| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-26147 | Cri | 0.64 | 9.8 | 0.03 | Jun 21, 2022 | The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection. | ||
| CVE-2022-29775 | Cri | 0.68 | 9.8 | 0.61 | Jun 21, 2022 | iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL. | ||
| CVE-2022-29774 | Cri | 0.64 | 9.8 | 0.06 | Jun 21, 2022 | iSpy v7.2.2.0 is vulnerable to remote command execution via path traversal. | ||
| CVE-2022-33139 | Cri | 0.64 | 9.8 | 0.01 | Jun 21, 2022 | A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All versions), SIMATIC WinCC OA V3.16 (All versions in default configuration), SIMATIC WinCC OA V3.17 (All versions in non-default configuration), SIMATIC WinCC OA… | ||
| CVE-2022-31374 | Cri | 0.64 | 9.8 | 0.02 | Jun 21, 2022 | An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a crafted php file. | ||
| CVE-2022-31801 | Cri | 0.64 | 9.8 | 0.01 | Jun 21, 2022 | An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order to gain full control over the device. | ||
| CVE-2022-31800 | Cri | 0.64 | 9.8 | 0.01 | Jun 21, 2022 | An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device. | ||
| CVE-2022-2128 | Cri | 0.00 | 9.8 | 0.03 | Jun 20, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4. | ||
| CVE-2022-22318 | Cri | 0.64 | 9.8 | 0.00 | Jun 20, 2022 | IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. | ||
| CVE-2022-22317 | Cri | 0.64 | 9.8 | 0.00 | Jun 20, 2022 | IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281. | ||
| CVE-2022-31795 | Cri | 0.64 | 9.8 | 0.03 | Jun 20, 2022 | An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the grel_finfo function in grel.php. An attacker is able to influence the username (user), password (pw), and file-name (file) parameters and… | ||
| CVE-2022-31794 | Cri | 0.64 | 9.8 | 0.03 | Jun 20, 2022 | An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the requestTempFile function in hw_view.php. An attacker is able to influence the unitName POST parameter and inject special characters such… | ||
| CVE-2022-25772 | Cri | 0.60 | 9.6 | 0.61 | Jun 20, 2022 | A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript | ||
| CVE-2022-1905 | Cri | 0.67 | 9.8 | 0.37 | Jun 20, 2022 | The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection | ||
| CVE-2022-2023 | Cri | 0.00 | 9.8 | 0.03 | Jun 20, 2022 | Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4. | ||
| CVE-2022-34005 | Cri | 0.64 | 9.8 | 0.02 | Jun 19, 2022 | An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. There is Remote Code Execution due to a hardcoded password for the sa account on the Microsoft SQL Express 2019 instance installed by default during TitanFTP NextGen installation, aka NX-I674 (sub-issue… | ||
| CVE-2022-31874 | Cri | 0.65 | 9.8 | 0.19 | Jun 17, 2022 | ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface. | ||
| CVE-2022-31941 | — | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via \rdms\admin?page=user\manage_user&id=. | |
| CVE-2022-29496 | Cri | 0.64 | 9.8 | 0.02 | Jun 17, 2022 | A stack-based buffer overflow vulnerability exists in the BlynkConsole.h runCommand functionality of Blynk -Library v1.0.1. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability. | ||
| CVE-2022-21806 | Cri | 0.64 | 9.8 | 0.02 | Jun 17, 2022 | A use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to remote code execution. The device is exposed to attacks from the network. | ||
| CVE-2022-30422 | Cri | 0.64 | 9.8 | 0.04 | Jun 17, 2022 | Proietti Tech srl Planet Time Enterprise 4.2.0.1,4.2.0.0,4.1.0.0,4.0.0.0,3.3.1.0,3.3.0.0 is vulnerable to Remote code execution via the Viewstate parameter. | ||
| CVE-2022-22485 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2022 | In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this vulnerability… | ||
| CVE-2022-31357 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2022 | Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=. | ||
| CVE-2022-31356 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2022 | Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=. | ||
| CVE-2022-31355 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2022 | Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=. | ||
| CVE-2021-40903 | Cri | 0.64 | 9.8 | 0.04 | Jun 17, 2022 | A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however it is static. | ||
