| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-36683 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_payment. | ||
| CVE-2022-36682 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_student. | ||
| CVE-2022-36681 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_account. | |
| CVE-2022-36680 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule. | ||
| CVE-2022-36679 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user. | ||
| CVE-2022-36678 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category. | ||
| CVE-2022-31499 | Cri | 0.69 | 9.8 | 0.65 | Aug 25, 2022 | Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256. | ||
| CVE-2022-28747 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Key reuse in GoSecure Titan Inbox Detection & Response (IDR) through 2022-04-05 leads to remote code execution. To exploit this vulnerability, an attacker must craft and sign a serialized payload. | ||
| CVE-2022-36719 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the ok parameter at /admin/history.php. | ||
| CVE-2022-36716 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/changestock.php. | ||
| CVE-2022-36715 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/search.php. | ||
| CVE-2022-36697 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_waste. | ||
| CVE-2022-36696 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockout. | ||
| CVE-2022-36695 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockin. | ||
| CVE-2022-36693 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_item. | ||
| CVE-2022-36692 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category. | ||
| CVE-2021-43329 | Cri | 0.64 | 9.8 | 0.02 | Aug 25, 2022 | A SQL injection vulnerability in license_update.php in Mumara Classic through 2.93 allows a remote unauthenticated attacker to execute arbitrary SQL commands via the license parameter. | ||
| CVE-2022-37159 | Cri | 0.66 | 9.8 | 0.25 | Aug 25, 2022 | Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload. | ||
| CVE-2022-37158 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | RuoYi v3.8.3 has a Weak password vulnerability in the management system. | ||
| CVE-2022-37816 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetIpMacBind. | ||
| CVE-2022-37815 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the PPPOEPassword parameter in the function formQuickIndex. | ||
| CVE-2022-37814 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain multiple stack overflows via the deviceMac and the device_id parameters in the function addWifiMacFilter. | ||
| CVE-2022-37813 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetSysTime. | ||
| CVE-2022-37812 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the firewallEn parameter in the function formSetFirewallCfg. | ||
| CVE-2022-37811 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the startIp parameter in the function formSetPPTPServer. | ||
| CVE-2022-37810 | Cri | 0.64 | 9.8 | 0.02 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac. | ||
| CVE-2022-37809 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the speed_dir parameter in the function formSetSpeedWan. | ||
| CVE-2022-37808 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the index parameter in the function formWifiWpsOOB. | ||
| CVE-2022-37807 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function formSetClientState. | ||
| CVE-2022-37806 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromDhcpListClient. | ||
| CVE-2022-37805 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromWizardHandle. | ||
| CVE-2022-37804 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo. | ||
| CVE-2022-37803 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromAddressNat. | ||
| CVE-2022-37802 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromNatStaticSetting. | ||
| CVE-2022-37801 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetQosBand. | ||
| CVE-2022-37800 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function fromSetRouteStatic. | ||
| CVE-2022-37799 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter at the function setSmartPowerManagement. | ||
| CVE-2022-37798 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetVirtualSer. | ||
| CVE-2022-37242 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter. | ||
| CVE-2022-37240 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter. | ||
| CVE-2022-37100 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateMacClone. | |
| CVE-2022-37099 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateSnat. | |
| CVE-2022-37098 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateIpv6Params. | |
| CVE-2022-37097 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | H3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetAPInfoById. | |
| CVE-2022-37096 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EnableIpv6. | |
| CVE-2022-37095 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateWanParams. | |
| CVE-2022-37094 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | H3C H200 H200V100R004 was discovered to contain a stack overflow via the function Edit_BasicSSID_5G. | |
| CVE-2022-37093 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | H3C H200 H200V100R004 was discovered to contain a stack overflow via the function AddMacList. | |
| CVE-2022-37092 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | H3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetAPWifiorLedInfoById. | |
| CVE-2022-37091 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EditWlanMacList. |
- risk 0.64cvss 9.8epss 0.01
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_payment.
- risk 0.64cvss 9.8epss 0.01
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_student.
- risk 0.64cvss 9.8epss 0.01
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_account.
- risk 0.64cvss 9.8epss 0.01
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule.
- risk 0.64cvss 9.8epss 0.01
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user.
- risk 0.64cvss 9.8epss 0.01
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.
- risk 0.69cvss 9.8epss 0.65
Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.
- risk 0.64cvss 9.8epss 0.01
Key reuse in GoSecure Titan Inbox Detection & Response (IDR) through 2022-04-05 leads to remote code execution. To exploit this vulnerability, an attacker must craft and sign a serialized payload.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the ok parameter at /admin/history.php.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/changestock.php.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/search.php.
- risk 0.64cvss 9.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_waste.
- risk 0.64cvss 9.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockout.
- risk 0.64cvss 9.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockin.
- risk 0.64cvss 9.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_item.
- risk 0.64cvss 9.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.
- risk 0.64cvss 9.8epss 0.02
A SQL injection vulnerability in license_update.php in Mumara Classic through 2.93 allows a remote unauthenticated attacker to execute arbitrary SQL commands via the license parameter.
- risk 0.66cvss 9.8epss 0.25
Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.
- risk 0.64cvss 9.8epss 0.01
RuoYi v3.8.3 has a Weak password vulnerability in the management system.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetIpMacBind.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the PPPOEPassword parameter in the function formQuickIndex.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain multiple stack overflows via the deviceMac and the device_id parameters in the function addWifiMacFilter.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetSysTime.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the firewallEn parameter in the function formSetFirewallCfg.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the startIp parameter in the function formSetPPTPServer.
- risk 0.64cvss 9.8epss 0.02
Tenda AC1206 V15.03.06.23 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the speed_dir parameter in the function formSetSpeedWan.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the index parameter in the function formWifiWpsOOB.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function formSetClientState.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromDhcpListClient.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromWizardHandle.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromAddressNat.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromNatStaticSetting.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetQosBand.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function fromSetRouteStatic.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter at the function setSmartPowerManagement.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetVirtualSer.
- risk 0.64cvss 9.8epss 0.01
MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter.
- risk 0.64cvss 9.8epss 0.01
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter.
- risk 0.64cvss 9.8epss 0.01
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateMacClone.
- risk 0.64cvss 9.8epss 0.01
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateSnat.
- risk 0.64cvss 9.8epss 0.01
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateIpv6Params.
- risk 0.64cvss 9.8epss 0.01
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetAPInfoById.
- risk 0.64cvss 9.8epss 0.01
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EnableIpv6.
- risk 0.64cvss 9.8epss 0.01
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateWanParams.
- risk 0.64cvss 9.8epss 0.01
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function Edit_BasicSSID_5G.
- risk 0.64cvss 9.8epss 0.01
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function AddMacList.
- risk 0.64cvss 9.8epss 0.01
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetAPWifiorLedInfoById.
- risk 0.64cvss 9.8epss 0.01
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EditWlanMacList.