| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-3586 | Cri | 0.64 | 9.8 | 0.01 | Aug 22, 2022 | A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allowing access to all ports on these resources from any pod. The highest threat from this vulnerability is to data confidentiality… | ||
| CVE-2020-27836 | Cri | 0.00 | 9.8 | 0.01 | Aug 22, 2022 | A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker to access resources that would otherwise be restricted to specified IP ranges. The highest threat from this vulnerability is to… | ||
| CVE-2022-2927 | Cri | 0.57 | 9.8 | 0.01 | Aug 22, 2022 | Weak Password Requirements in GitHub repository notrinos/notrinoserp prior to 0.7. | ||
| CVE-2022-36198 | Cri | 0.64 | 9.8 | 0.01 | Aug 22, 2022 | Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin/pass-bwdates-reports-details.php, buspassms/admin/changeimage.php, buspassms/admin/search-pass.php, buspassms/admin/edit-category-detail.php, and… | ||
| CVE-2022-34916 | — | Cri | 0.57 | 9.8 | 0.02 | Aug 21, 2022 | Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI to allow only… | |
| CVE-2022-36030 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2022 | Project-nexus is a general-purpose blog website framework. Affected versions are subject to SQL injection due to a lack of sensitization of user input. This issue has not yet been patched. Users are advised to restrict user input and to upgrade when a new release becomes… | ||
| CVE-2020-27794 | Cri | 0.00 | 9.1 | 0.01 | Aug 19, 2022 | A double free issue was discovered in radare2 in cmd_info.c:cmd_info(). Successful exploitation could lead to modification of unexpected memory locations and potentially causing a crash. | ||
| CVE-2022-37175 | Cri | 0.64 | 9.8 | 0.01 | Aug 19, 2022 | Tenda ac15 firmware V15.03.05.18 httpd server has stack buffer overflow in /goform/formWifiBasicSet. | ||
| CVE-2022-22489 | Cri | 0.59 | 9.1 | 0.01 | Aug 19, 2022 | IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 226339. | ||
| CVE-2022-36578 | Cri | 0.64 | 9.8 | 0.01 | Aug 19, 2022 | jizhicms v2.3.1 has SQL injection in the background. | ||
| CVE-2022-36606 | Cri | 0.64 | 9.8 | 0.01 | Aug 19, 2022 | Ywoa before v6.1 was discovered to contain a SQL injection vulnerability via /oa/setup/checkPool?database. | ||
| CVE-2022-36605 | Cri | 0.64 | 9.8 | 0.01 | Aug 19, 2022 | Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter. | ||
| CVE-2022-35201 | Cri | 0.64 | 9.8 | 0.03 | Aug 19, 2022 | Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability. | ||
| CVE-2022-34615 | Cri | 0.64 | 9.8 | 0.01 | Aug 19, 2022 | Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. | ||
| CVE-2022-36220 | Cri | 0.57 | 9.8 | 0.01 | Aug 19, 2022 | Kiosk breakout (without quit password) in Safe Exam Browser (Windows) <3.4.0, which allows an attacker to achieve code execution via the browsers' print dialog. | ||
| CVE-2022-29805 | Cri | 0.66 | 9.8 | 0.27 | Aug 19, 2022 | A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code via a crafted XML payload. | ||
| CVE-2022-35540 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access. | |
| CVE-2020-36599 | Cri | 0.57 | 9.8 | 0.01 | Aug 18, 2022 | lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. | ||
| CVE-2022-36947 | Cri | 0.64 | 9.8 | 0.02 | Aug 18, 2022 | Unsafe Parsing of a PNG tRNS chunk in FastStone Image Viewer through 7.5 results in a stack buffer overflow. | ||
| CVE-2022-30601 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable information disclosure and escalation of privilege via network access. | ||
| CVE-2022-36729 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /librarian/del.php. | ||
| CVE-2022-36728 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /staff/delstu.php. | ||
| CVE-2022-36727 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /staff/delete.php. | ||
| CVE-2022-36725 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /student/dele.php. | ||
| CVE-2022-36722 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the title parameter at /librarian/history.php. | ||
| CVE-2022-25899 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | Authentication bypass for the Open AMT Cloud Toolkit software maintained by Intel(R) before versions 2.0.2 and 2.2.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access. | ||
| CVE-2022-22730 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | Improper authentication in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an unauthenticated user to potentially enable escalation of privilege via network access. | ||
| CVE-2022-37061 | Cri | 0.75 | 9.8 | 1.00 | Aug 18, 2022 | All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell commands as the root user through the id HTTP POST parameter in the res.php endpoint. A successful… | ||
