vciy

CVEs we hold for Labredescefetrj

Records whose assigning authority named Labredescefetrj as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-76634WeGIA < 3.9.2 Insecure Direct Object Reference via profile_funcionario.phpLabRedesCefetRJ WeGIA
CVE-2026-76633WeGIA < 3.9.2 Authorization Bypass Password Change via alterarSenhaLabRedesCefetRJ WeGIA
CVE-2026-54767WeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_socios.phpLabRedesCefetRJ WeGIA
CVE-2026-54671WeGIA: Authorization Bypass via Empty Resource Array in InternoControleLabRedesCefetRJ WeGIA
CVE-2026-54670WeGIA: Unauthenticated Auth Bypass + Local File InclusionLabRedesCefetRJ WeGIA
CVE-2026-45335WeGIA: Middleware whitelist bypass → open redirect via InternoControle.nextPageLabRedesCefetRJ WeGIA
CVE-2026-45027WeGIA: Use of Weak Password Hashing Algorithm (SHA-256, no salt) in html/login.phpLabRedesCefetRJ WeGIA
CVE-2026-45026WeGIA: Stored XSS in html/atendido/processo_aceitacao.phpLabRedesCefetRJ WeGIA
CVE-2026-45025WeGIA: Stored XSS in html/atendido/etapa_processo.phpLabRedesCefetRJ WeGIA
CVE-2026-42873WeGIA: Error Handling Upload DocDependenteLabRedesCefetRJ WeGIA
CVE-2026-42872WeGIA: Reflected XSS in listar_arquivos_etapa.phpLabRedesCefetRJ WeGIA
CVE-2026-42871WeGIA: Error Handling familiar_docfamiliarLabRedesCefetRJ WeGIA
CVE-2026-42870WeGIA: Cross-Site Scripting (XSS) Stored endpoint 'informacao_adicional.php' parameter 'descricao'LabRedesCefetRJ WeGIA
CVE-2026-40286WeGIA has Cross-Site Scripting in Controle de ContribuiçãoLabRedesCefetRJ WeGIA
CVE-2026-40285WeGIA has SQL Injection via Session Variable Override in DespachoControle.phpLabRedesCefetRJ WeGIA
CVE-2026-40284WeGIA has stored XSS in listar_despachos.phpLabRedesCefetRJ WeGIA
CVE-2026-40283WeGIA has stored XSS in profile_paciente.phpLabRedesCefetRJ WeGIA
CVE-2026-40282WeGIA has stored XSS in intercorrencia_visualizar.phpLabRedesCefetRJ WeGIA
CVE-2026-35475WeGIA - Open Redirect - backup redirection — Unvalidated $_GET['redirect']LabRedesCefetRJ WeGIA
CVE-2026-35474WeGIA - Open Redirect - atualizacao redirection - Unvalidated $_GET['redirect']LabRedesCefetRJ WeGIA
CVE-2026-35473WeGIA - Open Redirect - IentradaControle - listarId() - Unvalidated $_GET['nextPage']LabRedesCefetRJ WeGIA
CVE-2026-35472WeGIA - Open Redirect - EstoqueControle - listarTodos() - Unvalidated $_GET['nextPage']LabRedesCefetRJ WeGIA
CVE-2026-35399WeGIA has Stored XSS in backup file namesLabRedesCefetRJ WeGIA
CVE-2026-35398WeGIA - Open Redirect - OrigemControle - listarTodos() & listarId_Nome() - Unvalidated $_GET['nextPage']LabRedesCefetRJ WeGIA
CVE-2026-35396WeGIA - Open Redirect - IsaidaControle - listarId() - Unvalidated $_GET['nextPage']LabRedesCefetRJ WeGIA
CVE-2026-35395WeGIA has a SQL Injection in DespachoDAO.php via id_memorando parameterLabRedesCefetRJ WeGIA
CVE-2026-33991WeGIA has SQL Injection in deletar_tag.phpLabRedesCefetRJ WeGIA
CVE-2026-33136WeGIA has Reflected Cross-Site Scripting (XSS) in `listar_memorandos_ativos.php` via `sccd` parameterLabRedesCefetRJ WeGIA
CVE-2026-33135WeGIA has Reflected Cross-Site Scripting (XSS) in `novo_memorandoo.php` via `sccs` parameterLabRedesCefetRJ WeGIA
CVE-2026-33134WeGIA has Authenticated Time-Based Blind SQL Injection in `restaurar_produto.php` via `id_produto` parameterLabRedesCefetRJ WeGIA
