Search Results (361553 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-35168 1 Sap 1 Business One 2024-11-21 7.5 High
Due to improper input sanitization of XML input in SAP Business One - version 10.0, an attacker can perform a denial-of-service attack rendering the system temporarily inoperative.
CVE-2022-35167 1 Prinitix 1 Cloud Print Management 2024-11-21 8.8 High
Printix Cloud Print Management v1.3.1149.0 for Windows was discovered to contain insecure permissions.
CVE-2022-35166 1 Jpeg 1 Libjpeg 2024-11-21 5.5 Medium
libjpeg commit 842c7ba was discovered to contain an infinite loop via the component JPEG::ReadInternal.
CVE-2022-35165 1 Axiosys 1 Bento4 2024-11-21 5.5 Medium
An issue in AP4_SgpdAtom::AP4_SgpdAtom() of Bento4-1.6.0-639 allows attackers to cause a Denial of Service (DoS) via a crafted mp4 input.
CVE-2022-35164 1 Gnu 1 Libredwg 2024-11-21 9.8 Critical
LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via bit_copy_chain.
CVE-2022-35163 1 Complete Online Job Search System Project 1 Complete Online Job Search System 2024-11-21 4.8 Medium
Complete Online Job Search System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the U_NAME parameter at /category/controller.php?action=edit.
CVE-2022-35162 1 Complete Online Job Search System Project 1 Complete Online Job Search System 2024-11-21 4.8 Medium
Complete Online Job Search System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the CATEGORY parameter at /category/controller.php?action=edit.
CVE-2022-35161 1 Generalized Electric Vehicle Reverse Engineering Tool Project 1 Generalized Electric Vehicle Reverse Engineering Tool 2024-11-21 9.8 Critical
GVRET Stable Release as of Aug 15, 2015 was discovered to contain a buffer overflow via the handleConfigCmd function at SerialConsole.cpp.
CVE-2022-35158 1 Tencent 1 Tscancode 2024-11-21 7.5 High
A vulnerability in the lua parser of TscanCode tsclua v2.15.01 allows attackers to cause a Denial of Service (DoS) via a crafted lua script.
CVE-2022-35154 1 Shopro 1 Mall System 2024-11-21 9.8 Critical
Shopro Mall System v1.3.8 was discovered to contain a SQL injection vulnerability via the value parameter.
CVE-2022-35153 1 Fusionpbx 1 Fusionpbx 2024-11-21 9.8 Critical
FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.
CVE-2022-35151 1 Keking 1 Kkfileview 2024-11-21 6.1 Medium
kkFileView v4.1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the urls and currentUrl parameters at /controller/OnlinePreviewController.java.
CVE-2022-35150 1 Baijiacms Project 1 Baijiacms 2024-11-21 9.8 Critical
Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.
CVE-2022-35148 1 Maccms 1 Maccms 2024-11-21 6.5 Medium
maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html.
CVE-2022-35147 1 Html-js 1 Doracms 2024-11-21 9.8 Critical
DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request.
CVE-2022-35144 1 Raneto Project 1 Raneto 2024-11-21 4.8 Medium
Renato v0.17.0 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2022-35143 1 Raneto Project 1 Raneto 2024-11-21 9.8 Critical
Renato v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks.
CVE-2022-35142 1 Raneto Project 1 Raneto 2024-11-21 7.5 High
An issue in Renato v0.17.0 allows attackers to cause a Denial of Service (DoS) via a crafted payload injected into the Search parameter.
CVE-2022-35133 1 Cherrytree Project 1 Cherrytree 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in CherryTree v0.99.30 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field when creating a node.
CVE-2022-35131 1 Joplinapp 1 Joplin 2024-11-21 9.0 Critical
Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.