Latest CVE Feed
-
7.1
HIGHCVE-2024-33990
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser... Read more
Affected Products : school_event_management_system- Published: Aug. 06, 2024
- Modified: Aug. 15, 2024
-
7.1
HIGHCVE-2024-33989
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser... Read more
Affected Products : school_event_management_system- Published: Aug. 06, 2024
- Modified: Aug. 15, 2024
-
7.1
HIGHCVE-2024-33985
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie vi... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 15, 2024
-
7.1
HIGHCVE-2024-33986
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie vi... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 15, 2024
-
7.1
HIGHCVE-2024-33987
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie vi... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 15, 2024
-
7.1
HIGHCVE-2024-33988
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie vi... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 15, 2024
-
7.1
HIGHCVE-2024-33984
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie vi... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 15, 2024
-
7.1
HIGHCVE-2024-33983
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie vi... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 15, 2024
-
7.1
HIGHCVE-2024-33982
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie vi... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 15, 2024
-
7.1
HIGHCVE-2024-33978
Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session cookie details via 'category' parameter in '/index.php'.... Read more
Affected Products : young_entrepreneur_e-negosyo_system- Published: Aug. 06, 2024
- Modified: Aug. 15, 2024
-
7.1
HIGHCVE-2024-33977
Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session cookie details via 'view' parameter in /admin/orders/index.php'.... Read more
Affected Products : young_entrepreneur_e-negosyo_system- Published: Aug. 06, 2024
- Modified: Aug. 15, 2024
-
7.1
HIGHCVE-2024-33976
Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially take over their browser session via '... Read more
Affected Products : young_entrepreneur_e-negosyo_system- Published: Aug. 06, 2024
- Modified: Aug. 15, 2024
-
7.1
HIGHCVE-2024-33975
Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially take over their browser session via '... Read more
Affected Products : young_entrepreneur_e-negosyo_system- Published: Aug. 06, 2024
- Modified: Aug. 15, 2024
-
9.8
CRITICALCVE-2024-33958
SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in 'phonenumber' in '/passwordrecover.php' param... Read more
Affected Products : young_entrepreneur_e-negosyo_system- Published: Aug. 06, 2024
- Modified: Aug. 15, 2024
-
5.5
MEDIUMCVE-2024-34118
Illustrator versions 28.5, 27.9.4 and earlier are affected by an Improper Input Validation vulnerability that could lead to an application denial-of-service condition. An attacker could exploit this vulnerability to render the application unresponsive or ... Read more
- Published: Aug. 14, 2024
- Modified: Aug. 15, 2024
-
7.8
HIGHCVE-2024-34133
Illustrator versions 28.5, 27.9.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must... Read more
- Published: Aug. 14, 2024
- Modified: Aug. 15, 2024
-
5.5
MEDIUMCVE-2024-34135
Illustrator versions 28.5, 27.9.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this iss... Read more
- Published: Aug. 14, 2024
- Modified: Aug. 15, 2024
-
9.8
CRITICALCVE-2024-33957
SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in 'id' in '/admin/orders/controller.php' parame... Read more
Affected Products : young_entrepreneur_e-negosyo_system- Published: Aug. 06, 2024
- Modified: Aug. 15, 2024
-
5.5
MEDIUMCVE-2024-34136
Illustrator versions 28.5, 27.9.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS). An attacker could exploit this vulnerability to crash the application, resulting in a denial ... Read more
- Published: Aug. 14, 2024
- Modified: Aug. 15, 2024
-
5.5
MEDIUMCVE-2024-34137
Illustrator versions 28.5, 27.9.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS) condition. An attacker could exploit this vulnerability to crash the application, resulting in... Read more
- Published: Aug. 14, 2024
- Modified: Aug. 15, 2024