| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-32400 | Hig | 0.47 | 7.2 | 0.01 | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/user/manage_user.php:4. | ||
| CVE-2022-32399 | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/view_crime.php:4 | ||
| CVE-2022-32398 | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/manage_cell.php:4 | ||
| CVE-2022-32397 | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/view_visit.php:4 | ||
| CVE-2022-32396 | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/manage_visit.php:4 | ||
| CVE-2022-32395 | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/manage_crime.php:4 | ||
| CVE-2022-32394 | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/view_inmate.php:3 | ||
| CVE-2022-32393 | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/view_cell.php:4 | ||
| CVE-2022-32392 | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/manage_action.php:4 | ||
| CVE-2022-32391 | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/view_action.php:4 | ||
| CVE-2022-2183 | Hig | 0.00 | 7.8 | 0.01 | Jun 23, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2182 | Hig | 0.00 | 7.8 | 0.01 | Jun 23, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-34300 | Hig | 0.57 | 8.8 | 0.01 | Jun 23, 2022 | In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData. | ||
| CVE-2022-34299 | Hig | 0.00 | 8.1 | 0.01 | Jun 23, 2022 | There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b. | ||
| CVE-2022-34296 | Hig | 0.42 | 7.5 | 0.01 | Jun 23, 2022 | In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request. | ||
| CVE-2022-34203 | Hig | 0.57 | 8.8 | 0.01 | Jun 23, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins EasyQA Plugin 1.0 and earlier allows attackers to connect to an attacker-specified HTTP server. | ||
| CVE-2022-34200 | Hig | 0.57 | 8.8 | 0.01 | Jun 23, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers to connect to an attacker-specified URL. | ||
| CVE-2022-34180 | Hig | 0.42 | 7.5 | 0.01 | Jun 23, 2022 | Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for "unprotected" status badge access, allowing attackers without any permissions to obtain the build status badge icon for any… | ||
| CVE-2022-34179 | Hig | 0.42 | 7.5 | 0.02 | Jun 23, 2022 | Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a `style` query parameter that is used to choose a different SVG image style without restricting possible values, resulting in a relative path traversal vulnerability that allows attackers without… | ||
| CVE-2022-34177 | Hig | 0.42 | 7.5 | 0.01 | Jun 23, 2022 | Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `file` parameters for Pipeline `input` steps on the controller as part of build metadata, using the parameter name without sanitization as a relative path inside a build-related… | ||
| CVE-2022-34175 | Hig | 0.42 | 7.5 | 0.01 | Jun 23, 2022 | Jenkins 2.335 through 2.355 (both inclusive) allows attackers in some cases to bypass a protection mechanism, thereby directly accessing some view fragments containing sensitive information, bypassing any permission checks in the corresponding view. | ||
| CVE-2022-34174 | Hig | 0.42 | 7.5 | 0.01 | Jun 23, 2022 | In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database… | ||
| CVE-2022-33114 | Hig | 0.47 | 7.2 | 0.01 | Jun 23, 2022 | Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/system/dict/list. | ||
| CVE-2022-33105 | Hig | 0.00 | 7.5 | 0.03 | Jun 23, 2022 | Redis v7.0 was discovered to contain a memory leak via the component streamGetEdgeID. | ||
| CVE-2022-33097 | Hig | 0.49 | 7.5 | 0.01 | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/campus/campus_job. | ||
| CVE-2022-33096 | Hig | 0.49 | 7.5 | 0.01 | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/resume/index. | ||
| CVE-2022-33095 | Hig | 0.49 | 7.5 | 0.01 | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist. | ||
| CVE-2022-33094 | Hig | 0.49 | 7.5 | 0.01 | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/map. | ||
| CVE-2022-33093 | Hig | 0.49 | 7.5 | 0.01 | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the key parameter at /freelance/resume_list. | ||
| CVE-2022-33092 | Hig | 0.49 | 7.5 | 0.01 | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/index. | ||
| CVE-2022-33034 | Hig | 0.51 | 7.8 | 0.01 | Jun 23, 2022 | LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at decode_r2007.c. | ||
| CVE-2022-33033 | Hig | 0.51 | 7.8 | 0.01 | Jun 23, 2022 | LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c. | ||
