| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-34265 | Cri | 0.63 | 9.8 | 0.73 | Jul 4, 2022 | An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe… | ||
| CVE-2022-33171 | Cri | 0.58 | 9.8 | 0.20 | Jul 4, 2022 | The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input to the function is a user-controlled parsed JSON object, supplying a crafted FindOneOptions instead of an id string leads to SQL injection. NOTE: the vendor's… | ||
| CVE-2022-34913 | — | Cri | 0.64 | 9.8 | 0.03 | Jul 2, 2022 | md2roff 1.7 has a stack-based buffer overflow via a Markdown file containing a large number of consecutive characters to be processed. NOTE: the vendor's position is that the product is not intended for untrusted input | |
| CVE-2022-32324 | Cri | 0.64 | 9.8 | 0.01 | Jul 1, 2022 | PDFAlto v0.4 was discovered to contain a heap buffer overflow via the component /pdfalto/src/pdfalto.cc. | ||
| CVE-2022-32095 | Cri | 0.64 | 9.8 | 0.02 | Jul 1, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at orders.php. | ||
| CVE-2022-32094 | Cri | 0.64 | 9.8 | 0.07 | Jul 1, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doctorlogin.php. | ||
| CVE-2022-32093 | Cri | 0.64 | 9.8 | 0.02 | Jul 1, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at adminlogin.php. | ||
| CVE-2022-31943 | — | Cri | 0.64 | 9.8 | 0.02 | Jul 1, 2022 | MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability. | |
| CVE-2022-32032 | Cri | 0.64 | 9.8 | 0.10 | Jul 1, 2022 | Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the deviceList parameter in the function formAddMacfilterRule. | ||
| CVE-2022-31605 | — | Cri | 0.57 | 9.8 | 0.02 | Jul 1, 2022 | NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.safe_load(). The deserialization of Untrusted Data, may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of… | |
| CVE-2022-31604 | — | Cri | 0.57 | 9.8 | 0.02 | Jul 1, 2022 | NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pickle and no safe deserialization. The deserialization of Untrusted Data may allow an unprivileged network attacker to cause Remote Code… | |
| CVE-2022-2185 | Cri | 0.71 | 9.9 | 0.77 | Jul 1, 2022 | A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code… | ||
| CVE-2022-2253 | Cri | 0.59 | 9.1 | 0.01 | Jul 1, 2022 | A user with administrative privileges in Distributed Data Systems WebHMI 4.1.1.7662 may send OS commands to execute on the host server. | ||
| CVE-2022-2274 | Cri | 0.67 | 9.8 | 0.45 | Jul 1, 2022 | The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the… | ||
| CVE-2022-32295 | Cri | 0.64 | 9.8 | 0.01 | Jul 1, 2022 | On Ampere Altra and AltraMax devices before SRP 1.09, the Altra reference design of UEFI accesses allows insecure access to SPI-NOR by the OS/hypervisor component. | ||
| CVE-2021-32428 | Cri | 0.64 | 9.8 | 0.01 | Jul 1, 2022 | SQL Injection vulnerability in viaviwebtech Android EBook App (Books App, PDF, ePub, Online Book Reading, Download Books) 10 via the author_id parameter to api.php. | ||
| CVE-2014-0156 | — | Cri | 0.57 | 9.8 | 0.03 | Jun 30, 2022 | Awesome spawn contains OS command injection vulnerability, which allows execution of additional commands passed to Awesome spawn as arguments. If untrusted input was included in command arguments, attacker could use this flaw to execute arbitrary command. | |
| CVE-2022-33329 | Cri | 0.64 | 9.8 | 0.04 | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these… | ||
| CVE-2022-33328 | Cri | 0.64 | 9.8 | 0.04 | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these… | ||
| CVE-2022-33327 | Cri | 0.64 | 9.8 | 0.04 | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these… | ||
| CVE-2022-33326 | Cri | 0.64 | 9.8 | 0.04 | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these… | ||
| CVE-2022-33325 | Cri | 0.64 | 9.8 | 0.04 | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these… | ||
| CVE-2022-33314 | Cri | 0.64 | 9.8 | 0.04 | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these… | ||
