| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-38165 | Cri | 0.64 | 9.8 | 0.01 | Nov 17, 2022 | Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with the contents in arbitrary locations on the F-Secure Policy Manager Server. | ||
| CVE-2022-36787 | Cri | 0.64 | 9.8 | 0.01 | Nov 17, 2022 | webvendome - webvendome SQL Injection. SQL Injection in the Parameter " DocNumber" Request : Get Request : /webvendome/showfiles.aspx?jobnumber=nullDoc Number=HERE. | ||
| CVE-2022-36786 | Cri | 0.64 | 9.9 | 0.01 | Nov 17, 2022 | DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router. | ||
| CVE-2022-36784 | Cri | 0.64 | 9.8 | 0.01 | Nov 17, 2022 | Elsight – Elsight Halo Remote Code Execution (RCE) Elsight Halo web panel allows us to perform connection validation. through the POST request : /api/v1/nics/wifi/wlan0/ping we can abuse DESTINATION parameter and leverage it to remote code execution. | ||
| CVE-2022-44001 | Cri | 0.64 | 9.8 | 0.01 | Nov 17, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. User authentication for accessing the CORBA back-end services can be bypassed. | ||
| CVE-2022-43138 | — | Cri | 0.57 | 9.8 | 0.01 | Nov 17, 2022 | Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API. | |
| CVE-2022-42245 | Cri | 0.64 | 9.8 | 0.01 | Nov 17, 2022 | Dreamer CMS 4.0.01 is vulnerable to SQL Injection. | ||
| CVE-2022-40881 | Cri | 0.66 | 9.8 | 0.29 | Nov 17, 2022 | SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php | ||
| CVE-2022-43782 | Cri | 0.64 | 9.8 | 0.01 | Nov 17, 2022 | Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path. This vulnerability can only be exploited by… | ||
| CVE-2022-43781 | Cri | 0.75 | 9.8 | 0.98 | Nov 17, 2022 | There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the… | ||
| CVE-2022-44006 | Cri | 0.64 | 9.8 | 0.02 | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files outside the intended target location. Achieving remote code execution is… | ||
| CVE-2022-44004 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can complete the password-reset process for any account and set a new password. | ||
| CVE-2022-44003 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations. | ||
| CVE-2022-44000 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is possible to execute arbitrary system commands on the server. | ||
| CVE-2022-40752 | Cri | 0.64 | 9.8 | 0.02 | Nov 16, 2022 | IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: 236687. | ||
| CVE-2022-43999 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system commands can be executed on the server. | ||
| CVE-2022-43135 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /diagnostic/login.php. | ||
| CVE-2022-43262 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2022 | Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /hrm/controller/login.php. | ||
| CVE-2022-43256 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2022 | SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php. | ||
| CVE-2022-43234 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2022 | An arbitrary file upload vulnerability in the /attachments component of Hoosk v1.8 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-3980 | Cri | 0.64 | 9.8 | 0.08 | Nov 16, 2022 | An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4. | ||
| CVE-2022-45047 | Cri | 0.57 | 9.8 | 0.04 | Nov 16, 2022 | Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apache MINA SSHD can choose for… | ||
| CVE-2022-2166 | Cri | 0.00 | 9.8 | 0.01 | Nov 16, 2022 | Improper Restriction of Excessive Authentication Attempts in GitHub repository mastodon/mastodon prior to 4.0.0. | ||
| CVE-2022-43265 | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2022 | An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-42785 | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2022 | Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker, can log in without knowledge of the password by crafting a modified HTTP GET Request. | ||
| CVE-2022-24942 | Cri | 0.59 | 9.1 | 0.02 | Nov 15, 2022 | Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTTP request. | ||
| CVE-2022-45400 | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2022 | Jenkins JAPEX Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2022-45397 | Cri | 0.57 | 9.8 | 0.01 | Nov 15, 2022 | Jenkins OSF Builder Suite : : XML Linter Plugin 1.0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2022-45396 | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2022 | Jenkins SourceMonitor Plugin 0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2022-45395 | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2022 | Jenkins CCCC Plugin 0.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2022-41558 | Cri | 0.59 | 9.0 | 0.01 | Nov 15, 2022 | The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analyst, TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Desktop, TIBCO Spotfire Desktop, TIBCO Spotfire Desktop, TIBCO Spotfire Server,… | ||
