CVE Database

CVE-2022-41226CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

CVE-2022-32882CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. An app may be able to bypass Privacy preferences.

CVE-2022-40357CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

A security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the zb_users/plugin/UEditor/php/action_crawler.php file allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the source parameter.

CVE-2022-38619CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf.

CVE-2022-41220CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

md2roff 1.9 has a stack-based buffer overflow via a Markdown file, a different vulnerability than CVE-2022-34913. NOTE: the vendor's position is that the product is not intended for untrusted input

CVE-2022-37026CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.

CVE-2022-41237CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

CVE-2022-41238CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-862

A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository for attacker-specified commits.

CVE-2022-40030CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at changeStatus.php.

CVE-2021-43310CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-290

A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent were being re-added to a verifier. This could lead to a remote code execution.

CVE-2022-3268CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-521

Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.

CVE-2022-31937CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Netgear N300 wireless router wnr2000v4-V1.0.0.70 was discovered to contain a stack overflow via strcpy in uhttpd.

CVE-2022-36934CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

An integer overflow in WhatsApp could result in remote code execution in an established video call.

CVE-2022-40087CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-40089CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow_url_include is set to On.

CVE-2022-38573CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

10-Strike Network Inventory Explorer v9.3 was discovered to contain a buffer overflow via the Add Computers function.

CVE-2022-37232CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Netgear N300 wireless router wnr2000v4-V1.0.0.70 is vulnerable to Buffer Overflow via uhttpd. There is a stack overflow vulnerability caused by strcpy.

CVE-2022-37235CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncat

CVE-2022-35951CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

Redis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Integer Overflow. Executing an `XAUTOCLAIM` command on a stream key in a specific state, with a specially crafted `COUNT` argument may cause an integer overflow, a subsequent heap overflow, and potentially lead to remote code execution. This has been patched in Redis version 7.0.5. No known workarounds exist.

CVE-2022-26112CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support. In order to avoid this, we disabled the groovy function support by default from Pinot release 0.11.0. See https://docs.pinot.apache.org/basics/releases/0.11.0

CVE-2022-3269CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-384

Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7.

CVE-2022-40851CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AC15 V15.03.05.19 contained a stack overflow via the function fromAddressNat.

CVE-2022-40854CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AC18 router contained a stack overflow vulnerability in /goform/fast_setting_wifi_set

CVE-2022-40853CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AC15 router V15.03.05.19 contains a stack overflow via the list parameter at /goform/fast_setting_wifi_set

CVE-2022-40860CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AC15 router V15.03.05.19 contains a stack overflow vulnerability in the function formSetQosBand->FUN_0007dd20 with request /goform/SetNetControlList

CVE-2022-40862CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulnerability in the function fromNatStaticSetting with the request /goform/NatStaticSetting

CVE-2022-40864CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function setSmartPowerManagement with the request /goform/PowerSaveSet

CVE-2022-40865CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AC15 and AC18 routers V15.03.05.19 contain heap overflow vulnerabilities in the function setSchedWifi with the request /goform/openSchedWifi/

CVE-2022-40869CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function fromDhcpListClient with a combined parameter "list*" ("%s%d","list").

CVE-2022-40855CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda W20E router V15.11.0.6 contains a stack overflow in the function formSetPortMapping with post request 'goform/setPortMapping/'. This vulnerability allows attackers to cause a Denial of Service (DoS) or Remote Code Execution (RCE) via the portMappingServer, portMappingProtocol, portMappingWan, porMappingtInternal, and portMappingExternal parameters.

CVE-2022-40866CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formSetDebugCfg with request /goform/setDebugCfg/

CVE-2022-40867CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formIPMacBindDel with the request /goform/delIpMacBind/

CVE-2022-40868CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formDelDhcpRule with the request /goform/delDhcpRules/

CVE-2022-2970CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) does not sanitize input before memcpy is used, which could allow an attacker to crash the device or remotely execute arbitrary code.

CVE-2022-2972CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) is vulnerable to a stack-based buffer overflow, which could allow an attacker to crash the device or remotely execute arbitrary code.

CVE-2022-38742CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. An attacker could send a specifically crafted TFTP or HTTPS request, causing a heap-based buffer overflow that crashes the ThinServer process. If successfully exploited, this could expose the server to arbitrary remote code execution.

CVE-2022-40628CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper control of code generation in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted device. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary commands on the targeted device.

CVE-2022-36944CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0 functions) via a gadget chain.

CVE-2022-40122CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/edit_customer_action.php.

CVE-2022-40100CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Tenda i9 v1.0.0.8(3828) was discovered to contain a command injection vulnerability via the FormexeCommand function.

CVE-2022-40121CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/manage_customers.php.

CVE-2022-40630CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-384

This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper session management in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted device. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to perform session fixation on the targeted device.

CVE-2022-40113CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/send_funds.php.

CVE-2022-40114CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/edit_customer.php.

CVE-2022-40115CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/delete_beneficiary.php.

CVE-2022-40116CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/beneficiary.php.

CVE-2022-40117CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/delete_customer.php.

CVE-2022-40118CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/send_funds_action.php.

CVE-2022-40119CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net-banking/transactions.php.

CVE-2022-40120CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net-banking/customer_transactions.php.

← PreviousPage 451 / 7034Next →