Search Results (369410 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-23358 1 Easycms 1 Easycms 2024-11-21 9.8 Critical
EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php. In the background, search terms provided by the user were not sanitized and were used directly to construct a SQL statement.
CVE-2022-23357 1 Mozilo 1 Mozilocms 2024-11-21 9.1 Critical
mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir.
CVE-2022-23352 1 Bigantsoft 1 Bigant Server 2024-11-21 7.5 High
An issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS).
CVE-2022-23350 1 Bigantsoft 1 Bigant Server 2024-11-21 5.4 Medium
BigAnt Software BigAnt Server v5.6.06 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2022-23349 1 Bigantsoft 1 Bigant Server 2024-11-21 8.8 High
BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF).
CVE-2022-23348 1 Bigantsoft 1 Bigant Server 2024-11-21 5.3 Medium
BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.
CVE-2022-23347 1 Bigantsoft 1 Bigant Server 2024-11-21 7.5 High
BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.
CVE-2022-23346 1 Bigantsoft 1 Bigant Server 2024-11-21 8.8 High
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.
CVE-2022-23345 1 Bigantsoft 1 Bigant Server 2024-11-21 7.5 High
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.
CVE-2022-23342 1 Hyland 1 Onbase 2024-11-21 5.3 Medium
The Hyland Onbase Application Server releases prior to 20.3.58.1000 and OnBase releases 21.1.1.1000 through 21.1.15.1000 are vulnerable to a username enumeration vulnerability. An attacker can obtain valid users based on the response returned for invalid and valid users by sending a POST login request to the /mobilebroker/ServiceToBroker.svc/Json/Connect endpoint. This can lead to user enumeration against the underlying Active Directory integrated systems.
CVE-2022-23340 1 Joplin Project 1 Joplin 2024-11-21 9.8 Critical
Joplin 2.6.10 allows remote attackers to execute system commands through malicious code in user search results.
CVE-2022-23337 1 Dedecms 1 Dedecms 2024-11-21 9.8 Critical
DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter.
CVE-2022-23336 1 S-cms 1 S-cms 2024-11-21 9.8 Critical
S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter.
CVE-2022-23335 1 Metinfo 1 Metinfo 2024-11-21 9.8 Critical
Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in language_general.class.php via doModifyParameter.
CVE-2022-23332 1 Ejointech 6 Acom508, Acom508 Firmware, Acom516 and 3 more 2024-11-21 8.8 High
Command injection vulnerability in Manual Ping Form (Web UI) in Shenzhen Ejoin Information Technology Co., Ltd. ACOM508/ACOM516/ACOM532 609-915-041-100-020 allows a remote attacker to inject arbitrary code via the field.
CVE-2022-23331 1 Dataease 1 Dataease 2024-11-21 8.8 High
In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the administrator password.
CVE-2022-23330 1 Jpress 1 Jpress 2024-11-21 8.8 High
A remote code execution (RCE) vulnerability in HelloWorldAddonController.java of jpress v4.2.0 allows attackers to execute arbitrary code via a crafted JAR package.
CVE-2022-23329 1 Ujcms 1 Jspxcms 2024-11-21 9.8 Critical
A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploading malicious files.
CVE-2022-23328 1 Ethereum 1 Go Ethereum 2024-11-21 7.5 High
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's memory pool and then occupy the memory pool to prevent new transactions from entering the pool, resulting in a denial of service (DoS).
CVE-2022-23327 1 Ethereum 1 Go Ethereum 2024-11-21 7.5 High
A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a denial of service (DoS).