| CVE-2022-33313 | Cri | 0.64 | 9.8 | 0.04 | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these… | ||
| CVE-2022-33312 | Cri | 0.64 | 9.8 | 0.04 | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these… | ||
| CVE-2022-32585 | Cri | 0.64 | 9.8 | 0.03 | Jun 30, 2022 | A command execution vulnerability exists in the clish art2 functionality of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability. | ||
| CVE-2022-2197 | Cri | 0.64 | 9.8 | 0.01 | Jun 30, 2022 | By using a specific credential string, an attacker with network access to the device’s web interface could circumvent the authentication scheme and perform administrative operations. | ||
| CVE-2022-28127 | Cri | 0.62 | 9.1 | 0.35 | Jun 30, 2022 | A data removal vulnerability exists in the web_server /action/remove/ API functionality of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary file deletion. An attacker can send a sequence of requests to trigger this vulnerability. | ||
| CVE-2013-4561 | Cri | 0.52 | 9.1 | 0.01 | Jun 30, 2022 | In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and integrity. | ||
| CVE-2013-4144 | Cri | 0.64 | 9.8 | 0.01 | Jun 30, 2022 | There is an object injection vulnerability in swfupload plugin for wordpress. | ||
| CVE-2022-22487 | Cri | 0.64 | 9.8 | 0.01 | Jun 30, 2022 | An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vulnerability using brute force techniques… | ||
| CVE-2021-37778 | Cri | 0.64 | 9.8 | 0.02 | Jun 30, 2022 | There is a buffer overflow in gps-sdr-sim v1.0 when parsing long command line parameters, which can lead to DoS or code execution. | ||
| CVE-2021-41506 | Cri | 0.64 | 9.8 | 0.02 | Jun 30, 2022 | Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39 V4.02.R11.7601.Nat.Onvif.20170420, V4.02.R11.Nat.Onvif.20160422, V4.02.R11.7601.Nat.Onvif.20170424, V4.02.R11.Nat.Onvif.20170327,… | ||
| CVE-2021-40663 | — | Cri | 0.64 | 9.8 | 0.02 | Jun 30, 2022 | deep.assign npm package 0.0.0-alpha.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'). | |
| CVE-2021-40643 | Cri | 0.64 | 9.8 | 0.03 | Jun 30, 2022 | EyesOfNetwork before 07-07-2021 has a Remote Code Execution vulnerability on the mail options configuration page. In the location of the "sendmail" application in the "cacti" configuration page (by default/usr/sbin/sendmail) it is possible to execute any command, which will be… | ||
| CVE-2022-34835 | Cri | 0.64 | 9.8 | 0.02 | Jun 30, 2022 | In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the corruption of the return address pointer of the do_i2c_md function. | ||
| CVE-2021-40597 | Cri | 0.64 | 9.8 | 0.02 | Jun 29, 2022 | The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password. | ||
| CVE-2022-33107 | Cri | 0.65 | 9.8 | 0.23 | Jun 29, 2022 | ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\AbstractCache.php. This vulnerability allows attackers to execute arbitrary code via a crafted payload. | ||
| CVE-2022-32532 | — | Cri | 0.66 | 9.8 | 0.25 | Jun 29, 2022 | Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass. | |
| CVE-2022-31887 | Cri | 0.64 | 9.8 | 0.02 | Jun 28, 2022 | Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, this means that the user can also escalate achieve Privilege Escalation by changing the administrator password. | ||
| CVE-2020-19896 | Cri | 0.64 | 9.8 | 0.01 | Jun 28, 2022 | File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php. | ||
| CVE-2022-31885 | Cri | 0.69 | 9.8 | 0.32 | Jun 28, 2022 | Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts. | ||
| CVE-2022-31229 | Cri | 0.62 | 9.6 | 0.01 | Jun 28, 2022 | Dell PowerScale OneFS, 8.2.x through 9.3.0.x, contain an error message with sensitive information. An administrator could potentially exploit this vulnerability, leading to disclosure of sensitive information. This sensitive information can be used to access sensitive resources. | ||
