Search Results (357844 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-34611 1 Online Fire Reporting System Project 1 Online Fire Reporting System 2024-11-21 5.4 Medium
A cross-site scripting (XSS) vulnerability in /index.php/?p=report of Online Fire Reporting System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "Contac #" text field.
CVE-2022-34610 1 H3c 2 Magic R200, Magic R200 Firmware 2024-11-21 9.8 Critical
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the URL /ihomers/app.
CVE-2022-34609 1 H3c 2 Magic R200, Magic R200 Firmware 2024-11-21 9.8 Critical
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the INTF parameter at /doping.asp.
CVE-2022-34608 1 H3c 2 Magic R200, Magic R200 Firmware 2024-11-21 9.8 Critical
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the ajaxmsg parameter at /AJAX/ajaxget.
CVE-2022-34607 1 H3c 2 Magic R200, Magic R200 Firmware 2024-11-21 9.8 Critical
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the HOST parameter at /doping.asp.
CVE-2022-34606 1 H3c 2 Magic R200, Magic R200 Firmware 2024-11-21 9.8 Critical
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EditvsList parameter at /dotrace.asp.
CVE-2022-34605 1 H3c 2 Magic R200, Magic R200 Firmware 2024-11-21 9.8 Critical
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the HOST parameter at /dotrace.asp.
CVE-2022-34604 1 H3c 2 Magic R200, Magic R200 Firmware 2024-11-21 9.8 Critical
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the INTF parameter at /dotrace.asp.
CVE-2022-34603 1 H3c 2 Magic R200, Magic R200 Firmware 2024-11-21 9.8 Critical
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the DelDNSHnList interface at /goform/aspForm.
CVE-2022-34602 1 H3c 2 Magic R200, Magic R200 Firmware 2024-11-21 9.8 Critical
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the ipqos_lanip_editlist interface at /goform/aspForm.
CVE-2022-34601 1 H3c 2 Magic R200, Magic R200 Firmware 2024-11-21 9.8 Critical
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the Delstlist interface at /goform/aspForm.
CVE-2022-34600 1 H3c 2 Magic R200, Magic R200 Firmware 2024-11-21 9.8 Critical
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EditSTList interface at /goform/aspForm.
CVE-2022-34599 1 H3c 2 Magic R200, Magic R200 Firmware 2024-11-21 9.8 Critical
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EdittriggerList interface at /goform/aspForm.
CVE-2022-34598 1 H3c 2 Magic R100, Magic R100 Firmware 2024-11-21 9.8 Critical
The udpserver in H3C Magic R100 V200R004 and V100R005 has the 9034 port opened, allowing attackers to execute arbitrary commands.
CVE-2022-34597 1 Tenda 2 Ax1806, Ax1806 Firmware 2024-11-21 9.8 Critical
Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability via the function WanParameterSetting.
CVE-2022-34596 1 Tenda 2 Ax1803, Ax1803 Firmware 2024-11-21 9.8 Critical
Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function WanParameterSetting.
CVE-2022-34595 1 Tenda 2 Ax1803, Ax1803 Firmware 2024-11-21 9.8 Critical
Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function setipv6status.
CVE-2022-34594 1 Advanced School Management System Project 1 Advanced School Management System 2024-11-21 4.8 Medium
Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component ip/school/moudel/update_subject.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit Subject text field.
CVE-2022-34593 1 Dptech 1 Dptech Vpn 2024-11-21 7.5 High
DPTech VPN v8.1.28.0 was discovered to contain an arbitrary file read vulnerability.
CVE-2022-34592 1 Wavlink 2 Wl-wn575a3, Wl-wn575a3 Firmware 2024-11-21 9.8 Critical
Wavlink WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability via the function obtw. This vulnerability allows attackers to execute arbitrary commands via a crafted POST request.