| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-30818 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Wedding Management System v1.0 is vulnerable to SQL injection via /Wedding-Management/admin/blog_events_edit.php?id=31. | ||
| CVE-2022-30799 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php. | ||
| CVE-2022-30798 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php. | ||
| CVE-2022-30795 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php. | ||
| CVE-2022-30794 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php. | ||
| CVE-2022-30540 | — | Hig | 0.51 | 7.8 | 0.01 | Jun 2, 2022 | The affected product is vulnerable to a heap-based buffer overflow via uninitialized pointer, which may allow an attacker to execute arbitrary code | |
| CVE-2022-30496 | Hig | 0.49 | 7.5 | 0.01 | Jun 2, 2022 | SQL injection in Logon Page of IDCE MV's application, version 1.0, allows an attacker to inject SQL payloads in the user field, connecting to a database to access enterprise's private and sensitive information. | ||
| CVE-2022-30425 | Hig | 0.59 | 8.8 | 0.19 | Jun 2, 2022 | Tenda Technology Co.,Ltd HG6 3.3.0-210926 was discovered to contain a command injection vulnerability via the pingAddr and traceAddr parameters. This vulnerability is exploited via a crafted POST request. | ||
| CVE-2022-30034 | — | Hig | 0.49 | 8.6 | 0.01 | Jun 2, 2022 | Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RPC calls or deny service by shutting down Celery task nodes. | |
| CVE-2022-29735 | Hig | 0.57 | 8.8 | 0.01 | Jun 2, 2022 | Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 allows attackers to execute arbitrary commands via a crafted HTTP request. | ||
| CVE-2022-29729 | Hig | 0.49 | 7.5 | 0.01 | Jun 2, 2022 | Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page. | ||
| CVE-2022-29725 | Hig | 0.57 | 8.8 | 0.01 | Jun 2, 2022 | An arbitrary file upload in the image upload component of wityCMS v0.6.2 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-29695 | Hig | 0.00 | 7.5 | 0.01 | Jun 2, 2022 | Unicorn Engine v2.0.0-rc7 contains memory leaks caused by an incomplete unicorn engine initialization. | ||
| CVE-2022-29694 | Hig | 0.00 | 7.5 | 0.02 | Jun 2, 2022 | Unicorn Engine v2.0.0-rc7 and below was discovered to contain a NULL pointer dereference via qemu_ram_free. | ||
| CVE-2022-29693 | Hig | 0.00 | 7.5 | 0.01 | Jun 2, 2022 | Unicorn Engine v2.0.0-rc7 and below was discovered to contain a memory leak via the function uc_close at /my/unicorn/uc.c. | ||
| CVE-2022-29692 | Hig | 0.51 | 7.8 | 0.01 | Jun 2, 2022 | Unicorn Engine v1.0.3 was discovered to contain a use-after-free vulnerability via the hook function. | ||
| CVE-2022-29647 | — | Hig | 0.57 | 8.8 | 0.01 | Jun 2, 2022 | An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do. | |
| CVE-2022-29624 | Hig | 0.57 | 8.8 | 0.01 | Jun 2, 2022 | An arbitrary file upload vulnerability in the Add File function of TPCMS v3.2 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-29488 | — | Hig | 0.51 | 7.8 | 0.01 | Jun 2, 2022 | The affected product is vulnerable to an out-of-bounds read via uninitialized pointer, which may allow an attacker to execute arbitrary code. | |
| CVE-2022-29483 | Hig | 0.51 | 7.8 | 0.00 | Jun 2, 2022 | Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine. | ||
| CVE-2022-28799 | Hig | 0.58 | 8.8 | 0.16 | Jun 2, 2022 | The TikTok application before 23.7.3 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force the com.zhiliaoapp.musically WebView to load an arbitrary website. This may allow an attacker to leverage an attached JavaScript interface for the takeover… | ||
| CVE-2022-28690 | — | Hig | 0.51 | 7.8 | 0.01 | Jun 2, 2022 | The affected product is vulnerable to an out-of-bounds write via uninitialized pointer, which may allow an attacker to execute arbitrary code. | |
| CVE-2022-27782 | Hig | 0.42 | 7.5 | 0.03 | Jun 2, 2022 | libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However,… | ||
| CVE-2022-27781 | Hig | 0.42 | 7.5 | 0.03 | Jun 2, 2022 | libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to… | ||
| CVE-2022-27780 | Hig | 0.49 | 7.5 | 0.02 | Jun 2, 2022 | The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it is later retrieved.For example, a URL like `http://example.com%2F127.0.0.1/`, would be allowed bythe… | ||
