| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-24877 | Cri | 0.57 | 9.9 | 0.01 | May 6, 2022 | Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to expose sensitive data from the controller’s pod filesystem and possibly privilege escalation in… | ||
| CVE-2022-24884 | Cri | 0.00 | 10.0 | 0.01 | May 6, 2022 | ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` does not check whether the signature values `r` and `s` are non-zero. A signature consisting only of zeroes is always considered valid, making it trivial to forge… | ||
| CVE-2022-24817 | Cri | 0.64 | 9.9 | 0.01 | May 6, 2022 | Flux2 is an open and extensible continuous delivery solution for Kubernetes. Flux2 versions between 0.1.0 and 0.29.0, helm-controller 0.1.0 to v0.19.0, and kustomize-controller 0.1.0 to v0.23.0 are vulnerable to Code Injection via malicious Kubeconfig. In multi-tenancy… | ||
| CVE-2022-29535 | Cri | 0.71 | 9.8 | 0.93 | May 5, 2022 | Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports. | ||
| CVE-2022-29176 | Cri | 0.64 | 9.9 | 0.02 | May 5, 2022 | Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action, it was possible for any RubyGems.org user to remove and replace certain gems even if that user was not authorized to do so. To be vulnerable, a gem needed:… | ||
| CVE-2022-27411 | Cri | 0.64 | 9.8 | 0.03 | May 5, 2022 | TOTOLINK N600R v5.3c.5507_B20171031 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter in the "Main" function. | ||
| CVE-2022-27360 | Cri | 0.64 | 9.8 | 0.02 | May 5, 2022 | SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment. | ||
| CVE-2022-28584 | Cri | 0.64 | 9.8 | 0.03 | May 5, 2022 | It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload. | ||
| CVE-2022-28583 | Cri | 0.64 | 9.8 | 0.03 | May 5, 2022 | It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload. | ||
| CVE-2022-28582 | Cri | 0.64 | 9.8 | 0.03 | May 5, 2022 | It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload. | ||
| CVE-2022-28581 | Cri | 0.64 | 9.8 | 0.03 | May 5, 2022 | It is found that there is a command injection vulnerability in the setWiFiAdvancedCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload. | ||
| CVE-2022-28580 | Cri | 0.64 | 9.8 | 0.03 | May 5, 2022 | It is found that there is a command injection vulnerability in the setL2tpServerCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload. | ||
| CVE-2022-28579 | Cri | 0.64 | 9.8 | 0.03 | May 5, 2022 | It is found that there is a command injection vulnerability in the setParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload. | ||
| CVE-2022-28578 | Cri | 0.64 | 9.8 | 0.03 | May 5, 2022 | It is found that there is a command injection vulnerability in the setOpenVpnCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload. | ||
| CVE-2022-28577 | Cri | 0.64 | 9.8 | 0.03 | May 5, 2022 | It is found that there is a command injection vulnerability in the delParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload. | ||
| CVE-2022-28575 | Cri | 0.64 | 9.8 | 0.03 | May 5, 2022 | It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows attackers to execute arbitrary commands through a carefully constructed payload | ||
| CVE-2022-29592 | Cri | 0.65 | 9.8 | 0.20 | May 5, 2022 | Tenda TX9 Pro 22.03.02.10 devices allow OS command injection via set_route (called by doSystemCmd_route). | ||
| CVE-2022-29502 | Cri | 0.64 | 9.8 | 0.02 | May 5, 2022 | SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges. | ||
| CVE-2022-28606 | Cri | 0.64 | 9.8 | 0.01 | May 5, 2022 | An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can be exploited by an attacker to gain control of the server. | ||
| CVE-2022-28533 | Cri | 0.64 | 9.8 | 0.02 | May 5, 2022 | Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php. | ||
| CVE-2022-28530 | Cri | 0.64 | 9.8 | 0.02 | May 5, 2022 | Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory. | ||
| CVE-2022-28120 | Cri | 0.64 | 9.8 | 0.01 | May 5, 2022 | Beijing Runnier Network Technology Co., Ltd Open virtual simulation experiment teaching management platform software 2.0 has a file upload vulnerability, which can be exploited by an attacker to gain control of the server. | ||
| CVE-2022-27588 | Cri | 0.64 | 9.8 | 0.01 | May 5, 2022 | We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.6 build 20220401 and later | ||
| CVE-2022-1388 | Cri | 0.93 | 9.8 | 1.00 | KEV | May 5, 2022 | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which… | |
| CVE-2022-28461 | Cri | 0.64 | 9.8 | 0.01 | May 5, 2022 | mingyuefusu Library Management System all versions as of 03-27-2022 is vulnerable to SQL Injection. | ||