| CVE-2022-31784 | Cri | 0.64 | 9.8 | 0.02 | Jun 17, 2022 | A vulnerability in the management interface of MiVoice Business through 9.3 PR1 and MiVoice Business Express through 8.0 SP3 PR3 could allow an unauthenticated attacker (that has network access to the management interface) to conduct a buffer overflow attack due to insufficient… | ||
| CVE-2022-31296 | Cri | 0.64 | 9.8 | 0.02 | Jun 17, 2022 | Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php. | ||
| CVE-2021-45024 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2022 | ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE). | ||
| CVE-2021-41408 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2022 | VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter. | ||
| CVE-2022-30329 | Cri | 0.64 | 9.8 | 0.02 | Jun 16, 2022 | An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. An OS injection vulnerability exists within the web interface, allowing an attacker with valid credentials to execute arbitrary shell commands. | ||
| CVE-2022-33754 | Cri | 0.64 | 9.8 | 0.02 | Jun 16, 2022 | CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary code. | ||
| CVE-2022-33752 | Cri | 0.64 | 9.8 | 0.02 | Jun 16, 2022 | CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary code. | ||
| CVE-2022-33750 | Cri | 0.64 | 9.8 | 0.02 | Jun 16, 2022 | CA Automic Automation 12.2 and 12.3 contain an authentication error vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary commands. | ||
| CVE-2022-24562 | Cri | 0.71 | 9.8 | 0.53 | Jun 16, 2022 | In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution. | ||
| CVE-2021-41487 | Cri | 0.64 | 9.8 | 0.02 | Jun 16, 2022 | NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'. | ||
| CVE-2022-31384 | Cri | 0.64 | 9.8 | 0.02 | Jun 16, 2022 | Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php. | ||
| CVE-2022-31383 | Cri | 0.64 | 9.8 | 0.02 | Jun 16, 2022 | Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php. | ||
| CVE-2022-31382 | Cri | 0.64 | 9.8 | 0.02 | Jun 16, 2022 | Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php. | ||
| CVE-2021-41654 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2022 | SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php | ||
| CVE-2022-2098 | Cri | 0.00 | 9.8 | 0.01 | Jun 16, 2022 | Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1. | ||
| CVE-2021-41411 | — | Cri | 0.00 | 9.8 | 0.01 | Jun 16, 2022 | drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability. | |
| CVE-2022-30136 | Cri | 0.70 | 9.8 | 0.78 | Jun 15, 2022 | Windows Network File System Remote Code Execution Vulnerability | ||
| CVE-2021-41403 | Cri | 0.65 | 9.8 | 0.18 | Jun 15, 2022 | flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities. | ||
| CVE-2021-41418 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2022 | AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' access rights. | ||
| CVE-2022-20825 | Cri | 0.64 | 9.8 | 0.03 | Jun 15, 2022 | A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service… | ||
| CVE-2022-20798 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2022 | A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass authentication and… | ||
| CVE-2017-20049 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2022 | A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. | ||
| CVE-2022-32301 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2022 | YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the IdList parameter at /App/Lib/Action/Home/ApiAction.class.php. | ||
| CVE-2022-32158 | Cri | 0.59 | 9.0 | 0.01 | Jun 15, 2022 | Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients through the deployment server. An attacker that compromised a Universal Forwarder endpoint could use the vulnerability to execute… |
- risk 0.64cvss 9.8epss 0.03
The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.
- risk 0.68cvss 9.8epss 0.61
iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.
- risk 0.64cvss 9.8epss 0.06
iSpy v7.2.2.0 is vulnerable to remote command execution via path traversal.
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All versions), SIMATIC WinCC OA V3.16 (All versions in default configuration), SIMATIC WinCC OA V3.17 (All versions in non-default configuration), SIMATIC WinCC OA…
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a crafted php file.
- risk 0.64cvss 9.8epss 0.01
An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.