| CVE-2022-35975 | Cri | 0.59 | 9.0 | 0.01 | Aug 18, 2022 | The GitOps Tools Extension for VSCode can make it easier to manage Flux objects. A specially crafted Flux object may allow for remote code execution in the machine running the extension, in the context of the user that is running VSCode. Users using the VSCode extension to… | ||
| CVE-2022-35175 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /blotter/blotter.php. | ||
| CVE-2022-35164 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via bit_copy_chain. | ||
| CVE-2022-35154 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | Shopro Mall System v1.3.8 was discovered to contain a SQL injection vulnerability via the value parameter. | ||
| CVE-2022-35153 | Cri | 0.00 | 9.8 | 0.02 | Aug 18, 2022 | FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php. | ||
| CVE-2022-35606 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameter 'customerCode.' | ||
| CVE-2022-35605 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as 'users', 'pass', etc. | ||
| CVE-2022-35603 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter searchTxt. | ||
| CVE-2022-35602 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter user. | ||
| CVE-2022-35601 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter searchTxt. | ||
| CVE-2022-35599 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter productcode. | ||
| CVE-2022-35598 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | A SQL injection vulnerability in ConnectionFactoryDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter username. | ||
| CVE-2022-35147 | Cri | 0.64 | 9.8 | 0.01 | Aug 17, 2022 | DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request. | ||
| CVE-2022-35122 | Cri | 0.59 | 9.1 | 0.01 | Aug 17, 2022 | An access control issue in Ecowitt GW1100 Series Weather Stations <=GW1100B_v2.1.5 allows unauthenticated attackers to access sensitive information including device and local WiFi passwords. | ||
| CVE-2022-2336 | Cri | 0.64 | 9.8 | 0.01 | Aug 17, 2022 | Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`. This allows Softing to log in to the server directly to perform administrative functions. Upon installation or upon… | ||
| CVE-2022-23747 | Cri | 0.65 | 9.8 | 0.10 | Aug 17, 2022 | In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed during music playback. | ||
| CVE-2022-35516 | Cri | 0.64 | 9.8 | 0.02 | Aug 17, 2022 | DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php. | ||
| CVE-2022-35121 | Cri | 0.64 | 9.8 | 0.01 | Aug 17, 2022 | Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java. | ||
| CVE-2022-22455 | Cri | 0.64 | 9.8 | 0.00 | Aug 17, 2022 | IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 224989. | ||
| CVE-2022-36190 | Cri | 0.57 | 9.8 | 0.01 | Aug 17, 2022 | GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function gf_isom_dovi_config_get. This vulnerability was fixed in commit fef6242. | ||
| CVE-2022-1399 | Cri | 0.59 | 9.1 | 0.01 | Aug 17, 2022 | An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery component of Device42 CMDB allows a local attacker to run arbitrary code on the appliance with root privileges. This issue affects: Device42 CMDB version 18.01.00… | ||
| CVE-2022-2662 | Cri | 0.62 | 9.6 | 0.01 | Aug 16, 2022 | Sequi PortBloque S has a improper authentication issues which may allow an attacker to bypass the authentication process and gain user-level access to the device. |
- risk 0.64cvss 9.8epss 0.01
A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allowing access to all ports on these resources from any pod. The highest threat from this vulnerability is to data confidentiality…
- risk 0.00cvss 9.8epss 0.01
A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker to access resources that would otherwise be restricted to specified IP ranges. The highest threat from this vulnerability is to…
- risk 0.57cvss 9.8epss 0.01
Weak Password Requirements in GitHub repository notrinos/notrinoserp prior to 0.7.
- risk 0.64cvss 9.8epss 0.01
Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin/pass-bwdates-reports-details.php, buspassms/admin/changeimage.php, buspassms/admin/search-pass.php, buspassms/admin/edit-category-detail.php, and…
- risk 0.57cvss 9.8epss 0.02
Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI to allow only…
- risk 0.64cvss 9.8epss 0.01
Project-nexus is a general-purpose blog website framework. Affected versions are subject to SQL injection due to a lack of sensitization of user input. This issue has not yet been patched. Users are advised to restrict user input and to upgrade when a new release becomes…
- risk 0.00cvss 9.1epss 0.01
A double free issue was discovered in radare2 in cmd_info.c:cmd_info(). Successful exploitation could lead to modification of unexpected memory locations and potentially causing a crash.
