| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-30123 | Cri | 0.58 | 10.0 | 0.02 | Dec 5, 2022 | A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack. | ||
| CVE-2022-27773 | Cri | 0.64 | 9.8 | 0.03 | Dec 5, 2022 | A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elevated privileges. | ||
| CVE-2022-46169 | Cri | 0.23 | 9.8 | 1.00 | KEV | Dec 5, 2022 | Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti, if… | |
| CVE-2022-46164 | Cri | 0.58 | 9.4 | 0.47 | Dec 5, 2022 | NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts. This vulnerability has been patched in version 2.6.1.… | ||
| CVE-2022-45481 | Cri | 0.64 | 9.8 | 0.02 | Dec 5, 2022 | The default configuration of Lazy Mouse does not require a password, allowing remote unauthenticated users to execute arbitrary code with no prior authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | ||
| CVE-2022-45479 | Cri | 0.64 | 9.8 | 0.02 | Dec 5, 2022 | PC Keyboard allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | ||
| CVE-2022-44039 | Cri | 0.64 | 9.8 | 0.01 | Dec 5, 2022 | Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrite (remote). ¶¶ An attacker can overwrite system files like [system.conf] and [passwd], this occurs because the insecure usage of "fopen" system function with… | ||
| CVE-2022-45477 | Cri | 0.64 | 9.8 | 0.02 | Dec 5, 2022 | Telepad allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | ||
| CVE-2022-45822 | Cri | 0.65 | 10.0 | 0.01 | Dec 5, 2022 | Unauth. SQL Injection (SQLi) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress. | ||
| CVE-2022-42496 | Cri | 0.64 | 9.8 | 0.02 | Dec 5, 2022 | OS command injection vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to obtain appkey of the product and execute an arbitrary OS command on the product. | ||
| CVE-2022-41642 | Cri | 0.57 | 9.8 | 0.02 | Dec 5, 2022 | OS command injection vulnerability in Nadesiko3 (PC Version) v3.3.61 and earlier allows a remote attacker to execute an arbitrary OS command when processing compression and decompression on the product. | ||
| CVE-2022-35508 | Cri | 0.64 | 9.8 | 0.01 | Dec 4, 2022 | Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP request to achieve SSRF and file disclosure of any files on… | ||
| CVE-2022-46414 | Cri | 0.64 | 9.8 | 0.01 | Dec 4, 2022 | An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command execution can occur via the management portal. | ||
| CVE-2022-44945 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter. | ||
| CVE-2022-44291 | Cri | 0.64 | 9.8 | 0.04 | Dec 2, 2022 | webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php. | ||
| CVE-2022-44290 | Cri | 0.64 | 9.8 | 0.04 | Dec 2, 2022 | webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php. | ||
| CVE-2022-2641 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2022 | Horner Automation’s RCC 972 with firmware version 15.40 has a static encryption key on the device. This could allow an attacker to perform unauthorized changes to the device, remotely execute arbitrary code, or cause a denial-of-service condition. | ||
| CVE-2022-3520 | Cri | 0.00 | 9.8 | 0.01 | Dec 2, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765. | ||
| CVE-2022-44367 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2022 | Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setUplinkInfo. | ||
| CVE-2022-44366 | Cri | 0.64 | 9.8 | 0.10 | Dec 2, 2022 | Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setDiagnoseInfo. | ||
| CVE-2022-44365 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2022 | Tenda i21 V1.0.0.14(4656) has a stack overflow vulnerability via /goform/setSysPwd. | ||
| CVE-2022-44363 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2022 | Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setSnmpInfo. | ||
| CVE-2022-44362 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2022 | Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/AddSysLogRule. | ||
| CVE-2022-45482 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2022 | Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticated users to easily and quickly brute force the PIN and execute arbitrary commands. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | ||
| CVE-2022-46366 | Cri | 0.64 | 9.8 | 0.04 | Dec 2, 2022 | Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability only affects Apache Tapestry version… | ||
| CVE-2022-2807 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2022 | SQL Injection vulnerability in Algan Software Prens Student Information System allows SQL Injection. This issue affects Prens Student Information System: before 2.1.11. | ||
| CVE-2022-44930 | Cri | 0.64 | 9.8 | 0.03 | Dec 2, 2022 | D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function. | ||
