| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-27428 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2022 | GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of firmware file before uploading the UR IED. An illegitimate user could upgrade… | ||
| CVE-2021-27426 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2022 | GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user. | ||
| CVE-2021-38278 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2022 | Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the urls parameter in the saveParentControlInfo function. | ||
| CVE-2021-43736 | Cri | 0.64 | 9.8 | 0.02 | Mar 23, 2022 | CmsWing CMS 1.3.7 is affected by a Remote Code Execution (RCE) vulnerability via parameter: log rule | ||
| CVE-2021-43735 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2022 | CmsWing 1.3.7 is affected by a SQLi vulnerability via parameter: behavior rule. | ||
| CVE-2021-45756 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2022 | Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi. | ||
| CVE-2022-26189 | Cri | 0.64 | 9.8 | 0.03 | Mar 22, 2022 | TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the langType parameter in the login interface. | ||
| CVE-2022-26188 | Cri | 0.64 | 9.8 | 0.03 | Mar 22, 2022 | TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via /setting/NTPSyncWithHost. | ||
| CVE-2022-26187 | Cri | 0.65 | 9.8 | 0.20 | Mar 22, 2022 | TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the pingCheck function. | ||
| CVE-2022-26186 | Cri | 0.64 | 9.8 | 0.04 | Mar 22, 2022 | TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi. | ||
| CVE-2022-26260 | — | Cri | 0.57 | 9.8 | 0.01 | Mar 22, 2022 | Simple-Plist v1.3.0 was discovered to contain a prototype pollution vulnerability via .parse(). | |
| CVE-2022-25517 | Cri | 0.64 | 9.8 | 0.02 | Mar 22, 2022 | MyBatis plus v3.4.3 was discovered to contain a SQL injection vulnerability via the Column parameter in /core/conditions/AbstractWrapper.java. NOTE: the vendor's position is that the reported execution of a SQL statement was intended behavior. | ||
| CVE-2022-27228 | Cri | 0.65 | 9.8 | 0.20 | Mar 22, 2022 | In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code. | ||
| CVE-2021-41736 | Cri | 0.64 | 9.8 | 0.01 | Mar 22, 2022 | Faust v2.35.0 was discovered to contain a heap-buffer overflow in the function realPropagate() at propagate.cpp. | ||
| CVE-2021-43650 | Cri | 0.67 | 9.8 | 0.06 | Mar 22, 2022 | WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process. | ||
| CVE-2021-45809 | Cri | 0.64 | 9.8 | 0.02 | Mar 22, 2022 | GlobalProtect-openconnect versions prior to 1.4.3 are affected by incorrect access control in GPService through DBUS, GUI Application. The way GlobalProtect-Openconnect is set up enables arbitrary users to execute commands as root by submitting the `--script=` parameter. | ||
| CVE-2022-26285 | Cri | 0.64 | 9.8 | 0.02 | Mar 21, 2022 | Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the apply endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests. | ||
| CVE-2022-26284 | — | Cri | 0.64 | 9.8 | 0.02 | Mar 21, 2022 | Simple Client Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the manage_client endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests. | |
| CVE-2022-26283 | Cri | 0.64 | 9.8 | 0.02 | Mar 21, 2022 | Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests. | ||
| CVE-2022-26184 | — | Cri | 0.57 | 9.8 | 0.02 | Mar 21, 2022 | Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows… | |
| CVE-2022-26174 | Cri | 0.64 | 9.8 | 0.02 | Mar 21, 2022 | A remote code execution (RCE) vulnerability in Beekeeper Studio v3.2.0 allows attackers to execute arbitrary code via a crafted payload injected into the display fields. | ||
| CVE-2022-26148 | Cri | 0.68 | 9.8 | 0.53 | Mar 21, 2022 | An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search… | ||
| CVE-2022-24766 | Cri | 0.57 | 9.8 | 0.02 | Mar 21, 2022 | mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.4 and below, a malicious client or server is able to perform HTTP request smuggling attacks through mitmproxy. This means that a malicious client/server could smuggle a request/response through… | ||
| CVE-2022-0760 | Cri | 0.58 | 9.8 | 0.11 | Mar 21, 2022 | The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL… | ||
| CVE-2022-0747 | Cri | 0.65 | 9.8 | 0.15 | Mar 21, 2022 | The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection | ||
| CVE-2022-0739 | Cri | 0.63 | 9.8 | 0.37 | Mar 21, 2022 | The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_services AJAX action (available to unauthenticated users), leading to an… | ||
