CVE Database

CVE-2022-36735CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /admin/delete.php.

CVE-2022-40109CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-276

TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa.

CVE-2022-36749CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php. This vulnerability is exploited via a crafted payload injected into the file name of an uploaded file.

CVE-2022-37021CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. Any user still on Java 8 who wishes to protect against deserialization attacks involving JMX or RMI should upgrade to Apache Geode 1.15 and Java 11. If upgrading to Java 11 is not possible, then upgrade to Apache Geode 1.15 and specify "--J=-Dgeode.enableGlobalSerialFilter=true" when starting any Locators or Servers. Follow the documentation for details on specifying any user classes that may be serialized/deserialized with the "serializable-object-filter" configuration option. Using a global serial filter will impact performance.

CVE-2022-36045CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-330

NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interactions and real-time notifications. `utils.generateUUID`, a helper function available in essentially all versions of NodeBB (as far back as v1.0.1 and potentially earlier) used a cryptographically insecure Pseudo-random number generator (`Math.random()`), which meant that a specially crafted script combined with multiple invocations of the password reset functionality could enable an attacker to correctly calculate the reset code for an account they do not have access to. This vulnerability impacts all installations of NodeBB. The vulnerability allows for an attacker to take over any account without the involvement of the victim, and as such, the remediation should be applied immediately (either via NodeBB upgrade or cherry-pick of the specific changeset. The vulnerability has been patched in version 2.x and 1.19.x. There is no known workaround, but the patch sets listed above will fully patch the vulnerability.

CVE-2022-21941CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to the system.

CVE-2022-2466CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-444

It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior.

CVE-2022-30318CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell ControlEdge hardcoded credentials issue. The affected components are characterized as: SSH. The potential impact is: Remote code execution, manipulate configuration, denial of service. The Honeywell ControlEdge PLC and RTU product line exposes an SSH service on port 22/TCP. Login as root to this service is permitted and credentials for the root user are hardcoded without automatically changing them upon first commissioning. The credentials for the SSH service are hardcoded in the firmware. The credentials grant an attacker access to a root shell on the PLC/RTU, allowing for remote code execution, configuration manipulation and denial of service.

CVE-2022-36566CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function.

CVE-2022-37128CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-665

In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.

CVE-2022-36201CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Doctor’s Appointment System v1.0 is vulnerable to Blind SQLi via settings.php.

CVE-2022-36202CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-639

Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter.

CVE-2022-37125CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.

CVE-2022-37130CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is met, setnum will be spliced into v10 by snprintf, and the system will be executed, resulting in a command injection vulnerability

CVE-2020-35527CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.

CVE-2022-34379CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Dell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability. A remote attacker, with the knowledge of the active directory usernames, could potentially exploit this vulnerability to gain unauthorized access to the system.

CVE-2022-36601CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The Eclipse TCF debug interface in JasMiner-X4-Server-20220621-090907 and below is open on port 1534. This issue allows unauthenticated attackers to gain root privileges on the affected device and access sensitive data or execute arbitrary commands.

CVE-2022-36609CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Clinic's Patient Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pms/update_patient.php.

CVE-2022-36759CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /dishes.php?res_id=.

CVE-2022-36594CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Mapper v4.0.0 to v4.2.0 was discovered to contain a SQL injection vulnerability via the ids parameter at the selectByIds function.

CVE-2022-25371CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142) it is possible to perform a remote code execution (RCE) attack in Apache OFBiz, release 18.12.05 and earlier.

CVE-2022-29063CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or on a server restart, in order to run arbitrary code. Upgrade to at least 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12646.

CVE-2022-38054CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-384

In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.

