vulnerability is an unknown functionality of the file /user/chat/mynewuser of the component Chat. The manipulation of the argument users[] with the input 1'+AND+(SELECT+3220+FROM+(SELECT(SLEEP(5)))ZNun)+AND+'WwBM'%3d'WwBM as part of POST Request Parameter leads to sql injection.
This vulnerability is known as CVE-2024-8784. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.