Page 95 of 3547 results (0.082 seconds)

CVSS: 9.8EPSS: 0%CPEs: -EXPL: 0

SQL Injection vulnerability in Razor 0.8.0 allows a remote attacker to escalate privileges via the ChannelModel::updateapk method of the channelmodle.php Vulnerabilidad de inyección SQL en Razor 0.8.0 permite a un atacante remoto escalar privilegios a través del método ChannelModel::updateapk de channelmodle.php • https://gist.github.com/LioTree/003202727a61c0fb3ec3c948ab5e38f9 https://github.com/cobub/razor/issues/178 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 8.8EPSS: 0%CPEs: 4EXPL: 0

Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges. • https://checkmk.com/werk/16198 • CWE-272: Least Privilege Violation CWE-807: Reliance on Untrusted Inputs in a Security Decision •

CVSS: 8.2EPSS: 0%CPEs: 4EXPL: 0

Least privilege violation in the Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges. • https://checkmk.com/werk/16232 • CWE-272: Least Privilege Violation •

CVSS: 8.8EPSS: 0%CPEs: -EXPL: 0

SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the setPrice() function of the Goodsbatchset.php component. • https://chiggerlor.substack.com/p/cve-2024-28560-cve-2024-28559 https://gitee.com/niushop-team/niushop_b2c_v5 https://v5.niuteam.cn https://www.niushop.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 5.4EPSS: 0%CPEs: -EXPL: 0

SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the deleteArea() function of the Address.php component. • https://chiggerlor.substack.com/p/cve-2024-28560-cve-2024-28559 https://gitee.com/niushop-team/niushop_b2c_v5 https://v5.niuteam.cn https://www.niushop.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •