VYPR

CVEs

31,785 total · page 337 of 636

  • CVE-2022-29985CriMay 12, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_category.

  • CVE-2022-29984CriMay 12, 2022
    risk 0.64cvss 9.8epss 0.02

    Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=client/view_client&id=.

  • CVE-2022-29983CriMay 12, 2022
    risk 0.64cvss 9.8epss 0.02

    Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/view_invoice&id=.

  • CVE-2022-29982CriMay 12, 2022
    risk 0.64cvss 9.8epss 0.02

    Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/maintenance/manage_service.php?id=.

  • CVE-2022-29981CriMay 12, 2022
    risk 0.64cvss 9.8epss 0.02

    Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Users.php?f=delete.

  • CVE-2022-29980CriMay 12, 2022
    risk 0.64cvss 9.8epss 0.02

    Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=user/manage_user&id=.

  • CVE-2022-29979CriMay 12, 2022
    risk 0.64cvss 9.8epss 0.02

    Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_designation.

  • CVE-2022-29751CriMay 12, 2022
    risk 0.64cvss 9.8epss 0.02

    Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_client.

  • CVE-2022-29750CriMay 12, 2022
    risk 0.64cvss 9.8epss 0.02

    Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_service.

  • CVE-2022-29749CriMay 12, 2022
    risk 0.64cvss 9.8epss 0.02

    Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_invoice.

  • CVE-2022-29748CriMay 12, 2022
    risk 0.64cvss 9.8epss 0.02

    Simple Client Management System 1.0 is vulnerable to SQL Injection via \cms\admin?page=client/manage_client&id=.

  • CVE-2022-29747CriMay 12, 2022
    risk 0.64cvss 9.8epss 0.02

    Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/manage_invoice&id= // Leak place ---> id.

  • CVE-2022-29539CriMay 12, 2022
    risk 0.64cvss 9.8epss 0.02

    resi-calltrace in RESI Gemini-Net 4.2 is affected by OS Command Injection. It does not properly check the parameters sent as input before they are processed on the server. Due to the lack of validation of user input, an unauthenticated attacker can bypass the syntax intended by…

  • CVE-2022-30525CriKEVMay 12, 2022
    risk 0.87cvss 9.8epss 1.00

    A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00…

  • CVE-2021-42863CriMay 12, 2022
    risk 0.00cvss 9.8epss 0.02

    A buffer overflow in ecma_builtin_typedarray_prototype_filter() in JerryScript version fe3a5c0 allows an attacker to construct a fake object or a fake arraybuffer with unlimited size.

  • CVE-2022-30592CriMay 11, 2022
    risk 0.00cvss 9.8epss 0.03

    liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY.

  • CVE-2022-29596CriMay 11, 2022
    risk 0.64cvss 9.8epss 0.02

    MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../../../../../../../windows/win.ini%00.jpg&Pwd=_any_password_&ConnMode=1&3054=Login substring for directory traversal.

  • CVE-2022-30450CriMay 11, 2022
    risk 0.65cvss 9.8epss 0.21

    A Remote Code Execution (RCE) vulnerability exists in waimairen 9.1 via wx.php

  • CVE-2022-30449CriMay 11, 2022
    risk 0.64cvss 9.8epss 0.02

    Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in room.php.

  • CVE-2022-30448CriMay 11, 2022
    risk 0.64cvss 9.8epss 0.02

    Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrecord.php.

  • CVE-2022-30063CriMay 11, 2022
    risk 0.65cvss 9.8epss 0.17

    ftcms <=2.1 was discovered to be vulnerable to code execution attacks .

  • CVE-2022-30453CriMay 11, 2022
    risk 0.65cvss 9.8epss 0.15

    ShopWind <= 3.4.2 has a RCE vulnerability in Database.php

  • CVE-2022-30048CriMay 11, 2022
    risk 0.64cvss 9.8epss 0.01

    Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.

  • CVE-2022-30047CriMay 11, 2022
    risk 0.64cvss 9.8epss 0.01

    Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.

  • CVE-2021-42646CriMay 11, 2022
    risk 0.00cvss 9.1epss 0.04

    XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0,…

  • CVE-2021-34085CriMay 11, 2022
    risk 0.64cvss 9.8epss 0.02

    Read access violation in the III_dequantize_sample function in mpglibDBL/layer3.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact, a different vulnerability than CVE-2017-9872.…

  • CVE-2021-33316CriMay 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulnerability. This vulnerability exists in its lldp related component. Due to lack of proper validation on length field of ChassisID TLV, by sending a crafted lldp packet to the…

  • CVE-2021-33315CriMay 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulnerability. This vulnerability exists in its lldp related component. Due to lack of proper validation on length field of PortID TLV, by sending a crafted lldp packet to the…

  • CVE-2021-38969CriMay 11, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials. IBM X-Force ID: 212609.

  • CVE-2022-29898CriMay 11, 2022
    risk 0.59cvss 9.1epss 0.01

    On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration file uploader in the WebUI to execute arbitrary code with root privileges on the OS due to an improper validation of an integrity check value in all versions of the firmware.

  • CVE-2022-29897CriMay 11, 2022
    risk 0.59cvss 9.1epss 0.01

    On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the traceroute utility integrated in the WebUI to execute arbitrary code with root privileges on the OS due to an improper input validation in all versions of the firmware.

  • CVE-2022-29009CriMay 11, 2022
    risk 0.65cvss 9.8epss 0.23

    Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.

  • CVE-2022-29007CriMay 11, 2022
    risk 0.65cvss 9.8epss 0.19

    Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.

  • CVE-2022-29006CriMay 11, 2022
    risk 0.65cvss 9.8epss 0.19

    Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.

  • CVE-2022-29656CriMay 11, 2022
    risk 0.64cvss 9.8epss 0.01

    Wedding Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Wedding-Management/package_detail.php.

  • CVE-2022-29317CriMay 11, 2022
    risk 0.64cvss 9.8epss 0.01

    Simple Bus Ticket Booking System v1.0 was discovered to contain multiple SQL injection vulnerbilities via the username and password parameters at /assets/partials/_handleLogin.php.

  • CVE-2022-29316CriMay 11, 2022
    risk 0.64cvss 9.8epss 0.03

    Complete Online Job Search System v1.0 was discovered to contain a SQL injection vulnerability via /eris/index.php?q=result&searchfor=advancesearch.

  • CVE-2022-29130CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

  • CVE-2022-26937CriMay 10, 2022
    risk 0.70cvss 9.8epss 0.77

    Windows Network File System Remote Code Execution Vulnerability

  • CVE-2022-22012CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

  • CVE-2022-20120CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-203213034References: N/A

  • CVE-2022-29399CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the url parameter in the function FUN_00415bf0.

  • CVE-2022-29398CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the File parameter in the function FUN_0041309c.

  • CVE-2022-29397CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004196c8.

  • CVE-2022-29396CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_00418f10.

  • CVE-2022-29395CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the apcliKey parameter in the function FUN_0041bac4.

  • CVE-2022-29394CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macAddress parameter in the function FUN_0041b448.

  • CVE-2022-29393CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004192cc.

  • CVE-2022-29392CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_00418c24.

  • CVE-2022-29391CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004200c8.