Search Results (359539 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-36242 1 Oretnom23 1 Clinic\'s Patient Management System 2024-11-21 9.8 Critical
Clinic's Patient Management System v1.0 is vulnerable to SQL Injection via /pms/update_medicine.php?id=.
CVE-2022-36234 1 Simplenetwork Project 1 Simplenetwork 2024-11-21 7.5 High
SimpleNetwork TCP Server commit 29bc615f0d9910eb2f59aa8dff1f54f0e3af4496 was discovered to contain a double free vulnerability which is exploited via crafted TCP packets.
CVE-2022-36233 1 Tendacn 2 Ac9, Ac9 Firmware 2024-11-21 5.5 Medium
Tenda AC9 V15.03.2.13 is vulnerable to Buffer Overflow via httpd, form_fast_setting_wifi_set. httpd.
CVE-2022-36228 1 Janusintl 6 Noke Hd\+ Smart Padlock, Noke Hd\+ Smart Padlock Firmware, Noke Hd Smart Padlock and 3 more 2024-11-21 7.3 High
Nokelock Smart padlock O1 Version 5.3.0 is vulnerable to Insecure Permissions. By sending a request, you can add any device and set the device password in the Nokelock app.
CVE-2022-36226 1 Siteservercms Project 1 Siteservercms 2024-11-21 7.2 High
SiteServerCMS 5.X has a Remote-download-Getshell-vulnerability via /SiteServer/Ajax/ajaxOtherService.aspx.
CVE-2022-36225 1 Eyoucms 1 Eyoucms 2024-11-21 8.8 High
EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.
CVE-2022-36224 1 Xunruicms 1 Xunruicms 2024-11-21 8.8 High
XunRuiCMS V4.5.6 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2022-36220 1 Ethz 1 Safe Exam Browser 2024-11-21 9.8 Critical
Kiosk breakout (without quit password) in Safe Exam Browser (Windows) <3.4.0, which allows an attacker to achieve code execution via the browsers' print dialog.
CVE-2022-36216 1 Dedecms 1 Dedecms 2024-11-21 7.2 High
DedeCMS v5.7.94 - v5.7.97 was discovered to contain a remote code execution vulnerability in member_toadmin.php.
CVE-2022-36215 1 Dedebiz 1 Dedecmsv6 2024-11-21 7.2 High
DedeBIZ v6 was discovered to contain a remote code execution vulnerability in sys_info.php.
CVE-2022-36203 1 Doctor\'s Appointment System Project 1 Doctor\'s Appointment System 2024-11-21 6.1 Medium
Doctor's Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) via the admin panel. In addition, it leads to takeover the administrator account by stealing the cookie via XSS.
CVE-2022-36202 1 Doctor\'s Appointment System Project 1 Doctor\'s Appointment System 2024-11-21 9.8 Critical
Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter.
CVE-2022-36201 1 Doctor\'s Appointment System Project 1 Doctor\'s Appointment System 2024-11-21 9.8 Critical
Doctor’s Appointment System v1.0 is vulnerable to Blind SQLi via settings.php.
CVE-2022-36200 1 Fiberhome 2 Hg150-ub, Hg150-ub Firmware 2024-11-21 7.5 High
In FiberHome VDSL2 Modem HG150-Ub_V3.0, Credentials of Admin are submitted in URL, which can be logged/sniffed.
CVE-2022-36198 1 Phpgurukul 1 Bus Pass Management System 2024-11-21 9.8 Critical
Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin/pass-bwdates-reports-details.php, buspassms/admin/changeimage.php, buspassms/admin/search-pass.php, buspassms/admin/edit-category-detail.php, and buspassms/admin/edit-pass-detail.php
CVE-2022-36197 1 Bigtreecms 1 Bigtree Cms 2024-11-21 5.4 Medium
BigTree CMS 4.4.16 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PDF file.
CVE-2022-36194 1 Centreon 1 Centreon 2024-11-21 5.4 Medium
Centreon 22.04.0 is vulnerable to Cross Site Scripting (XSS) from the function Pollers > Broker Configuration by adding a crafted payload into the name parameter.
CVE-2022-36191 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
A heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isomedia/avc_ext.c:2490, as demonstrated by MP4Box. This vulnerability was fixed in commit fef6242.
CVE-2022-36190 1 Gpac 1 Gpac 2024-11-21 9.8 Critical
GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function gf_isom_dovi_config_get. This vulnerability was fixed in commit fef6242.
CVE-2022-36186 1 Gpac 1 Gpac 2024-11-21 7.5 High
A Null Pointer dereference vulnerability exists in GPAC 2.1-DEV-revUNKNOWN-master via the function gf_filter_pid_set_property_full () at filter_core/filter_pid.c:5250,which causes a Denial of Service (DoS). This vulnerability was fixed in commit b43f9d1.