| CVE-2022-33032 | Hig | 0.51 | 7.8 | 0.01 | Jun 23, 2022 | LibreDWG v0.12.4.4608 was discovered to contain a heap-buffer-overflow via the function decode_preR13_section_hdr at decode_r11.c. | ||
| CVE-2022-33028 | Hig | 0.51 | 7.8 | 0.01 | Jun 23, 2022 | LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function dwg_add_object at decode.c. | ||
| CVE-2022-33027 | Hig | 0.51 | 7.8 | 0.01 | Jun 23, 2022 | LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function dwg_add_handleref at dwg.c. | ||
| CVE-2022-33026 | Hig | 0.51 | 7.8 | 0.01 | Jun 23, 2022 | LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c. | ||
| CVE-2022-33025 | Hig | 0.51 | 7.8 | 0.01 | Jun 23, 2022 | LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function decode_preR13_section at decode_r11.c. | ||
| CVE-2022-33024 | Hig | 0.49 | 7.5 | 0.01 | Jun 23, 2022 | There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dwg2dxf: decode.c:5801 in libredwg v0.12.4.4608. | ||
| CVE-2022-32553 | Hig | 0.57 | 8.8 | 0.01 | Jun 23, 2022 | Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade products running Purity//FB 3.3.0, 3.2.0 - 3.2.4, 3.1.0 - 3.1.12, 3.0.x and prior Purity//FB… | ||
| CVE-2022-32552 | Hig | 0.57 | 8.8 | 0.01 | Jun 23, 2022 | Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade products running Purity//FB 3.3.0, 3.2.0 - 3.2.4, 3.1.0 - 3.1.12, 3.0.x and prior Purity//FB… | ||
| CVE-2022-32536 | Hig | 0.57 | 8.8 | 0.01 | Jun 23, 2022 | The user access rights validation in the web server of the Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 was insufficient. This would allow a non-administrator user to obtain administrator user access rights. | ||
| CVE-2022-32534 | Hig | 0.57 | 8.8 | 0.02 | Jun 23, 2022 | The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostics web interface. This allows execution of shell commands. | ||
| CVE-2022-31395 | Hig | 0.57 | 8.8 | 0.03 | Jun 23, 2022 | Algo Communication Products Ltd. 8373 IP Zone Paging Adapter Firmware 1.7.6 allows attackers to perform a directory traversal via a web request sent to /fm-data.lua. | ||
| CVE-2022-31362 | Hig | 0.59 | 8.8 | 0.18 | Jun 23, 2022 | Docebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | ||
| CVE-2022-22967 | Hig | 0.57 | 8.8 | 0.02 | Jun 23, 2022 | An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their account is locked. This affects both local shell… | ||
| CVE-2021-40956 | Hig | 0.49 | 7.5 | 0.01 | Jun 23, 2022 | LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obtained. | ||
| CVE-2021-40955 | Hig | 0.47 | 7.2 | 0.01 | Jun 23, 2022 | SQL injection exists in LaiKetui v3.5.0 the background administrator list. | ||
| CVE-2021-26638 | Hig | 0.48 | 7.3 | 0.03 | Jun 23, 2022 | Improper Authentication vulnerability in S&D smarthome(smartcare) application can cause authentication bypass and information exposure. Remote attackers can use this vulerability to take control of the home environment including indoor control. | ||
| CVE-2021-26637 | Hig | 0.57 | 8.8 | 0.02 | Jun 23, 2022 | There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device. | ||
| CVE-2021-26636 | Hig | 0.57 | 8.8 | 0.01 | Jun 23, 2022 | Stored XSS and SQL injection vulnerability in MaxBoard could lead to occur Remote Code Execution, which could lead to information exposure and privilege escalation. |
- risk 0.47cvss 7.2epss 0.01
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/user/manage_user.php:4.
- risk 0.57cvss 8.8epss 0.01
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/view_crime.php:4
- risk 0.57cvss 8.8epss 0.01
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/manage_cell.php:4
- risk 0.57cvss 8.8epss 0.01
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/view_visit.php:4
- risk 0.57cvss 8.8epss 0.01
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/manage_visit.php:4
- risk 0.57cvss 8.8epss 0.01
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/manage_crime.php:4
- risk 0.57cvss 8.8epss 0.01
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/view_inmate.php:3
- risk 0.57cvss 8.8epss 0.01
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/view_cell.php:4
- risk 0.57cvss 8.8epss 0.01
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/manage_action.php:4
- risk 0.57cvss 8.8epss 0.01
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/view_action.php:4
- risk 0.00cvss 7.8epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.57cvss 8.8epss 0.01
In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData.
