CVE Database

CVE-2022-44785CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection vulnerabilities, some of which executable even by unauthenticated users, as demonstrated by the GetListaEnti.do cfamm parameter.

CVE-2022-44190CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter enable_band_steering.

CVE-2022-36179CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-613

Fusiondirectory 1.3 suffers from Improper Session Handling.

CVE-2022-41326CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper authorization controls. A successful exploit could allow remote code execution within the context of the application.

CVE-2022-43214CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php.

CVE-2022-43215CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php.

CVE-2022-36227CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-476

In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."

CVE-2022-40602CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an improper pre-configured password if the remote administration feature has been enabled by an authenticated administrator.

CVE-2022-38649CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access to DAG files. This issue affects Apache Airflow Pinot Provider versions prior to 4.0.0. It also impacts any Apache Airflow versions prior to 2.3.0 in case Apache Airflow Pinot Provider is installed (Apache Airflow Pinot Provider 4.0.0 can only be installed for Airflow 2.3.0+). Note that you need to manually install the Pinot Provider version 4.0.0 in order to get rid of the vulnerability on top of Airflow 2.3.0+ version.

CVE-2022-44191CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameters KEY1 and KEY2.

CVE-2022-40189CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access to DAG files. This issue affects Pig Provider versions prior to 4.0.0. It also impacts any Apache Airflow versions prior to 2.3.0 in case Pig Provider is installed (Pig Provider 4.0.0 can only be installed for Airflow 2.3.0+). Note that you need to manually install the Pig Provider version 4.0.0 in order to get rid of the vulnerability on top of Airflow 2.3.0+ version.

CVE-2022-44193CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameters: starthour, startminute , endhour, and endminute.

CVE-2022-44186CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_pri.

CVE-2022-44187CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via wan_dns1_pri.

CVE-2022-44194CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_dns1_pri and apmode_dns1_sec.

CVE-2022-44196CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_push1.

CVE-2022-44197CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.

CVE-2022-44198CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_push1.

CVE-2022-44199CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.

CVE-2022-44200CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Netgear R7000P V1.3.0.8, V1.3.1.64 is vulnerable to Buffer Overflow via parameters: stamode_dns1_pri and stamode_dns1_sec.

CVE-2022-44184CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_sec.

CVE-2022-44201CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.

CVE-2022-44202CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow.

CVE-2022-44801CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control.

CVE-2022-44804CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

D-Link DIR-882 1.10B02 and1.20B06 is vulnerable to Buffer Overflow via the websRedirect function.

CVE-2022-44806CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow.

CVE-2022-44807CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow via webGetVarString.

CVE-2022-44808CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can process the request, the system function executes an untrusted command that triggers the vulnerability.

CVE-2022-39070CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote attackers could use the vulnerability to log in to the device and execute any operation.

CVE-2022-43212CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php.

CVE-2022-4116CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution.

CVE-2020-23583CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that leads to COMMAND EXECUTION. An attacker can successfully trigger the COMMAND and can compromise full system.

CVE-2020-23584CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute commands on " /diag_tracert_admin.asp " in the "PingTest" parameter that leads to command execution.

CVE-2020-23591CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker to upload arbitrary files through " /mgm_dev_upgrade.asp " which can "delete every file for Denial of Service (using 'rm -rf *.*' in the code), reverse connection (using '.asp' webshell), backdoor.

CVE-2022-43213CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php.

CVE-2022-45462CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade to version 2.0.6 or higher

CVE-2022-44139CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php.

CVE-2022-44249CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.

CVE-2022-44250CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.

CVE-2022-44251CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.

CVE-2022-44252CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.

CVE-2022-44255CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main function via long post data.

CVE-2021-35284CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection vulnerability in function get_user in login_manager.php in rizalafani cms-php v1.

CVE-2022-44118CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php.

CVE-2022-44120CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.

CVE-2022-41922CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

`yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. This has been patched in 1.1.27.

CVE-2022-41875CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

A remote code execution (RCE) vulnerability in Optica allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Specially crafted JSON payloads may lead to RCE (remote code execution) on the attacked system running Optica. The vulnerability was patched in v. 0.10.2, where the call to the function `oj.load` was changed to `oj.safe_load`.

CVE-2022-41923CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-269

Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to one endpoint (i.e. the targeted endpoint) using the authorization requirements of a different endpoint (i.e. the donor endpoint). In some Grails framework applications, access to the targeted endpoint will be granted based on meeting the authorization requirements of the donor endpoint, which can result in a privilege escalation attack. This vulnerability has been patched in grails-spring-security-core versions 3.3.2, 4.0.5 and 5.1.1. Impacted Applications: Grails Spring Security Core plugin versions: 1.x 2.x >=3.0.0 <3.3.2 >=4.0.0 <4.0.5 >=5.0.0 <5.1.1 We strongly suggest that all Grails framework applications using the Grails Spring Security Core plugin be updated to a patched release of the plugin. Workarounds: Users should create a subclass extending one of the following classes from the `grails.plugin.springsecurity.web.access.intercept` package, depending on their security configuration: * `AnnotationFilterInvocationDefinition` * `InterceptUrlMapFilterInvocationDefinition` * `RequestmapFilterInvocationDefinition` In each case, the subclass should override the `calculateUri` method like so: ``` @Override protected String calculateUri(HttpServletRequest request) { UrlPathHelper.defaultInstance.getRequestUri(request) } ``` This should be considered a temporary measure, as the patched versions of grails-spring-security-core deprecates the `calculateUri` method. Once upgraded to a patched version of the plugin, this workaround is no longer needed. The workaround is especially important for version 2.x, as no patch is available version 2.x of the GSSC plugin.

CVE-2022-44117CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa does not ship with any support for SQL.

CVE-2022-45276CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-425

An issue in the /index/user/user_edit.html component of YJCMS v1.0.9 allows unauthenticated attackers to obtain the Administrator account password.

← PreviousPage 462 / 7034Next →