Search Results (372505 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-35151 1 Keking 1 Kkfileview 2024-11-21 6.1 Medium
kkFileView v4.1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the urls and currentUrl parameters at /controller/OnlinePreviewController.java.
CVE-2022-35150 1 Baijiacms Project 1 Baijiacms 2024-11-21 9.8 Critical
Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.
CVE-2022-35148 1 Maccms 1 Maccms 2024-11-21 6.5 Medium
maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html.
CVE-2022-35147 1 Html-js 1 Doracms 2024-11-21 9.8 Critical
DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request.
CVE-2022-35144 1 Raneto Project 1 Raneto 2024-11-21 4.8 Medium
Renato v0.17.0 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2022-35143 1 Raneto Project 1 Raneto 2024-11-21 9.8 Critical
Renato v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks.
CVE-2022-35142 1 Raneto Project 1 Raneto 2024-11-21 7.5 High
An issue in Renato v0.17.0 allows attackers to cause a Denial of Service (DoS) via a crafted payload injected into the Search parameter.
CVE-2022-35133 1 Cherrytree Project 1 Cherrytree 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in CherryTree v0.99.30 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field when creating a node.
CVE-2022-35131 1 Joplinapp 1 Joplin 2024-11-21 9.0 Critical
Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
CVE-2022-35122 1 Ecowitt 2 Gw1100, Gw1100 Firmware 2024-11-21 9.1 Critical
An access control issue in Ecowitt GW1100 Series Weather Stations <=GW1100B_v2.1.5 allows unauthenticated attackers to access sensitive information including device and local WiFi passwords.
CVE-2022-35121 1 Xxyopen 1 Novel-plus 2024-11-21 9.8 Critical
Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java.
CVE-2022-35118 1 Pyrocms 1 Pyrocms 2024-11-21 6.1 Medium
PyroCMS v3.9 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.
CVE-2022-35117 1 Oretnom23 1 Clinic\'s Patient Management System 2024-11-21 4.8 Medium
Clinic's Patient Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via update_medicine_details.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Packing text box under the Update Medical Details module.
CVE-2022-35115 1 Icewarp 1 Webclient Dc2 2024-11-21 9.8 Critical
IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /webmail/server/webmail.php.
CVE-2022-35114 1 Swftools 1 Swftools 2024-11-21 5.5 Medium
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via extractFrame at /readers/swf.c.
CVE-2022-35113 1 Swftools 1 Swftools 2024-11-21 5.5 Medium
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via swf_DefineLosslessBitsTagToImage at /modules/swfbits.c.
CVE-2022-35111 1 Swftools 1 Swftools 2024-11-21 5.5 Medium
SWFTools commit 772e55a2 was discovered to contain a stack overflow via __sanitizer::StackDepotNode::hash(__sanitizer::StackTrace const&) at /sanitizer_common/sanitizer_stackdepot.cpp.
CVE-2022-35110 1 Swftools 1 Swftools 2024-11-21 5.5 Medium
SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c.
CVE-2022-35109 1 Swftools 1 Swftools 2024-11-21 5.5 Medium
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via draw_stroke at /gfxpoly/stroke.c.
CVE-2022-35108 1 Swftools 1 Swftools 2024-11-21 5.5 Medium
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via DCTStream::getChar() at /xpdf/Stream.cc.