lopalopa kayıtları
lopalopa üreticisine ait 112 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 22
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')54
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')27
- CWE-284 Improper Access Control14
- CWE-434 Unrestricted Upload of File with Dangerous Type5
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')3
- CWE-352 Cross-Site Request Forgery (CSRF)3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
112 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-40482İstismar yok | An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System v1.0, which allows lopalopa · live membership system · CWE-79 | Kritik9,8 | — | %1,2 | 12 Ağu 2024 |
39İzleyin | CVE-2024-40486İstismar yok | A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commlopalopa · live membership system · CWE-89 | Kritik9,8 | — | %1,0 | 12 Ağu 2024 |
39İzleyin | CVE-2024-54918İstismar yok | Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php.lopalopa · e-learning management system · CWE-434 | Kritik9,8 | — | %0,9 | 9 Ara 2024 |
39İzleyin | CVE-2024-42777İstismar yok | An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allolopalopa · music management system · CWE-434 | Kritik9,8 | — | %0,7 | 21 Ağu 2024 |
39İzleyin | CVE-2024-42781İstismar yok | A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote attackers to executelopalopa · music management system · CWE-89 | Kritik9,8 | — | %0,7 | 21 Ağu 2024 |
39İzleyin | CVE-2024-50833İstismar yok | A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the username and password palopalopa · e-learning management system · CWE-89 | Kritik9,8 | — | %0,6 | 14 Kas 2024 |
39İzleyin | CVE-2024-42784İstismar yok | A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attacker to exelopalopa · music management system · CWE-89 | Kritik9,8 | — | %0,6 | 21 Ağu 2024 |
39İzleyin | CVE-2024-54925İstismar yok | A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execulopalopa · e-learning management system · CWE-89 | Kritik9,8 | — | %0,6 | 9 Ara 2024 |
39İzleyin | CVE-2024-54924İstismar yok | A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to executlopalopa · e-learning management system · CWE-89 | Kritik9,8 | — | %0,6 | 9 Ara 2024 |
39İzleyin | CVE-2024-54923İstismar yok | A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attaclopalopa · e-learning management system · CWE-89 | Kritik9,8 | — | %0,6 | 9 Ara 2024 |
39İzleyin | CVE-2024-54931İstismar yok | A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to executlopalopa · e-learning management system · CWE-89 | Kritik9,8 | — | %0,6 | 9 Ara 2024 |
39İzleyin | CVE-2024-54921İstismar yok | A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arlopalopa · e-learning management system · CWE-89 | Kritik9,8 | — | %0,6 | 9 Ara 2024 |
39İzleyin | CVE-2024-54920İstismar yok | A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackerslopalopa · e-learning management system · CWE-89 | Kritik9,8 | — | %0,6 | 9 Ara 2024 |
39İzleyin | CVE-2024-41237İstismar yok | A SQL injection vulnerability in /smsa/teacher_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to executelopalopa · responsive school management system · CWE-89 | Kritik9,8 | — | %0,6 | 7 Ağu 2024 |
39İzleyin | CVE-2024-42797İstismar yok | An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0.lopalopa · music management system · CWE-284 | Kritik9,8 | — | %0,6 | 24 Eyl 2024 |
39İzleyin | CVE-2024-54934İstismar yok | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php.lopalopa · e-learning management system · CWE-89 | Kritik9,8 | — | %0,5 | 9 Ara 2024 |
39İzleyin | CVE-2024-54932İstismar yok | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.lopalopa · e-learning management system · CWE-89 | Kritik9,8 | — | %0,5 | 9 Ara 2024 |
39İzleyin | CVE-2024-50823İstismar yok | A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and passwlopalopa · e-learning management system · CWE-89 | Kritik9,8 | — | %0,5 | 14 Kas 2024 |
39İzleyin | CVE-2024-42782İstismar yok | A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an attacker to executelopalopa · music management system · CWE-89 | Kritik9,8 | — | %0,5 | 21 Ağu 2024 |
39İzleyin | CVE-2024-42783İstismar yok | Kashipara Music Management System v1.0 is vulnerable to SQL Injection via /music/manage_playlist_items.php.lopalopa · music management system · CWE-89 | Kritik9,8 | — | %0,4 | 21 Ağu 2024 |
35İzleyin | CVE-2024-42780İstismar yok | An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management System v1.0.lopalopa · music management system · CWE-434 | Yüksek8,8 | — | %0,8 | 21 Ağu 2024 |
35İzleyin | CVE-2024-42778İstismar yok | An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System v1.0.lopalopa · music management system · CWE-434 | Yüksek8,8 | — | %0,8 | 21 Ağu 2024 |
35İzleyin | CVE-2024-42779İstismar yok | An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0.lopalopa · music management system · CWE-434 | Yüksek8,8 | — | %0,8 | 21 Ağu 2024 |
35İzleyin | CVE-2024-42791İstismar yok | A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_genrlopalopa · music management system · CWE-79 | Yüksek8,8 | — | %0,6 | 26 Ağu 2024 |
35İzleyin | CVE-2024-54926İstismar yok | A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers tlopalopa · e-learning management system · CWE-89 | Yüksek8,8 | — | %0,6 | 9 Ara 2024 |
- CVE-2024-4048239İzleyin
An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System v1.0, which allows
KritikCVSS 9,8İstismar yokEPSS %1lopalopa · live membership system12 Ağu 2024
- CVE-2024-4048639İzleyin
A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL comm
KritikCVSS 9,8İstismar yokEPSS %1lopalopa · live membership system12 Ağu 2024
- CVE-2024-5491839İzleyin
Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php.
