| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-25411 | Cri | 0.64 | 9.8 | 0.03 | Feb 28, 2022 | A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2021-45414 | Cri | 0.64 | 9.8 | 0.04 | Feb 28, 2022 | A Remote Code Execution (RCE) vulnerability exists in DataRobot through 2021-10-28 because it allows submission of a Docker environment or Java driver. | ||
| CVE-2022-24711 | Cri | 0.54 | 9.4 | 0.01 | Feb 28, 2022 | CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input validation vulnerability allows attackers to execute CLI routes via HTTP request. Version 4.1.9 contains a patch. There are currently no known workarounds for… | ||
| CVE-2021-43086 | Cri | 0.64 | 9.8 | 0.01 | Feb 28, 2022 | ARM astcenc 3.2.0 is vulnerable to Buffer Overflow. When the compression function of the astc-encoder project with -cl option was used, a stack-buffer-overflow occurred in function encode_ise() in function compress_symbolic_block_for_partition_2planes() in… | ||
| CVE-2022-24571 | Cri | 0.64 | 9.8 | 0.02 | Feb 28, 2022 | Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access. | ||
| CVE-2022-0768 | Cri | 0.52 | 9.1 | 0.02 | Feb 28, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2. | ||
| CVE-2022-0412 | Cri | 0.70 | 9.8 | 0.74 | Feb 28, 2022 | The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated… | ||
| CVE-2021-25010 | Cri | 0.62 | 9.6 | 0.01 | Feb 28, 2022 | The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arbitrary snippets. Furthermore, imported snippers are not sanitised and escaped, which could lead to Stored Cross-Site Scripting… | ||
| CVE-2022-25359 | Cri | 0.65 | 9.1 | 0.37 | Feb 26, 2022 | On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files. | ||
| CVE-2022-25096 | Cri | 0.64 | 9.8 | 0.02 | Feb 26, 2022 | Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /members/view_member.php. | ||
| CVE-2022-25095 | Cri | 0.64 | 9.8 | 0.01 | Feb 26, 2022 | Home Owners Collection Management System v1.0 allows unauthenticated attackers to compromise user accounts via a crafted POST request. | ||
| CVE-2022-25263 | Cri | 0.64 | 9.8 | 0.02 | Feb 25, 2022 | JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration. | ||
| CVE-2022-25262 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | In JetBrains Hub before 2022.1.14434, SAML request takeover was possible. | ||
| CVE-2022-25260 | Cri | 0.59 | 9.1 | 0.02 | Feb 25, 2022 | JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF). | ||
| CVE-2022-25064 | Cri | 0.67 | 9.8 | 0.36 | Feb 25, 2022 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr. | ||
| CVE-2022-25061 | Cri | 0.69 | 9.8 | 0.59 | Feb 25, 2022 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute. | ||
| CVE-2022-25060 | Cri | 0.68 | 9.8 | 0.40 | Feb 25, 2022 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing. | ||
| CVE-2022-24442 | Cri | 0.64 | 9.8 | 0.04 | Feb 25, 2022 | JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates. | ||
| CVE-2021-42952 | Cri | 0.64 | 9.9 | 0.02 | Feb 25, 2022 | Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution from the Notebook, users can then use that to subsequently escape the running context sandbox and proceed to access internal Zepl assets including cloud metadata… | ||
| CVE-2021-40046 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | PCManager versions 11.1.1.95 has a privilege escalation vulnerability. Successful exploit could allow the attacker to access certain resource beyond its privilege. | ||
| CVE-2021-22480 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to heap memory overflow. | ||
| CVE-2021-22448 | Cri | 0.59 | 9.1 | 0.01 | Feb 25, 2022 | There is an improper verification vulnerability in smartphones. Successful exploitation of this vulnerability may cause unauthorized read and write of some files. | ||
| CVE-2021-22434 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | There is a memory address out of bounds vulnerability in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed. | ||
| CVE-2021-22433 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed. | ||
| CVE-2021-22432 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access. | ||
| CVE-2021-22431 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access. | ||
| CVE-2021-22430 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | There is a logic bypass vulnerability in smartphones. Successful exploitation of this vulnerability may cause code injection. | ||
| CVE-2021-22429 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed. | ||
