| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29985 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_category. | ||
| CVE-2022-29984 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=client/view_client&id=. | ||
| CVE-2022-29983 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/view_invoice&id=. | ||
| CVE-2022-29982 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/maintenance/manage_service.php?id=. | ||
| CVE-2022-29981 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Users.php?f=delete. | ||
| CVE-2022-29980 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=user/manage_user&id=. | ||
| CVE-2022-29979 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_designation. | ||
| CVE-2022-29751 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_client. | ||
| CVE-2022-29750 | — | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_service. | |
| CVE-2022-29749 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_invoice. | ||
| CVE-2022-29748 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via \cms\admin?page=client/manage_client&id=. | ||
| CVE-2022-29747 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/manage_invoice&id= // Leak place ---> id. | ||
| CVE-2022-29539 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | resi-calltrace in RESI Gemini-Net 4.2 is affected by OS Command Injection. It does not properly check the parameters sent as input before they are processed on the server. Due to the lack of validation of user input, an unauthenticated attacker can bypass the syntax intended by… | ||
| CVE-2022-30525 | Cri | 0.87 | 9.8 | 1.00 | KEV | May 12, 2022 | A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00… | |
| CVE-2021-42863 | Cri | 0.00 | 9.8 | 0.02 | May 12, 2022 | A buffer overflow in ecma_builtin_typedarray_prototype_filter() in JerryScript version fe3a5c0 allows an attacker to construct a fake object or a fake arraybuffer with unlimited size. | ||
| CVE-2022-30592 | Cri | 0.00 | 9.8 | 0.03 | May 11, 2022 | liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY. | ||
| CVE-2022-29596 | Cri | 0.64 | 9.8 | 0.02 | May 11, 2022 | MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../../../../../../../windows/win.ini%00.jpg&Pwd=_any_password_&ConnMode=1&3054=Login substring for directory traversal. | ||
| CVE-2022-30450 | Cri | 0.65 | 9.8 | 0.21 | May 11, 2022 | A Remote Code Execution (RCE) vulnerability exists in waimairen 9.1 via wx.php | ||
| CVE-2022-30449 | Cri | 0.64 | 9.8 | 0.02 | May 11, 2022 | Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in room.php. | ||
| CVE-2022-30448 | Cri | 0.64 | 9.8 | 0.02 | May 11, 2022 | Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrecord.php. | ||
| CVE-2022-30063 | Cri | 0.65 | 9.8 | 0.17 | May 11, 2022 | ftcms <=2.1 was discovered to be vulnerable to code execution attacks . | ||
| CVE-2022-30453 | Cri | 0.65 | 9.8 | 0.15 | May 11, 2022 | ShopWind <= 3.4.2 has a RCE vulnerability in Database.php | ||
| CVE-2022-30048 | Cri | 0.64 | 9.8 | 0.01 | May 11, 2022 | Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter. | ||
| CVE-2022-30047 | Cri | 0.64 | 9.8 | 0.01 | May 11, 2022 | Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter. | ||
| CVE-2021-42646 | — | Cri | 0.00 | 9.1 | 0.04 | May 11, 2022 | XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0,… | |
| CVE-2021-34085 | Cri | 0.64 | 9.8 | 0.02 | May 11, 2022 | Read access violation in the III_dequantize_sample function in mpglibDBL/layer3.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact, a different vulnerability than CVE-2017-9872.… | ||
| CVE-2021-33316 | Cri | 0.64 | 9.8 | 0.01 | May 11, 2022 | The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulnerability. This vulnerability exists in its lldp related component. Due to lack of proper validation on length field of ChassisID TLV, by sending a crafted lldp packet to the… | ||
| CVE-2021-33315 | Cri | 0.64 | 9.8 | 0.01 | May 11, 2022 | The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulnerability. This vulnerability exists in its lldp related component. Due to lack of proper validation on length field of PortID TLV, by sending a crafted lldp packet to the… | ||
| CVE-2021-38969 | Cri | 0.64 | 9.8 | 0.01 | May 11, 2022 | IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials. IBM X-Force ID: 212609. | ||
