Search Results (357812 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-32425 1 Mealie 1 Mealie 2024-11-21 5.3 Medium
The login function of Mealie v1.0.0beta-2 allows attackers to enumerate existing usernames by timing the server's response time.
CVE-2022-32420 1 College Management System Project 1 College Management System 2024-11-21 8.8 High
College Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /College/admin/teacher.php. This vulnerability is exploited via a crafted PHP file.
CVE-2022-32417 1 Pbootcms 1 Pbootcms 2024-11-21 9.8 Critical
PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.
CVE-2022-32416 1 Product Show Room Site Project 1 Product Show Room Site 2024-11-21 7.2 High
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_product.
CVE-2022-32415 1 Product Show Room Site Project 1 Product Show Room Site 2024-11-21 8.8 High
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/?p=products/view_product&id=.
CVE-2022-32414 1 F5 1 Njs 2024-11-21 5.5 Medium
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_vmcode_interpreter at src/njs_vmcode.c.
CVE-2022-32413 1 Dice Project 1 Dice 2024-11-21 9.8 Critical
An arbitrary file upload vulnerability in Dice v4.2.0 allows attackers to execute arbitrary code via a crafted file.
CVE-2022-32412 1 Hongcms Project 1 Hongcms 2024-11-21 7.2 High
An issue in the /template/edit component of HongCMS v3.0 allows attackers to getshell.
CVE-2022-32411 1 Hongcms Project 1 Hongcms 2024-11-21 7.2 High
An issue in the languages config file of HongCMS v3.0 allows attackers to getshell.
CVE-2022-32409 1 Softwarepublico 1 I3geo 2024-11-21 9.8 Critical
A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to execute arbitrary PHP code via a crafted HTTP request.
CVE-2022-32406 1 Gtkradiant Project 1 Gtkradiant 2024-11-21 5.5 Medium
GtkRadiant v1.6.6 was discovered to contain a buffer overflow via the component q3map2. This vulnerability can cause a Denial of Service (DoS) via a crafted MAP file.
CVE-2022-32405 1 Prison Management System Project 1 Prison Management System 2024-11-21 8.8 High
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/view_prison.php:4
CVE-2022-32404 1 Prison Management System Project 1 Prison Management System 2024-11-21 8.8 High
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_inmate.php:3
CVE-2022-32403 1 Prison Management System Project 1 Prison Management System 2024-11-21 8.8 High
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_record.php:4
CVE-2022-32402 1 Prison Management System Project 1 Prison Management System 2024-11-21 8.8 High
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/manage_prison.php:4
CVE-2022-32401 1 Prison Management System Project 1 Prison Management System 2024-11-21 8.8 High
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_privilege.php:4
CVE-2022-32400 1 Prison Management System Project 1 Prison Management System 2024-11-21 7.2 High
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/user/manage_user.php:4.
CVE-2022-32399 1 Prison Management System Project 1 Prison Management System 2024-11-21 8.8 High
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/view_crime.php:4
CVE-2022-32398 1 Prison Management System Project 1 Prison Management System 2024-11-21 8.8 High
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/manage_cell.php:4
CVE-2022-32397 1 Prison Management System Project 1 Prison Management System 2024-11-21 8.8 High
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/view_visit.php:4