CVE-2026-33133WeGIA has an arbitrary SQL execution vulnerability via crafted backup archiveLabRedesCefetRJ WeGIA
CVE-2026-31896WeGIA has a Time-Based Blind SQL Injection in remover_produto_ocultar.phpLabRedesCefetRJ WeGIA
CVE-2026-31895WeGIA has a SQL Injection via Direct Query Interpolation in restaurar_produto.phpLabRedesCefetRJ WeGIA
CVE-2026-31894WeGIA affected by arbitrary file read via symlink in backup restoreLabRedesCefetRJ WeGIA
CVE-2026-28411WeGIA Vulnerable to Authentication Bypass via `extract($_REQUEST)`LabRedesCefetRJ WeGIA
CVE-2026-28409WeGIA Vulnerable to Remote Code Execution (RCE) via OS Command InjectionLabRedesCefetRJ WeGIA
CVE-2026-28408WeGIA lacks authentication verification in adicionar_tipo_docs_atendido.phpLabRedesCefetRJ WeGIA
CVE-2026-23731WeGIA Clickjacking VulnerabilityLabRedesCefetRJ WeGIA
CVE-2026-23730WeGIA has an Open Redirect Vulnerability in control.php Endpoint via nextPage Parameter (metodo=listarTodos…LabRedesCefetRJ WeGIA
CVE-2026-23729WeGIA has an Open Redirect Vulnerability in control.php Endpoint via nextPage Parameter (metodo=listarDescricao…LabRedesCefetRJ WeGIA
CVE-2026-23728WeGIA has an Open Redirect Vulnerability in control.php Endpoint via nextPage Parameter (metodo=listarTodos…LabRedesCefetRJ WeGIA
CVE-2026-23727WeGIA has an Open Redirect Vulnerability in control.php Endpoint via nextPage Parameter (metodo=listarTodos…LabRedesCefetRJ WeGIA
CVE-2026-23726WeGIA has an Open Redirect Vulnerability in control.php Endpoint via nextPage Parameter (metodo=listarTodos…LabRedesCefetRJ WeGIA
CVE-2026-23725WeGIA Stored Cross-Site Scripting (XSS) – nome Parameter on Adopters Information PageLabRedesCefetRJ WeGIA
CVE-2026-23724WeGIA Stored Cross-Site Scripting (XSS) – atendido_idatendido Parameter on Occurrence Registration PageLabRedesCefetRJ WeGIA
CVE-2026-23723WeGIA has a Critical SQL Injection in Atendido_ocorrenciaControle via id_memorando parameterLabRedesCefetRJ WeGIA
CVE-2026-23722WeGIA has a Reflected Cross-Site Scripting (XSS) vulnerability allowing arbitrary code execution and UI redressing.LabRedesCefetRJ WeGIA
CVE-2025-67501WeGIA is vulnerable to SQL Injection via editar_categoria endpoint parameterLabRedesCefetRJ WeGIA
CVE-2025-67496WeGia is Vulnerable to XSS through id_pessoa Parameter on Password Configuration PageLabRedesCefetRJ WeGIA
CVE-2025-6699LabRedesCefetRJ WeGIA Cadastro de Funcionário cadastro_funcionario.php cross site scriptingLabRedesCefetRJ WeGIA
CVE-2025-6698LabRedesCefetRJ WeGIA Adicionar tipo adicionar_tipoSaida.php cross site scriptingLabRedesCefetRJ WeGIA
CVE-2025-6697LabRedesCefetRJ WeGIA Adicionar tipo adicionar_tipoEntrada.php cross site scriptingLabRedesCefetRJ WeGIA
CVE-2025-6696LabRedesCefetRJ WeGIA Cadastro de Atendio Cadastro_Atendido.php cross site scriptingLabRedesCefetRJ WeGIA
CVE-2025-6695LabRedesCefetRJ WeGIA Additional Categoria adicionar_categoria.php cross site scriptingLabRedesCefetRJ WeGIA
CVE-2025-6694LabRedesCefetRJ WeGIA Adicionar Unidade adicionar_unidade.php cross site scriptingLabRedesCefetRJ WeGIA
CVE-2025-62598WeGIA Vulnerable to Reflected Cross-Site Scripting via Endpoint 'pessoa/editar_info_pessoal.php' Parameter 'action'LabRedesCefetRJ WeGIA
