| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-36045 | Cri | 0.52 | 9.0 | 0.01 | Aug 31, 2022 | NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interactions and real-time notifications. `utils.generateUUID`, a helper function available in essentially all versions of NodeBB (as far… | ||
| CVE-2022-37021 | — | Cri | 0.64 | 9.8 | 0.02 | Aug 31, 2022 | Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. Any user still on Java 8 who wishes to protect against deserialization attacks involving JMX or RMI should upgrade to Apache Geode… | |
| CVE-2022-36749 | Cri | 0.64 | 9.8 | 0.02 | Aug 30, 2022 | RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php. This vulnerability is exploited via a crafted payload injected into the file name of an uploaded file. | ||
| CVE-2022-36735 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /admin/delete.php. | ||
| CVE-2022-36734 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /admin/delstu.php. | ||
| CVE-2022-36733 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /admin/del.php. | ||
| CVE-2022-36732 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /librarian/dele.php. | ||
| CVE-2022-36731 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /librarian/delstu.php. | ||
| CVE-2022-36730 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /librarian/delete.php. | ||
| CVE-2022-37176 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2022 | Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability which allows attackers to remove the Wi-Fi password and force the device into open security mode via a crafted packet sent to goform/setWizard. | ||
| CVE-2022-37149 | Cri | 0.64 | 9.8 | 0.03 | Aug 30, 2022 | WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi. This vulnerability allows attackers to execute arbitrary commands via the username parameter. | ||
| CVE-2022-38116 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2022 | Le-yan Personnel and Salary Management System has hard-coded database account and password within the website source code. An unauthenticated remote attacker can access, modify system data or disrupt service. | ||
| CVE-2022-36714 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Section parameter at /staff/lab.php. | ||
| CVE-2022-36713 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Section parameter at /librarian/lab.php. | ||
| CVE-2022-36712 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/studentdetails.php. | ||
| CVE-2022-36711 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/bookdetails.php. | ||
| CVE-2022-36709 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/edit_book_details.php. | ||
| CVE-2022-36560 | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2022 | Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers are able to access the passcodes at /etc/srapi/config/system.conf and /usr/sbin/ssol-sshd.sh. | ||
| CVE-2022-36559 | Cri | 0.64 | 9.8 | 0.02 | Aug 29, 2022 | Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi. | ||
| CVE-2022-36558 | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2022 | Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able to access the passcord via the file /etc/ciel.cfg. | ||
| CVE-2022-36557 | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2022 | Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers to execute arbitrary code via a crafted html file. | ||
| CVE-2022-36556 | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2022 | Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08execute_ping_01. | ||
| CVE-2022-36555 | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2022 | Hytec Inter HWL-2511-SS v1.05 and below implements a SHA512crypt hash for the root account which can be easily cracked via a brute-force attack. | ||
| CVE-2022-36554 | Cri | 0.64 | 9.8 | 0.02 | Aug 29, 2022 | A command injection vulnerability in the CLI (Command Line Interface) implementation of Hytec Inter HWL-2511-SS v1.05 and below allows attackers to execute arbitrary commands with root privileges. | ||
| CVE-2022-36553 | Cri | 0.71 | 9.8 | 0.91 | Aug 29, 2022 | Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi. | ||
| CVE-2022-32993 | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2022 | TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh. | ||
| CVE-2022-32548 | Cri | 0.68 | 10.0 | 0.34 | Aug 29, 2022 | An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or password to the aa or ab field. | ||
| CVE-2022-22897 | Cri | 0.65 | 9.8 | 0.11 | Aug 29, 2022 | A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for PrestaShop allows unauthenticated attackers to exfiltrate database data. | ||
| CVE-2022-25644 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2022 | All versions of package @pendo324/get-process-by-name are vulnerable to Arbitrary Code Execution due to improper sanitization of getProcessByName function. | |
| CVE-2022-21165 | — | Cri | 0.64 | 9.8 | 0.03 | Aug 29, 2022 | All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of input that potentially flows into the child_process.exec() function. | |
| CVE-2022-34668 | — | Cri | 0.60 | 9.8 | 0.09 | Aug 29, 2022 | NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and Integrity. | |
| CVE-2022-36572 | Cri | 0.65 | 9.8 | 0.21 | Aug 29, 2022 | Sinsiu Sinsiu Enterprise Website System v1.1.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /upload/admin.php?/deal/. | ||
| CVE-2022-36708 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /student/bookdetails.php. | ||
| CVE-2022-36706 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /stocks/manage_stockout.php. | ||
| CVE-2022-36705 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /stocks/manage_waste.php. | ||
| CVE-2022-38555 | Cri | 0.64 | 9.8 | 0.09 | Aug 28, 2022 | Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name. | ||
| CVE-2022-37056 | Cri | 0.65 | 9.8 | 0.10 | Aug 28, 2022 | D-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin, hnap_main, | ||
| CVE-2022-37055 | Cri | 0.80 | 9.8 | 0.57 | KEV | Aug 28, 2022 | D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main, | |
| CVE-2022-38557 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2022 | D-Link DIR845L v1.00-v1.03 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh. | ||
| CVE-2022-38556 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2022 | Trendnet TEW733GR v1.03B01 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh. | ||
| CVE-2022-37057 | Cri | 0.66 | 9.8 | 0.25 | Aug 28, 2022 | D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin, ssdpcgi_main. | ||
| CVE-2022-37053 | Cri | 0.64 | 9.8 | 0.02 | Aug 28, 2022 | TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php. | ||