| CVE-2022-25727 | Cri | 0.64 | 9.8 | 0.00 | Nov 15, 2022 | Memory Corruption in modem due to improper length check while copying into memory in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music | ||
| CVE-2022-42058 | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2022 | Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setRemoteWebManage function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data. | ||
| CVE-2022-42122 | — | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2022 | A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL. | |
| CVE-2022-42120 | — | Cri | 0.57 | 9.8 | 0.01 | Nov 15, 2022 | A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute. | |
| CVE-2022-42984 | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2022 | WoWonder Social Network Platform 4.1.4 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=search&s=recipients. | ||
| CVE-2022-43294 | Cri | 0.00 | 9.8 | 0.01 | Nov 14, 2022 | Tasmota before commit 066878da4d4762a9b6cb169fdf353e804d735cfd was discovered to contain a stack overflow via the ClientPortPtr parameter at lib/libesp32/rtsp/CRtspSession.cpp. | ||
| CVE-2022-3362 | — | Cri | 0.57 | 9.8 | 0.01 | Nov 14, 2022 | Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0. | |
| CVE-2022-37109 | Cri | 0.64 | 9.8 | 0.49 | Nov 14, 2022 | patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control. Access to the password.txt file is not properly restricted as it is in the root directory served by StaticFileHandler and the Tornado rule to throw a… | ||
| CVE-2022-3993 | Cri | 0.00 | 9.4 | 0.01 | Nov 14, 2022 | Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3. | ||
| CVE-2022-45136 | Cri | 0.64 | 9.8 | 0.02 | Nov 14, 2022 | Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the underlying database server to return malicious data. The mySQL JDBC driver in particular is known to be vulnerable to this class of… | ||
| CVE-2022-3574 | Cri | 0.64 | 9.8 | 0.01 | Nov 14, 2022 | The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection. | ||
| CVE-2022-3477 | Cri | 0.64 | 9.8 | 0.04 | Nov 14, 2022 | The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their… | ||
| CVE-2022-45378 | Cri | 0.64 | 9.8 | 0.02 | Nov 14, 2022 | In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are available on the classpath this might even… | ||
| CVE-2022-38652 | Cri | 0.64 | 9.9 | 0.01 | Nov 12, 2022 | A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authenticated user to run arbitrary code or malware within a Hyperic Agent instance and its host operating system with the privileges of… | ||
| CVE-2022-38651 | Cri | 0.64 | 9.8 | 0.01 | Nov 12, 2022 | A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some authentication requirements when issuing requests to Hyperic Server. NOTE: This vulnerability only affects products that are no… | ||
| CVE-2022-38650 | Cri | 0.65 | 10.0 | 0.01 | Nov 12, 2022 | A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to run arbitrary code or malware within Hyperic Server and the host operating system with the privileges of the… | ||
| CVE-2022-43672 | Cri | 0.69 | 9.8 | 0.67 | Nov 12, 2022 | Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671. | ||
| CVE-2022-43671 | Cri | 0.70 | 9.8 | 0.75 | Nov 12, 2022 | Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection. | ||
| CVE-2022-45182 | Cri | 0.00 | 9.8 | 0.01 | Nov 11, 2022 | Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter. |
- risk 0.64cvss 9.8epss 0.01
Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with the contents in arbitrary locations on the F-Secure Policy Manager Server.
- risk 0.64cvss 9.8epss 0.01
webvendome - webvendome SQL Injection. SQL Injection in the Parameter " DocNumber" Request : Get Request : /webvendome/showfiles.aspx?jobnumber=nullDoc Number=HERE.
- risk 0.64cvss 9.9epss 0.01
DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router.
- risk 0.64cvss 9.8epss 0.01
Elsight – Elsight Halo Remote Code Execution (RCE) Elsight Halo web panel allows us to perform connection validation. through the POST request : /api/v1/nics/wifi/wlan0/ping we can abuse DESTINATION parameter and leverage it to remote code execution.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in BACKCLICK Professional 5.9.63. User authentication for accessing the CORBA back-end services can be bypassed.
