CVE Database

CVE-2022-45872CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

iTerm2 before 3.4.18 mishandles a DECRQSS response.

CVE-2022-4136CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-749

Dangerous method exposed which can lead to RCE in qmpass/leadshop v1.4.15 allows an attacker to control the target host by calling any function in leadshop.php via the GET method.

CVE-2022-4088CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-707

A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some unknown functionality of the file /pages/processlogin.php. The manipulation of the argument user/password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-214322 is the identifier assigned to this vulnerability.

CVE-2022-2650CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

Improper Restriction of Excessive Authentication Attempts in GitHub repository wger-project/wger prior to 2.2.

CVE-2022-45206CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.

CVE-2022-45207CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.

CVE-2022-41705CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate the data uploaded by users.

CVE-2022-44401CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php.

CVE-2022-45476CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is possible because the application is vulnerable to insecure file upload.

CVE-2022-41157CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the SYSTEM authority. This vulnerability could allow attackers to leak or steal sensitive information or execute malicious commands.

CVE-2022-41158CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Remote code execution vulnerability can be achieved by using cookie values as paths to a file by this builder program. A remote attacker could exploit the vulnerability to execute or inject malicious code.

CVE-2022-44843CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port parameter in the setting/setOpenVpnClientCfg function.

CVE-2022-44844CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass parameter in the setting/setOpenVpnCfg function.

CVE-2022-45907CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.

CVE-2022-45908CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on a user-supplied winstr. This may lead to arbitrary code execution.

CVE-2022-36193CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.

CVE-2022-3603CRITICALnone
CVSS 9.8
EPSS
Priority 0

The Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list WordPress plugin before 2.0.69 does not validate data when outputting it back in a CSV file, which could lead to CSV injection.

CVE-2022-44400CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info.

CVE-2022-41912CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version.

CVE-2022-44283CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

AVS Audio Converter 10.3 is vulnerable to Buffer Overflow.

CVE-2022-44399CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Poultry Farm Management System v1.0 contains a SQL injection vulnerability via the del parameter at /Redcock-Farm/farm/category.php.

CVE-2022-42109CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php.

CVE-2022-44038CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Russound XSourcePlayer 777D v06.08.03 was discovered to contain a remote code execution vulnerability via the scriptRunner.cgi component.

CVE-2022-44367CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setUplinkInfo.

CVE-2022-44136CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).

CVE-2022-3751CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection in GitHub repository owncast/owncast prior to 0.0.13.

CVE-2022-44151CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php.

CVE-2022-44097CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Book Store Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.

CVE-2022-44096CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Sanitization Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.

CVE-2022-4222CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-707

A vulnerability was found in SourceCodester Canteen Management System. It has been rated as critical. This issue affects the function query of the file ajax_invoice.php of the component POST Request Handler. The manipulation of the argument search leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-214523.

CVE-2022-4229CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

A vulnerability classified as critical was found in SourceCodester Book Store Management System 1.0. This vulnerability affects unknown code of the file /bsms_ci/index.php. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214588.

CVE-2022-4232CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-266

A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. Affected is an unknown function. The manipulation of the argument cmd leads to unrestricted upload. It is possible to launch the attack remotely. VDB-214590 is the identifier assigned to this vulnerability.

CVE-2022-44262CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).

CVE-2022-37016CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

CVE-2022-46162CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

discourse-bbcode is the official BBCode plugin for Discourse. Prior to commit 91478f5, CSS injection can occur when rendering content generated with the discourse-bccode plugin. This vulnerability only affects sites which have the discourse-bbcode plugin installed and enabled. This issue is patched in commit 91478f5. As a workaround, ensure that the Content Security Policy is enabled and monitor any posts that contain bbcode.

CVE-2022-36431CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file. Issue fixed in version 7.9.6.1.

CVE-2022-4247CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-707

A vulnerability classified as critical was found in Movie Ticket Booking System. This vulnerability affects unknown code of the file booking.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214624.

CVE-2022-4248CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-707

A vulnerability, which was classified as critical, has been found in Movie Ticket Booking System. This issue affects some unknown processing of the file editBooking.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-214625 was assigned to this vulnerability.

CVE-2022-4221CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated attacker to inject arbitrary OS commands via unsanitized cookie values.This issue affects NAS-M25: through 1.0.1.7.

CVE-2022-1471CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.

CVE-2022-3270CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1059

In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.

CVE-2022-30528CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to execute arbitrary commands via the username parameter to /system/user/modules/mod_users/controller.php.

CVE-2022-43333CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the component action_export_control.php.

CVE-2022-43325CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows attackers to execute arbitrary commands via a crafted payload injected into the license input.

CVE-2022-44928CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.

CVE-2022-44929CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles.

CVE-2022-44930CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function.

CVE-2022-2807CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection vulnerability in Algan Software Prens Student Information System allows SQL Injection. This issue affects Prens Student Information System: before 2.1.11.

CVE-2022-46366CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability only affects Apache Tapestry version line 3.x, which is no longer supported by the maintainer. Users are recommended to upgrade to a supported version line of Apache Tapestry.

CVE-2022-45482CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-521

Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticated users to easily and quickly brute force the PIN and execute arbitrary commands. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

← PreviousPage 463 / 7034Next →