Vulnerabilities (CVE)

Filtered by CWE-89
Total 18642 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-7373 1 Oretnom23 1 Simple Realtime Quiz System 2024-08-07 6.5 MEDIUM 8.8 HIGH
A vulnerability classified as critical has been found in SourceCodester Simple Realtime Quiz System 1.0. This affects an unknown part of the file /ajax.php?action=load_answered. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273357 was assigned to this vulnerability.
CVE-2024-33974 1 Janobe 2 School Attendence Monitoring System, School Event Management System 2024-08-07 N/A 9.8 CRITICAL
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Users in '/report/printlogs.php' parameter.