| CVE-2021-22426 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed. | ||
| CVE-2021-22394 | Cri | 0.59 | 9.1 | 0.01 | Feb 25, 2022 | There is a buffer overflow vulnerability in smartphones. Successful exploitation of this vulnerability may cause DoS of the apps during Multi-Screen Collaboration. | ||
| CVE-2022-24340 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible. | ||
| CVE-2022-24331 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible. | ||
| CVE-2021-45977 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm… | ||
| CVE-2021-39363 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2022 | Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved. | ||
| CVE-2022-25149 | Cri | 0.70 | 9.8 | 0.77 | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to… | ||
| CVE-2022-25148 | Cri | 0.73 | 9.8 | 0.81 | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL… | ||
| CVE-2022-25004 | Cri | 0.64 | 9.8 | 0.02 | Feb 24, 2022 | Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/manage_doctor.php. | ||
| CVE-2022-25003 | Cri | 0.64 | 9.8 | 0.02 | Feb 24, 2022 | Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/view_doctor.php. | ||
| CVE-2022-0651 | Cri | 0.66 | 9.8 | 0.32 | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL… | ||
| CVE-2021-44663 | Cri | 0.64 | 9.8 | 0.04 | Feb 24, 2022 | A Remote Code Execution (RCE) vulnerability exists in the Xerte Project Xerte through 3.8.4 via a crafted php file through elfinder in connetor.php. | ||
| CVE-2020-10640 | Cri | 0.65 | 10.0 | 0.03 | Feb 24, 2022 | Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service. | ||
| CVE-2022-25809 | Cri | 0.64 | 9.8 | 0.03 | Feb 24, 2022 | Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices via a malicious skill (in the case of remote attackers) or by pairing a malicious Bluetooth device (in the case of physically… | ||
| CVE-2022-25643 | Cri | 0.00 | 9.8 | 0.02 | Feb 24, 2022 | seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root. The attack vector is a user-supplied socket pathname. | ||
| CVE-2022-25418 | Cri | 0.64 | 9.8 | 0.02 | Feb 24, 2022 | Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function openSchedWifi. | ||
| CVE-2022-25417 | Cri | 0.64 | 9.8 | 0.02 | Feb 24, 2022 | Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function saveparentcontrolinfo. | ||
| CVE-2022-25414 | Cri | 0.65 | 9.8 | 0.10 | Feb 24, 2022 | Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR. | ||
| CVE-2022-25406 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2022 | Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete_query.php via the DELETE_STR parameter. | ||
| CVE-2022-25405 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2022 | Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in change_box.php via the DELETE_STR parameter. | ||
| CVE-2022-25404 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2022 | Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete.php via the DELETE_STR parameter. | ||
| CVE-2022-25403 | Cri | 0.64 | 9.8 | 0.02 | Feb 24, 2022 | HMS v1.0 was discovered to contain a SQL injection vulnerability via the component admin.php. |
- risk 0.64cvss 9.8epss 0.03
A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.04
A Remote Code Execution (RCE) vulnerability exists in DataRobot through 2021-10-28 because it allows submission of a Docker environment or Java driver.
- risk 0.54cvss 9.4epss 0.01
CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input validation vulnerability allows attackers to execute CLI routes via HTTP request. Version 4.1.9 contains a patch. There are currently no known workarounds for…
- risk 0.64cvss 9.8epss 0.01
ARM astcenc 3.2.0 is vulnerable to Buffer Overflow. When the compression function of the astc-encoder project with -cl option was used, a stack-buffer-overflow occurred in function encode_ise() in function compress_symbolic_block_for_partition_2planes() in…
- risk 0.64cvss 9.8epss 0.02
Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access.
- risk 0.52cvss 9.1epss 0.02
Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2.
- risk 0.70cvss 9.8epss 0.74
The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated…
- risk 0.62cvss 9.6epss 0.01
The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arbitrary snippets. Furthermore, imported snippers are not sanitised and escaped, which could lead to Stored Cross-Site Scripting…
- risk 0.65cvss 9.1epss 0.37
On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.