| CVE-2022-27778 | Hig | 0.53 | 8.1 | 0.04 | Jun 2, 2022 | A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`. | ||
| CVE-2022-27775 | Hig | 0.49 | 7.5 | 0.03 | Jun 2, 2022 | An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead. | ||
| CVE-2022-27184 | — | Hig | 0.51 | 7.8 | 0.01 | Jun 2, 2022 | The affected product is vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code. | |
| CVE-2022-26975 | Hig | 0.49 | 7.5 | 0.01 | Jun 2, 2022 | Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication. | ||
| CVE-2022-24701 | Hig | 0.51 | 7.8 | 0.00 | Jun 2, 2022 | An issue was discovered in WinAPRS 2.9.0. A buffer overflow in national.txt processing allows a local attacker to cause a denial of service or possibly achieve code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | ||
| CVE-2022-24700 | Hig | 0.49 | 7.5 | 0.02 | Jun 2, 2022 | An issue was discovered in WinAPRS 2.9.0. A buffer overflow in DIGI address processing for VHF KISS packets allows a remote attacker to cause a denial of service (daemon crash) via a malicious AX.25 packet over the air. NOTE: This vulnerability only affects products that are no… | ||
| CVE-2022-24581 | Hig | 0.49 | 7.5 | 0.01 | Jun 2, 2022 | ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce the victim server to disclose the username and password hash of the user executing the ACEweb… | ||
| CVE-2022-24241 | Hig | 0.49 | 7.5 | 0.01 | Jun 2, 2022 | ACEweb Online Portal 3.5.065 was discovered to contain an External Controlled File Path and Name vulnerability via the txtFilePath parameter in attachments.awp. | ||
| CVE-2022-22767 | Hig | 0.57 | 8.8 | 0.00 | Jun 2, 2022 | Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s)… | ||
| CVE-2022-1968 | Hig | 0.00 | 7.8 | 0.01 | Jun 2, 2022 | Use After Free in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1949 | Hig | 0.49 | 7.5 | 0.01 | Jun 2, 2022 | An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a… | ||
| CVE-2022-1943 | Hig | 0.00 | 7.8 | 0.00 | Jun 2, 2022 | A flaw out of bounds memory write in the Linux kernel UDF file system functionality was found in the way user triggers some file operation which triggers udf_write_fi(). A local user could use this flaw to crash the system or potentially | ||
| CVE-2022-1786 | Hig | 0.51 | 7.8 | 0.01 | Jun 2, 2022 | A use-after-free flaw was found in the Linux kernel’s io_uring subsystem in the way a user sets up a ring with IORING_SETUP_IOPOLL with more than one task completing submissions on this ring. This flaw allows a local user to crash or escalate their privileges on the system. | ||
| CVE-2022-1661 | Hig | 0.50 | 7.5 | 0.15 | Jun 2, 2022 | The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating system files. | ||
| CVE-2022-1652 | Hig | 0.51 | 7.8 | 0.01 | Jun 2, 2022 | Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-free flaw in the bad_flp_intr function. By executing a specially-crafted program, an attacker could exploit this vulnerability to execute arbitrary code or cause… | ||
| CVE-2022-1419 | — | Hig | 0.51 | 7.8 | 0.00 | Jun 2, 2022 | The root cause of this vulnerability is that the ioctl$DRM_IOCTL_MODE_DESTROY_DUMB can decrease refcount of *drm_vgem_gem_object *(created in *vgem_gem_dumb_create*) concurrently, and *vgem_gem_dumb_create *will access the freed drm_vgem_gem_object. | |
| CVE-2022-1215 | Hig | 0.51 | 7.8 | 0.00 | Jun 2, 2022 | A format string vulnerability was found in libinput | ||
| CVE-2021-44080 | Hig | 0.49 | 7.2 | 0.24 | Jun 2, 2022 | A Command Injection vulnerability in httpd web server (setup.cgi) in SerComm h500s, FW: lowi-h500s-v3.4.22 allows logged in administrators to arbitrary OS commands as root in the device via the connection_type parameter of the statussupport_diagnostic_tracing.json endpoint. | ||
| CVE-2021-42204 | Hig | 0.51 | 7.8 | 0.01 | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetBits() located in rfxswf.c. It allows an attacker to cause code execution. | ||
| CVE-2021-42203 | Hig | 0.51 | 7.8 | 0.01 | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A heap-use-after-free exists in the function swf_FontExtract_DefineTextCallback() located in swftext.c. It allows an attacker to cause code execution. | ||