| CVE-2022-31061 | Cri | 0.04 | 9.8 | 0.51 | Jun 28, 2022 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions there is a SQL injection vulnerability which is possible on login page. No user credentials are required to exploit… | ||
| CVE-2022-31056 | Cri | 0.67 | 9.8 | 0.09 | Jun 28, 2022 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all assistance forms (Ticket/Change/Problem) permit sql injection on the actor fields. This issue has been resolved… | ||
| CVE-2022-34132 | Cri | 0.00 | 9.8 | 0.02 | Jun 28, 2022 | Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leaves.php. | ||
| CVE-2022-32995 | Cri | 0.65 | 9.8 | 0.16 | Jun 27, 2022 | Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function. | ||
| CVE-2022-32994 | Cri | 0.65 | 9.8 | 0.17 | Jun 27, 2022 | Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload. | ||
| CVE-2022-32092 | Cri | 0.64 | 9.8 | 0.06 | Jun 27, 2022 | D-Link DIR-645 v1.03 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter at __ajax_explorer.sgi. | ||
| CVE-2022-31098 | Cri | 0.52 | 9.0 | 0.01 | Jun 27, 2022 | Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in the logging of Weave GitOps could allow an authenticated remote attacker to view sensitive cluster configurations, aka… |
- risk 0.63cvss 9.8epss 0.73
An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe…
- risk 0.58cvss 9.8epss 0.20
The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input to the function is a user-controlled parsed JSON object, supplying a crafted FindOneOptions instead of an id string leads to SQL injection. NOTE: the vendor's…
- risk 0.64cvss 9.8epss 0.03
md2roff 1.7 has a stack-based buffer overflow via a Markdown file containing a large number of consecutive characters to be processed. NOTE: the vendor's position is that the product is not intended for untrusted input
- risk 0.64cvss 9.8epss 0.01
PDFAlto v0.4 was discovered to contain a heap buffer overflow via the component /pdfalto/src/pdfalto.cc.
- risk 0.64cvss 9.8epss 0.02
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at orders.php.
- risk 0.64cvss 9.8epss 0.07
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doctorlogin.php.
- risk 0.64cvss 9.8epss 0.02
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at adminlogin.php.
- risk 0.64cvss 9.8epss 0.02
MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.
- risk 0.64cvss 9.8epss 0.10
Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the deviceList parameter in the function formAddMacfilterRule.
- risk 0.57cvss 9.8epss 0.02
NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.safe_load(). The deserialization of Untrusted Data, may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of…
- risk 0.57cvss 9.8epss 0.02
NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pickle and no safe deserialization. The deserialization of Untrusted Data may allow an unprivileged network attacker to cause Remote Code…
- risk 0.71cvss 9.9epss 0.77
A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code…
- risk 0.59cvss 9.1epss 0.01
A user with administrative privileges in Distributed Data Systems WebHMI 4.1.1.7662 may send OS commands to execute on the host server.
- risk 0.67cvss 9.8epss 0.45
The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the…
- risk 0.64cvss 9.8epss 0.01
On Ampere Altra and AltraMax devices before SRP 1.09, the Altra reference design of UEFI accesses allows insecure access to SPI-NOR by the OS/hypervisor component.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in viaviwebtech Android EBook App (Books App, PDF, ePub, Online Book Reading, Download Books) 10 via the author_id parameter to api.php.
- risk 0.57cvss 9.8epss 0.03
Awesome spawn contains OS command injection vulnerability, which allows execution of additional commands passed to Awesome spawn as arguments. If untrusted input was included in command arguments, attacker could use this flaw to execute arbitrary command.
