Search Results (356046 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-37128 1 Dlink 2 Dir-816, Dir-816 Firmware 2024-11-21 9.8 Critical
In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.
CVE-2022-37125 1 Dlink 2 Dir-816, Dir-816 Firmware 2024-11-21 9.8 Critical
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.
CVE-2022-37123 1 Dlink 2 Dir-816, Dir-816 Firmware 2024-11-21 8.8 High
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi.
CVE-2022-37122 1 Carel 4 Applica, Pcoweb Card, Pcoweb Card Firmware and 1 more 2024-11-21 7.5 High
Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' GET parameter through the 'logdownload.cgi' Bash script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks.
CVE-2022-37113 1 Bluecms Project 1 Bluecms 2024-11-21 9.8 Critical
Bluecms 1.6 has SQL injection in line 132 of admin/area.php
CVE-2022-37112 1 Bluecms Project 1 Bluecms 2024-11-21 9.8 Critical
BlueCMS 1.6 has SQL injection in line 55 of admin/model.php
CVE-2022-37111 1 Bluecms Project 1 Bluecms 2024-11-21 9.8 Critical
BlueCMS 1.6 has SQL injection in line 132 of admin/article.php
CVE-2022-37108 1 Securonix 1 Snypr 2024-11-21 8.7 High
An injection vulnerability in the syslog-ng configuration wizard in Securonix Snypr 6.4 allows an application user with the "Manage Ingesters" permission to execute arbitrary code on remote ingesters by appending arbitrary text to text files that are executed by the system, such as users' crontab files. The patch for this was present in SNYPR version 6.4 Jun 2022 R3_[06170871], but may have been introduced sooner.
CVE-2022-37100 1 H3c 2 H200, H200 Firmware 2024-11-21 9.8 Critical
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateMacClone.
CVE-2022-37099 1 H3c 2 H200, H200 Firmware 2024-11-21 9.8 Critical
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateSnat.
CVE-2022-37098 1 H3c 2 H200, H200 Firmware 2024-11-21 9.8 Critical
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateIpv6Params.
CVE-2022-37097 1 H3c 2 H200, H200 Firmware 2024-11-21 9.8 Critical
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetAPInfoById.
CVE-2022-37096 1 H3c 2 H200, H200 Firmware 2024-11-21 9.8 Critical
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EnableIpv6.
CVE-2022-37095 1 H3c 2 H200, H200 Firmware 2024-11-21 9.8 Critical
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateWanParams.
CVE-2022-37094 1 H3c 2 H200, H200 Firmware 2024-11-21 9.8 Critical
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function Edit_BasicSSID_5G.
CVE-2022-37093 1 H3c 2 H200, H200 Firmware 2024-11-21 9.8 Critical
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function AddMacList.
CVE-2022-37092 1 H3c 2 H200, H200 Firmware 2024-11-21 9.8 Critical
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetAPWifiorLedInfoById.
CVE-2022-37091 1 H3c 2 H200, H200 Firmware 2024-11-21 9.8 Critical
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EditWlanMacList.
CVE-2022-37090 1 H3c 2 H200, H200 Firmware 2024-11-21 9.8 Critical
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function Edit_BasicSSID.
CVE-2022-37089 1 H3c 2 H200, H200 Firmware 2024-11-21 9.8 Critical
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EditMacList.