CVE-2021-45788 Time-based SQL Injection was found in Metersphere v1.15.4 via the "orders" parameter.
A Cross-site scripting vulnerability was found in X-Rite’s iColor Passport v3.2.2 via the "password" parameter.
A SQL Injection was found
CVE-2022-34394 Dell OS10.5.3.4 contains an Improper Certificate Validation vulnerability in Support Assist. An attacker could exploit this vulnerability to access switch configuration data.
The vulnerable component of Dell Support Assist is accessible via the web interface (port 443). While default port configuration of the web interface (443) is
CVE-2022-3332 A critical vulnerability has been found in SourceCodester Food Ordering Management System affecting POST Parameter Handler.
The researcher who discovered this problem has published a detailed report about it. The researcher has publicly disclosed this information so that it is known.
CVE-2022-40354 The v1.0 of the Tours & Travels Management System was found to have a SQL injection vulnerability.
An attacker can inject malicious code to run arbitrary SQL commands. This vulnerability can be exploited by hackers to compromise the system, obtain sensitive information
CVE-2022-40878 Exam Reviewer Management System 1.0 allows an attacker to upload a web-shell php file and achieve RCE.
An attacker can do this by setting up a fake facebook account or by manipulating the system to access the system’s data. By uploading
Episode
00:00:00
00:00:00