| CVE-2022-0694 | Cri | 0.64 | 9.8 | 0.02 | Mar 21, 2022 | The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an… | ||
| CVE-2022-0591 | Cri | 0.61 | 9.1 | 0.20 | Mar 21, 2022 | The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users | ||
| CVE-2022-26960 | — | Cri | 0.56 | 9.1 | 0.51 | Mar 21, 2022 | connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths. | |
| CVE-2021-45878 | Cri | 0.59 | 9.1 | 0.01 | Mar 21, 2022 | Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by incorrect access control. Lack of access control on the web manger pages allows any user to view and modify information. | ||
| CVE-2021-45877 | Cri | 0.64 | 9.8 | 0.01 | Mar 21, 2022 | Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /etc/tomcat8/tomcat-user.xml, which allows attackers to gain authorized access and control the tomcat completely on port 8000 in the tomcat manger page. | ||
| CVE-2021-45876 | Cri | 0.64 | 9.8 | 0.01 | Mar 21, 2022 | Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of the function module downloadAndUpdate is vulnerable to an command Injection. Unfiltered user input is used to generate code which then gets executed when… | ||
| CVE-2022-25505 | Cri | 0.64 | 9.8 | 0.01 | Mar 21, 2022 | Taocms v3.0.2 was discovered to contain a SQL injection vulnerability via the id parameter in \include\Model\Category.php. | ||
| CVE-2021-39384 | Cri | 0.64 | 9.8 | 0.01 | Mar 20, 2022 | DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.java. | ||
| CVE-2021-39383 | Cri | 0.64 | 9.8 | 0.03 | Mar 20, 2022 | DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java. | ||
| CVE-2022-24126 | Cri | 0.64 | 9.8 | 0.04 | Mar 20, 2022 | A buffer overflow in the NRSessionSearchResult parser in Bandai Namco FromSoftware Dark Souls III through 2022-03-19 allows remote attackers to execute arbitrary code via matchmaking servers, a different vulnerability than CVE-2021-34170. | ||
| CVE-2022-26265 | — | Cri | 0.66 | 9.8 | 0.30 | Mar 18, 2022 | Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter. | |
| CVE-2022-25578 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file. | ||
| CVE-2022-25390 | Cri | 0.64 | 9.8 | 0.03 | Mar 18, 2022 | DCN Firewall DCME-520 was discovered to contain a remote command execution (RCE) vulnerability via the host parameter in the file /system/tool/ping.php. | ||
| CVE-2022-27250 | Cri | 0.64 | 9.8 | 0.01 | Mar 18, 2022 | The UNISOC chipset through 2022-03-15 allows attackers to obtain remote control of a mobile phone, e.g., to obtain sensitive information from text messages or the device's screen, record video of the device's physical environment, or modify data. | ||
| CVE-2022-25461 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the startip parameter in the SetPptpServerCfg function. | ||
| CVE-2022-25460 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the endip parameter in the SetPptpServerCfg function. | ||
| CVE-2022-25459 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the S1 parameter in the SetSysTimeCfg function. | ||
| CVE-2022-25458 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the cmdinput parameter in the exeCommand function. | ||
| CVE-2022-25457 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function. | ||
| CVE-2022-25456 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the security_5g parameter in the WifiBasicSet function. | ||
| CVE-2022-25455 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function. | ||
| CVE-2022-25454 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the loginpwd parameter in the SetFirewallCfg function. | ||
| CVE-2022-25453 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the saveParentControlInfo function. | ||
| CVE-2022-25452 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the URLs parameter in the saveParentControlInfo function. |
- risk 0.64cvss 9.8epss 0.01
GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of firmware file before uploading the UR IED. An illegitimate user could upgrade…
- risk 0.64cvss 9.8epss 0.01
GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the urls parameter in the saveParentControlInfo function.
- risk 0.64cvss 9.8epss 0.02
CmsWing CMS 1.3.7 is affected by a Remote Code Execution (RCE) vulnerability via parameter: log rule
- risk 0.64cvss 9.8epss 0.01
CmsWing 1.3.7 is affected by a SQLi vulnerability via parameter: behavior rule.
- risk 0.64cvss 9.8epss 0.01
Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi.
- risk 0.64cvss 9.8epss 0.03
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the langType parameter in the login interface.