- risk 0.64cvss 9.8epss 0.01
An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.
- risk 0.00cvss 9.8epss 0.03
Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4.
- risk 0.64cvss 9.8epss 0.00
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
- risk 0.64cvss 9.8epss 0.00
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281.
- risk 0.64cvss 9.8epss 0.03
An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the grel_finfo function in grel.php. An attacker is able to influence the username (user), password (pw), and file-name (file) parameters and…
- risk 0.64cvss 9.8epss 0.03
An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the requestTempFile function in hw_view.php. An attacker is able to influence the unitName POST parameter and inject special characters such…
- risk 0.60cvss 9.6epss 0.61
A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript
- risk 0.67cvss 9.8epss 0.37
The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
- risk 0.00cvss 9.8epss 0.03
Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. There is Remote Code Execution due to a hardcoded password for the sa account on the Microsoft SQL Express 2019 instance installed by default during TitanFTP NextGen installation, aka NX-I674 (sub-issue…
- risk 0.65cvss 9.8epss 0.19
ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via \rdms\admin?page=user\manage_user&id=.
- risk 0.64cvss 9.8epss 0.02
A stack-based buffer overflow vulnerability exists in the BlynkConsole.h runCommand functionality of Blynk -Library v1.0.1. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.
- risk 0.64cvss 9.8epss 0.02
A use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to remote code execution. The device is exposed to attacks from the network.
- risk 0.64cvss 9.8epss 0.04
Proietti Tech srl Planet Time Enterprise 4.2.0.1,4.2.0.0,4.1.0.0,4.0.0.0,3.3.1.0,3.3.0.0 is vulnerable to Remote code execution via the Viewstate parameter.
- risk 0.64cvss 9.8epss 0.01
In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this vulnerability…
- risk 0.64cvss 9.8epss 0.01
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=.
- risk 0.64cvss 9.8epss 0.04
A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however it is static.
- risk 0.64cvss 9.8epss 0.02
A vulnerability in the management interface of MiVoice Business through 9.3 PR1 and MiVoice Business Express through 8.0 SP3 PR3 could allow an unauthenticated attacker (that has network access to the management interface) to conduct a buffer overflow attack due to insufficient…
- risk 0.64cvss 9.8epss 0.02
Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php.
- risk 0.64cvss 9.8epss 0.01
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).
- risk 0.64cvss 9.8epss 0.01
VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.
- risk 0.64cvss 9.8epss 0.02
An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. An OS injection vulnerability exists within the web interface, allowing an attacker with valid credentials to execute arbitrary shell commands.
- risk 0.64cvss 9.8epss 0.02
CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary code.
- risk 0.64cvss 9.8epss 0.02
CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary code.
- risk 0.64cvss 9.8epss 0.02
CA Automic Automation 12.2 and 12.3 contain an authentication error vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary commands.
- risk 0.71cvss 9.8epss 0.53
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.
- risk 0.64cvss 9.8epss 0.02
NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.
- risk 0.64cvss 9.8epss 0.02
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.
- risk 0.64cvss 9.8epss 0.02
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.
- risk 0.64cvss 9.8epss 0.02
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php
- risk 0.00cvss 9.8epss 0.01
Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1.
- risk 0.00cvss 9.8epss 0.01
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
- risk 0.70cvss 9.8epss 0.78
Windows Network File System Remote Code Execution Vulnerability
- risk 0.65cvss 9.8epss 0.18
flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.
- risk 0.64cvss 9.8epss 0.01
AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' access rights.
- risk 0.64cvss 9.8epss 0.03
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service…
- risk 0.64cvss 9.8epss 0.01
A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass authentication and…
- risk 0.64cvss 9.8epss 0.01
A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely.
- risk 0.64cvss 9.8epss 0.01
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the IdList parameter at /App/Lib/Action/Home/ApiAction.class.php.
- risk 0.59cvss 9.0epss 0.01
Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients through the deployment server. An attacker that compromised a Universal Forwarder endpoint could use the vulnerability to execute…