CVE-2022-22096CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Memory corruption in Bluetooth HOST due to stack-based buffer overflow when when extracting data using command length parameter in Snapdragon Connectivity, Snapdragon Mobile

CVE-2022-25657CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Memory corruption due to buffer overflow occurs while processing invalid MKV clip which has invalid seek header in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

CVE-2022-25658CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Memory corruption due to incorrect pointer arithmetic when attempting to change the endianness in video parser function in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2022-25659CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Memory corruption due to buffer overflow while parsing MKV clips with invalid bitmap size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2022-25668CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

Memory corruption in video driver due to double free while parsing ASF clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2020-22669CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.

CVE-2021-27693CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.

CVE-2022-34371CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-522

Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3, contain an unprotected transport of credentials vulnerability. A malicious unprivileged network attacker could potentially exploit this vulnerability, leading to full system compromise.

CVE-2022-40111CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware.

CVE-2022-36640CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-276

influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If InfluxDB is being deployed on a publicly accessible endpoint, we strongly recommend authentication be enabled. Otherwise the data will be publicly available to any unauthenticated user. The default settings do NOT enable authentication and authorization."

CVE-2022-3118CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in Sourcecodehero ERP System Project. It has been rated as critical. This issue affects some unknown processing of the file /pages/processlogin.php. The manipulation of the argument user leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-207845 was assigned to this vulnerability.

CVE-2022-3120CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability classified as critical was found in SourceCodester Clinics Patient Management System. Affected by this vulnerability is an unknown functionality of the file index.php of the component Login. The manipulation of the argument user_name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-207847.

CVE-2022-2830CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Deserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console allows an attacker to pass unsafe commands to the environment. This issue affects: Bitdefender GravityZone Console On-Premise versions prior to 6.29.2-1. Bitdefender GravityZone Cloud Console versions prior to 6.27.2-2.

CVE-2022-3122CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file medicine_details.php. The manipulation of the argument medicine leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-207854 is the identifier assigned to this vulnerability.

CVE-2022-34747CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-134

A format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to achieve unauthorized remote code execution via a crafted UDP packet.

CVE-2022-2714CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-130

Improper Handling of Length Parameter Inconsistency in GitHub repository francoisjacquet/rosariosis prior to 10.0.

CVE-2022-36584CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, the getsinglepppuser function has a buffer overflow caused by sscanf.

CVE-2022-37839CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

TOTOLINK A860R V4.1.2cu.5182_B20201027 is vulnerable to Buffer Overflow via Cstecgi.cgi.

CVE-2022-37840CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

In TOTOLINK A860R V4.1.2cu.5182_B20201027, the main function in downloadfile.cgi has a buffer overflow vulnerability.

CVE-2022-37842CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

In TOTOLINK A860R V4.1.2cu.5182_B20201027, the parameters in infostat.cgi are not filtered, causing a buffer overflow vulnerability.

CVE-2022-37843CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

In TOTOLINK A860R V4.1.2cu.5182_B20201027 in cstecgi.cgi, the acquired parameters are directly put into the system for execution without filtering, resulting in a command injection vulnerability.

CVE-2022-26447CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In BT firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06784478; Issue ID: ALPS06784478.

CVE-2022-31789CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

An integer overflow in WatchGuard Firebox and XTM appliances allows an unauthenticated remote attacker to trigger a buffer overflow and potentially execute arbitrary code by sending a malicious request to exposed management ports. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4.

CVE-2022-31860CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue was discovered in OpenRemote through 1.0.4 allows attackers to execute arbitrary code via a crafted Groovy rule.

CVE-2022-36425CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-264

Broken Access Control vulnerability in Beaver Builder plugin <= 2.5.4.3 at WordPress.

CVE-2020-21516CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP code.

CVE-2022-36061CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-665

Elrond go is the go implementation for the Elrond Network protocol. In versions prior to 1.3.35, read only calls between contracts can generate smart contracts results. For example, if contract A calls in read only mode contract B and the called function will make changes upon the contract's B state, the state will be altered for contract B as if the call was not made in the read-only mode. This can lead to some effects not designed by the original smart contracts programmers. This issue was patched in version 1.3.35. There are no known workarounds.

← PreviousPage 447 / 7034Next →