| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-44807 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow via webGetVarString. | ||
| CVE-2022-44806 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow. | ||
| CVE-2022-44804 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | D-Link DIR-882 1.10B02 and1.20B06 is vulnerable to Buffer Overflow via the websRedirect function. | ||
| CVE-2022-44801 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control. | ||
| CVE-2022-44202 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow. | ||
| CVE-2022-44201 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | D-Link DIR823G 1.02B05 is vulnerable to Commad Injection. | ||
| CVE-2022-44184 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_sec. | ||
| CVE-2022-44200 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | Netgear R7000P V1.3.0.8, V1.3.1.64 is vulnerable to Buffer Overflow via parameters: stamode_dns1_pri and stamode_dns1_sec. | ||
| CVE-2022-44199 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_server_ip. | ||
| CVE-2022-44198 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_push1. | ||
| CVE-2022-44197 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_server_ip. | ||
| CVE-2022-44196 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_push1. | ||
| CVE-2022-44194 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_dns1_pri and apmode_dns1_sec. | ||
| CVE-2022-44193 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameters: starthour, startminute , endhour, and endminute. | ||
| CVE-2022-44191 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameters KEY1 and KEY2. | ||
| CVE-2022-44190 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter enable_band_steering. | ||
| CVE-2022-44188 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter enable_band_steering. | ||
| CVE-2022-44187 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via wan_dns1_pri. | ||
| CVE-2022-44186 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_pri. | ||
| CVE-2022-42989 | Cri | 0.59 | 9.0 | 0.01 | Nov 22, 2022 | ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa de Entrada. | ||
| CVE-2022-40189 | Cri | 0.57 | 9.8 | 0.04 | Nov 22, 2022 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access to DAG files. This issue… | ||
| CVE-2022-38649 | Cri | 0.57 | 9.8 | 0.03 | Nov 22, 2022 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access to DAG files. This issue… | ||
| CVE-2022-40602 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an improper pre-configured password if the remote administration feature has been enabled by an authenticated administrator. | ||
| CVE-2022-36227 | Cri | 0.64 | 9.8 | 0.02 | Nov 22, 2022 | In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties… | ||
| CVE-2022-43215 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php. | ||
| CVE-2022-43214 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php. | ||
| CVE-2022-41937 | Cri | 0.55 | 9.6 | 0.01 | Nov 22, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application allows anyone with view access to modify any page of the wiki by importing a crafted XAR package. The problem has been patched in XWiki 14.6RC1, 14.6 and… | ||
| CVE-2022-41326 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper authorization controls. A successful exploit could allow remote code execution within the context of the application. | ||
| CVE-2022-40842 | Cri | 0.59 | 9.1 | 0.01 | Nov 22, 2022 | ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php. | ||
| CVE-2022-36180 | Cri | 0.62 | 9.6 | 0.01 | Nov 22, 2022 | Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout=1&message=[injection]&plug=106. | ||
| CVE-2022-36179 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | Fusiondirectory 1.3 suffers from Improper Session Handling. | ||
| CVE-2022-44785 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection vulnerabilities, some of which executable even by unauthenticated users, as demonstrated by the GetListaEnti.do cfamm parameter. | ||
| CVE-2022-30258 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effects of an exploit would… | ||
| CVE-2022-30257 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effects of an exploit would… | ||
| CVE-2022-43143 | Cri | 0.62 | 9.6 | 0.01 | Nov 21, 2022 | A cross-site scripting (XSS) vulnerability in Beekeeper Studio v3.6.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error modal container. | ||
| CVE-2022-44183 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetWifiGuestBasic. | ||
| CVE-2022-44180 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function addWifiMacFilter. | ||
| CVE-2022-44178 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow. via function formWifiWpsOOB. | ||
| CVE-2022-44177 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formWifiWpsStart. | ||
| CVE-2022-44176 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic. | ||
| CVE-2022-44175 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetMacFilterCfg. | ||
| CVE-2022-44174 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | Tenda AC18 V15.03.05.05 is vulnerable to Buffer Overflow via function formSetDeviceName. | ||
| CVE-2022-44172 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function R7WebsSecurityHandler. | ||
| CVE-2022-44171 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function form_fast_setting_wifi_set. | ||
| CVE-2022-3634 | Cri | 0.64 | 9.8 | 0.04 | Nov 21, 2022 | The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV file, which could lead to CSV injection | ||
| CVE-2022-3600 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which could lead to CSV injection. | ||
| CVE-2021-24649 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having access to the AUTH_KEY and… | ||
| CVE-2022-4093 | Cri | 0.57 | 9.8 | 0.04 | Nov 21, 2022 | SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to reputational damage and… | ||
| CVE-2022-4070 | Cri | 0.57 | 9.8 | 0.01 | Nov 20, 2022 | Insufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0. | ||
| CVE-2022-41938 | Cri | 0.52 | 9.0 | 0.01 | Nov 19, 2022 | Flarum is an open source discussion platform. Flarum's page title system allowed for page titles to be converted into HTML DOM nodes when pages were rendered. The change was made after `v1.5` and was not noticed. This allowed an attacker to inject malicious HTML markup using a… |
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow via webGetVarString.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-882 1.10B02 and1.20B06 is vulnerable to Buffer Overflow via the websRedirect function.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.