| CVE-2022-29898 | Cri | 0.59 | 9.1 | 0.01 | May 11, 2022 | On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration file uploader in the WebUI to execute arbitrary code with root privileges on the OS due to an improper validation of an integrity check value in all versions of the firmware. | ||
| CVE-2022-29897 | Cri | 0.59 | 9.1 | 0.01 | May 11, 2022 | On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the traceroute utility integrated in the WebUI to execute arbitrary code with root privileges on the OS due to an improper input validation in all versions of the firmware. | ||
| CVE-2022-29009 | Cri | 0.65 | 9.8 | 0.23 | May 11, 2022 | Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication. | ||
| CVE-2022-29007 | Cri | 0.65 | 9.8 | 0.19 | May 11, 2022 | Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication. | ||
| CVE-2022-29006 | Cri | 0.65 | 9.8 | 0.19 | May 11, 2022 | Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication. | ||
| CVE-2022-29656 | Cri | 0.64 | 9.8 | 0.01 | May 11, 2022 | Wedding Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Wedding-Management/package_detail.php. | ||
| CVE-2022-29317 | Cri | 0.64 | 9.8 | 0.01 | May 11, 2022 | Simple Bus Ticket Booking System v1.0 was discovered to contain multiple SQL injection vulnerbilities via the username and password parameters at /assets/partials/_handleLogin.php. | ||
| CVE-2022-29316 | — | Cri | 0.64 | 9.8 | 0.03 | May 11, 2022 | Complete Online Job Search System v1.0 was discovered to contain a SQL injection vulnerability via /eris/index.php?q=result&searchfor=advancesearch. | |
| CVE-2022-29130 | Cri | 0.64 | 9.8 | 0.04 | May 10, 2022 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2022-26937 | Cri | 0.70 | 9.8 | 0.77 | May 10, 2022 | Windows Network File System Remote Code Execution Vulnerability | ||
| CVE-2022-22012 | Cri | 0.64 | 9.8 | 0.04 | May 10, 2022 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2022-20120 | Cri | 0.64 | 9.8 | 0.01 | May 10, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-203213034References: N/A | ||
| CVE-2022-29399 | Cri | 0.64 | 9.8 | 0.02 | May 10, 2022 | TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the url parameter in the function FUN_00415bf0. | ||
| CVE-2022-29398 | Cri | 0.64 | 9.8 | 0.02 | May 10, 2022 | TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the File parameter in the function FUN_0041309c. | ||
| CVE-2022-29397 | Cri | 0.64 | 9.8 | 0.02 | May 10, 2022 | TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004196c8. | ||
| CVE-2022-29396 | Cri | 0.64 | 9.8 | 0.02 | May 10, 2022 | TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_00418f10. | ||
| CVE-2022-29395 | Cri | 0.64 | 9.8 | 0.02 | May 10, 2022 | TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the apcliKey parameter in the function FUN_0041bac4. | ||
| CVE-2022-29394 | Cri | 0.64 | 9.8 | 0.02 | May 10, 2022 | TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macAddress parameter in the function FUN_0041b448. | ||
| CVE-2022-29393 | Cri | 0.64 | 9.8 | 0.02 | May 10, 2022 | TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004192cc. | ||
| CVE-2022-29392 | Cri | 0.64 | 9.8 | 0.02 | May 10, 2022 | TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_00418c24. | ||
| CVE-2022-29391 | Cri | 0.64 | 9.8 | 0.02 | May 10, 2022 | TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004200c8. |
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_category.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=client/view_client&id=.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/view_invoice&id=.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/maintenance/manage_service.php?id=.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Users.php?f=delete.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=user/manage_user&id=.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_designation.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_client.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_service.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_invoice.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via \cms\admin?page=client/manage_client&id=.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/manage_invoice&id= // Leak place ---> id.