CVE-2025-62597WeGIA Vulnerable to Reflected Cross-Site Scripting via Endpoint 'pessoa/editar_info_pessoal.php' Parameter 'sql'LabRedesCefetRJ WeGIA
CVE-2025-62361WeGIA Open Redirect Vulnerability in `control.php` endpoint `nextPage` parameter (metodo=listarTodos…LabRedesCefetRJ WeGIA
CVE-2025-62360WeGIA SQL Injection via 'id_dependente' param at endpoint `/html/funcionario/dependente_documento.php`LabRedesCefetRJ WeGIA
CVE-2025-62359WeGIA Cross-Site Scripting (XSS) Reflected endpoint id_petLabRedesCefetRJ WeGIA
CVE-2025-62358WeGIA Reflected XSS to Account TakeOver at /html/configuracao/configuracao_geral.php via log parameterLabRedesCefetRJ WeGIA
CVE-2025-62179WeGIA SQL Injection via 'cpf' param at endpoint `/html/funcionario/cadastro_funcionario_pessoa_existente.php`LabRedesCefetRJ WeGIA
CVE-2025-62178WeGIA Cross-Site Scripting (XSS) Reflected endpoint '/html/atendido/cadastro_atendido_parentesco_pessoa_nova.php'…LabRedesCefetRJ WeGIA
CVE-2025-62177WeGIA vulnerable to SQL Injection via 'id_funcionario' param at endpoint `/html/funcionario/dependente_listar.php`LabRedesCefetRJ WeGIA
CVE-2025-61665WeGIA: Broken Access Control in `get_relatorios_socios.php` EndpointLabRedesCefetRJ WeGIA
CVE-2025-61606WeGIA: Open Redirect Vulnerability in `control.php` endpointLabRedesCefetRJ WeGIA
CVE-2025-61605WeGIA: SQL Injection (Blind Time-Based) Vulnerability in /pet/profile_pet.php EndpointLabRedesCefetRJ WeGIA
CVE-2025-61604WeGIA: Cross-Site Request Forgery (CSRF) Vulnerability in `control.php` EndpointLabRedesCefetRJ WeGIA
CVE-2025-61603WeGIA: SQL Injection (Blind Time-Based) Vulnerability in API `descricao` ParameterLabRedesCefetRJ WeGIA
CVE-2025-59939WeGIA vulnerable to SQL Injection into method `excluir` of the `ProdutoControle` class in the parameter `id_produto`.LabRedesCefetRJ WeGIA
CVE-2025-58745WeGIA has a bypass for the fix for CVE-2025-22133 - Arbitrary File Upload leads to Remote Code Execution (RCE)LabRedesCefetRJ WeGIA
CVE-2025-58454WeGIA vulnerable to Blind Time-Based SQL Injection in endpoint 'listar_despachos.php' parameter 'id_memorando'LabRedesCefetRJ WeGIA
CVE-2025-58453WeGIA vulnerable to Blind Time-Based SQL Injection in endpoint 'exibe_anexo.php' parameter 'id_anexo'LabRedesCefetRJ WeGIA
CVE-2025-58452WeGIA vulnerable to Reflected Cross-Site Scripting (XSS) in endpoint 'listar_despachos.php' parameter 'id_memorando'LabRedesCefetRJ WeGIA
CVE-2025-58159WeGIA Authenticated Arbitrary File Upload Leading To Remote Code Execution (RCE)LabRedesCefetRJ WeGIA
CVE-2025-57765WeGIA Cross-Site Scripting (XSS) Reflected endpoint 'pre_cadastro_adotante.php' parameter 'msg_e'LabRedesCefetRJ WeGIA
CVE-2025-57764WeGIA Cross-Site Scripting (XSS) Reflected endpoint 'cargos.php' parameter 'msg_e'LabRedesCefetRJ WeGIA
CVE-2025-57763Cross-Site Scripting (XSS) Reflected in 'insere_despacho.php' parameter 'sccs'LabRedesCefetRJ WeGIA
CVE-2025-57762WeGIA Stored Cross-Site Scripting (XSS) vulnerability in the endpoint 'dependente_docdependente.php' with parameter…LabRedesCefetRJ WeGIA
CVE-2025-57761WeGIA SQL Injection vulnerability via 'id_funcionario' param at endpoint `/html/funcionario/dependente_remover.php`LabRedesCefetRJ WeGIA
CVE-2025-55171WeGIA Anonymous Attacker can Delete Arbitrary Image file at endpoint `/html/personalizacao_remover.php`LabRedesCefetRJ WeGIA
