Search Results (361193 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-36579 1 Wellcms 1 Wellcms 2024-11-21 8.8 High
Wellcms 2.2.0 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2022-36578 1 Jizhicms 1 Jizhicms 2024-11-21 9.8 Critical
jizhicms v2.3.1 has SQL injection in the background.
CVE-2022-36577 1 Jizhicms 1 Jizhicms 2024-11-21 8.8 High
An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin.
CVE-2022-36573 1 Pagekit 1 Pagekit 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in Pagekit CMS v1.0.18 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Markdown text box under /blog/post/edit.
CVE-2022-36572 1 Sinsiu 1 Enterprise Website System 2024-11-21 9.8 Critical
Sinsiu Sinsiu Enterprise Website System v1.1.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /upload/admin.php?/deal/.
CVE-2022-36571 1 Tenda 2 Ac9, Ac9 Firmware 2024-11-21 7.2 High
Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the mask parameter at /goform/WanParameterSetting.
CVE-2022-36570 1 Tenda 2 Ac9, Ac9 Firmware 2024-11-21 7.2 High
Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the time parameter at /goform/SetLEDCfg.
CVE-2022-36569 1 Tenda 2 Ac9, Ac9 Firmware 2024-11-21 8.8 High
Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCfg.
CVE-2022-36568 1 Tenda 2 Ac9, Ac9 Firmware 2024-11-21 8.8 High
Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the list parameter at /goform/setPptpUserList.
CVE-2022-36566 1 Yogeshojha 1 Rengine 2024-11-21 9.8 Critical
Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function.
CVE-2022-36565 1 Wampserver 1 Wampserver 2024-11-21 8.8 High
Incorrect access control in the install directory (C:\Wamp64) of Wamp v3.2.6 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.
CVE-2022-36564 2 Microsoft, Strawberryperl 2 Windows, Strawberryperl 2024-11-21 8.8 High
Incorrect access control in the install directory (C:\Strawberry) of StrawberryPerl v5.32.1.1 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.
CVE-2022-36563 1 Rubyinstaller 1 Rubyinstaller2 2024-11-21 8.8 High
Incorrect access control in the install directory (C:\RailsInstaller) of Rubyinstaller2 v3.1.2 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.
CVE-2022-36562 1 Rubyinstaller 1 Rubyinstaller2 2024-11-21 8.8 High
Incorrect access control in the install directory (C:\Ruby31-x64) of Rubyinstaller2 v3.1.2 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.
CVE-2022-36561 1 Xpdfreader 1 Xpdf 2024-11-21 5.5 Medium
XPDF v4.0.4 was discovered to contain a segmentation violation via the component /xpdf/AcroForm.cc:538.
CVE-2022-36560 1 Seiko-sol 2 Skybridge Mb-a200, Skybridge Mb-a200 Firmware 2024-11-21 9.8 Critical
Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers are able to access the passcodes at /etc/srapi/config/system.conf and /usr/sbin/ssol-sshd.sh.
CVE-2022-36559 1 Seiko-sol 2 Skybridge Mb-a200, Skybridge Mb-a200 Firmware 2024-11-21 9.8 Critical
Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi.
CVE-2022-36558 1 Seiko-sol 4 Skybridge Mb-a100, Skybridge Mb-a100 Firmware, Skybridge Mb-a110 and 1 more 2024-11-21 9.8 Critical
Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able to access the passcord via the file /etc/ciel.cfg.
CVE-2022-36557 1 Seiko-sol 4 Skybridge Mb-a100, Skybridge Mb-a100 Firmware, Skybridge Mb-a110 and 1 more 2024-11-21 9.8 Critical
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers to execute arbitrary code via a crafted html file.
CVE-2022-36556 1 Seiko-sol 4 Skybridge Mb-a100, Skybridge Mb-a100 Firmware, Skybridge Mb-a110 and 1 more 2024-11-21 9.8 Critical
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08execute_ping_01.