Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2020-37084 School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile phot… School Erp Pro No fix yet Fix from $1,9502026-02-03 CRITICAL 9.8 CVE-2020-37090 School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upl… School Erp Pro Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2020-37089 School ERP Pro 1.0 contains a SQL injection vulnerability in the 'es_messagesid' parameter that allows attackers to manipulate database queries throu… School Erp Pro Mitigation only Fix from $2,3002026-02-03 HIGH 7.5 CVE-2020-37088 School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'docume… School Erp Pro No fix yet Fix from $1,9502026-02-03 CRITICAL 9.8 CVE-2024-4824 Vulnerability in School ERP Pro+Responsive 1.0 that allows SQL injection through the '/SchoolERP/office_admin/' index in the parameters groups_id, ex… School Erp Pro\+responsive Mitigation only Fix from $2,3002024-05-14 MEDIUM 6.1 CVE-2024-4823 Vulnerability in School ERP Pro+Responsive 1.0 that allows XSS via the index '/schoolerp/office_admin/' in the parameters es_bankacc, es_bank_name, e… School Erp Pro\+responsive Mitigation only Fix from $1,6002024-05-14 MEDIUM 6.1 CVE-2024-4822 Vulnerability in School ERP Pro+Responsive 1.0 that allows XSS via the username and password parameters in '/index.php'. This vulnerability allows an… School Erp Pro\+responsive Mitigation only Fix from $1,6002024-05-14 HIGH 8.8 CVE-2022-32119 Arox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo function at photogalleries.inc.ph… School Erp Pro Mitigation only Fix from $1,9502022-07-15 MEDIUM 6.1 CVE-2022-32118 Arox School ERP Pro v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the dispatchcategory parameter in backoffice.inc.ph… School Erp Pro No fix yet Fix from $1,6002022-07-15 CRITICAL 9.8 CVE-2019-13294EPSS 19% AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthentic… School Erp No fix yet Fix from $2,3002019-07-04 CRITICAL 9.8 CVE-2017-15978 AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter. School Erp Php Script No fix yet Fix from $2,3002017-10-31