lopalopa records
112 published records for vendor lopalopa.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 22
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')54
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')27
- CWE-284 Improper Access Control14
- CWE-434 Unrestricted Upload of File with Dangerous Type5
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')3
- CWE-352 Cross-Site Request Forgery (CSRF)3
The weakness classes this vendor ships most often: where to look.
CWEAll records
112 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-40482No exploit | An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System v1.0, which allows lopalopa · live membership system · CWE-79 | Critical9.8 | — | 1.2% | Aug 12, 2024 |
39Monitor | CVE-2024-40486No exploit | A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commlopalopa · live membership system · CWE-89 | Critical9.8 | — | 1.0% | Aug 12, 2024 |
39Monitor | CVE-2024-54918No exploit | Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php.lopalopa · e-learning management system · CWE-434 | Critical9.8 | — | 0.9% | Dec 9, 2024 |
39Monitor | CVE-2024-42777No exploit | An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allolopalopa · music management system · CWE-434 | Critical9.8 | — | 0.7% | Aug 21, 2024 |
39Monitor | CVE-2024-42781No exploit | A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote attackers to executelopalopa · music management system · CWE-89 | Critical9.8 | — | 0.7% | Aug 21, 2024 |
39Monitor | CVE-2024-50833No exploit | A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the username and password palopalopa · e-learning management system · CWE-89 | Critical9.8 | — | 0.6% | Nov 14, 2024 |
39Monitor | CVE-2024-42784No exploit | A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attacker to exelopalopa · music management system · CWE-89 | Critical9.8 | — | 0.6% | Aug 21, 2024 |
39Monitor | CVE-2024-54925No exploit | A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execulopalopa · e-learning management system · CWE-89 | Critical9.8 | — | 0.6% | Dec 9, 2024 |
39Monitor | CVE-2024-54924No exploit | A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to executlopalopa · e-learning management system · CWE-89 | Critical9.8 | — | 0.6% | Dec 9, 2024 |
39Monitor | CVE-2024-54923No exploit | A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attaclopalopa · e-learning management system · CWE-89 | Critical9.8 | — | 0.6% | Dec 9, 2024 |
39Monitor | CVE-2024-54931No exploit | A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to executlopalopa · e-learning management system · CWE-89 | Critical9.8 | — | 0.6% | Dec 9, 2024 |
39Monitor | CVE-2024-54921No exploit | A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arlopalopa · e-learning management system · CWE-89 | Critical9.8 | — | 0.6% | Dec 9, 2024 |
39Monitor | CVE-2024-54920No exploit | A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackerslopalopa · e-learning management system · CWE-89 | Critical9.8 | — | 0.6% | Dec 9, 2024 |
39Monitor | CVE-2024-41237No exploit | A SQL injection vulnerability in /smsa/teacher_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to executelopalopa · responsive school management system · CWE-89 | Critical9.8 | — | 0.6% | Aug 7, 2024 |
39Monitor | CVE-2024-42797No exploit | An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0.lopalopa · music management system · CWE-284 | Critical9.8 | — | 0.6% | Sep 24, 2024 |
39Monitor | CVE-2024-54934No exploit | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php.lopalopa · e-learning management system · CWE-89 | Critical9.8 | — | 0.5% | Dec 9, 2024 |
39Monitor | CVE-2024-54932No exploit | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.lopalopa · e-learning management system · CWE-89 | Critical9.8 | — | 0.5% | Dec 9, 2024 |
39Monitor | CVE-2024-50823No exploit | A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and passwlopalopa · e-learning management system · CWE-89 | Critical9.8 | — | 0.5% | Nov 14, 2024 |
39Monitor | CVE-2024-42782No exploit | A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an attacker to executelopalopa · music management system · CWE-89 | Critical9.8 | — | 0.5% | Aug 21, 2024 |
39Monitor | CVE-2024-42783No exploit | Kashipara Music Management System v1.0 is vulnerable to SQL Injection via /music/manage_playlist_items.php.lopalopa · music management system · CWE-89 | Critical9.8 | — | 0.4% | Aug 21, 2024 |
35Monitor | CVE-2024-42780No exploit | An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management System v1.0.lopalopa · music management system · CWE-434 | High8.8 | — | 0.8% | Aug 21, 2024 |
35Monitor | CVE-2024-42778No exploit | An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System v1.0.lopalopa · music management system · CWE-434 | High8.8 | — | 0.8% | Aug 21, 2024 |
35Monitor | CVE-2024-42779No exploit | An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0.lopalopa · music management system · CWE-434 | High8.8 | — | 0.8% | Aug 21, 2024 |
35Monitor | CVE-2024-42791No exploit | A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_genrlopalopa · music management system · CWE-79 | High8.8 | — | 0.6% | Aug 26, 2024 |
35Monitor | CVE-2024-54926No exploit | A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers tlopalopa · e-learning management system · CWE-89 | High8.8 | — | 0.6% | Dec 9, 2024 |
- CVE-2024-4048239Monitor
An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System v1.0, which allows
CriticalCVSS 9.8No exploitEPSS 1%lopalopa · live membership systemAug 12, 2024
- CVE-2024-4048639Monitor
A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL comm
CriticalCVSS 9.8No exploitEPSS 1%lopalopa · live membership systemAug 12, 2024
- CVE-2024-5491839Monitor
Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php.