CVE-2025-55170WeGIA reflected XSS via `verificacao` and `redir_config` param at endpoint `/html/alterar_senha.php`LabRedesCefetRJ WeGIA
CVE-2025-55169WeGIA Path Traversal at endpoint 'html/socio/sistema/download_remessa.php' via parameter 'file'LabRedesCefetRJ WeGIA
CVE-2025-55168WeGIA SQL Injection via id_fichamedica at endpoint `GET /html/saude/aplicar_medicamento.php`LabRedesCefetRJ WeGIA
CVE-2025-55167WeGIA SQL Injection via id_fichamedica at endpoint `GET/html/funcionario/dependente_remover.php`LabRedesCefetRJ WeGIA
CVE-2025-54079WeGIA vulnerable to SQL Injection (Blind Time-Based) in endpoint 'Profile_Atendido.php' parameter 'idatendido'LabRedesCefetRJ WeGIA
CVE-2025-54078WeGIA Reflected Cross-Site Scripting (XSS) vulnerability in endpoint 'personalizacao_imagem.php' parameter 'err'LabRedesCefetRJ WeGIA
CVE-2025-54077WeGIA Reflected Cross-Site Scripting (XSS) vulnerability in endpoint 'personalizacao.php' parameter 'err'LabRedesCefetRJ WeGIA
CVE-2025-54076WeGIA Reflected Cross-Site Scripting (XSS) vulnerability in endpoint 'pre_cadastro_atendido.php' parameter 'msg_e'LabRedesCefetRJ WeGIA
CVE-2025-54062WeGIA SQL Injection (Blind Time-Based) Vulnerability in id_dependente Parameter on profile_dependente.php EndpointLabRedesCefetRJ WeGIA
CVE-2025-54061WeGIASQL Injection (Blind Time-Based) Vulnerability in idatendido_familiares Parameter on dependente_editarDoc.php…LabRedesCefetRJ WeGIA
CVE-2025-54060WeGIA SQL Injection (Blind Time-Based) Vulnerability in idatendido_familiares Parameter on…LabRedesCefetRJ WeGIA
CVE-2025-54058WeGIA SQL Injection (Blind Time-Based) Vulnerability in idatendido_familiares Parameter on…LabRedesCefetRJ WeGIA
CVE-2025-53946WeGIA vulnerable to SQL Injection in endpoint profile_paciente.php parameter id_fichamedicaLabRedesCefetRJ WeGIA
CVE-2025-53938WeGIA vulnerable to Authentication Bypass due to Missing Session Validation in multiple endpointsLabRedesCefetRJ WeGIA
CVE-2025-53937WeGIA has SQL Injection (Blind Time-Based) Vulnerability in `cargo` Parameter on `control.php` EndpointLabRedesCefetRJ WeGIA
CVE-2025-53936WeGIA vulnerable to Reflected Cross-Site Scripting via endpoint `personalizacao_selecao.php` parameter `nome_car`LabRedesCefetRJ WeGIA
CVE-2025-53935WeGIA vulnerable to Reflected Cross-Site Scripting via endpoint `personalizacao_selecao.php` parameter `id`LabRedesCefetRJ WeGIA
CVE-2025-53934WeGIA vulnerable to Stored Cross-Site Scripting via endpoint 'control.php' parameter 'descricao_emergencia'LabRedesCefetRJ WeGIA
CVE-2025-53933WeGIA vulnerable to Stored Cross-Site Scripting via endpoint 'adicionar_enfermidade.php' parameter 'nome'LabRedesCefetRJ WeGIA
CVE-2025-53932WeGIA vulnerable to Reflected Cross-Site Scripting via endpoint 'cadastro_adotante.php' parameter 'cpf'LabRedesCefetRJ WeGIA
CVE-2025-53931WeGIA vulnerable to Stored Cross-Site Scripting via endpoint `adicionar_raca.php` parameter `raca`LabRedesCefetRJ WeGIA
CVE-2025-53930WeGIA vulnerable to Stored Cross-Site Scripting (XSS) via endpoint 'adicionar_especie.php' parameter 'especie'LabRedesCefetRJ WeGIA
CVE-2025-53929WeGIA vulnerable to Stored Cross-Site Scripting (XSS) via endpoint `adicionar_cor.php` parameter `cor`LabRedesCefetRJ WeGIA