- risk 0.64cvss 9.8epss 0.02
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /members/view_member.php.
- risk 0.64cvss 9.8epss 0.01
Home Owners Collection Management System v1.0 allows unauthenticated attackers to compromise user accounts via a crafted POST request.
- risk 0.64cvss 9.8epss 0.02
JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration.
- risk 0.64cvss 9.8epss 0.01
In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.
- risk 0.59cvss 9.1epss 0.02
JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).
- risk 0.67cvss 9.8epss 0.36
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.
- risk 0.69cvss 9.8epss 0.59
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
- risk 0.68cvss 9.8epss 0.40
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
- risk 0.64cvss 9.8epss 0.04
JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
- risk 0.64cvss 9.9epss 0.02
Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution from the Notebook, users can then use that to subsequently escape the running context sandbox and proceed to access internal Zepl assets including cloud metadata…
- risk 0.64cvss 9.8epss 0.01
PCManager versions 11.1.1.95 has a privilege escalation vulnerability. Successful exploit could allow the attacker to access certain resource beyond its privilege.
- risk 0.64cvss 9.8epss 0.01
The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to heap memory overflow.
- risk 0.59cvss 9.1epss 0.01
There is an improper verification vulnerability in smartphones. Successful exploitation of this vulnerability may cause unauthorized read and write of some files.
- risk 0.64cvss 9.8epss 0.01
There is a memory address out of bounds vulnerability in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
- risk 0.64cvss 9.8epss 0.01
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
- risk 0.64cvss 9.8epss 0.01
There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.
- risk 0.64cvss 9.8epss 0.01
There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.
- risk 0.64cvss 9.8epss 0.01
There is a logic bypass vulnerability in smartphones. Successful exploitation of this vulnerability may cause code injection.
- risk 0.64cvss 9.8epss 0.01
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
- risk 0.64cvss 9.8epss 0.01
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
- risk 0.59cvss 9.1epss 0.01
There is a buffer overflow vulnerability in smartphones. Successful exploitation of this vulnerability may cause DoS of the apps during Multi-Screen Collaboration.
- risk 0.64cvss 9.8epss 0.01
In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.
- risk 0.64cvss 9.8epss 0.01
In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.
- risk 0.64cvss 9.8epss 0.01
JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm…
- risk 0.64cvss 9.8epss 0.01
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved.
- risk 0.70cvss 9.8epss 0.77
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to…
- risk 0.73cvss 9.8epss 0.81
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL…
- risk 0.64cvss 9.8epss 0.02
Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/manage_doctor.php.
- risk 0.64cvss 9.8epss 0.02
Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/view_doctor.php.
- risk 0.66cvss 9.8epss 0.32
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL…
- risk 0.64cvss 9.8epss 0.04
A Remote Code Execution (RCE) vulnerability exists in the Xerte Project Xerte through 3.8.4 via a crafted php file through elfinder in connetor.php.
- risk 0.65cvss 10.0epss 0.03
Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service.
- risk 0.64cvss 9.8epss 0.03
Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices via a malicious skill (in the case of remote attackers) or by pairing a malicious Bluetooth device (in the case of physically…
- risk 0.00cvss 9.8epss 0.02
seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root. The attack vector is a user-supplied socket pathname.
- risk 0.64cvss 9.8epss 0.02
Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function openSchedWifi.
- risk 0.64cvss 9.8epss 0.02
Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function saveparentcontrolinfo.
- risk 0.65cvss 9.8epss 0.10
Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR.
- risk 0.64cvss 9.8epss 0.01
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete_query.php via the DELETE_STR parameter.
- risk 0.64cvss 9.8epss 0.01
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in change_box.php via the DELETE_STR parameter.
- risk 0.64cvss 9.8epss 0.01
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete.php via the DELETE_STR parameter.
- risk 0.64cvss 9.8epss 0.02
HMS v1.0 was discovered to contain a SQL injection vulnerability via the component admin.php.