CriticalCVSS 9.8No exploitEPSS 1%lopalopa · e-learning management systemDec 9, 2024
- CVE-2024-4277739Monitor
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allo
CriticalCVSS 9.8No exploitEPSS 1%lopalopa · music management systemAug 21, 2024
- CVE-2024-4278139Monitor
A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote attackers to execute
CriticalCVSS 9.8No exploitEPSS 1%lopalopa · music management systemAug 21, 2024
- CVE-2024-5083339Monitor
A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the username and password pa
CriticalCVSS 9.8No exploitEPSS 1%lopalopa · e-learning management systemNov 14, 2024
- CVE-2024-4278439Monitor
A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attacker to exe
CriticalCVSS 9.8No exploitEPSS 1%lopalopa · music management systemAug 21, 2024
- CVE-2024-5492539Monitor
A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execu
CriticalCVSS 9.8No exploitEPSS 1%lopalopa · e-learning management systemDec 9, 2024
- CVE-2024-5492439Monitor
A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execut
CriticalCVSS 9.8No exploitEPSS 1%lopalopa · e-learning management systemDec 9, 2024
- CVE-2024-5492339Monitor
A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attac
CriticalCVSS 9.8No exploitEPSS 1%lopalopa · e-learning management systemDec 9, 2024
- CVE-2024-5493139Monitor
A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execut
CriticalCVSS 9.8No exploitEPSS 1%lopalopa · e-learning management systemDec 9, 2024
- CVE-2024-5492139Monitor
A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute ar
CriticalCVSS 9.8No exploitEPSS 1%lopalopa · e-learning management systemDec 9, 2024
- CVE-2024-5492039Monitor
A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers
CriticalCVSS 9.8No exploitEPSS 1%lopalopa · e-learning management systemDec 9, 2024
- CVE-2024-4123739Monitor
A SQL injection vulnerability in /smsa/teacher_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute
CriticalCVSS 9.8No exploitEPSS 1%lopalopa · responsive school management systemAug 7, 2024
- CVE-2024-4279739Monitor
An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0.
CriticalCVSS 9.8No exploitEPSS 1%lopalopa · music management systemSep 24, 2024
- CVE-2024-5493439Monitor
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php.
CriticalCVSS 9.8No exploitEPSS 1%lopalopa · e-learning management systemDec 9, 2024
- CVE-2024-5493239Monitor
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.
CriticalCVSS 9.8No exploitEPSS 1%lopalopa · e-learning management systemDec 9, 2024
- CVE-2024-5082339Monitor
A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and passw
CriticalCVSS 9.8No exploitEPSS 0%lopalopa · e-learning management systemNov 14, 2024
- CVE-2024-4278239Monitor
A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an attacker to execute
CriticalCVSS 9.8No exploitEPSS 0%lopalopa · music management systemAug 21, 2024
- CVE-2024-4278339Monitor
Kashipara Music Management System v1.0 is vulnerable to SQL Injection via /music/manage_playlist_items.php.
CriticalCVSS 9.8No exploitEPSS 0%lopalopa · music management systemAug 21, 2024
- CVE-2024-4278035Monitor
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management System v1.0.
HighCVSS 8.8No exploitEPSS 1%lopalopa · music management systemAug 21, 2024
- CVE-2024-4277835Monitor
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System v1.0.
HighCVSS 8.8No exploitEPSS 1%lopalopa · music management systemAug 21, 2024
- CVE-2024-4277935Monitor
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0.
HighCVSS 8.8No exploitEPSS 1%lopalopa · music management systemAug 21, 2024
- CVE-2024-4279135Monitor
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_genr
HighCVSS 8.8No exploitEPSS 1%lopalopa · music management systemAug 26, 2024
- CVE-2024-5492635Monitor
A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers t
HighCVSS 8.8No exploitEPSS 1%lopalopa · e-learning management systemDec 9, 2024