| CVE-2022-36756 | — | Cri | 0.64 | 9.8 | 0.03 | Aug 28, 2022 | DIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php. | |
| CVE-2022-36755 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2022 | D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php. | ||
| CVE-2022-38792 | — | Cri | 0.57 | 9.8 | 0.01 | Aug 27, 2022 | The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code execution backdoor inserted by a third party. | |
| CVE-2019-15167 | Cri | 0.00 | 9.1 | 0.01 | Aug 27, 2022 | The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463. | ||
| CVE-2022-36545 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/settings.php. | ||
| CVE-2022-36544 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/booking.php. | ||
| CVE-2022-36543 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/doctors.php. | ||
| CVE-2022-37152 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob" parameter in "/classes/Users.php?f=save_client" |
- risk 0.52cvss 9.0epss 0.01
NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interactions and real-time notifications. `utils.generateUUID`, a helper function available in essentially all versions of NodeBB (as far…
- risk 0.64cvss 9.8epss 0.02
Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. Any user still on Java 8 who wishes to protect against deserialization attacks involving JMX or RMI should upgrade to Apache Geode…
- risk 0.64cvss 9.8epss 0.02
RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php. This vulnerability is exploited via a crafted payload injected into the file name of an uploaded file.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /admin/delete.php.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /admin/delstu.php.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /admin/del.php.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /librarian/dele.php.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /librarian/delstu.php.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /librarian/delete.php.
- risk 0.64cvss 9.8epss 0.01
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability which allows attackers to remove the Wi-Fi password and force the device into open security mode via a crafted packet sent to goform/setWizard.
- risk 0.64cvss 9.8epss 0.03
WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi. This vulnerability allows attackers to execute arbitrary commands via the username parameter.
- risk 0.64cvss 9.8epss 0.01
Le-yan Personnel and Salary Management System has hard-coded database account and password within the website source code. An unauthenticated remote attacker can access, modify system data or disrupt service.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Section parameter at /staff/lab.php.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Section parameter at /librarian/lab.php.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/studentdetails.php.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/bookdetails.php.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/edit_book_details.php.
- risk 0.64cvss 9.8epss 0.01
Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers are able to access the passcodes at /etc/srapi/config/system.conf and /usr/sbin/ssol-sshd.sh.
- risk 0.64cvss 9.8epss 0.02
Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi.
- risk 0.64cvss 9.8epss 0.01
Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able to access the passcord via the file /etc/ciel.cfg.
- risk 0.64cvss 9.8epss 0.01
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers to execute arbitrary code via a crafted html file.
- risk 0.64cvss 9.8epss 0.01
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08execute_ping_01.
- risk 0.64cvss 9.8epss 0.01
Hytec Inter HWL-2511-SS v1.05 and below implements a SHA512crypt hash for the root account which can be easily cracked via a brute-force attack.
- risk 0.64cvss 9.8epss 0.02
A command injection vulnerability in the CLI (Command Line Interface) implementation of Hytec Inter HWL-2511-SS v1.05 and below allows attackers to execute arbitrary commands with root privileges.
- risk 0.71cvss 9.8epss 0.91
Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh.
- risk 0.68cvss 10.0epss 0.34
An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or password to the aa or ab field.
- risk 0.65cvss 9.8epss 0.11
A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for PrestaShop allows unauthenticated attackers to exfiltrate database data.
- risk 0.64cvss 9.8epss 0.01
All versions of package @pendo324/get-process-by-name are vulnerable to Arbitrary Code Execution due to improper sanitization of getProcessByName function.
- risk 0.64cvss 9.8epss 0.03
All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of input that potentially flows into the child_process.exec() function.
- risk 0.60cvss 9.8epss 0.09
NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and Integrity.
- risk 0.65cvss 9.8epss 0.21
Sinsiu Sinsiu Enterprise Website System v1.1.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /upload/admin.php?/deal/.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /student/bookdetails.php.
- risk 0.64cvss 9.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /stocks/manage_stockout.php.
- risk 0.64cvss 9.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /stocks/manage_waste.php.
- risk 0.64cvss 9.8epss 0.09
Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.
- risk 0.65cvss 9.8epss 0.10
D-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin, hnap_main,
- risk 0.80cvss 9.8epss 0.57
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,
- risk 0.64cvss 9.8epss 0.01
D-Link DIR845L v1.00-v1.03 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.
- risk 0.64cvss 9.8epss 0.01
Trendnet TEW733GR v1.03B01 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.
- risk 0.66cvss 9.8epss 0.25
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin, ssdpcgi_main.
- risk 0.64cvss 9.8epss 0.02
TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.
- risk 0.64cvss 9.8epss 0.03
DIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php.
- risk 0.57cvss 9.8epss 0.01
The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code execution backdoor inserted by a third party.
- risk 0.00cvss 9.1epss 0.01
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463.
- risk 0.64cvss 9.8epss 0.01
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/settings.php.
- risk 0.64cvss 9.8epss 0.01
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/booking.php.
- risk 0.64cvss 9.8epss 0.01
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/doctors.php.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob" parameter in "/classes/Users.php?f=save_client"