jayesh 漏洞與 CVE 列表(18)

產品(CPE): — CVE 數: 18

jayesh 漏洞概覽

彙總 jayesh 相關全部產品的 CVE 與安全漏洞情報,包括 CVSS、EPSS、公開時間與漏洞情報資料。

已披露問題常與 跨站腳本、SQL 注入與CSRF 相關,可能在 生產負載與軟體部署 場景中帶來 工作階段劫持與資料外洩 等暴露風險。

相關漏洞資料主要來源於公開漏洞披露與安全公告,可用於評估歷史漏洞暴露面與修補優先順序。

漏洞分布趨勢(近 24 個月)

顯示 11818 CVE 數
«« 第一頁 « 上一頁 第 1 / 1 頁 下一頁 »
CVE 摘要 來源 最高 CVSS EPSS % 公開時間 更新時間
CVE-2025-51567 A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the rname, rcollage, rnumber, rgender and rpassword parameters in a POST HTTP request. [email protected] 9.1 0.35% 2026-01-12 2026-01-16
CVE-2024-42773 An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to edit the valid hotel room entries in the administrator section. [email protected] 9.1 0.49% 2024-08-22 2025-04-30
CVE-2024-42767 Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php. [email protected] 7.2 0.58% 2024-08-22 2025-04-30
CVE-2024-42776 Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php. [email protected] 7.2 0.53% 2024-08-22 2025-04-30
CVE-2024-42775 An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room entries in the administrator section via the direct URL access. [email protected] 9.1 0.48% 2024-08-22 2025-04-30
CVE-2024-42774 An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to delete valid hotel room entries in the administrator section. [email protected] 7.5 0.41% 2024-08-22 2025-04-30
CVE-2024-42772 An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to view valid hotel room entries in administrator section. [email protected] 7.5 0.48% 2024-08-22 2025-04-30
CVE-2024-42768 A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_room.php. [email protected] 6.8 0.17% 2024-08-22 2025-04-30
CVE-2024-42771 A Stored Cross Site Scripting (XSS) vulnerability was found in " /admin/edit_room_controller.php" of the Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "room_name" parameter. [email protected] 4.8 0.42% 2024-08-22 2025-04-30
CVE-2024-42770 A Stored Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php" of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via the "user_email" parameter. [email protected] 4.7 0.48% 2024-08-22 2025-04-30
CVE-2024-42769 A Reflected Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php " of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "user_fname" and "user_lname" parameters. [email protected] 6.1 0.37% 2024-08-22 2025-04-30
CVE-2024-40480 A Broken Access Control vulnerability was found in /admin/update.php and /admin/dashboard.php in Kashipara Online Exam System v1.0, which allows remote unauthenticated attackers to view administrator dashboard and delete valid user accounts via the direct URL access. [email protected] 9.8 0.53% 2024-08-12 2025-03-14
CVE-2024-40479 A SQL injection vulnerability in "/admin/quizquestion.php" in Kashipara Online Exam System v1.0 allows remote attackers to execute arbitrary SQL commands via the "eid" parameter. [email protected] 8.1 0.80% 2024-08-12 2025-11-19
CVE-2024-40478 A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin/afeedback.php" in Kashipara Online Exam System v1.0, which allows remote attackers to execute arbitrary code via "rname" and "email" parameter fields [email protected] 5.4 0.60% 2024-08-12 2025-03-13
CVE-2023-49272 Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'children' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response. [email protected] 5.4 0.37% 2023-12-20 2025-12-05
CVE-2023-49271 Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_out_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response. [email protected] 5.4 0.38% 2023-12-20 2026-01-06
CVE-2023-49270 Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_in_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response. [email protected] 5.4 0.38% 2023-12-20 2026-01-06
CVE-2023-49269 Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'adults' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response. [email protected] 5.4 0.37% 2023-12-20 2026-01-06
«« 第一頁 « 上一頁 第 1 / 1 頁 下一頁 »
cvelogic Threat Intelligence