CVE Database

CVE-2022-35711CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent to the server.

CVE-2022-35712CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent to the server.

CVE-2022-38418CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

CVE-2022-42163CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/fromNatStaticSetting.

CVE-2022-42164CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetClientState.

CVE-2017-20149CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthenticated user can trigger the vulnerability by sending a crafted HTTP request. An attacker can use this vulnerability to execute arbitrary code on the affected system, as exploited in the wild in mid-2017 and later.

CVE-2022-42165CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetDeviceName.

CVE-2022-42968CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-88

Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.

CVE-2022-42980CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

go-admin (aka GO Admin) 2.0.12 uses the string go-admin as a production JWT key.

CVE-2022-2052CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use these accounts to remotely gain full access to the system.

CVE-2022-42154CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-42166CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetSpeedWan.

CVE-2022-42167CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetFirewallCfg.

CVE-2022-42168CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/fromSetIpMacBind.

CVE-2022-42169CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/addWifiMacFilter.

CVE-2022-42170CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formWifiWpsStart.

CVE-2022-42171CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/saveParentControlInfo.

CVE-2022-42237CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL Injection issue in Merchandise Online Store v.1.0 allows an attacker to log in to the admin account.

CVE-2022-0699CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attacker to cause a denial of service or have other unspecified impact via control over malloc.

CVE-2022-22128CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow remote code execution.Tableau only supports product versions for 24 months after release. Older versions have reached their End of Life and are no longer supported. They are also not assessed for potential security issues and do not receive security updates.

CVE-2022-23769CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Remote code execution vulnerability due to insufficient user privilege verification in reverseWall-MDS. Remote attackers can exploit the vulnerability such as stealing account, through remote code execution.

CVE-2022-23770CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

This vulnerability could allow a remote attacker to execute remote commands with improper validation of parameters of certain API constructors. Remote attackers could use this vulnerability to execute malicious commands such as directory traversal.

CVE-2022-40055CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page.

CVE-2022-42149CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java.

CVE-2022-22241CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data without proper authorization. Utilizing a crafted POST request, deserialization may occur which could lead to unauthorized local file access or the ability to execute arbitrary commands. This issue affects Juniper Networks Junos OS: all versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S7; 19.4 versions prior to 19.4R2-S7, 19.4R3-S9; 20.1 versions prior to 20.1R3-S5; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S4; 21.1 versions prior to 21.1R3-S2; 21.2 versions prior to 21.2R3-S1; 21.3 versions prior to 21.3R2-S2, 21.3R3; 21.4 versions prior to 21.4R1-S2, 21.4R2-S1, 21.4R3; 22.1 versions prior to 22.1R1-S1, 22.1R2.

CVE-2022-39056CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

RAVA certificate validation system has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify and delete database.

CVE-2022-3579CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-707

A vulnerability classified as critical was found in SourceCodester Cashier Queuing System 1.0. This vulnerability affects unknown code of the file /queuing/login.php of the component Login Page. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-211186 is the identifier assigned to this vulnerability.

CVE-2022-3583CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-707

A vulnerability was found in SourceCodester Canteen Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument business leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-211192.

CVE-2022-40889CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.

CVE-2022-35846CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiTester Telnet port 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to guess the credentials of an admin user via a brute force attack.

CVE-2022-33872CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute arbitrary command in the underlying shell.

CVE-2022-33873CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Console login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to execute arbitrary command in the underlying shell.

CVE-2022-33874CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in SSH login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute arbitrary command in the underlying shell.

CVE-2022-43260CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AC18 V15.03.05.19(6318) was discovered to contain a stack overflow via the time parameter in the fromSetSysTime function.

CVE-2022-39198CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.17 and prior versions; Apache Dubbo 3.0.x version 3.0.11 and prior versions; Apache Dubbo 3.1.x version 3.1.0 and prior versions.

CVE-2022-43019CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.

CVE-2022-43184CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

D-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc.cgi.

CVE-2022-39428CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2016-20016CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /shell URI. A remote unauthenticated attacker can execute arbitrary operating system commands as root. This vulnerability has also been referred to as the "JAWS webserver RCE" because of the easily identifying HTTP response server field. Other firmware versions, at least from 2014 through 2019, can be affected. This was exploited in the wild in 2017 through 2022.

CVE-2016-20017KEVCRITICALin_the_wild
CVSS 9.8
EPSS 93.41%
Priority 70

D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.

CVE-2022-25748CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

Memory corruption in WLAN due to integer overflow to buffer overflow while parsing GTK frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

CVE-2022-25687CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

memory corruption in video due to buffer overflow while parsing asf clips in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2022-25718CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-252

Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

CVE-2022-25720CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-129

Memory corruption in WLAN due to out of bound array access during connect/roaming in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2022-41415CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Acer Altos W2000h-W570h F4 R01.03.0018 was discovered to contain a stack overflow in the RevserveMem component. This vulnerability allows attackers to cause a Denial of Service (DoS) via injecting crafted shellcode into the NVRAM variable.

CVE-2022-43024CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.

CVE-2022-43025CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the startIp parameter at /goform/SetPptpServerCfg.

CVE-2022-43026CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the endIp parameter at /goform/SetPptpServerCfg.

CVE-2022-43027CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the firewallEn parameter at /goform/SetFirewallCfg.

CVE-2022-43028CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the timeZone parameter at /goform/SetSysTimeCfg.

← PreviousPage 455 / 7034Next →