Search Results (357535 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-30909 1 H3c 2 Magic R100, Magic R100 Firmware 2024-11-21 9.8 Critical
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the CMD parameter at /goform/aspForm.
CVE-2022-30903 1 Nokia 2 G-2425g-a, G-2425g-a Firmware 2024-11-21 4.8 Medium
Nokia "G-2425G-A" Bharti Airtel Routers Hardware version "3FE48299DEAA" Software Version "3FE49362IJHK42" is vulnerable to Cross-Site Scripting (XSS) via the admin->Maintenance>Device Management.
CVE-2022-30899 1 Partkeepr 1 Partkeepr 2024-11-21 4.8 Medium
A Cross Site Scripting vulnerabilty exists in PartKeepr 1.4.0 via the 'name' field in /api/part_categories.
CVE-2022-30898 1 Chshcms 1 Cscms 2024-11-21 6.5 Medium
A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password.
CVE-2022-30887 1 Pharmacy Management System Project 1 Pharmacy Management System 2024-11-21 9.8 Critical
Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.
CVE-2022-30886 1 School Dormitory Management System Project 1 School Dormitory Management System 2024-11-21 9.8 Critical
School Dormitory Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /dms/admin/reports/daily_collection_report.php.
CVE-2022-30885 1 Esa 1 Pyesasky 2024-11-21 9.8 Critical
The pyesasky for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2.0-1.4.2.
CVE-2022-30882 1 Pyanxdns Project 1 Pyanxdns 2024-11-21 9.8 Critical
pyanxdns package in PyPI version 0.2 is vulnerable to code execution backdoor. The impact is: execute arbitrary code (remote). When installing the pyanxdns package of version 0.2, the request package will be installed.
CVE-2022-30877 1 Keep Project 1 Keep 2024-11-21 9.8 Critical
The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2.
CVE-2022-30875 1 Dolibarr 1 Dolibarr Erp\/crm 2024-11-21 6.1 Medium
Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.
CVE-2022-30874 1 Nukeviet 1 Nukeviet 2024-11-21 5.4 Medium
There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02.
CVE-2022-30863 1 Fudforum 1 Fudforum 2024-11-21 4.8 Medium
FUDForum 3.1.2 is vulnerable to Cross Site Scripting (XSS) via page_title param in Page Manager in the Admin Control Panel.
CVE-2022-30861 1 Fudforum 1 Fudforum 2024-11-21 4.8 Medium
FUDforum 3.1.2 is vulnerable to Stored XSS via Forum Name field in Forum Manager Feature.
CVE-2022-30860 1 Fudforum 1 Fudforum 2024-11-21 7.2 High
FUDforum 3.1.2 is vulnerable to Remote Code Execution through Upload File feature of File Administration System in Admin Control Panel.
CVE-2022-30858 1 Miniupnp Project 1 Ngiflib 2024-11-21 6.5 Medium
An issue was discovered in ngiflib 0.4. There is SEGV in SDL_LoadAnimatedGif when use SDLaffgif. poc : ./SDLaffgif CA_file2_0
CVE-2022-30852 1 Withknown 1 Known 2024-11-21 4.3 Medium
Known v1.3.1 was discovered to contain an Insecure Direct Object Reference (IDOR).
CVE-2022-30843 1 Room Rent Portal Site Project 1 Room Rent Portal Site 2024-11-21 8.8 High
Room-rent-portal-site v1.0 is vulnerable to SQL Injection via /rrps/classes/Master.php?f=delete_category, id.
CVE-2022-30842 1 Covid 19 Travel Pass Management System Project 1 Covid 19 Travel Pass Management System 2024-11-21 5.4 Medium
Covid-19 Travel Pass Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /ctpms/classes/Users.php?f=save, firstname.
CVE-2022-30839 1 Room Rent Portal Site Project 1 Room Rent Portal Site 2024-11-21 6.1 Medium
Room-rent-portal-site v1.0 is vulnerable to Cross Site Scripting (XSS) via /rrps/classes/Master.php?f=save_category, vehicle_name.
CVE-2022-30838 1 Covid 19 Travel Pass Management System Project 1 Covid 19 Travel Pass Management System 2024-11-21 9.8 Critical
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=update_application_status