CVE Database

CVE-2022-30595CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files.

CVE-2022-29379CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/njs_module.c. NOTE: multiple third parties dispute this report, e.g., the behavior is only found in unreleased development code that was not part of the 0.7.2, 0.7.3, or 0.7.4 release

CVE-2022-1664CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially crafted orig.tar and debian.tar tarballs.

CVE-2022-29660CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del.

CVE-2022-21831CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.

CVE-2022-30493CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

In oretnom23 Automotive Shop Management System v1.0, the product id parameter suffers from a blind SQL Injection Vulnerability allowing remote attackers to dump all database credential and gain admin access(privilege escalation).

CVE-2022-30495CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-639

In oretnom23 Automotive Shop Management System v1.0, the name id parameter is vulnerable to IDOR - Broken Access Control allowing attackers to change the admin password(vertical privilege escalation)

CVE-2022-30516CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

In Hospital-Management-System v1.0, the editid parameter in the doctor.php page is vulnerable to SQL injection attacks.

CVE-2022-26708CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4. An attacker may be able to cause unexpected application termination or arbitrary code execution.

CVE-2022-26711CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

An integer overflow issue was addressed with improved input validation. This issue is fixed in tvOS 15.5, iTunes 12.12.4 for Windows, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.

CVE-2022-29775CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.

CVE-2022-26723CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. Mounting a maliciously crafted Samba network share may lead to arbitrary code execution.

CVE-2019-12349CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id parameter.

CVE-2022-26775CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4. An attacker may be able to cause unexpected application termination or arbitrary code execution.

CVE-2022-26776CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. An attacker may be able to cause unexpected application termination or arbitrary code execution.

CVE-2022-29632CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

An arbitrary file upload vulnerability in the component /course/api/upload/pic of Roncoo Education v9.0.0 allows attackers to execute arbitrary code via a crafted file.

CVE-2022-29633CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

An access control issue in Linglong v1.0 allows attackers to access the background of the application via a crafted cookie.

CVE-2019-12350CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_download.php via an id parameter value with a trailing comma.

CVE-2022-31003CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, when parsing each line of a sdp message, `rest = record + 2` will access the memory behind `\0` and cause an out-of-bounds write. An attacker can send a message with evil sdp to FreeSWITCH, causing a crash or more serious consequence, such as remote code execution. Version 1.13.8 contains a patch for this issue.

CVE-2022-31013CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Chat Server is the chat server for Vartalap, an open-source messaging application. Versions 2.3.2 until 2.6.0 suffer from a bug in validating the access token, resulting in authentication bypass. The function `this.authProvider.verifyAccessKey` is an async function, as the code is not using `await` to wait for the verification result. Every time the function responds back with success, along with an unhandled exception if the token is invalid. A patch is available in version 2.6.0.

CVE-2022-29875CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM X.cite (All versions < VA30 SP5 or VA40 SP2), SOMATOM X.creed (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.All (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Now (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Open Pro (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Sim (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Top (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Up (All versions < VA30 SP5 or VA40 SP2), Symbia E/S (All VB22 versions < VB22A-UD03), Symbia Evo (All VB22 versions < VB22A-UD03), Symbia Intevo (All VB22 versions < VB22A-UD03), Symbia T (All VB22 versions < VB22A-UD03), Symbia.net (All VB22 versions < VB22A-UD03), syngo.via VB10 (All versions), syngo.via VB20 (All versions), syngo.via VB30 (All versions), syngo.via VB40 (All versions < VB40B HF06), syngo.via VB50 (All versions), syngo.via VB60 (All versions < VB60B HF02). The application deserialises untrusted data without sufficient validations that could result in an arbitrary deserialization. This could allow an unauthenticated attacker to execute code in the affected system if ports 32912/tcp or 32914/tcp are reachable.

CVE-2019-12351CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_print.php via an id parameter value with a trailing comma.

CVE-2021-34082CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

OS Command Injection vulnerability in allenhwkim proctree through 0.1.1 and commit 0ac10ae575459457838f14e21d5996f2fa5c7593 for Node.js, allows attackers to execute arbitrary commands via the fix function.

CVE-2021-34079CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

OS Command injection vulnerability in Mintzo Docker-Tester through 1.2.1 allows attackers to execute arbitrary commands via shell metacharacters in the 'ports' entry of a crafted docker-compose.yml file.

CVE-2021-34080CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

OS Command Injection vulnerability in es128 ssl-utils 1.0.0 for Node.js allows attackers to execute arbitrary commands via unsanitized shell metacharacters provided to the createCertRequest() and the createCert() functions.

CVE-2021-34084CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to execute arbitrary commands via the metadata() function.

CVE-2021-44095CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL injection vulnerability exists in ProjectWorlds Hospital Management System in php 1.0 on login page that allows a remote attacker to compromise Application SQL database.

CVE-2021-44096CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise Application SQL database.

CVE-2021-44097CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This allows a remote attacker to compromise Application SQL database.

CVE-2021-44098CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database.

CVE-2022-30490CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php.

CVE-2022-1660CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker to remotely execute arbitrary code.

CVE-2022-30810CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

elitecms v1.01 is vulnerable to SQL Injection via admin/edit_post.php.

CVE-2022-24239CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file upload vulnerability via attachments.awp.

CVE-2022-24240CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp.

CVE-2022-24702CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

An issue was discovered in WinAPRS 2.9.0. A buffer overflow in the VHF KISS TNC component allows a remote attacker to achieve remote code execution via malicious AX.25 packets over the air. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2022-30813CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

elitecms 1.01 is vulnerable to SQL Injection via /admin/add_post.php.

CVE-2022-28605CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Hardcoded admin token in SoundBar apps in Linkplay SDK 1.00 allows remote attackers to gain admin privilege access in linkplay antifactory

CVE-2022-28945CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traversal via a crafted ZIP file.

CVE-2022-29730CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 was discovered to contain hard-coded credentials for its highest privileged account. The credentials cannot be altered through normal operation of the device.

CVE-2022-30481CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Food-order-and-table-reservation-system- 1.0 is vulnerable to SQL Injection in categorywise-menu.php via the catid parameters.

CVE-2022-29776CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component DesktopEditor/common/File.cpp.

CVE-2022-29777CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fontengine/fontconverter/FontFileBase.h.

CVE-2022-30324CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client agent host. Fixed in 1.1.14, 1.2.8, and 1.3.1.

CVE-2022-30352CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

phpABook 0.9i is vulnerable to SQL Injection due to insufficient sanitization of user-supplied data in the "auth_user" parameter in index.php script.

CVE-2022-30423CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Merchandise Online Store v1.0 by oretnom23 has an arbitrary code execution (RCE) vulnerability in the user profile upload point in the system information.

CVE-2022-30470CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

In Afian Filerun 20220202 Changing the "search_tika_path" variable to a custom (and previously uploaded) jar file results in remote code execution in the context of the webserver user.

CVE-2022-30478CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in \search_product.php via the keyword parameters.

CVE-2022-30521CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

The LAN-side Web-Configuration Interface has Stack-based Buffer Overflow vulnerability in the D-Link Wi-Fi router firmware DIR-890L DIR890LA1_FW107b09.bin and previous versions. The function created at 0x17958 of /htdocs/cgibin will call sprintf without checking the length of strings in parameters given by HTTP header and can be controlled by users easily. The attackers can exploit the vulnerability to carry out arbitrary code by means of sending a specially constructed payload to port 49152.

CVE-2022-30797CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php.

← PreviousPage 431 / 7034Next →