| CVE-2021-42242 | Cri | 0.64 | 9.8 | 0.02 | May 5, 2022 | A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor. | ||
| CVE-2022-1575 | Cri | 0.00 | 9.6 | 0.02 | May 5, 2022 | Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remote) code execution in the desktop app. - Stored XSS in the web app. | ||
| CVE-2021-41739 | Cri | 0.64 | 9.8 | 0.03 | May 5, 2022 | A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp. | ||
| CVE-2022-28890 | Cri | 0.64 | 9.8 | 0.03 | May 5, 2022 | A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities. | ||
| CVE-2022-30292 | Cri | 0.00 | 10.0 | 0.04 | May 4, 2022 | Heap-based buffer overflow in sqbaselib.cpp in SQUIRREL 3.2 due to lack of a certain sq_reservestack call. | ||
| CVE-2022-30284 | — | Cri | 0.52 | 9.0 | 0.05 | May 4, 2022 | In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not validate arguments). NOTE: the vendor believes it would be unrealistic for an application to call NmapProcess with arguments taken from input… | |
| CVE-2022-29155 | Cri | 0.69 | 9.8 | 0.64 | May 4, 2022 | In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack… | ||
| CVE-2022-20780 | Cri | 0.65 | 9.9 | 0.11 | May 4, 2022 | Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM. For more… | ||
| CVE-2022-20779 | Cri | 0.65 | 9.9 | 0.10 | May 4, 2022 | Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM. For more… | ||
| CVE-2022-20777 | Cri | 0.65 | 9.9 | 0.11 | May 4, 2022 | Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM. For more… | ||
| CVE-2021-42235 | Cri | 0.00 | 9.8 | 0.01 | May 4, 2022 | SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality. | ||
| CVE-2022-28557 | Cri | 0.65 | 9.8 | 0.23 | May 4, 2022 | There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arbitrary command execution | ||
| CVE-2022-29347 | Cri | 0.64 | 9.8 | 0.02 | May 4, 2022 | An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file. | ||
| CVE-2022-28568 | Cri | 0.64 | 9.8 | 0.03 | May 4, 2022 | Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored. | ||
| CVE-2022-28512 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2022 | A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantasticblog/single.php" via the "id=5" parameters. | ||
| CVE-2022-28082 | Cri | 0.64 | 9.8 | 0.09 | May 4, 2022 | Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the list parameter at /goform/SetNetControlList. | ||
| CVE-2022-25784 | Cri | 0.59 | 9.1 | 0.01 | May 4, 2022 | Cross-site Scripting (XSS) vulnerability in Web GUI of SiteManager allows logged-in user to inject scripting. This issue affects: Secomea SiteManager all versions prior to 9.7. | ||
| CVE-2022-28111 | — | Cri | 0.57 | 9.8 | 0.02 | May 4, 2022 | MyBatis PageHelper v1.x.x-v3.7.0 v4.0.0-v5.0.0,v5.1.0-v5.3.0 was discovered to contain a time-blind SQL injection vulnerability via the orderBy parameter. | |
| CVE-2021-42185 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2022 | wdja v2.1 is affected by a SQL injection vulnerability in the foreground search function. | ||
| CVE-2022-28055 | Cri | 0.00 | 9.8 | 0.01 | May 4, 2022 | Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function. | ||
| CVE-2022-27431 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2022 | Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the groupid parameter at /coreframe/app/member/admin/group.php. | ||
| CVE-2022-27420 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php. | ||
| CVE-2021-43163 | Cri | 0.64 | 9.8 | 0.02 | May 4, 2022 | A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth. | ||
| CVE-2022-27413 | Cri | 0.64 | 9.8 | 0.03 | May 3, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in admin.php. | ||
| CVE-2022-28585 | Cri | 0.64 | 9.8 | 0.01 | May 3, 2022 | EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php |
- risk 0.57cvss 9.9epss 0.01
Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to expose sensitive data from the controller’s pod filesystem and possibly privilege escalation in…
- risk 0.00cvss 10.0epss 0.01
ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` does not check whether the signature values `r` and `s` are non-zero. A signature consisting only of zeroes is always considered valid, making it trivial to forge…
- risk 0.64cvss 9.9epss 0.01
Flux2 is an open and extensible continuous delivery solution for Kubernetes. Flux2 versions between 0.1.0 and 0.29.0, helm-controller 0.1.0 to v0.19.0, and kustomize-controller 0.1.0 to v0.23.0 are vulnerable to Code Injection via malicious Kubeconfig. In multi-tenancy…
- risk 0.71cvss 9.8epss 0.93
Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.
