| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29353 | Cri | 0.64 | 9.8 | 0.02 | May 16, 2022 | An arbitrary file upload vulnerability in the file upload module of Graphql-upload v13.0.0 allows attackers to execute arbitrary code via a crafted filename. | ||
| CVE-2022-29351 | — | Cri | 0.64 | 9.8 | 0.02 | May 16, 2022 | An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file. Note: The vendor argues that this is not a legitimate issue and there is no vulnerability here. | |
| CVE-2021-42897 | Cri | 0.64 | 9.8 | 0.02 | May 16, 2022 | A remote command execution (RCE) vulnerability was found in FeMiner wms V1.0 in /wms/src/system/datarec.php. The $_POST[r_name] is directly passed into the $mysqlstr and is executed by exec. | ||
| CVE-2022-30011 | Cri | 0.65 | 9.8 | 0.18 | May 16, 2022 | In HMS 1.0 when requesting appointment.php through POST, multiple parameters can lead to a SQL injection vulnerability. | ||
| CVE-2022-30767 | Cri | 0.00 | 9.8 | 0.03 | May 16, 2022 | nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196. | ||
| CVE-2022-30765 | — | Cri | 0.57 | 9.8 | 0.01 | May 16, 2022 | Calibre-Web before 0.6.18 allows user table SQL Injection. | |
| CVE-2022-28930 | Cri | 0.64 | 9.8 | 0.01 | May 15, 2022 | ERP-Pro v3.7.5 was discovered to contain a SQL injection vulnerability via the component /base/SysEveMenuAuthPointMapper.xml.. | ||
| CVE-2022-28929 | Cri | 0.64 | 9.8 | 0.02 | May 15, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the delid parameter at viewtreatmentrecord.php. | ||
| CVE-2022-1379 | Cri | 0.00 | 9.1 | 0.02 | May 14, 2022 | URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal… | ||
| CVE-2022-22282 | Cri | 0.64 | 9.8 | 0.07 | May 13, 2022 | SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an unauthorized actor leading to Improper Access Control vulnerability. | ||
| CVE-2022-1715 | Cri | 0.57 | 9.8 | 0.01 | May 13, 2022 | Account Takeover in GitHub repository neorazorx/facturascripts prior to 2022.07. | ||
| CVE-2022-30413 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=delete_application. | ||
| CVE-2022-30407 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Pharmacy Sales And Inventory System v1.0 is vulnerable to SQL Injection via /pharmacy-sales-and-inventory-system/manage_user.php?id=. | ||
| CVE-2022-30395 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_cart. | ||
| CVE-2022-30392 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_sub_category. | ||
| CVE-2022-30391 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_category. | ||
| CVE-2022-30387 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=pay_order. | ||
| CVE-2022-30386 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_featured. | ||
| CVE-2022-30385 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_order. | ||
| CVE-2022-30384 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_inventory. | ||
| CVE-2022-29794 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | The frame scheduling module has a Use After Free (UAF) vulnerability.Successful exploitation of this vulnerability will affect data integrity, availability, and confidentiality. | ||
| CVE-2022-25591 | Cri | 0.59 | 9.1 | 0.03 | May 13, 2022 | BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to delete files within the web server root directory via a crafted HTTP request. | ||
| CVE-2022-22260 | Cri | 0.59 | 9.1 | 0.01 | May 13, 2022 | The kernel module has a UAF vulnerability.Successful exploitation of this vulnerability will affect data integrity and availability. | ||
| CVE-2021-46786 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | The audio module has a vulnerability in verifying the parameters passed by the application space.Successful exploitation of this vulnerability may cause out-of-bounds memory access. | ||
| CVE-2022-30370 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo_type. | ||
| CVE-2022-29383 | Cri | 0.68 | 9.8 | 0.49 | May 13, 2022 | NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi. | ||
| CVE-2021-42967 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an attacker to upload malicious JSP files. | ||
| CVE-2022-29363 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability allows attackers to getshell via writing arbitrary files. | ||
| CVE-2022-30001 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editAgent.php?agent_id=. | ||
| CVE-2022-30000 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editPayment.php?recipt_no=. | ||
| CVE-2022-29999 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editClient.php?client_id=. | ||
| CVE-2022-29998 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/clientStatus.php?client_id=. | ||
| CVE-2022-29746 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/classes/Users.php?f=delete. | ||
| CVE-2022-29745 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Money Transfer Management System 1.0 is vulnerable to SQL Injection via \mtms\classes\Master.php?f=delete_transaction. | ||
| CVE-2022-29741 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Money Transfer Management System 1.0 is vulnerable to SQL Injection via \mtms\classes\Master.php?f=delete_fee. | ||
| CVE-2022-29739 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/admin/?page=user/manage_user&id=. | ||
| CVE-2022-29738 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/admin/?page=transaction/send&id=, id. | ||
| CVE-2022-29307 | Cri | 0.65 | 9.8 | 0.18 | May 12, 2022 | IonizeCMS v1.0.8.1 was discovered to contain a command injection vulnerability via the function copy_lang_content in application/models/lang_model.php. | ||
| CVE-2022-29306 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | IonizeCMS v1.0.8.1 was discovered to contain a SQL injection vulnerability via the id_page parameter in application/models/article_model.php. | ||
| CVE-2022-29303 | Cri | 0.87 | 9.8 | 0.98 | KEV | May 12, 2022 | SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php. | |
| CVE-2022-22413 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 223022. | ||
| CVE-2022-29995 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=clients/manage_client&id=. | ||
| CVE-2022-29994 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=facilities/manage_facility&id=. | ||
| CVE-2022-29993 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/bookings/view_booking.php?id=. | ||
| CVE-2022-29992 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/categories/manage_category.php?id=. | ||
| CVE-2022-29990 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/categories/view_category.php?id=. | ||
| CVE-2022-29989 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_booking. | ||
| CVE-2022-29988 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete. | ||
| CVE-2022-29987 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=user/manage_user&id=. | ||
| CVE-2022-29986 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_facility. |
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in the file upload module of Graphql-upload v13.0.0 allows attackers to execute arbitrary code via a crafted filename.
