CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1
OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upload_module…
OpenSTAManager has a SQL Injection via righe Parameter in confronta_righe Modals
OpenSTAManager: SQL Injection via Aggiornamenti Module
OpenSTAManager: Time-Based Blind SQL Injection via `options[stato]` Parameter
OpenSTAManager: Remote Code Execution via Insecure Deserialization in OAuth2
Unauthenticated privilege escalation in OpenSTAManager via modules/utenti/actions.php
OpenSTAManager affected by reflected XSS in modifica_iva.php via righe parameter
OpenSTAManager has an OS Command Injection in P7M File Processing
OpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint)
OpenSTAManager has an SQL Injection in Scadenzario Print Template
OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing Module
OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service
OpenSTAManager has an SQL Injection vulnerability in the Scadenzario bulk operations module
OpenSTAManager has an SQL Injection in the Prima Nota module
OpenSTAManager has an SQL Injection in the Stampe Module
OpenSTAManager has a SQL Injection in ajax_complete.php (get_sedi endpoint)
A reflected cross-site scripting (XSS) vulnerability in DevCode OpenSTAManager versions 2.4.24 to 2.4.47 may allow a remote attacker to execute arbitrary JavaS…
Showing 1 to 17 CVEs · page 1