CVE Database

CVE-2021-43329CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL injection vulnerability in license_update.php in Mumara Classic through 2.93 allows a remote unauthenticated attacker to execute arbitrary SQL commands via the license parameter.

CVE-2022-36692CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.

CVE-2022-36693CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_item.

CVE-2022-36695CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockin.

CVE-2022-36696CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockout.

CVE-2022-36697CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_waste.

CVE-2022-36715CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/search.php.

CVE-2022-28747CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Key reuse in GoSecure Titan Inbox Detection & Response (IDR) through 2022-04-05 leads to remote code execution. To exploit this vulnerability, an attacker must craft and sign a serialized payload.

CVE-2022-36678CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.

CVE-2022-36679CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user.

CVE-2022-36680CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule.

CVE-2022-36681CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_account.

CVE-2022-36682CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_student.

CVE-2022-36683CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_payment.

CVE-2022-37152CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob" parameter in "/classes/Users.php?f=save_client"

CVE-2022-36545CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/settings.php.

CVE-2022-37053CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.

CVE-2022-36543CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/doctors.php.

CVE-2022-36544CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/booking.php.

CVE-2022-3013CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability classified as critical has been found in SourceCodester Simple Task Managing System. This affects an unknown part of the file /loginVaLidation.php. The manipulation of the argument login leads to sql injection. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-207423.

CVE-2022-38792CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code execution backdoor inserted by a third party.

CVE-2022-36755CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php.

CVE-2022-36756CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

DIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php.

CVE-2022-37057CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin, ssdpcgi_main.

CVE-2022-38556CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Trendnet TEW733GR v1.03B01 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.

CVE-2022-38557CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

D-Link DIR845L v1.00-v1.03 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.

CVE-2022-38555CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.

CVE-2022-36705CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /stocks/manage_waste.php.

CVE-2022-36706CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /stocks/manage_stockout.php.

CVE-2022-36708CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /student/bookdetails.php.

CVE-2022-36572CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Sinsiu Sinsiu Enterprise Website System v1.1.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /upload/admin.php?/deal/.

CVE-2022-21165CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of input that potentially flows into the child_process.exec() function.

CVE-2022-25644CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

All versions of package @pendo324/get-process-by-name are vulnerable to Arbitrary Code Execution due to improper sanitization of getProcessByName function.

CVE-2022-25921CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

All versions of package morgan-json are vulnerable to Arbitrary Code Execution due to missing sanitization of input passed to the Function constructor.

CVE-2022-32548CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or password to the aa or ab field.

CVE-2022-36554CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

A command injection vulnerability in the CLI (Command Line Interface) implementation of Hytec Inter HWL-2511-SS v1.05 and below allows attackers to execute arbitrary commands with root privileges.

CVE-2022-36555CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-326

Hytec Inter HWL-2511-SS v1.05 and below implements a SHA512crypt hash for the root account which can be easily cracked via a brute-force attack.

CVE-2022-36556CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08execute_ping_01.

CVE-2022-36557CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers to execute arbitrary code via a crafted html file.

CVE-2022-36558CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able to access the passcord via the file /etc/ciel.cfg.

CVE-2022-36709CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/edit_book_details.php.

CVE-2022-36711CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/bookdetails.php.

CVE-2022-36712CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/studentdetails.php.

CVE-2022-36713CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Section parameter at /librarian/lab.php.

CVE-2022-36714CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Section parameter at /staff/lab.php.

CVE-2022-37149CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi. This vulnerability allows attackers to execute arbitrary commands via the username parameter.

CVE-2022-37176CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability which allows attackers to remove the Wi-Fi password and force the device into open security mode via a crafted packet sent to goform/setWizard.

CVE-2022-31232CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

SmartFabric storage software version 1.0.0 contains a Command-Injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access and perform actions on the affected system.

CVE-2022-36730CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /librarian/delete.php.

CVE-2022-36731CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /librarian/delstu.php.

← PreviousPage 446 / 7034Next →