CVE Database

CVE-2022-23463CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-917

Nepxion Discovery is a solution for Spring Cloud. Discover is vulnerable to SpEL Injection in discovery-commons. DiscoveryExpressionResolver’s eval method is evaluating expression with a StandardEvaluationContext, allowing the expression to reach and interact with Java classes such as java.lang.Runtime, leading to Remote Code Execution. There is no patch available for this issue at time of publication. There are no known workarounds.

CVE-2022-21797CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.

CVE-2022-39243CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

NuProcess is an external process execution implementation for Java. In all the versions of NuProcess where it forks processes by using the JVM's Java_java_lang_UNIXProcess_forkAndExec method (1.2.0+), attackers can use NUL characters in their strings to perform command line injection. Java's ProcessBuilder isn't vulnerable because of a check in ProcessBuilder.start. NuProcess is missing that check. This vulnerability can only be exploited to inject command line arguments on Linux. Version 2.0.5 contains a patch. As a workaround, users of the library can sanitize command strings to remove NUL characters prior to passing them to NuProcess for execution.

CVE-2022-40483CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /wedding_details.php.

CVE-2022-40484CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_edit.php.

CVE-2022-40485CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /package_detail.php.

CVE-2022-28721CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Certain HP Print Products are potentially vulnerable to Remote Code Execution.

CVE-2022-28722CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Certain HP Print Products are potentially vulnerable to Buffer Overflow.

CVE-2022-30004CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing remote attackers to dump the SQL database via time-based SQL injection..

CVE-2022-40050CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1.

CVE-2021-41433CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection vulnerability exists in version 1.0 of the Resumes Management and Job Application Website application login form by EGavilan Media that allows authentication bypass through login.php.

CVE-2022-37346CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a remote unauthenticated attacker to upload arbitrary files other than image files. If a user with an administrative privilege of EC-CUBE where the vulnerable plugin is installed is led to upload a specially crafted file, an arbitrary script may be executed on the system.

CVE-2022-40877CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter.

CVE-2022-41570CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Unauthenticated SQL injection can occur.

CVE-2022-41571CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Local file inclusion can occur.

CVE-2022-39033CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication, access restricted paths to download and delete arbitrary system files to disrupt service.

CVE-2022-3332CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-707

A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System. This affects an unknown part of the file router.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-209583.

CVE-2022-40942CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda TX3 US_TX3V1.0br_V16.03.13.11 is vulnerable to stack overflow via compare_parentcontrol_time.

CVE-2022-22522CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain full access to the device.

CVE-2022-22526CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a missing authentication allows for full access via API.

CVE-2022-28811CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could utilize an improper input validation on an API-submitted parameter to execute arbitrary OS commands.

CVE-2022-28812CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain SuperUser access to the device.

CVE-2022-28814CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-23

Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a relative path traversal vulnerability which enables remote attackers to read arbitrary files and gain full control of the device.

CVE-2022-40929CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).

CVE-2016-2338CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function heap buffer "head" allocation is made based on tags array length. Specially constructed object passed as element of tags array can increase this array size after mentioned allocation and cause heap overflow.

CVE-2020-15331CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-311

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.

CVE-2020-15332CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-312

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.

CVE-2020-15347CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-522

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account.

CVE-2020-27602CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.

CVE-2020-35674CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

BigProf Online Invoicing System before 2.9 suffers from an unauthenticated SQL Injection found in /membership_passwordReset.php (the endpoint that is responsible for issuing self-service password resets). An unauthenticated attacker is able to send a request containing a crafted payload that can result in sensitive information being extracted from the database, eventually leading into an application takeover. This vulnerability was introduced as a result of the developer trying to roll their own sanitization implementation in order to allow the application to be used in legacy environments.

CVE-2021-45790CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where attackers can write a cron job to execute commands.

CVE-2022-42302CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a SQL Injection attack affecting the NBFSMCLIENT service.

CVE-2022-42303CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a second-order SQL Injection attack affecting the NBFSMCLIENT service by leveraging CVE-2022-42302.

CVE-2022-42304CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a SQL Injection attack affecting idm, nbars, and SLP manager code.

CVE-2022-29503CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An attacker can create threads to trigger this vulnerability.

CVE-2022-40887CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SourceCodester Best Student Result Management System 1.0 is vulnerable to SQL Injection.

CVE-2022-39266CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

isolated-vm is a library for nodejs which gives the user access to v8's Isolate interface. In versions 4.3.6 and prior, if the untrusted v8 cached data is passed to the API through CachedDataOptions, attackers can bypass the sandbox and run arbitrary code in the nodejs process. Version 4.3.7 changes the documentation to warn users that they should not accept `cachedData` payloads from a user.

CVE-2022-33880CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

hms-staff.php in Projectworlds Hospital Management System Mini-Project through 2018-06-17 allows SQL injection via the type parameter.

CVE-2022-2778CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.

CVE-2022-40314CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.

CVE-2022-40315CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A limited SQL injection risk was identified in the "browse list of users" site administration page.

CVE-2022-40944CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file.

CVE-2022-35156CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..

CVE-2022-40943CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file.

CVE-2022-40721CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Arbitrary file upload vulnerability in php uploader

CVE-2022-42307CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) Injection attack through the DiscoveryService service.

CVE-2022-33882CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Under certain conditions, an attacker could create an unintended sphere of control through a vulnerability present in file delete operation in Autodesk desktop app (ADA). An attacker could leverage this vulnerability to escalate privileges and execute arbitrary code.

CVE-2022-41443CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-116

phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.

CVE-2022-3398CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code.

CVE-2022-37888CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute arbitrary code as a privileged user on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InnstantOS that address these security vulnerabilities.

← PreviousPage 452 / 7034Next →