KritikCVSS 9,8İstismar yokEPSS %1lopalopa · e-learning management system9 Ara 2024
- CVE-2024-4277739İzleyin
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allo
KritikCVSS 9,8İstismar yokEPSS %1lopalopa · music management system21 Ağu 2024
- CVE-2024-4278139İzleyin
A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote attackers to execute
KritikCVSS 9,8İstismar yokEPSS %1lopalopa · music management system21 Ağu 2024
- CVE-2024-5083339İzleyin
A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the username and password pa
KritikCVSS 9,8İstismar yokEPSS %1lopalopa · e-learning management system14 Kas 2024
- CVE-2024-4278439İzleyin
A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attacker to exe
KritikCVSS 9,8İstismar yokEPSS %1lopalopa · music management system21 Ağu 2024
- CVE-2024-5492539İzleyin
A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execu
KritikCVSS 9,8İstismar yokEPSS %1lopalopa · e-learning management system9 Ara 2024
- CVE-2024-5492439İzleyin
A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execut
KritikCVSS 9,8İstismar yokEPSS %1lopalopa · e-learning management system9 Ara 2024
- CVE-2024-5492339İzleyin
A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attac
KritikCVSS 9,8İstismar yokEPSS %1lopalopa · e-learning management system9 Ara 2024
- CVE-2024-5493139İzleyin
A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execut
KritikCVSS 9,8İstismar yokEPSS %1lopalopa · e-learning management system9 Ara 2024
- CVE-2024-5492139İzleyin
A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute ar
KritikCVSS 9,8İstismar yokEPSS %1lopalopa · e-learning management system9 Ara 2024
- CVE-2024-5492039İzleyin
A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers
KritikCVSS 9,8İstismar yokEPSS %1lopalopa · e-learning management system9 Ara 2024
- CVE-2024-4123739İzleyin
A SQL injection vulnerability in /smsa/teacher_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute
KritikCVSS 9,8İstismar yokEPSS %1lopalopa · responsive school management system7 Ağu 2024
- CVE-2024-4279739İzleyin
An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0.
KritikCVSS 9,8İstismar yokEPSS %1lopalopa · music management system24 Eyl 2024
- CVE-2024-5493439İzleyin
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php.
KritikCVSS 9,8İstismar yokEPSS %1lopalopa · e-learning management system9 Ara 2024
- CVE-2024-5493239İzleyin
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.
KritikCVSS 9,8İstismar yokEPSS %1lopalopa · e-learning management system9 Ara 2024
- CVE-2024-5082339İzleyin
A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and passw
KritikCVSS 9,8İstismar yokEPSS %0lopalopa · e-learning management system14 Kas 2024
- CVE-2024-4278239İzleyin
A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an attacker to execute
KritikCVSS 9,8İstismar yokEPSS %0lopalopa · music management system21 Ağu 2024
- CVE-2024-4278339İzleyin
Kashipara Music Management System v1.0 is vulnerable to SQL Injection via /music/manage_playlist_items.php.
KritikCVSS 9,8İstismar yokEPSS %0lopalopa · music management system21 Ağu 2024
- CVE-2024-4278035İzleyin
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management System v1.0.
YüksekCVSS 8,8İstismar yokEPSS %1lopalopa · music management system21 Ağu 2024
- CVE-2024-4277835İzleyin
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System v1.0.
YüksekCVSS 8,8İstismar yokEPSS %1lopalopa · music management system21 Ağu 2024
- CVE-2024-4277935İzleyin
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0.
YüksekCVSS 8,8İstismar yokEPSS %1lopalopa · music management system21 Ağu 2024
- CVE-2024-4279135İzleyin
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_genr
YüksekCVSS 8,8İstismar yokEPSS %1lopalopa · music management system26 Ağu 2024
- CVE-2024-5492635İzleyin
A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers t
YüksekCVSS 8,8İstismar yokEPSS %1lopalopa · e-learning management system9 Ara 2024