- risk 0.57cvss 9.8epss 0.01
Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.
- risk 0.64cvss 9.8epss 0.01
Dreamer CMS 4.0.01 is vulnerable to SQL Injection.
- risk 0.66cvss 9.8epss 0.29
SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
- risk 0.64cvss 9.8epss 0.01
Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path. This vulnerability can only be exploited by…
- risk 0.75cvss 9.8epss 0.98
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the…
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files outside the intended target location. Achieving remote code execution is…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can complete the password-reset process for any account and set a new password.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is possible to execute arbitrary system commands on the server.
- risk 0.64cvss 9.8epss 0.02
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: 236687.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system commands can be executed on the server.
- risk 0.64cvss 9.8epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /diagnostic/login.php.
- risk 0.64cvss 9.8epss 0.01
Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /hrm/controller/login.php.
- risk 0.64cvss 9.8epss 0.01
SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the /attachments component of Hoosk v1.8 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.08
An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.
- risk 0.57cvss 9.8epss 0.04
Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apache MINA SSHD can choose for…
- risk 0.00cvss 9.8epss 0.01
Improper Restriction of Excessive Authentication Attempts in GitHub repository mastodon/mastodon prior to 4.0.0.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.01
Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker, can log in without knowledge of the password by crafting a modified HTTP GET Request.
- risk 0.59cvss 9.1epss 0.02
Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTTP request.
- risk 0.64cvss 9.8epss 0.01
Jenkins JAPEX Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.57cvss 9.8epss 0.01
Jenkins OSF Builder Suite : : XML Linter Plugin 1.0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.64cvss 9.8epss 0.01
Jenkins SourceMonitor Plugin 0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.64cvss 9.8epss 0.01
Jenkins CCCC Plugin 0.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.59cvss 9.0epss 0.01
The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analyst, TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Desktop, TIBCO Spotfire Desktop, TIBCO Spotfire Desktop, TIBCO Spotfire Server,…
- risk 0.64cvss 9.8epss 0.00
Memory Corruption in modem due to improper length check while copying into memory in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music
- risk 0.64cvss 9.8epss 0.01
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setRemoteWebManage function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.
- risk 0.57cvss 9.8epss 0.01
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.
- risk 0.64cvss 9.8epss 0.01
WoWonder Social Network Platform 4.1.4 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=search&s=recipients.
- risk 0.00cvss 9.8epss 0.01
Tasmota before commit 066878da4d4762a9b6cb169fdf353e804d735cfd was discovered to contain a stack overflow via the ClientPortPtr parameter at lib/libesp32/rtsp/CRtspSession.cpp.
- risk 0.57cvss 9.8epss 0.01
Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0.
- risk 0.64cvss 9.8epss 0.49
patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control. Access to the password.txt file is not properly restricted as it is in the root directory served by StaticFileHandler and the Tornado rule to throw a…
- risk 0.00cvss 9.4epss 0.01
Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3.
- risk 0.64cvss 9.8epss 0.02
Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the underlying database server to return malicious data. The mySQL JDBC driver in particular is known to be vulnerable to this class of…
- risk 0.64cvss 9.8epss 0.01
The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.
- risk 0.64cvss 9.8epss 0.04
The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their…
- risk 0.64cvss 9.8epss 0.02
In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are available on the classpath this might even…
- risk 0.64cvss 9.9epss 0.01
A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authenticated user to run arbitrary code or malware within a Hyperic Agent instance and its host operating system with the privileges of…
- risk 0.64cvss 9.8epss 0.01
A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some authentication requirements when issuing requests to Hyperic Server. NOTE: This vulnerability only affects products that are no…
- risk 0.65cvss 10.0epss 0.01
A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to run arbitrary code or malware within Hyperic Server and the host operating system with the privileges of the…
- risk 0.69cvss 9.8epss 0.67
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671.
- risk 0.70cvss 9.8epss 0.75
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection.
- risk 0.00cvss 9.8epss 0.01
Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.