CVE-2025-53824WeGIA ReflectedCross-Site Scripting (XSS) vulnerability in endpoint 'cadastro_pet.php' parameter 'msg'LabRedesCefetRJ WeGIA
CVE-2025-53823WeGIA vulnerable to SQL Injection (Blind Time-Based) in `processa_deletar_socio.php` parameter `id_socio`LabRedesCefetRJ WeGIA
CVE-2025-53822WeGIA vulnerable to Reflected Cross-Site Scripting in endpoint 'relatorio_geracao.php' parameter 'tipo_relatorio'LabRedesCefetRJ WeGIA
CVE-2025-53821WeGIA vulnerable to Open Redirect in endpoint 'control.php' parameter 'nextPage'LabRedesCefetRJ WeGIA
CVE-2025-53820WeGIA vulnerable to Cross-Site Scripting (XSS) Reflected via endpoint 'index.php' parameter 'erro'LabRedesCefetRJ WeGIA
CVE-2025-53531WeGIA allows Uncontrolled Resource Consumption via the fid parameterLabRedesCefetRJ WeGIA
CVE-2025-53530WeGIA allows Uncontrolled Resource Consumption via the errorstr parameterLabRedesCefetRJ WeGIA
CVE-2025-53529WeGIA allows SQL Injection in html/funcionario/profile_funcionario.php (id_funcionario parameter)LabRedesCefetRJ WeGIA
CVE-2025-53527WeGIA allows Time-Based Blind SQL Injection in the relatorio_geracao.php endpointLabRedesCefetRJ WeGIA
CVE-2025-53526WeGIA allows Stored XSS attacks in novo_memorando.phpLabRedesCefetRJ WeGIA
CVE-2025-53525WebGia allows Cross-Site Scripting (XSS) in profile_familiar.php via the id_dependente parameterLabRedesCefetRJ WeGIA
CVE-2025-53377WebGia allows Cross-Site Scripting (XSS) in cadastro_dependente_pessoa_nova.php via the id_funcionario parameterLabRedesCefetRJ WeGIA
CVE-2025-53091WeGIA has Unauthenticated Time-Based Blind SQL Injection in almox ParameterLabRedesCefetRJ WeGIA
CVE-2025-52474WeGIA SQL Injection Vulnerability in id Parameter on control.php EndpointLabRedesCefetRJ WeGIA
CVE-2025-50201WeGIA OS Command Injection in debug_info.php parameter 'branch'LabRedesCefetRJ WeGIA
CVE-2025-46828Unauthenticated SQL Injection on get_socios.php endpointLabRedesCefetRJ WeGIA
CVE-2025-30367WeGIA SQL Injection Vulnerability in nextPage Parameter on control.php EndpointLabRedesCefetRJ WeGIA
CVE-2025-30366WeGIA vulnerable to Stored XSS in personalizacao.phpLabRedesCefetRJ WeGIA
CVE-2025-30365SQL Injection in query_geracao_auto.phpLabRedesCefetRJ WeGIA
CVE-2025-30364WeGIA vulnerable to SQL Injection (Blind Time-Based) in remuneracao.php parameter id_funcionarioLabRedesCefetRJ WeGIA
CVE-2025-30363WeGIA vulnerable to Stored XSS in documentos_funcionario.php parameter dados_addInfoLabRedesCefetRJ WeGIA
CVE-2025-30362WeGIA vulnerable to Stored XSS in documentos_funcionario.php parameter idLabRedesCefetRJ WeGIA
CVE-2025-30361WeGIA Vulnerable to Broken Authentication - Old Password ValidationLabRedesCefetRJ WeGIA
CVE-2025-29782WeGIA Cross-Site Scripting (XSS) Stored in endpoint `adicionar_tipo_docs_atendido.php` parameter `tipo`LabRedesCefetRJ WeGIA
CVE-2025-27499WeGIA has a stored Cross-Site Scripting (XSS) in 'processa_edicao_socio.php' via the 'socio_nome' parameterLabRedesCefetRJ WeGIA
CVE-2025-27420WeGIA contains a Stored Cross-Site Scripting (XSS) in 'atendido_parentesco_adicionar.php' via the 'descricao' parameterLabRedesCefetRJ WeGIA
CVE-2025-27419Denial of Service (DoS) in WeGIA due to Recursive Crawling of Dynamic URLsLabRedesCefetRJ WeGIA
CVE-2025-27418WeGIA contains a Stored Cross-Site Scripting (XSS) in 'adicionar_tipo_atendido.php' via the 'tipo' parameterLabRedesCefetRJ WeGIA
