CVE Database

CVE-2022-24942CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTTP request.

CVE-2022-42245CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Dreamer CMS 4.0.01 is vulnerable to SQL Injection.

CVE-2022-42785CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker, can log in without knowledge of the password by crafting a modified HTTP GET Request.

CVE-2022-43265CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-2166CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

Improper Restriction of Excessive Authentication Attempts in GitHub repository mastodon/mastodon prior to 4.0.0.

CVE-2022-4011CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-707

A vulnerability was found in Simple History Plugin. It has been rated as critical. This issue affects some unknown processing of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to improper output neutralization for logs. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-213785 was assigned to this vulnerability.

CVE-2022-4012CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-707

A vulnerability classified as critical has been found in Hospital Management Center. Affected is an unknown function of the file patient-info.php. The manipulation of the argument pt_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-213786 is the identifier assigned to this vulnerability.

CVE-2022-4015CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-707

A vulnerability, which was classified as critical, was found in Sports Club Management System 119. This affects an unknown part of the file admin/make_payments.php. The manipulation of the argument m_id/plan leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-213789 was assigned to this vulnerability.

CVE-2022-45047CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apache MINA SSHD can choose for loading the host keys of an SSH server.

CVE-2022-43234CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

An arbitrary file upload vulnerability in the /attachments component of Hoosk v1.8 allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-43256CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.

CVE-2022-43262CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /hrm/controller/login.php.

CVE-2022-43135CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /diagnostic/login.php.

CVE-2022-43999CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

An issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system commands can be executed on the server.

CVE-2022-40752CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID:  236687.

CVE-2022-44000CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

An issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is possible to execute arbitrary system commands on the server.

CVE-2022-44003CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations.

CVE-2022-44004CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-640

An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can complete the password-reset process for any account and set a new password.

CVE-2022-44006CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files outside the intended target location. Achieving remote code execution is possible, e.g., by uploading an executable file.

CVE-2022-43781CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.

CVE-2022-44183CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetWifiGuestBasic.

CVE-2022-43138CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.

CVE-2022-4051CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-707

A vulnerability has been found in Hostel Searching Project and classified as critical. This vulnerability affects unknown code of the file view-property.php. The manipulation of the argument property_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-213844.

CVE-2022-44001CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

An issue was discovered in BACKCLICK Professional 5.9.63. User authentication for accessing the CORBA back-end services can be bypassed.

CVE-2022-36787CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

webvendome - webvendome SQL Injection. SQL Injection in the Parameter " DocNumber" Request : Get Request : /webvendome/showfiles.aspx?jobnumber=nullDoc Number=HERE.

CVE-2022-38165CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with the contents in arbitrary locations on the F-Secure Policy Manager Server.

CVE-2022-39180CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

College Management System v1.0 - SQL Injection (SQLi). By inserting SQL commands to the username and password fields in the login.php page

CVE-2022-44204CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

D-Link DIR3060 DIR3060A1_FW111B04.bin is vulnerable to Buffer Overflow.

CVE-2022-45474CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

drachtio-server 0.8.18 has a request-handler.cpp event_cb use-after-free for any request.

CVE-2022-41652CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.

CVE-2022-41781CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-264

Broken Access Control vulnerability in Permalink Manager Lite plugin <= 2.2.20 on WordPress.

CVE-2022-44172CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function R7WebsSecurityHandler.

CVE-2022-41900CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

TensorFlow is an open source platform for machine learning. The security vulnerability results in FractionalMax(AVG)Pool with illegal pooling_ratio. Attackers using Tensorflow can exploit the vulnerability. They can access heap memory which is not in the control of user, leading to a crash or remote code execution. We have patched the issue in GitHub commit 216525144ee7c910296f5b05d214ca1327c9ce48. The fix will be included in TensorFlow 2.11.0. We will also cherry pick this commit on TensorFlow 2.10.1.

CVE-2021-34182CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-276

An issue in ttyd v.1.6.3 allows attacker to execute arbitrary code via default configuration permissions.

CVE-2022-42497CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Arbitrary Code Execution vulnerability in Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress.

CVE-2022-42698CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Unauth. Arbitrary File Upload vulnerability in WordPress Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress.

CVE-2022-44174CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Tenda AC18 V15.03.05.05 is vulnerable to Buffer Overflow via function formSetDeviceName.

CVE-2022-45132CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configuration files in lava-server loads input as a Jinja2 template in a way that can be used to trigger remote code execution in the LAVA server.

CVE-2022-44175CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetMacFilterCfg.

CVE-2022-41155CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Block BYPASS vulnerability in iQ Block Country plugin <= 1.2.18 on WordPress.

CVE-2022-4070CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-613

Insufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0.

CVE-2022-4093CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to reputational damage and regulatory fines. In some cases, an attacker can obtain a persistent backdoor into an organization's systems, leading to a long-term compromise that can go unnoticed for an extended period. This affect 16.0.1 and 16.0.2 only. 16.0.0 or lower, and 16.0.3 or higher are not affected

CVE-2021-24649CRITICALnone
CVSS 9.8
EPSS
Priority 0

The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having access to the AUTH_KEY and AUTH_SALT constant (via an arbitrary file access issue for example, or if the blog is using the default keys) to create an account with any role they want, such as admin

CVE-2022-3600CRITICALnone
CVSS 9.8
EPSS
Priority 0

The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which could lead to CSV injection.

CVE-2022-3634CRITICALnone
CVSS 9.8
EPSS
Priority 0

The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV file, which could lead to CSV injection

CVE-2022-44171CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function form_fast_setting_wifi_set.

CVE-2022-44188CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter enable_band_steering.

CVE-2022-30257CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-706

An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effects of an exploit would be widespread and highly impactful, because the exploitation conforms to de facto DNS specifications and operational practices, and overcomes current mitigation patches for "Ghost" domain names.

CVE-2022-30258CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-706

An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effects of an exploit would be widespread and highly impactful, because the exploitation conforms to de facto DNS specifications and operational practices, and overcomes current mitigation patches for "Ghost" domain names.

CVE-2022-41945CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

super-xray is a vulnerability scanner (xray) GUI launcher. In version 0.1-beta, the URL is not filtered and directly spliced ​​into the command, resulting in a possible RCE vulnerability. Users should upgrade to super-xray 0.2-beta.

← PreviousPage 461 / 7034Next →