| CVE-2021-42201 | Hig | 0.51 | 7.8 | 0.01 | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetD64() located in rfxswf.c. It allows an attacker to cause code execution. | ||
| CVE-2021-42199 | Hig | 0.51 | 7.8 | 0.01 | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A heap buffer overflow exists in the function swf_FontExtract_DefineTextCallback() located in swftext.c. It allows an attacker to cause code execution. | ||
| CVE-2021-42197 | Hig | 0.51 | 7.8 | 0.01 | Jun 2, 2022 | An issue was discovered in swftools through 20201222 through a memory leak in the swftools when swfdump is used. It allows an attacker to cause code execution. | ||
| CVE-2021-42195 | Hig | 0.51 | 7.8 | 0.01 | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function handleEditText() located in swfdump.c. It allows an attacker to cause code Execution. | ||
| CVE-2021-34083 | — | Hig | 0.53 | 8.1 | 0.02 | Jun 2, 2022 | Google-it is a Node.js package which allows its users to send search queries to Google and receive the results in a JSON format. When using the 'Open in browser' option in versions up to 1.6.2, google-it will unsafely concat the result's link retrieved from google to a shell… |
- risk 0.47cvss 7.2epss 0.01
Wedding Management System v1.0 is vulnerable to SQL injection via /Wedding-Management/admin/blog_events_edit.php?id=31.
- risk 0.47cvss 7.2epss 0.01
Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php.
- risk 0.47cvss 7.2epss 0.01
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php.
- risk 0.47cvss 7.2epss 0.01
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php.
- risk 0.47cvss 7.2epss 0.01
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php.
- risk 0.51cvss 7.8epss 0.01
The affected product is vulnerable to a heap-based buffer overflow via uninitialized pointer, which may allow an attacker to execute arbitrary code
- risk 0.49cvss 7.5epss 0.01
SQL injection in Logon Page of IDCE MV's application, version 1.0, allows an attacker to inject SQL payloads in the user field, connecting to a database to access enterprise's private and sensitive information.
- risk 0.59cvss 8.8epss 0.19
Tenda Technology Co.,Ltd HG6 3.3.0-210926 was discovered to contain a command injection vulnerability via the pingAddr and traceAddr parameters. This vulnerability is exploited via a crafted POST request.
- risk 0.49cvss 8.6epss 0.01
Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RPC calls or deny service by shutting down Celery task nodes.
- risk 0.57cvss 8.8epss 0.01
Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 allows attackers to execute arbitrary commands via a crafted HTTP request.
- risk 0.49cvss 7.5epss 0.01
Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.
- risk 0.57cvss 8.8epss 0.01
An arbitrary file upload in the image upload component of wityCMS v0.6.2 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.00cvss 7.5epss 0.01
Unicorn Engine v2.0.0-rc7 contains memory leaks caused by an incomplete unicorn engine initialization.
- risk 0.00cvss 7.5epss 0.02
Unicorn Engine v2.0.0-rc7 and below was discovered to contain a NULL pointer dereference via qemu_ram_free.
- risk 0.00cvss 7.5epss 0.01
Unicorn Engine v2.0.0-rc7 and below was discovered to contain a memory leak via the function uc_close at /my/unicorn/uc.c.
- risk 0.51cvss 7.8epss 0.01
Unicorn Engine v1.0.3 was discovered to contain a use-after-free vulnerability via the hook function.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.
- risk 0.57cvss 8.8epss 0.01
An arbitrary file upload vulnerability in the Add File function of TPCMS v3.2 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.51cvss 7.8epss 0.01
The affected product is vulnerable to an out-of-bounds read via uninitialized pointer, which may allow an attacker to execute arbitrary code.
- risk 0.51cvss 7.8epss 0.00
Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine.
- risk 0.58cvss 8.8epss 0.16
The TikTok application before 23.7.3 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force the com.zhiliaoapp.musically WebView to load an arbitrary website. This may allow an attacker to leverage an attached JavaScript interface for the takeover…
- risk 0.51cvss 7.8epss 0.01
The affected product is vulnerable to an out-of-bounds write via uninitialized pointer, which may allow an attacker to execute arbitrary code.