CVE-2025-27417WeGIA Contains a Stored Cross-Site Scripting (XSS) in 'adicionar_status_atendido.php' via the 'status' parameterLabRedesCefetRJ WeGIA
CVE-2025-27140WeGIA vulnerable to OS Command Injection at endpoint 'importar_dump.php' parameter 'import' (RCE)LabRedesCefetRJ WeGIA
CVE-2025-27133WeGIA has SQL Injection endpoint at 'dao/pet/adicionar_tipo_exame.php' parameter 'tipo_exame'LabRedesCefetRJ WeGIA
CVE-2025-27096SQL Injection endpoint 'html/personalizacao_upload.php' parameter 'id_campo' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-26617SQL Injection endpoint 'historico_paciente.php' parameter 'id_fichamedica' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-26616Path Traversal endpoint 'exportar_dump.php' parameter 'file' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-26615Path Traversal endpoint 'examples.php' parameter 'src' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-26614SQL Injection endpoint 'deletar_documento.php' parameter 'id_cargo' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-26613OS Command Injection endpoint 'gerenciar_backup.php' parameter 'file' (RCE) in WeGIALabRedesCefetRJ WeGIA
CVE-2025-26612SQL Injection endpoint 'adicionar_almoxarife.php' parameter 'id_almoxarifado', 'id_funcionario' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-26611SQL Injection endpoint 'remover_produto.php' parameter 'id_produto' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-26610SQL Injection endpoint 'restaurar_produto_desocultar.php' parameter 'id_produto' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-26609SQL Injection endpoint 'familiar_docfamiliar.php' parameter 'id_dependente', 'id_doc' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-26608SQL Injection endpoint 'dependente_docdependente.php' parameter 'id_dependente', 'id_doc' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-26607SQL Injection endpoint 'documento_excluir.php' parameter 'id_funcionario' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-26606SQL Injection endpoint 'informacao_adicional.php' parameter 'id_descricao' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-26605SQL Injection endpoint 'deletar_cargo.php' parameter 'id_cargo' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-24958SQL Injection endpoint 'salvar_tag.php' parameter 'id_tag' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-24957SQL Injection endpoint 'get_detalhes_socio.php' parameter 'id_socio' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-24906SQL Injection endpoint 'get_detalhes_cobranca.php' parameter 'codigo' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-24905SQL Injection endpoint 'get_codigobarras_cobranca.php' parameter 'codigo' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-24902SQL Injection endpoint 'salvar_cargo.php' parameter 'id_cargo' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-24901SQL Injection endpoint 'deletar_permissao.php' parameter 'c', 'a', 'r' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-24020WeGIA Open Redirect vulnerabilityLabRedesCefetRJ WeGIA
CVE-2025-23220WeGIA has a SQL Injection endpoint 'adicionar_raca.php' parameter 'raca'LabRedesCefetRJ WeGIA
