Search Results (361192 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-36609 1 Oretnom23 1 Clinic\'s Patient Management System 2024-11-21 9.8 Critical
Clinic's Patient Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pms/update_patient.php.
CVE-2022-36606 1 Yimihome 1 Ywoa 2024-11-21 9.8 Critical
Ywoa before v6.1 was discovered to contain a SQL injection vulnerability via /oa/setup/checkPool?database.
CVE-2022-36605 1 Yimihome 1 Ywoa 2024-11-21 9.8 Critical
Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter.
CVE-2022-36604 1 Canaan 2 Avalon Asic Miner, Avalon Asic Miner Firmware 2024-11-21 7.5 High
An access control issue in Canaan Avalon ASIC Miner 2020.3.30 and below allows unauthenticated attackers to arbitrarily change user passwords via a crafted POST request.
CVE-2022-36603 1 Innosilicon 2 T3t\+, T3t\+ Firmware 2024-11-21 8.8 High
InnoSilicon T3T+ t2t+_soc_20190911_151433.swu was discovered to contain a remote code execution (RCE) vulnerability in the checkUrl function.
CVE-2022-36602 1 Innosilicon 2 A10, A10 Firmware 2024-11-21 8.8 High
InnoSilicon A10 a10_20200924_120556 was discovered to contain a remote code execution (RCE) vulnerability in the setPlatformAPI function.
CVE-2022-36601 1 Jinglemining 2 Jasminer X4 Server, Jasminer X4 Server Firmware 2024-11-21 9.8 Critical
The Eclipse TCF debug interface in JasMiner-X4-Server-20220621-090907 and below is open on port 1534. This issue allows unauthenticated attackers to gain root privileges on the affected device and access sensitive data or execute arbitrary commands.
CVE-2022-36600 1 Blogengine 1 Blogengine.net 2024-11-21 4.8 Medium
BlogEngine v3.3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blogengine/api/posts. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.
CVE-2022-36599 1 Mingsoft 1 Mcms 2024-11-21 9.8 Critical
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.
CVE-2022-36594 1 Mybatis 1 Mapper 2024-11-21 9.8 Critical
Mapper v4.0.0 to v4.2.0 was discovered to contain a SQL injection vulnerability via the ids parameter at the selectByIds function.
CVE-2022-36593 1 Keking 1 Kkfileview 2024-11-21 6.5 Medium
kkFileView v4.0.0 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter at /controller/FileController.java.
CVE-2022-36588 1 Dlink 2 Dap-1650, Dap-1650 Firmware 2024-11-21 9.8 Critical
In D-Link DAP1650 v1.04 firmware, the fileaccess.cgi program in the firmware has a buffer overflow vulnerability caused by strncpy.
CVE-2022-36586 1 Tenda 2 G3, G3 Firmware 2024-11-21 9.8 Critical
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by strcpy in function 0x869f4 in the httpd binary.
CVE-2022-36585 1 Tenda 2 G3, G3 Firmware 2024-11-21 9.8 Critical
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, in httpd binary, the addDhcpRule function has a buffer overflow caused by sscanf.
CVE-2022-36584 1 Tenda 2 G3, G3 Firmware 2024-11-21 9.8 Critical
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, the getsinglepppuser function has a buffer overflow caused by sscanf.
CVE-2022-36583 1 Dedecms 1 Dedecms 2024-11-21 6.1 Medium
DedeCMS V5.7.97 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/co_do.php via the dopost, rpok, and aid parameters.
CVE-2022-36582 1 Garage Management System Project 1 Garage Management System 2024-11-21 7.2 High
An arbitrary file upload vulnerability in the component /php_action/createProduct.php of Garage Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-36581 1 Online Ordering System Project 1 Online Ordering System 2024-11-21 7.5 High
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /admin/login.php.
CVE-2022-36580 1 Online Ordering System Project 1 Online Ordering System 2024-11-21 7.2 High
An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering System v2.3.2 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-36579 1 Wellcms 1 Wellcms 2024-11-21 8.8 High
Wellcms 2.2.0 is vulnerable to Cross Site Request Forgery (CSRF).