- risk 0.64cvss 9.8epss 0.02
resi-calltrace in RESI Gemini-Net 4.2 is affected by OS Command Injection. It does not properly check the parameters sent as input before they are processed on the server. Due to the lack of validation of user input, an unauthenticated attacker can bypass the syntax intended by…
- risk 0.87cvss 9.8epss 1.00
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00…
- risk 0.00cvss 9.8epss 0.02
A buffer overflow in ecma_builtin_typedarray_prototype_filter() in JerryScript version fe3a5c0 allows an attacker to construct a fake object or a fake arraybuffer with unlimited size.
- risk 0.00cvss 9.8epss 0.03
liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY.
- risk 0.64cvss 9.8epss 0.02
MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../../../../../../../windows/win.ini%00.jpg&Pwd=_any_password_&ConnMode=1&3054=Login substring for directory traversal.
- risk 0.65cvss 9.8epss 0.21
A Remote Code Execution (RCE) vulnerability exists in waimairen 9.1 via wx.php
- risk 0.64cvss 9.8epss 0.02
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in room.php.
- risk 0.64cvss 9.8epss 0.02
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrecord.php.
- risk 0.65cvss 9.8epss 0.17
ftcms <=2.1 was discovered to be vulnerable to code execution attacks .
- risk 0.65cvss 9.8epss 0.15
ShopWind <= 3.4.2 has a RCE vulnerability in Database.php
- risk 0.64cvss 9.8epss 0.01
Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.
- risk 0.64cvss 9.8epss 0.01
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.
- risk 0.00cvss 9.1epss 0.04
XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0,…
- risk 0.64cvss 9.8epss 0.02
Read access violation in the III_dequantize_sample function in mpglibDBL/layer3.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact, a different vulnerability than CVE-2017-9872.…
- risk 0.64cvss 9.8epss 0.01
The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulnerability. This vulnerability exists in its lldp related component. Due to lack of proper validation on length field of ChassisID TLV, by sending a crafted lldp packet to the…
- risk 0.64cvss 9.8epss 0.01
The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulnerability. This vulnerability exists in its lldp related component. Due to lack of proper validation on length field of PortID TLV, by sending a crafted lldp packet to the…
- risk 0.64cvss 9.8epss 0.01
IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials. IBM X-Force ID: 212609.
- risk 0.59cvss 9.1epss 0.01
On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration file uploader in the WebUI to execute arbitrary code with root privileges on the OS due to an improper validation of an integrity check value in all versions of the firmware.
- risk 0.59cvss 9.1epss 0.01
On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the traceroute utility integrated in the WebUI to execute arbitrary code with root privileges on the OS due to an improper input validation in all versions of the firmware.
- risk 0.65cvss 9.8epss 0.23
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.
- risk 0.65cvss 9.8epss 0.19
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.
- risk 0.65cvss 9.8epss 0.19
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.
- risk 0.64cvss 9.8epss 0.01
Wedding Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Wedding-Management/package_detail.php.
- risk 0.64cvss 9.8epss 0.01
Simple Bus Ticket Booking System v1.0 was discovered to contain multiple SQL injection vulnerbilities via the username and password parameters at /assets/partials/_handleLogin.php.
- risk 0.64cvss 9.8epss 0.03
Complete Online Job Search System v1.0 was discovered to contain a SQL injection vulnerability via /eris/index.php?q=result&searchfor=advancesearch.
- risk 0.64cvss 9.8epss 0.04
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.70cvss 9.8epss 0.77
Windows Network File System Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.04
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.01
Product: AndroidVersions: Android kernelAndroid ID: A-203213034References: N/A
- risk 0.64cvss 9.8epss 0.02
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the url parameter in the function FUN_00415bf0.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the File parameter in the function FUN_0041309c.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004196c8.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_00418f10.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the apcliKey parameter in the function FUN_0041bac4.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macAddress parameter in the function FUN_0041b448.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004192cc.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_00418c24.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004200c8.