CVE-2025-23219WeGIA has a SQL Injection endpoint 'adicionar_cor.php' parameter 'cor'LabRedesCefetRJ WeGIA
CVE-2025-23218WeGIA has a SQL Injection endpoint 'adicionar_especie.php' parameter 'especie'LabRedesCefetRJ WeGIA
CVE-2025-23038Cross-Site Scripting (XSS) Stored endpoint 'remuneracao.php ' parameter 'descricao' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-23037Cross-Site Scripting (XSS) Stored endpoint 'control.php' parameter 'cargo' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-23036Cross-Site Scripting (XSS) Reflected endpoint 'pre_cadastro_funcionario.php' parameter 'msg_e' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-23035Cross-Site Scripting (XSS) Stored endpoint 'adicionar_tipo_quadro_horario.php' parameter 'tipo' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-23034Cross-Site Scripting (XSS) Reflected endpoint 'tags.php' parameter 'msg_e' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-23033Cross-Site Scripting (XSS) Stored endpoint 'adicionar_situacao.php' parameter 'situacao' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-23032Cross-Site Scripting (XSS) Stored endpoint 'adicionar_escala.php' parameter 'escala' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-23031Cross-Site Scripting (XSS) Stored endpoint 'adicionar_alergia.php' parameter 'nome' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-23030Cross-Site Scripting (XSS) Reflected endpoint 'cadastro_funcionario.php' parameter 'cpf' in WeGIALabRedesCefetRJ WeGIA
CVE-2025-22619WeGIA Cross-Site Scripting (XSS) Reflected endpoint 'editar_permissoes.php' parameter 'msg_c'LabRedesCefetRJ WeGIA
CVE-2025-22618WeGIA Cross-Site Scripting (XSS) Stored endpoint 'adicionar_cargo.php' parameter 'cargo'LabRedesCefetRJ WeGIA
CVE-2025-22617WeGIA Cross-Site Scripting (XSS) Reflected endpoint 'editar_socio.php' parameter 'socio'LabRedesCefetRJ WeGIA
CVE-2025-22616WeGIA Cross-Site Scripting (XSS) Stored endpoint 'dependente_parentesco_adicionar.php' parameter 'descricao'LabRedesCefetRJ WeGIA
CVE-2025-22615WeGIA Cross-Site Scripting (XSS) Reflected endpoint 'Cadastro_Atendido.php' parameter 'cpf'LabRedesCefetRJ WeGIA
CVE-2025-22614WeGIA Cross-Site Scripting (XSS) Stored endpoint 'dependente_editarInfoPessoal.php ' parameters 'nome' 'SobrenomeForm'LabRedesCefetRJ WeGIA
CVE-2025-22613WeGIA Cross-Site Scripting (XSS) Stored endpoint 'informacao_adicional.php' parameter 'descricao'LabRedesCefetRJ WeGIA
CVE-2025-22600WeGIA has a Cross-Site Scripting (XSS) Reflected endpoint `configuracao_doacao.php` parameter `avulso`LabRedesCefetRJ WeGIA
CVE-2025-22599WeGIA has a Cross-Site Scripting (XSS) Reflected endpoint `home.php` parameter `msg_c`LabRedesCefetRJ WeGIA
CVE-2025-22598WeGIA has a Cross-Site Scripting (XSS) Stored endpoint 'cadastrarSocio.php' parameter 'nome'LabRedesCefetRJ WeGIA
CVE-2025-22597WeGIA has a Cross-Site Scripting (XSS) Stored endpoint 'CobrancaController.php' parameter 'local_recepcao'LabRedesCefetRJ WeGIA
CVE-2025-22596WeGIA has a Cross-Site Scripting (XSS) Reflected endpoint 'modulos_visiveis.php' parameter'msg_c'LabRedesCefetRJ WeGIA
CVE-2025-22143WeGIA Cross-Site Scripting (XSS) Reflected endpoint 'listar_permissoes.php' parameter 'msg_e'LabRedesCefetRJ WeGIA

181 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.