| CVE-2022-44929 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2022 | An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles. | ||
| CVE-2022-44928 | Cri | 0.64 | 9.8 | 0.03 | Dec 2, 2022 | D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function. | ||
| CVE-2022-43325 | Cri | 0.64 | 9.8 | 0.06 | Dec 2, 2022 | An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows attackers to execute arbitrary commands via a crafted payload injected into the license input. | ||
| CVE-2022-43333 | Cri | 0.64 | 9.8 | 0.02 | Dec 1, 2022 | Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the component action_export_control.php. | ||
| CVE-2022-37016 | Cri | 0.64 | 9.8 | 0.01 | Dec 1, 2022 | Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an… | ||
| CVE-2022-30528 | Cri | 0.64 | 9.8 | 0.01 | Dec 1, 2022 | SQL Injection vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to execute arbitrary commands via the username parameter to /system/user/modules/mod_users/controller.php. | ||
| CVE-2022-3270 | Cri | 0.64 | 9.8 | 0.01 | Dec 1, 2022 | In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability. | ||
| CVE-2022-4221 | Cri | 0.64 | 9.8 | 0.05 | Dec 1, 2022 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated attacker to inject arbitrary OS commands via unsanitized cookie values.This issue affects NAS-M25: through 1.0.1.7. | ||
| CVE-2022-36431 | Cri | 0.64 | 9.8 | 0.01 | Dec 1, 2022 | An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file. Issue fixed in version 7.9.6.1. | ||
| CVE-2022-44262 | — | Cri | 0.57 | 9.8 | 0.02 | Dec 1, 2022 | ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE). | |
| CVE-2022-44151 | Cri | 0.64 | 9.8 | 0.01 | Nov 30, 2022 | Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php. | ||
| CVE-2022-44136 | Cri | 0.57 | 9.8 | 0.01 | Nov 30, 2022 | Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE). | ||
| CVE-2022-44097 | Cri | 0.64 | 9.8 | 0.01 | Nov 30, 2022 | Book Store Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel. | ||
| CVE-2022-44096 | Cri | 0.64 | 9.8 | 0.01 | Nov 30, 2022 | Sanitization Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel. | ||
| CVE-2022-3751 | Cri | 0.57 | 9.8 | 0.01 | Nov 29, 2022 | SQL Injection in GitHub repository owncast/owncast prior to 0.0.13. | ||
| CVE-2022-44354 | Cri | 0.64 | 9.8 | 0.02 | Nov 29, 2022 | SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file. | ||
| CVE-2022-44038 | Cri | 0.64 | 9.8 | 0.02 | Nov 29, 2022 | Russound XSourcePlayer 777D v06.08.03 was discovered to contain a remote code execution vulnerability via the scriptRunner.cgi component. | ||
| CVE-2022-42109 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2022 | Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php. | ||
| CVE-2022-44399 | Cri | 0.64 | 9.8 | 0.01 | Nov 28, 2022 | Poultry Farm Management System v1.0 contains a SQL injection vulnerability via the del parameter at /Redcock-Farm/farm/category.php. | ||
| CVE-2022-44401 | Cri | 0.64 | 9.8 | 0.01 | Nov 28, 2022 | Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php. | ||
| CVE-2022-44400 | Cri | 0.64 | 9.8 | 0.01 | Nov 28, 2022 | Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info. | ||
| CVE-2022-44283 | Cri | 0.64 | 9.8 | 0.01 | Nov 28, 2022 | AVS Audio Converter 10.3 is vulnerable to Buffer Overflow. | ||
| CVE-2022-41912 | Cri | 0.52 | 9.1 | 0.02 | Nov 28, 2022 | The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version. |
- risk 0.58cvss 10.0epss 0.02
A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.
- risk 0.64cvss 9.8epss 0.03
A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elevated privileges.
- risk 0.23cvss 9.8epss 1.00
Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti, if…
- risk 0.58cvss 9.4epss 0.47
NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts. This vulnerability has been patched in version 2.6.1.…
- risk 0.64cvss 9.8epss 0.02
The default configuration of Lazy Mouse does not require a password, allowing remote unauthenticated users to execute arbitrary code with no prior authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- risk 0.64cvss 9.8epss 0.02
PC Keyboard allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- risk 0.64cvss 9.8epss 0.01
Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrite (remote). ¶¶ An attacker can overwrite system files like [system.conf] and [passwd], this occurs because the insecure usage of "fopen" system function with…
- risk 0.64cvss 9.8epss 0.02
Telepad allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- risk 0.65cvss 10.0epss 0.01
Unauth. SQL Injection (SQLi) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress.