- risk 0.64cvss 9.8epss 0.03
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via /setting/NTPSyncWithHost.
- risk 0.65cvss 9.8epss 0.20
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the pingCheck function.
- risk 0.64cvss 9.8epss 0.04
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi.
- risk 0.57cvss 9.8epss 0.01
Simple-Plist v1.3.0 was discovered to contain a prototype pollution vulnerability via .parse().
- risk 0.64cvss 9.8epss 0.02
MyBatis plus v3.4.3 was discovered to contain a SQL injection vulnerability via the Column parameter in /core/conditions/AbstractWrapper.java. NOTE: the vendor's position is that the reported execution of a SQL statement was intended behavior.
- risk 0.65cvss 9.8epss 0.20
In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
Faust v2.35.0 was discovered to contain a heap-buffer overflow in the function realPropagate() at propagate.cpp.
- risk 0.67cvss 9.8epss 0.06
WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.
- risk 0.64cvss 9.8epss 0.02
GlobalProtect-openconnect versions prior to 1.4.3 are affected by incorrect access control in GPService through DBUS, GUI Application. The way GlobalProtect-Openconnect is set up enables arbitrary users to execute commands as root by submitting the `--script=` parameter.
- risk 0.64cvss 9.8epss 0.02
Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the apply endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the manage_client endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.
- risk 0.64cvss 9.8epss 0.02
Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.
- risk 0.57cvss 9.8epss 0.02
Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows…
- risk 0.64cvss 9.8epss 0.02
A remote code execution (RCE) vulnerability in Beekeeper Studio v3.2.0 allows attackers to execute arbitrary code via a crafted payload injected into the display fields.
- risk 0.68cvss 9.8epss 0.53
An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search…
- risk 0.57cvss 9.8epss 0.02
mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.4 and below, a malicious client or server is able to perform HTTP request smuggling attacks through mitmproxy. This means that a malicious client/server could smuggle a request/response through…
- risk 0.58cvss 9.8epss 0.11
The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL…
- risk 0.65cvss 9.8epss 0.15
The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection
- risk 0.63cvss 9.8epss 0.37
The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_services AJAX action (available to unauthenticated users), leading to an…
- risk 0.64cvss 9.8epss 0.02
The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an…
- risk 0.61cvss 9.1epss 0.20
The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users
- risk 0.56cvss 9.1epss 0.51
connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths.
- risk 0.59cvss 9.1epss 0.01
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by incorrect access control. Lack of access control on the web manger pages allows any user to view and modify information.
- risk 0.64cvss 9.8epss 0.01
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /etc/tomcat8/tomcat-user.xml, which allows attackers to gain authorized access and control the tomcat completely on port 8000 in the tomcat manger page.
- risk 0.64cvss 9.8epss 0.01
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of the function module downloadAndUpdate is vulnerable to an command Injection. Unfiltered user input is used to generate code which then gets executed when…
- risk 0.64cvss 9.8epss 0.01
Taocms v3.0.2 was discovered to contain a SQL injection vulnerability via the id parameter in \include\Model\Category.php.
- risk 0.64cvss 9.8epss 0.01
DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.java.
- risk 0.64cvss 9.8epss 0.03
DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java.
- risk 0.64cvss 9.8epss 0.04
A buffer overflow in the NRSessionSearchResult parser in Bandai Namco FromSoftware Dark Souls III through 2022-03-19 allows remote attackers to execute arbitrary code via matchmaking servers, a different vulnerability than CVE-2021-34170.
- risk 0.66cvss 9.8epss 0.30
Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.
- risk 0.64cvss 9.8epss 0.02
taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file.
- risk 0.64cvss 9.8epss 0.03
DCN Firewall DCME-520 was discovered to contain a remote command execution (RCE) vulnerability via the host parameter in the file /system/tool/ping.php.
- risk 0.64cvss 9.8epss 0.01
The UNISOC chipset through 2022-03-15 allows attackers to obtain remote control of a mobile phone, e.g., to obtain sensitive information from text messages or the device's screen, record video of the device's physical environment, or modify data.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the startip parameter in the SetPptpServerCfg function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the endip parameter in the SetPptpServerCfg function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the S1 parameter in the SetSysTimeCfg function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the cmdinput parameter in the exeCommand function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the security_5g parameter in the WifiBasicSet function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the loginpwd parameter in the SetFirewallCfg function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the saveParentControlInfo function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the URLs parameter in the saveParentControlInfo function.