- risk 0.42cvss 7.5epss 0.03
libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However,…
- risk 0.42cvss 7.5epss 0.03
libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to…
- risk 0.49cvss 7.5epss 0.02
The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it is later retrieved.For example, a URL like `http://example.com%2F127.0.0.1/`, would be allowed bythe…
- risk 0.53cvss 8.1epss 0.04
A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.
- risk 0.49cvss 7.5epss 0.03
An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.
- risk 0.51cvss 7.8epss 0.01
The affected product is vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code.
- risk 0.49cvss 7.5epss 0.01
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication.
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in WinAPRS 2.9.0. A buffer overflow in national.txt processing allows a local attacker to cause a denial of service or possibly achieve code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in WinAPRS 2.9.0. A buffer overflow in DIGI address processing for VHF KISS packets allows a remote attacker to cause a denial of service (daemon crash) via a malicious AX.25 packet over the air. NOTE: This vulnerability only affects products that are no…
- risk 0.49cvss 7.5epss 0.01
ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce the victim server to disclose the username and password hash of the user executing the ACEweb…
- risk 0.49cvss 7.5epss 0.01
ACEweb Online Portal 3.5.065 was discovered to contain an External Controlled File Path and Name vulnerability via the txtFilePath parameter in attachments.awp.
- risk 0.57cvss 8.8epss 0.00
Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s)…
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 8.2.
- risk 0.49cvss 7.5epss 0.01
An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a…
- risk 0.00cvss 7.8epss 0.00
A flaw out of bounds memory write in the Linux kernel UDF file system functionality was found in the way user triggers some file operation which triggers udf_write_fi(). A local user could use this flaw to crash the system or potentially
- risk 0.51cvss 7.8epss 0.01
A use-after-free flaw was found in the Linux kernel’s io_uring subsystem in the way a user sets up a ring with IORING_SETUP_IOPOLL with more than one task completing submissions on this ring. This flaw allows a local user to crash or escalate their privileges on the system.
- risk 0.50cvss 7.5epss 0.15
The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating system files.
- risk 0.51cvss 7.8epss 0.01
Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-free flaw in the bad_flp_intr function. By executing a specially-crafted program, an attacker could exploit this vulnerability to execute arbitrary code or cause…
- risk 0.51cvss 7.8epss 0.00
The root cause of this vulnerability is that the ioctl$DRM_IOCTL_MODE_DESTROY_DUMB can decrease refcount of *drm_vgem_gem_object *(created in *vgem_gem_dumb_create*) concurrently, and *vgem_gem_dumb_create *will access the freed drm_vgem_gem_object.
- risk 0.51cvss 7.8epss 0.00
A format string vulnerability was found in libinput
- risk 0.49cvss 7.2epss 0.24
A Command Injection vulnerability in httpd web server (setup.cgi) in SerComm h500s, FW: lowi-h500s-v3.4.22 allows logged in administrators to arbitrary OS commands as root in the device via the connection_type parameter of the statussupport_diagnostic_tracing.json endpoint.
- risk 0.51cvss 7.8epss 0.01
An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetBits() located in rfxswf.c. It allows an attacker to cause code execution.
- risk 0.51cvss 7.8epss 0.01
An issue was discovered in swftools through 20201222. A heap-use-after-free exists in the function swf_FontExtract_DefineTextCallback() located in swftext.c. It allows an attacker to cause code execution.
- risk 0.51cvss 7.8epss 0.01
An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetD64() located in rfxswf.c. It allows an attacker to cause code execution.
- risk 0.51cvss 7.8epss 0.01
An issue was discovered in swftools through 20201222. A heap buffer overflow exists in the function swf_FontExtract_DefineTextCallback() located in swftext.c. It allows an attacker to cause code execution.
- risk 0.51cvss 7.8epss 0.01
An issue was discovered in swftools through 20201222 through a memory leak in the swftools when swfdump is used. It allows an attacker to cause code execution.
- risk 0.51cvss 7.8epss 0.01
An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function handleEditText() located in swfdump.c. It allows an attacker to cause code Execution.
- risk 0.53cvss 8.1epss 0.02
Google-it is a Node.js package which allows its users to send search queries to Google and receive the results in a JSON format. When using the 'Open in browser' option in versions up to 1.6.2, google-it will unsafely concat the result's link retrieved from google to a shell…