| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-31953 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incident_reports/view_report.php?id=. | ||
| CVE-2022-31952 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL injection via /rdms/classes/Master.php?f=delete_incident. | ||
| CVE-2022-31951 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_respondent_type. | ||
| CVE-2022-31948 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_report. | ||
| CVE-2022-31946 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_team. | ||
| CVE-2022-31945 | Cri | 0.59 | 9.1 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to Delete any file via /rdms/classes/Master.php?f=delete_img. | ||
| CVE-2022-31799 | — | Cri | 0.57 | 9.8 | 0.02 | Jun 2, 2022 | Bottle before 0.12.20 mishandles errors during early request binding. | |
| CVE-2022-31354 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=get_vehicle_service. | ||
| CVE-2022-31353 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/services/view_service.php?id=. | ||
| CVE-2022-31352 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 by oretnom23 has SQL injection in /ocwbs/admin/services/manage_service.php?id=. | ||
| CVE-2022-31351 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 by oretnom23 has SQL injection via /ocwbs/admin/services/manage_price.php?id=. | ||
| CVE-2022-31350 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/vehicles/manage_vehicle.php?id=. | ||
| CVE-2022-31348 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/bookings/update_status.php?id=. | ||
| CVE-2022-31347 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=delete_vehicle. | ||
| CVE-2022-31346 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=delete_service. | ||
| CVE-2022-31345 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/?page=user/manage_user&id=. | ||
| CVE-2022-31344 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=delete_booking. | ||
| CVE-2022-31343 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/?page=bookings/view_details&id=. | ||
| CVE-2022-31340 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php. | ||
| CVE-2022-31338 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/user/index.php?view=edit&id=. | ||
| CVE-2022-31337 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/category/index.php?view=edit&id=. | ||
| CVE-2022-31336 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/loaddata.php. | ||
| CVE-2022-31335 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/index.php?view=edit&id=. | ||
| CVE-2022-31329 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System By janobe 2.3.2 is vulnerable to SQL Injection via /ordering/admin/orders/loaddata.php. | ||
| CVE-2022-31328 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System By janobe 2.3.2 has SQL Injection via /ordering/admin/products/index.php?view=edit&id=. | ||
| CVE-2022-31327 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System By janobe 2.3.2 is vulneranle to SQL Injection via /ordering/index.php?q=products&id=. | ||
| CVE-2022-30817 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Simple Bus Ticket Booking System 1.0 is vulnerable to SQL Injection via /SimpleBusTicket/index.php. | ||
| CVE-2022-30816 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_sidebar.php. | ||
| CVE-2022-30815 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | elitecms 1.01 is vulnerable to SQL Injection via admin/edit_sidebar.php?page=2&sidebar= | ||
| CVE-2022-30814 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | elitecms v1.01 is vulnerable to SQL Injection via /admin/add_sidebar.php. | ||
| CVE-2022-30813 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | elitecms 1.01 is vulnerable to SQL Injection via /admin/add_post.php. | ||
| CVE-2022-30810 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | elitecms v1.01 is vulnerable to SQL Injection via admin/edit_post.php. | ||
| CVE-2022-30809 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_page.php?page=. | ||
| CVE-2022-30808 | Cri | 0.65 | 9.8 | 0.16 | Jun 2, 2022 | elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php. | ||
| CVE-2022-30797 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php. | ||
| CVE-2022-30521 | Cri | 0.65 | 9.8 | 0.14 | Jun 2, 2022 | The LAN-side Web-Configuration Interface has Stack-based Buffer Overflow vulnerability in the D-Link Wi-Fi router firmware DIR-890L DIR890LA1_FW107b09.bin and previous versions. The function created at 0x17958 of /htdocs/cgibin will call sprintf without checking the length of… | ||
| CVE-2022-30512 | Cri | 0.64 | 9.8 | 0.10 | Jun 2, 2022 | School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31. | ||
| CVE-2022-30511 | Cri | 0.64 | 9.8 | 0.04 | Jun 2, 2022 | School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/view_details.php:4. | ||
| CVE-2022-30510 | Cri | 0.64 | 9.8 | 0.04 | Jun 2, 2022 | School Dormitory Management System 1.0 is vulnerable to SQL Injection via reports/daily_collection_report.php:59. | ||
| CVE-2022-30506 | — | Cri | 0.64 | 9.8 | 0.03 | Jun 2, 2022 | An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP file. | |
| CVE-2022-30490 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php. | ||
| CVE-2022-30481 | — | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Food-order-and-table-reservation-system- 1.0 is vulnerable to SQL Injection in categorywise-menu.php via the catid parameters. | |
| CVE-2022-30478 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in \search_product.php via the keyword parameters. | ||
| CVE-2022-30470 | Cri | 0.64 | 9.8 | 0.03 | Jun 2, 2022 | In Afian Filerun 20220202 Changing the "search_tika_path" variable to a custom (and previously uploaded) jar file results in remote code execution in the context of the webserver user. | ||
| CVE-2022-30423 | Cri | 0.64 | 9.8 | 0.02 | Jun 2, 2022 | Merchandise Online Store v1.0 by oretnom23 has an arbitrary code execution (RCE) vulnerability in the user profile upload point in the system information. | ||
| CVE-2022-30352 | Cri | 0.64 | 9.8 | 0.02 | Jun 2, 2022 | phpABook 0.9i is vulnerable to SQL Injection due to insufficient sanitization of user-supplied data in the "auth_user" parameter in index.php script. | ||
| CVE-2022-30324 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client agent host. Fixed in 1.1.14, 1.2.8, and 1.3.1. | ||
| CVE-2022-29777 | Cri | 0.01 | 9.8 | 0.07 | Jun 2, 2022 | Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fontengine/fontconverter/FontFileBase.h. | ||
| CVE-2022-29776 | Cri | 0.01 | 9.8 | 0.07 | Jun 2, 2022 | Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component DesktopEditor/common/File.cpp. | ||
| CVE-2022-29730 | Cri | 0.64 | 9.8 | 0.02 | Jun 2, 2022 | USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 was discovered to contain hard-coded credentials for its highest privileged account. The credentials cannot be altered through normal operation of the device. |
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incident_reports/view_report.php?id=.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL injection via /rdms/classes/Master.php?f=delete_incident.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_respondent_type.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_report.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_team.