- risk 0.64cvss 9.8epss 0.04
Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these…
- risk 0.64cvss 9.8epss 0.04
Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these…
- risk 0.64cvss 9.8epss 0.04
Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these…
- risk 0.64cvss 9.8epss 0.04
Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these…
- risk 0.64cvss 9.8epss 0.04
Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these…
- risk 0.64cvss 9.8epss 0.04
Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these…
- risk 0.64cvss 9.8epss 0.04
Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these…
- risk 0.64cvss 9.8epss 0.04
Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these…
- risk 0.64cvss 9.8epss 0.03
A command execution vulnerability exists in the clish art2 functionality of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.
- risk 0.64cvss 9.8epss 0.01
By using a specific credential string, an attacker with network access to the device’s web interface could circumvent the authentication scheme and perform administrative operations.
- risk 0.62cvss 9.1epss 0.35
A data removal vulnerability exists in the web_server /action/remove/ API functionality of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary file deletion. An attacker can send a sequence of requests to trigger this vulnerability.
- risk 0.52cvss 9.1epss 0.01
In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and integrity.
- risk 0.64cvss 9.8epss 0.01
There is an object injection vulnerability in swfupload plugin for wordpress.
- risk 0.64cvss 9.8epss 0.01
An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vulnerability using brute force techniques…
- risk 0.64cvss 9.8epss 0.02
There is a buffer overflow in gps-sdr-sim v1.0 when parsing long command line parameters, which can lead to DoS or code execution.
- risk 0.64cvss 9.8epss 0.02
Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39 V4.02.R11.7601.Nat.Onvif.20170420, V4.02.R11.Nat.Onvif.20160422, V4.02.R11.7601.Nat.Onvif.20170424, V4.02.R11.Nat.Onvif.20170327,…
- risk 0.64cvss 9.8epss 0.02
deep.assign npm package 0.0.0-alpha.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution').
- risk 0.64cvss 9.8epss 0.03
EyesOfNetwork before 07-07-2021 has a Remote Code Execution vulnerability on the mail options configuration page. In the location of the "sendmail" application in the "cacti" configuration page (by default/usr/sbin/sendmail) it is possible to execute any command, which will be…
- risk 0.64cvss 9.8epss 0.02
In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the corruption of the return address pointer of the do_i2c_md function.
- risk 0.64cvss 9.8epss 0.02
The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password.
- risk 0.65cvss 9.8epss 0.23
ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\AbstractCache.php. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
- risk 0.66cvss 9.8epss 0.25
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
- risk 0.64cvss 9.8epss 0.02
Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, this means that the user can also escalate achieve Privilege Escalation by changing the administrator password.
- risk 0.64cvss 9.8epss 0.01
File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php.
- risk 0.69cvss 9.8epss 0.32
Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.
- risk 0.62cvss 9.6epss 0.01
Dell PowerScale OneFS, 8.2.x through 9.3.0.x, contain an error message with sensitive information. An administrator could potentially exploit this vulnerability, leading to disclosure of sensitive information. This sensitive information can be used to access sensitive resources.
- risk 0.04cvss 9.8epss 0.51
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions there is a SQL injection vulnerability which is possible on login page. No user credentials are required to exploit…
- risk 0.67cvss 9.8epss 0.09
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all assistance forms (Ticket/Change/Problem) permit sql injection on the actor fields. This issue has been resolved…
- risk 0.00cvss 9.8epss 0.02
Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leaves.php.
- risk 0.65cvss 9.8epss 0.16
Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function.
- risk 0.65cvss 9.8epss 0.17
Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload.
- risk 0.64cvss 9.8epss 0.06
D-Link DIR-645 v1.03 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter at __ajax_explorer.sgi.
- risk 0.52cvss 9.0epss 0.01
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in the logging of Weave GitOps could allow an authenticated remote attacker to view sensitive cluster configurations, aka…