- risk 0.64cvss 9.8epss 0.01
Tenda ac15 firmware V15.03.05.18 httpd server has stack buffer overflow in /goform/formWifiBasicSet.
- risk 0.59cvss 9.1epss 0.01
IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 226339.
- risk 0.64cvss 9.8epss 0.01
jizhicms v2.3.1 has SQL injection in the background.
- risk 0.64cvss 9.8epss 0.01
Ywoa before v6.1 was discovered to contain a SQL injection vulnerability via /oa/setup/checkPool?database.
- risk 0.64cvss 9.8epss 0.01
Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter.
- risk 0.64cvss 9.8epss 0.03
Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.
- risk 0.64cvss 9.8epss 0.01
Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the application via brute-force attacks.
- risk 0.57cvss 9.8epss 0.01
Kiosk breakout (without quit password) in Safe Exam Browser (Windows) <3.4.0, which allows an attacker to achieve code execution via the browsers' print dialog.
- risk 0.66cvss 9.8epss 0.27
A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code via a crafted XML payload.
- risk 0.64cvss 9.8epss 0.01
Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access.
- risk 0.57cvss 9.8epss 0.01
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.
- risk 0.64cvss 9.8epss 0.02
Unsafe Parsing of a PNG tRNS chunk in FastStone Image Viewer through 7.5 results in a stack buffer overflow.
- risk 0.64cvss 9.8epss 0.01
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable information disclosure and escalation of privilege via network access.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /librarian/del.php.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /staff/delstu.php.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /staff/delete.php.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /student/dele.php.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the title parameter at /librarian/history.php.
- risk 0.64cvss 9.8epss 0.01
Authentication bypass for the Open AMT Cloud Toolkit software maintained by Intel(R) before versions 2.0.2 and 2.2.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
- risk 0.64cvss 9.8epss 0.01
Improper authentication in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
- risk 0.75cvss 9.8epss 1.00
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell commands as the root user through the id HTTP POST parameter in the res.php endpoint. A successful…
- risk 0.59cvss 9.0epss 0.01
The GitOps Tools Extension for VSCode can make it easier to manage Flux objects. A specially crafted Flux object may allow for remote code execution in the machine running the extension, in the context of the user that is running VSCode. Users using the VSCode extension to…
- risk 0.64cvss 9.8epss 0.01
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /blotter/blotter.php.
- risk 0.64cvss 9.8epss 0.01
LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via bit_copy_chain.
- risk 0.64cvss 9.8epss 0.01
Shopro Mall System v1.3.8 was discovered to contain a SQL injection vulnerability via the value parameter.
- risk 0.00cvss 9.8epss 0.02
FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameter 'customerCode.'
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as 'users', 'pass', etc.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter searchTxt.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter user.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter searchTxt.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter productcode.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in ConnectionFactoryDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter username.
- risk 0.64cvss 9.8epss 0.01
DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request.
- risk 0.59cvss 9.1epss 0.01
An access control issue in Ecowitt GW1100 Series Weather Stations <=GW1100B_v2.1.5 allows unauthenticated attackers to access sensitive information including device and local WiFi passwords.
- risk 0.64cvss 9.8epss 0.01
Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`. This allows Softing to log in to the server directly to perform administrative functions. Upon installation or upon…
- risk 0.65cvss 9.8epss 0.10
In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed during music playback.
- risk 0.64cvss 9.8epss 0.02
DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php.
- risk 0.64cvss 9.8epss 0.01
Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java.
- risk 0.64cvss 9.8epss 0.00
IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 224989.
- risk 0.57cvss 9.8epss 0.01
GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function gf_isom_dovi_config_get. This vulnerability was fixed in commit fef6242.
- risk 0.59cvss 9.1epss 0.01
An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery component of Device42 CMDB allows a local attacker to run arbitrary code on the appliance with root privileges. This issue affects: Device42 CMDB version 18.01.00…
- risk 0.62cvss 9.6epss 0.01
Sequi PortBloque S has a improper authentication issues which may allow an attacker to bypass the authentication process and gain user-level access to the device.