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file. Note: The vendor argues that this is not a legitimate issue and there is no vulnerability here.
- risk 0.64cvss 9.8epss 0.02
A remote command execution (RCE) vulnerability was found in FeMiner wms V1.0 in /wms/src/system/datarec.php. The $_POST[r_name] is directly passed into the $mysqlstr and is executed by exec.
- risk 0.65cvss 9.8epss 0.18
In HMS 1.0 when requesting appointment.php through POST, multiple parameters can lead to a SQL injection vulnerability.
- risk 0.00cvss 9.8epss 0.03
nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196.
- risk 0.57cvss 9.8epss 0.01
Calibre-Web before 0.6.18 allows user table SQL Injection.
- risk 0.64cvss 9.8epss 0.01
ERP-Pro v3.7.5 was discovered to contain a SQL injection vulnerability via the component /base/SysEveMenuAuthPointMapper.xml..
- risk 0.64cvss 9.8epss 0.02
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the delid parameter at viewtreatmentrecord.php.
- risk 0.00cvss 9.1epss 0.02
URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal…
- risk 0.64cvss 9.8epss 0.07
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an unauthorized actor leading to Improper Access Control vulnerability.
- risk 0.57cvss 9.8epss 0.01
Account Takeover in GitHub repository neorazorx/facturascripts prior to 2022.07.
- risk 0.64cvss 9.8epss 0.01
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=delete_application.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Sales And Inventory System v1.0 is vulnerable to SQL Injection via /pharmacy-sales-and-inventory-system/manage_user.php?id=.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_cart.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_sub_category.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_category.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=pay_order.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_featured.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_order.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_inventory.
- risk 0.64cvss 9.8epss 0.01
The frame scheduling module has a Use After Free (UAF) vulnerability.Successful exploitation of this vulnerability will affect data integrity, availability, and confidentiality.
- risk 0.59cvss 9.1epss 0.03
BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to delete files within the web server root directory via a crafted HTTP request.
- risk 0.59cvss 9.1epss 0.01
The kernel module has a UAF vulnerability.Successful exploitation of this vulnerability will affect data integrity and availability.
- risk 0.64cvss 9.8epss 0.01
The audio module has a vulnerability in verifying the parameters passed by the application space.Successful exploitation of this vulnerability may cause out-of-bounds memory access.
- risk 0.64cvss 9.8epss 0.01
Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo_type.
- risk 0.68cvss 9.8epss 0.49
NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.
- risk 0.64cvss 9.8epss 0.01
Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an attacker to upload malicious JSP files.
- risk 0.64cvss 9.8epss 0.01
Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability allows attackers to getshell via writing arbitrary files.
- risk 0.64cvss 9.8epss 0.01
Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editAgent.php?agent_id=.
- risk 0.64cvss 9.8epss 0.01
Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editPayment.php?recipt_no=.
- risk 0.64cvss 9.8epss 0.01
Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editClient.php?client_id=.
- risk 0.64cvss 9.8epss 0.01
Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/clientStatus.php?client_id=.
- risk 0.64cvss 9.8epss 0.01
Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/classes/Users.php?f=delete.
- risk 0.64cvss 9.8epss 0.01
Money Transfer Management System 1.0 is vulnerable to SQL Injection via \mtms\classes\Master.php?f=delete_transaction.
- risk 0.64cvss 9.8epss 0.01
Money Transfer Management System 1.0 is vulnerable to SQL Injection via \mtms\classes\Master.php?f=delete_fee.
- risk 0.64cvss 9.8epss 0.01
Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/admin/?page=user/manage_user&id=.
- risk 0.64cvss 9.8epss 0.01
Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/admin/?page=transaction/send&id=, id.
- risk 0.65cvss 9.8epss 0.18
IonizeCMS v1.0.8.1 was discovered to contain a command injection vulnerability via the function copy_lang_content in application/models/lang_model.php.
- risk 0.64cvss 9.8epss 0.01
IonizeCMS v1.0.8.1 was discovered to contain a SQL injection vulnerability via the id_page parameter in application/models/article_model.php.
- risk 0.87cvss 9.8epss 0.98
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
- risk 0.64cvss 9.8epss 0.01
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 223022.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=clients/manage_client&id=.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=facilities/manage_facility&id=.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/bookings/view_booking.php?id=.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/categories/manage_category.php?id=.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/categories/view_category.php?id=.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_booking.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=user/manage_user&id=.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_facility.