Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

User Registration And Login System With Admin Panel CRITICAL 9.8
CVE-2021-44096

EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a…

No fix yet
Fix from $2,300 2022-06-02
Expense Management System CRITICAL 9.8
CVE-2021-44098

EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Appl…

No fix yet
Fix from $2,300 2022-06-02
Phpcrud MEDIUM 5.4
CVE-2020-36115

Stored Cross Site Scripting (XSS) vulnerability in EGavilan Media CRUD Operation with PHP, MySQL, Bootstrap, and Dompdf via First Name or Last Name p…

No fix yet
Fix from $1,600 2021-01-28
User Registration And Login System With Admin Panel CRITICAL 9.8
CVE-2020-35263

EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.

No fix yet
Fix from $2,300 2021-01-26
User Registration And Login System With Admin Panel HIGH 7.5
CVE-2020-29228

EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.

No fix yet
Fix from $1,950 2020-12-30
User Registration And Login System With Admin Panel MEDIUM 6.1
CVE-2020-29230

EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab …

No fix yet
Fix from $1,600 2020-12-30
User Registration And Login System With Admin Panel MEDIUM 5.4
CVE-2020-29231

EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page. This vulne…

No fix yet
Fix from $1,600 2020-12-30
Under Construction Page With Cpanel CRITICAL 9.8
CVE-2020-29472

EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using maliciou…

No fix yet
Fix from $2,300 2020-12-24
Egm Address Book CRITICAL 9.8
CVE-2020-29474

EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection que…

No fix yet
Fix from $2,300 2020-12-24
User Registration And Login System With Admin Panel MEDIUM 6.1
CVE-2020-35252

Cross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registration & Login System with Admi…

No fix yet
Fix from $1,600 2020-12-23
Ecm Address Book CRITICAL 9.8
CVE-2020-35276

EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and a…

Mitigation only
Fix from $2,300 2020-12-21
User Registration \& Login System With Admin Panel HIGH 8.0
CVE-2020-35273

EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in t…

Mitigation only
Fix from $1,950 2020-12-21
Expense Management System MEDIUM 6.1
CVE-2020-35395

XSS in the Add Expense Component of EGavilan Media Expense Management System 1.0 allows an attacker to permanently store malicious JavaScript code vi…

No fix yet
Fix from $1,600 2020-12-15
Barcodes Generator MEDIUM 6.1
CVE-2020-35396

EGavilan Barcodes generator 1.0 is affected by: Cross Site Scripting (XSS) via the index.php. An Attacker is able to inject the XSS payload in the we…

No fix yet
Fix from $1,600 2020-12-15