- risk 0.64cvss 9.9epss 0.02
Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action, it was possible for any RubyGems.org user to remove and replace certain gems even if that user was not authorized to do so. To be vulnerable, a gem needed:…
- risk 0.64cvss 9.8epss 0.03
TOTOLINK N600R v5.3c.5507_B20171031 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter in the "Main" function.
- risk 0.64cvss 9.8epss 0.02
SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.
- risk 0.64cvss 9.8epss 0.03
It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
- risk 0.64cvss 9.8epss 0.03
It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
- risk 0.64cvss 9.8epss 0.03
It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
- risk 0.64cvss 9.8epss 0.03
It is found that there is a command injection vulnerability in the setWiFiAdvancedCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
- risk 0.64cvss 9.8epss 0.03
It is found that there is a command injection vulnerability in the setL2tpServerCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
- risk 0.64cvss 9.8epss 0.03
It is found that there is a command injection vulnerability in the setParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
- risk 0.64cvss 9.8epss 0.03
It is found that there is a command injection vulnerability in the setOpenVpnCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
- risk 0.64cvss 9.8epss 0.03
It is found that there is a command injection vulnerability in the delParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
- risk 0.64cvss 9.8epss 0.03
It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows attackers to execute arbitrary commands through a carefully constructed payload
- risk 0.65cvss 9.8epss 0.20
Tenda TX9 Pro 22.03.02.10 devices allow OS command injection via set_route (called by doSystemCmd_route).
- risk 0.64cvss 9.8epss 0.02
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can be exploited by an attacker to gain control of the server.
- risk 0.64cvss 9.8epss 0.02
Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php.
- risk 0.64cvss 9.8epss 0.02
Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory.
- risk 0.64cvss 9.8epss 0.01
Beijing Runnier Network Technology Co., Ltd Open virtual simulation experiment teaching management platform software 2.0 has a file upload vulnerability, which can be exploited by an attacker to gain control of the server.
- risk 0.64cvss 9.8epss 0.01
We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.6 build 20220401 and later
- risk 0.93cvss 9.8epss 1.00
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which…
- risk 0.64cvss 9.8epss 0.01
mingyuefusu Library Management System all versions as of 03-27-2022 is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.02
A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.
- risk 0.00cvss 9.6epss 0.02
Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remote) code execution in the desktop app. - Stored XSS in the web app.
- risk 0.64cvss 9.8epss 0.03
A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.
- risk 0.64cvss 9.8epss 0.03
A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.
- risk 0.00cvss 10.0epss 0.04
Heap-based buffer overflow in sqbaselib.cpp in SQUIRREL 3.2 due to lack of a certain sq_reservestack call.
- risk 0.52cvss 9.0epss 0.05
In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not validate arguments). NOTE: the vendor believes it would be unrealistic for an application to call NmapProcess with arguments taken from input…
- risk 0.69cvss 9.8epss 0.64
In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack…
- risk 0.65cvss 9.9epss 0.11
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM. For more…
- risk 0.65cvss 9.9epss 0.10
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM. For more…
- risk 0.65cvss 9.9epss 0.11
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM. For more…
- risk 0.00cvss 9.8epss 0.01
SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.
- risk 0.65cvss 9.8epss 0.23
There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arbitrary command execution
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.03
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantasticblog/single.php" via the "id=5" parameters.
- risk 0.64cvss 9.8epss 0.09
Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the list parameter at /goform/SetNetControlList.
- risk 0.59cvss 9.1epss 0.01
Cross-site Scripting (XSS) vulnerability in Web GUI of SiteManager allows logged-in user to inject scripting. This issue affects: Secomea SiteManager all versions prior to 9.7.
- risk 0.57cvss 9.8epss 0.02
MyBatis PageHelper v1.x.x-v3.7.0 v4.0.0-v5.0.0,v5.1.0-v5.3.0 was discovered to contain a time-blind SQL injection vulnerability via the orderBy parameter.
- risk 0.64cvss 9.8epss 0.01
wdja v2.1 is affected by a SQL injection vulnerability in the foreground search function.
- risk 0.00cvss 9.8epss 0.01
Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.
- risk 0.64cvss 9.8epss 0.01
Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the groupid parameter at /coreframe/app/member/admin/group.php.
- risk 0.64cvss 9.8epss 0.01
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.
- risk 0.64cvss 9.8epss 0.02
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth.
- risk 0.64cvss 9.8epss 0.03
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in admin.php.
- risk 0.64cvss 9.8epss 0.01
EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php