Search Results (356046 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-38362 1 Apache 1 Apache-airflow-providers-docker 2024-11-21 8.8 High
Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.
CVE-2022-38359 1 Eyeofnetwork 1 Eyes Of Network Web 2024-11-21 8.8 High
Cross-site request forgery attacks can be carried out against the Eyes of Network web application, due to an absence of adequate protections. An attacker can, for instance, delete the admin user by directing an authenticated user to the URL https://<target-address>/module/admin_user/index.php?DataTables_Table_0_length=10&user_selected%5B%5D=1&user_mgt_list=delete_user&action=submit by means of a crafted link.
CVE-2022-38358 1 Eyeofnetwork 1 Eyes Of Network Web 2024-11-21 6.1 Medium
Improper neutralization of input during web page generation leaves the Eyes of Network web application vulnerable to cross-site scripting attacks at /module/admin_notifiers/rules.php and /module/report_event/indext.php via the parameters rule_notification, rule_name, and rule_name_old, and at /module/admin_user/add_modify_user.php via the parameters user_name and user_email.
CVE-2022-38357 1 Eyeofnetwork 1 Eyes Of Network Web 2024-11-21 8.8 High
Improper neutralization of special elements leaves the Eyes of Network Web application vulnerable to an iFrame injection attack, via the url parameter of /module/module_frame/index.php.
CVE-2022-38352 1 Thinkphp 1 Thinkphp 2024-11-21 9.8 Critical
ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
CVE-2022-38342 1 Safe 1 Fme Server 2024-11-21 8.5 High
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a XML External Entity (XXE) vulnerability which allows authenticated attackers to perform data exfiltration or Server-Side Request Forgery (SSRF) attacks.
CVE-2022-38341 1 Safe 1 Fme Server 2024-11-21 7.1 High
Safe Software FME Server v2021.2.5 and below does not employ server-side validation.
CVE-2022-38339 1 Safe 1 Fme Server 2024-11-21 9.6 Critical
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the login page.
CVE-2022-38334 1 Xpdfreader 1 Xpdf 2024-11-21 5.5 Medium
XPDF v4.04 and earlier was discovered to contain a stack overflow via the function Catalog::countPageTree() at Catalog.cc.
CVE-2022-38333 1 Openwrt 1 Openwrt 2024-11-21 7.5 High
Openwrt before v21.02.3 and Openwrt v22.03.0-rc6 were discovered to contain two skip loops in the function header_value(). This vulnerability allows attackers to access sensitive information via a crafted HTTP request.
CVE-2022-38326 1 Tendacn 4 Ac15, Ac15 Firmware, Ac18 and 1 more 2024-11-21 9.8 Critical
Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the page parameter at /goform/NatStaticSetting.
CVE-2022-38325 1 Tendacn 4 Ac15, Ac15 Firmware, Ac18 and 1 more 2024-11-21 9.8 Critical
Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the filePath parameter at /goform/expandDlnaFile.
CVE-2022-38323 1 Event Management System Project 1 Event Management System 2024-11-21 7.2 High
Event Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /Royal_Event/update_image.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-38314 1 Tenda 2 Ac18, Ac18 Firmware 2024-11-21 9.8 Critical
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /goform/saveParentControlInfo.
CVE-2022-38313 1 Tenda 2 Ac18, Ac18 Firmware 2024-11-21 9.8 Critical
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/saveParentControlInfo.
CVE-2022-38312 1 Tenda 2 Ac18, Ac18 Firmware 2024-11-21 9.8 Critical
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind.
CVE-2022-38311 1 Tenda 2 Ac18, Ac18 Firmware 2024-11-21 9.8 Critical
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/PowerSaveSet.
CVE-2022-38310 1 Tenda 2 Ac18, Ac18 Firmware 2024-11-21 9.8 Critical
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.
CVE-2022-38309 1 Tenda 2 Ac18, Ac18 Firmware 2024-11-21 9.8 Critical
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.
CVE-2022-38308 1 Totolink 2 A7000ru, A7000ru Firmware 2024-11-21 9.8 Critical
TOTOLink A700RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the lang parameter in the function cstesystem. This vulnerability allows attackers to execute arbitrary commands via a crafted payload.