CVE Database

CVE-2022-34718CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Windows TCP/IP Remote Code Execution Vulnerability

CVE-2022-34722CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability

CVE-2022-39205CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. In versions of Onedev prior to 7.3.0 unauthenticated users can take over a OneDev instance if there is no properly configured reverse proxy. The /git-prereceive-callback endpoint is used by the pre-receive git hook on the server to check for branch protections during a push event. It is only intended to be accessed from localhost, but the check relies on the X-Forwarded-For header. Invoking this endpoint leads to the execution of one of various git commands. The environment variables of this command execution can be controlled via query parameters. This allows attackers to write to arbitrary files, which can in turn lead to the execution of arbitrary code. Such an attack would be very hard to detect, which increases the potential impact even more. Users are advised to upgrade. There are no known workarounds for this issue.

CVE-2021-0942CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

The path in this case is a little bit convoluted. The end result is that via an ioctl an untrusted app can control the ui32PageIndex offset in the expression:sPA.uiAddr = page_to_phys(psOSPageArrayData->pagearray[ui32PageIndex]);With the current PoC this crashes as an OOB read. However, given that the OOB read value is ending up as the address field of a struct I think i seems plausible that this could lead to an OOB write if the attacker is able to cause the OOB read to pull an interesting kernel address. Regardless if this is a read or write, it is a High severity issue in the kernel.Product: AndroidVersions: Android SoCAndroid ID: A-238904312

CVE-2022-20385CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1284

a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it access polciy array 'policy[type]', which OOB access happens.Product: AndroidVersions: Android SoCAndroid ID: A-238379819

CVE-2022-20386CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227328

CVE-2022-20387CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227324

CVE-2022-20388CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227323

CVE-2022-20389CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257004

CVE-2022-20390CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257002

CVE-2022-20391CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257000

CVE-2022-38637CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password parameters on the Login page.

CVE-2022-39815CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated users to execute commands on the operating system.

CVE-2022-38768CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to bypass authorization.

CVE-2022-38771CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to send SCRIPT tags as injected input to the API request.

CVE-2022-34831CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-295

An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0, related to possible inconsistencies in DNS identifiers submitted in an ACME order and the corresponding CSR submitted during finalization. During the ACME enrollment process, an order is submitted containing an identifier for one or multiple dnsNames. These are validated properly in the ACME challenge. However, if the validation passes, a non-compliant client can include additional dnsNames the CSR sent to the finalize endpoint, resulting in EJBCA issuing a certificate including the identifiers that were not validated. This occurs even if the certificate profile is configured to not allow a DN override by the CSR.

CVE-2022-36436CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

OSU Open Source Lab VNCAuthProxy through 1.1.1 is affected by an vncap/vnc/protocol.py VNCServerAuthenticator authentication-bypass vulnerability that could allow a malicious actor to gain unauthorized access to a VNC session or to disconnect a legitimate user from a VNC session. A remote attacker with network access to the proxy server could leverage this vulnerability to connect to VNC servers protected by the proxy server without providing any authentication credentials. Exploitation of this issue requires that the proxy server is currently accepting connections for the target VNC server.

CVE-2022-36669CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

CVE-2022-37138CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Loan Management System 1.0 is vulnerable to SQL Injection at the login page, which allows unauthorized users to login as Administrator after injecting username form.

CVE-2022-35947CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Affected versions have been found to be vulnerable to a SQL injection attack which an attacker could leverage to simulate an arbitrary user login. Users are advised to upgrade to version 10.0.3. Users unable to upgrade should disable the `Enable login with external token` API configuration.

CVE-2022-38308CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOLink A700RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the lang parameter in the function cstesystem. This vulnerability allows attackers to execute arbitrary commands via a crafted payload.

CVE-2022-38352CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

CVE-2022-37257CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js.

CVE-2022-37266CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

Prototype pollution vulnerability in function extend in babel.js in stealjs steal 2.2.4 via the key variable in babel.js.

CVE-2022-2471CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

Stack-based Buffer Overflow vulnerability in the EZVIZ Motion Detection component as used in camera models CS-CV248, CS-C6N-A0-1C2WFR, CS-DB1C-A0-1E2W2FR, CS-C6N-B0-1G2WF, CS-C3W-A0-3H4WFRL allows a remote attacker to execute remote code on the device. This issue affects: EZVIZ CS-CV248 versions prior to 5.2.3 build 220725. EZVIZ CS-C6N-A0-1C2WFR versions prior to 5.3.0 build 220428. EZVIZ CS-DB1C-A0-1E2W2FR versions prior to 5.3.0 build 220802. EZVIZ CS-C6N-B0-1G2WF versions prior to 5.3.0 build 220712. EZVIZ CS-C3W-A0-3H4WFRL versions prior to 5.3.5 build 220723.

CVE-2022-37264CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

Prototype pollution vulnerability in stealjs steal 2.2.4 via the optionName variable in main.js.

CVE-2022-37861CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

There is a remote code execution (RCE) vulnerability in Tenhot TWS-100 V4.0-201809201424 router device. It is necessary to know that the device account password is allowed to escape the execution system command through the network tools in the network diagnostic component.

CVE-2022-38325CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the filePath parameter at /goform/expandDlnaFile.

CVE-2022-38326CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the page parameter at /goform/NatStaticSetting.

CVE-2022-26959CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version 6.3 application. The vulnerabilities exist in the userName parameter of the processlogin.jsp page in the /northstar/Portal/ directory and the userID parameter of the login.jsp page in the /northstar/iphone/ directory. Exploitation of the SQL injection vulnerabilities allows full access to the database which contains critical data for organization’s that make full use of the software suite.

CVE-2022-36536CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-330

An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens.

CVE-2022-22105CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

Memory corruption in bluetooth due to integer overflow while processing HFP-UNIT profile in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music

CVE-2022-25686CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Memory corruption in video module due to buffer overflow while processing WAV file in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

CVE-2022-25688CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Memory corruption in video due to buffer overflow while parsing ps video clips in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2022-25708CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Memory corruption in WLAN due to buffer copy without checking size of input while parsing keys in Snapdragon Connectivity, Snapdragon Mobile

CVE-2021-42949CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.

CVE-2022-38823CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample.

CVE-2022-38826CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

In TOTOLINK T6 V4.1.5cu.709_B20210518, there is an execute arbitrary command in cstecgi.cgi.

CVE-2022-38827CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to Buffer Overflow via cstecgi.cgi

CVE-2022-38828CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to command injection via cstecgi.cgi

CVE-2022-38829CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setMacFilterCfg.

CVE-2022-38830CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setIPv6Status.

CVE-2022-38831CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/SetNetControlList

CVE-2021-40017CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may result in out-of-bounds memory access.

CVE-2022-38999CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The AOD module has the improper update of reference count vulnerability. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.

CVE-2022-39000CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vulnerability will cause malicious apps to automatically start upon system startup.

CVE-2022-39002CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

Double free vulnerability in the storage module. Successful exploitation of this vulnerability will cause the memory to be freed twice.

CVE-2022-39007CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

The location module has a vulnerability of bypassing permission verification.Successful exploitation of this vulnerability may cause privilege escalation.

CVE-2022-39009CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

The WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause third-party apps to affect WLAN functions.

CVE-2022-38621CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Doufox v0.0.4 was discovered to contain a remote code execution (RCE) vulnerability via the edit file page. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

← PreviousPage 449 / 7034Next →