- risk 0.64cvss 9.8epss 0.01
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_sec.
- risk 0.64cvss 9.8epss 0.01
Netgear R7000P V1.3.0.8, V1.3.1.64 is vulnerable to Buffer Overflow via parameters: stamode_dns1_pri and stamode_dns1_sec.
- risk 0.64cvss 9.8epss 0.01
Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.
- risk 0.64cvss 9.8epss 0.01
Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_push1.
- risk 0.64cvss 9.8epss 0.01
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.
- risk 0.64cvss 9.8epss 0.01
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_push1.
- risk 0.64cvss 9.8epss 0.01
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_dns1_pri and apmode_dns1_sec.
- risk 0.64cvss 9.8epss 0.01
Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameters: starthour, startminute , endhour, and endminute.
- risk 0.64cvss 9.8epss 0.01
Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameters KEY1 and KEY2.
- risk 0.64cvss 9.8epss 0.01
Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter enable_band_steering.
- risk 0.64cvss 9.8epss 0.01
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter enable_band_steering.
- risk 0.64cvss 9.8epss 0.01
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via wan_dns1_pri.
- risk 0.64cvss 9.8epss 0.01
Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_pri.
- risk 0.59cvss 9.0epss 0.01
ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa de Entrada.
- risk 0.57cvss 9.8epss 0.04
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access to DAG files. This issue…
- risk 0.57cvss 9.8epss 0.03
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access to DAG files. This issue…
- risk 0.64cvss 9.8epss 0.01
A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an improper pre-configured password if the remote administration feature has been enabled by an authenticated administrator.
- risk 0.64cvss 9.8epss 0.02
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties…
- risk 0.64cvss 9.8epss 0.01
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php.
- risk 0.64cvss 9.8epss 0.01
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php.
- risk 0.55cvss 9.6epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application allows anyone with view access to modify any page of the wiki by importing a crafted XAR package. The problem has been patched in XWiki 14.6RC1, 14.6 and…
- risk 0.64cvss 9.8epss 0.01
The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper authorization controls. A successful exploit could allow remote code execution within the context of the application.
- risk 0.59cvss 9.1epss 0.01
ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php.
- risk 0.62cvss 9.6epss 0.01
Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout=1&message=[injection]&plug=106.
- risk 0.64cvss 9.8epss 0.01
Fusiondirectory 1.3 suffers from Improper Session Handling.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection vulnerabilities, some of which executable even by unauthenticated users, as demonstrated by the GetListaEnti.do cfamm parameter.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effects of an exploit would…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effects of an exploit would…
- risk 0.62cvss 9.6epss 0.01
A cross-site scripting (XSS) vulnerability in Beekeeper Studio v3.6.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error modal container.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetWifiGuestBasic.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function addWifiMacFilter.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow. via function formWifiWpsOOB.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formWifiWpsStart.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetMacFilterCfg.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 V15.03.05.05 is vulnerable to Buffer Overflow via function formSetDeviceName.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function R7WebsSecurityHandler.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function form_fast_setting_wifi_set.
- risk 0.64cvss 9.8epss 0.04
The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV file, which could lead to CSV injection
- risk 0.64cvss 9.8epss 0.01
The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which could lead to CSV injection.
- risk 0.64cvss 9.8epss 0.01
The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having access to the AUTH_KEY and…
- risk 0.57cvss 9.8epss 0.04
SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to reputational damage and…
- risk 0.57cvss 9.8epss 0.01
Insufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0.
- risk 0.52cvss 9.0epss 0.01
Flarum is an open source discussion platform. Flarum's page title system allowed for page titles to be converted into HTML DOM nodes when pages were rendered. The change was made after `v1.5` and was not noticed. This allowed an attacker to inject malicious HTML markup using a…