VYPR

CVEs

31,787 total · page 314 of 636

  • CVE-2022-36683CriAug 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_payment.

  • CVE-2022-36682CriAug 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_student.

  • CVE-2022-36681CriAug 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_account.

  • CVE-2022-36680CriAug 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule.

  • CVE-2022-36679CriAug 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user.

  • CVE-2022-36678CriAug 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.

  • CVE-2022-31499CriAug 25, 2022
    risk 0.69cvss 9.8epss 0.65

    Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.

  • CVE-2022-28747CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Key reuse in GoSecure Titan Inbox Detection & Response (IDR) through 2022-04-05 leads to remote code execution. To exploit this vulnerability, an attacker must craft and sign a serialized payload.

  • CVE-2022-36719CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the ok parameter at /admin/history.php.

  • CVE-2022-36716CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/changestock.php.

  • CVE-2022-36715CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/search.php.

  • CVE-2022-36697CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_waste.

  • CVE-2022-36696CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockout.

  • CVE-2022-36695CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockin.

  • CVE-2022-36693CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_item.

  • CVE-2022-36692CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.

  • CVE-2021-43329CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.02

    A SQL injection vulnerability in license_update.php in Mumara Classic through 2.93 allows a remote unauthenticated attacker to execute arbitrary SQL commands via the license parameter.

  • CVE-2022-37159CriAug 25, 2022
    risk 0.66cvss 9.8epss 0.25

    Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.

  • CVE-2022-37158CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    RuoYi v3.8.3 has a Weak password vulnerability in the management system.

  • CVE-2022-37816CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetIpMacBind.

  • CVE-2022-37815CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the PPPOEPassword parameter in the function formQuickIndex.

  • CVE-2022-37814CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain multiple stack overflows via the deviceMac and the device_id parameters in the function addWifiMacFilter.

  • CVE-2022-37813CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetSysTime.

  • CVE-2022-37812CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the firewallEn parameter in the function formSetFirewallCfg.

  • CVE-2022-37811CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the startIp parameter in the function formSetPPTPServer.

  • CVE-2022-37810CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC1206 V15.03.06.23 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.

  • CVE-2022-37809CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the speed_dir parameter in the function formSetSpeedWan.

  • CVE-2022-37808CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the index parameter in the function formWifiWpsOOB.

  • CVE-2022-37807CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function formSetClientState.

  • CVE-2022-37806CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromDhcpListClient.

  • CVE-2022-37805CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromWizardHandle.

  • CVE-2022-37804CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo.

  • CVE-2022-37803CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromAddressNat.

  • CVE-2022-37802CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromNatStaticSetting.

  • CVE-2022-37801CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetQosBand.

  • CVE-2022-37800CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function fromSetRouteStatic.

  • CVE-2022-37799CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter at the function setSmartPowerManagement.

  • CVE-2022-37798CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetVirtualSer.

  • CVE-2022-37242CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter.

  • CVE-2022-37240CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter.

  • CVE-2022-37100CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateMacClone.

  • CVE-2022-37099CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateSnat.

  • CVE-2022-37098CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateIpv6Params.

  • CVE-2022-37097CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetAPInfoById.

  • CVE-2022-37096CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EnableIpv6.

  • CVE-2022-37095CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateWanParams.

  • CVE-2022-37094CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C H200 H200V100R004 was discovered to contain a stack overflow via the function Edit_BasicSSID_5G.

  • CVE-2022-37093CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C H200 H200V100R004 was discovered to contain a stack overflow via the function AddMacList.

  • CVE-2022-37092CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetAPWifiorLedInfoById.

  • CVE-2022-37091CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EditWlanMacList.