- risk 0.64cvss 9.8epss 0.02
OS command injection vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to obtain appkey of the product and execute an arbitrary OS command on the product.
- risk 0.57cvss 9.8epss 0.02
OS command injection vulnerability in Nadesiko3 (PC Version) v3.3.61 and earlier allows a remote attacker to execute an arbitrary OS command when processing compression and decompression on the product.
- risk 0.64cvss 9.8epss 0.01
Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP request to achieve SSRF and file disclosure of any files on…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command execution can occur via the management portal.
- risk 0.64cvss 9.8epss 0.01
Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter.
- risk 0.64cvss 9.8epss 0.04
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
- risk 0.64cvss 9.8epss 0.04
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.
- risk 0.64cvss 9.8epss 0.01
Horner Automation’s RCC 972 with firmware version 15.40 has a static encryption key on the device. This could allow an attacker to perform unauthorized changes to the device, remotely execute arbitrary code, or cause a denial-of-service condition.
- risk 0.00cvss 9.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.
- risk 0.64cvss 9.8epss 0.01
Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setUplinkInfo.
- risk 0.64cvss 9.8epss 0.10
Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setDiagnoseInfo.
- risk 0.64cvss 9.8epss 0.01
Tenda i21 V1.0.0.14(4656) has a stack overflow vulnerability via /goform/setSysPwd.
- risk 0.64cvss 9.8epss 0.01
Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setSnmpInfo.
- risk 0.64cvss 9.8epss 0.01
Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/AddSysLogRule.
- risk 0.64cvss 9.8epss 0.01
Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticated users to easily and quickly brute force the PIN and execute arbitrary commands. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- risk 0.64cvss 9.8epss 0.04
Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability only affects Apache Tapestry version…
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Algan Software Prens Student Information System allows SQL Injection. This issue affects Prens Student Information System: before 2.1.11.
- risk 0.64cvss 9.8epss 0.03
D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function.
- risk 0.64cvss 9.8epss 0.01
An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles.
- risk 0.64cvss 9.8epss 0.03
D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.
- risk 0.64cvss 9.8epss 0.06
An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows attackers to execute arbitrary commands via a crafted payload injected into the license input.
- risk 0.64cvss 9.8epss 0.02
Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the component action_export_control.php.
- risk 0.64cvss 9.8epss 0.01
Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an…
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to execute arbitrary commands via the username parameter to /system/user/modules/mod_users/controller.php.
- risk 0.64cvss 9.8epss 0.01
In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.
- risk 0.64cvss 9.8epss 0.05
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated attacker to inject arbitrary OS commands via unsanitized cookie values.This issue affects NAS-M25: through 1.0.1.7.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file. Issue fixed in version 7.9.6.1.
- risk 0.57cvss 9.8epss 0.02
ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).
- risk 0.64cvss 9.8epss 0.01
Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php.
- risk 0.57cvss 9.8epss 0.01
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
- risk 0.64cvss 9.8epss 0.01
Book Store Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.
- risk 0.64cvss 9.8epss 0.01
Sanitization Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.
- risk 0.57cvss 9.8epss 0.01
SQL Injection in GitHub repository owncast/owncast prior to 0.0.13.
- risk 0.64cvss 9.8epss 0.02
SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.
- risk 0.64cvss 9.8epss 0.02
Russound XSourcePlayer 777D v06.08.03 was discovered to contain a remote code execution vulnerability via the scriptRunner.cgi component.
- risk 0.64cvss 9.8epss 0.01
Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php.
- risk 0.64cvss 9.8epss 0.01
Poultry Farm Management System v1.0 contains a SQL injection vulnerability via the del parameter at /Redcock-Farm/farm/category.php.
- risk 0.64cvss 9.8epss 0.01
Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php.
- risk 0.64cvss 9.8epss 0.01
Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info.
- risk 0.64cvss 9.8epss 0.01
AVS Audio Converter 10.3 is vulnerable to Buffer Overflow.
- risk 0.52cvss 9.1epss 0.02
The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version.