- risk 0.59cvss 9.1epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to Delete any file via /rdms/classes/Master.php?f=delete_img.
- risk 0.57cvss 9.8epss 0.02
Bottle before 0.12.20 mishandles errors during early request binding.
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=get_vehicle_service.
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/services/view_service.php?id=.
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 by oretnom23 has SQL injection in /ocwbs/admin/services/manage_service.php?id=.
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 by oretnom23 has SQL injection via /ocwbs/admin/services/manage_price.php?id=.
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/vehicles/manage_vehicle.php?id=.
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/bookings/update_status.php?id=.
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=delete_vehicle.
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=delete_service.
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/?page=user/manage_user&id=.
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=delete_booking.
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/?page=bookings/view_details&id=.
- risk 0.64cvss 9.8epss 0.01
Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/user/index.php?view=edit&id=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/category/index.php?view=edit&id=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/loaddata.php.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/index.php?view=edit&id=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System By janobe 2.3.2 is vulnerable to SQL Injection via /ordering/admin/orders/loaddata.php.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System By janobe 2.3.2 has SQL Injection via /ordering/admin/products/index.php?view=edit&id=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System By janobe 2.3.2 is vulneranle to SQL Injection via /ordering/index.php?q=products&id=.
- risk 0.64cvss 9.8epss 0.01
Simple Bus Ticket Booking System 1.0 is vulnerable to SQL Injection via /SimpleBusTicket/index.php.
- risk 0.64cvss 9.8epss 0.01
elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_sidebar.php.
- risk 0.64cvss 9.8epss 0.01
elitecms 1.01 is vulnerable to SQL Injection via admin/edit_sidebar.php?page=2&sidebar=
- risk 0.64cvss 9.8epss 0.01
elitecms v1.01 is vulnerable to SQL Injection via /admin/add_sidebar.php.
- risk 0.64cvss 9.8epss 0.01
elitecms 1.01 is vulnerable to SQL Injection via /admin/add_post.php.
- risk 0.64cvss 9.8epss 0.01
elitecms v1.01 is vulnerable to SQL Injection via admin/edit_post.php.
- risk 0.64cvss 9.8epss 0.01
elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_page.php?page=.
- risk 0.65cvss 9.8epss 0.16
elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php.
- risk 0.65cvss 9.8epss 0.14
The LAN-side Web-Configuration Interface has Stack-based Buffer Overflow vulnerability in the D-Link Wi-Fi router firmware DIR-890L DIR890LA1_FW107b09.bin and previous versions. The function created at 0x17958 of /htdocs/cgibin will call sprintf without checking the length of…
- risk 0.64cvss 9.8epss 0.10
School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31.
- risk 0.64cvss 9.8epss 0.04
School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/view_details.php:4.
- risk 0.64cvss 9.8epss 0.04
School Dormitory Management System 1.0 is vulnerable to SQL Injection via reports/daily_collection_report.php:59.
- risk 0.64cvss 9.8epss 0.03
An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP file.
- risk 0.64cvss 9.8epss 0.01
Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php.
- risk 0.64cvss 9.8epss 0.01
Food-order-and-table-reservation-system- 1.0 is vulnerable to SQL Injection in categorywise-menu.php via the catid parameters.
- risk 0.64cvss 9.8epss 0.01
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in \search_product.php via the keyword parameters.
- risk 0.64cvss 9.8epss 0.03
In Afian Filerun 20220202 Changing the "search_tika_path" variable to a custom (and previously uploaded) jar file results in remote code execution in the context of the webserver user.
- risk 0.64cvss 9.8epss 0.02
Merchandise Online Store v1.0 by oretnom23 has an arbitrary code execution (RCE) vulnerability in the user profile upload point in the system information.
- risk 0.64cvss 9.8epss 0.02
phpABook 0.9i is vulnerable to SQL Injection due to insufficient sanitization of user-supplied data in the "auth_user" parameter in index.php script.
- risk 0.64cvss 9.8epss 0.01
HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client agent host. Fixed in 1.1.14, 1.2.8, and 1.3.1.
- risk 0.01cvss 9.8epss 0.07
Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fontengine/fontconverter/FontFileBase.h.
- risk 0.01cvss 9.8epss 0.07
Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component DesktopEditor/common/File.cpp.
- risk 0.64cvss 9.8epss 0.02
USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 was discovered to contain hard-coded credentials for its highest privileged account. The credentials cannot be altered through normal operation of the device.