- risk 0.00cvss 8.1epss 0.01
There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.
- risk 0.42cvss 7.5epss 0.01
In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request.
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins EasyQA Plugin 1.0 and earlier allows attackers to connect to an attacker-specified HTTP server.
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers to connect to an attacker-specified URL.
- risk 0.42cvss 7.5epss 0.01
Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for "unprotected" status badge access, allowing attackers without any permissions to obtain the build status badge icon for any…
- risk 0.42cvss 7.5epss 0.02
Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a `style` query parameter that is used to choose a different SVG image style without restricting possible values, resulting in a relative path traversal vulnerability that allows attackers without…
- risk 0.42cvss 7.5epss 0.01
Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `file` parameters for Pipeline `input` steps on the controller as part of build metadata, using the parameter name without sanitization as a relative path inside a build-related…
- risk 0.42cvss 7.5epss 0.01
Jenkins 2.335 through 2.355 (both inclusive) allows attackers in some cases to bypass a protection mechanism, thereby directly accessing some view fragments containing sensitive information, bypassing any permission checks in the corresponding view.
- risk 0.42cvss 7.5epss 0.01
In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database…
- risk 0.47cvss 7.2epss 0.01
Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/system/dict/list.
- risk 0.00cvss 7.5epss 0.03
Redis v7.0 was discovered to contain a memory leak via the component streamGetEdgeID.
- risk 0.49cvss 7.5epss 0.01
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/campus/campus_job.
- risk 0.49cvss 7.5epss 0.01
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/resume/index.
- risk 0.49cvss 7.5epss 0.01
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.
- risk 0.49cvss 7.5epss 0.01
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/map.
- risk 0.49cvss 7.5epss 0.01
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the key parameter at /freelance/resume_list.
- risk 0.49cvss 7.5epss 0.01
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/index.
- risk 0.51cvss 7.8epss 0.01
LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at decode_r2007.c.
- risk 0.51cvss 7.8epss 0.01
LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c.
- risk 0.51cvss 7.8epss 0.01
LibreDWG v0.12.4.4608 was discovered to contain a heap-buffer-overflow via the function decode_preR13_section_hdr at decode_r11.c.
- risk 0.51cvss 7.8epss 0.01
LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function dwg_add_object at decode.c.
- risk 0.51cvss 7.8epss 0.01
LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function dwg_add_handleref at dwg.c.
- risk 0.51cvss 7.8epss 0.01
LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c.
- risk 0.51cvss 7.8epss 0.01
LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function decode_preR13_section at decode_r11.c.
- risk 0.49cvss 7.5epss 0.01
There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dwg2dxf: decode.c:5801 in libredwg v0.12.4.4608.
- risk 0.57cvss 8.8epss 0.01
Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade products running Purity//FB 3.3.0, 3.2.0 - 3.2.4, 3.1.0 - 3.1.12, 3.0.x and prior Purity//FB…
- risk 0.57cvss 8.8epss 0.01
Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade products running Purity//FB 3.3.0, 3.2.0 - 3.2.4, 3.1.0 - 3.1.12, 3.0.x and prior Purity//FB…
- risk 0.57cvss 8.8epss 0.01
The user access rights validation in the web server of the Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 was insufficient. This would allow a non-administrator user to obtain administrator user access rights.
- risk 0.57cvss 8.8epss 0.02
The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostics web interface. This allows execution of shell commands.
- risk 0.57cvss 8.8epss 0.03
Algo Communication Products Ltd. 8373 IP Zone Paging Adapter Firmware 1.7.6 allows attackers to perform a directory traversal via a web request sent to /fm-data.lua.
- risk 0.59cvss 8.8epss 0.18
Docebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
- risk 0.57cvss 8.8epss 0.02
An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their account is locked. This affects both local shell…
- risk 0.49cvss 7.5epss 0.01
LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obtained.
- risk 0.47cvss 7.2epss 0.01
SQL injection exists in LaiKetui v3.5.0 the background administrator list.
- risk 0.48cvss 7.3epss 0.03
Improper Authentication vulnerability in S&D smarthome(smartcare) application can cause authentication bypass and information exposure. Remote attackers can use this vulerability to take control of the home environment including indoor control.
- risk 0.57cvss 8.8epss 0.02
There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device.
- risk 0.57cvss 8.8epss 0.01
Stored XSS and SQL injection vulnerability in MaxBoard could lead to occur Remote Code Execution, which could lead to information exposure and privilege escalation.