Search Results (357410 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-30387 1 Merchandise Online Store Project 1 Merchandise Online Store 2024-11-21 9.8 Critical
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=pay_order.
CVE-2022-30386 1 Merchandise Online Store Project 1 Merchandise Online Store 2024-11-21 9.8 Critical
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_featured.
CVE-2022-30385 1 Merchandise Online Store Project 1 Merchandise Online Store 2024-11-21 9.8 Critical
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_order.
CVE-2022-30384 1 Merchandise Online Store Project 1 Merchandise Online Store 2024-11-21 9.8 Critical
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_inventory.
CVE-2022-30381 1 Merchandise Online Store Project 1 Merchandise Online Store 2024-11-21 6.5 Medium
Merchandise Online Store v1.0 is vulnerable to file deletion via /vloggers_merch/classes/Master.php?f=delete_img.
CVE-2022-30379 1 Simple Social Networking Site Project 1 Simple Social Networking Site 2024-11-21 7.2 High
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=user/manage_user&id=.
CVE-2022-30378 1 Simple Social Networking Site Project 1 Simple Social Networking Site 2024-11-21 7.2 High
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=posts/view_post&id=.
CVE-2022-30376 1 Simple Social Networking Site Project 1 Simple Social Networking Site 2024-11-21 7.2 High
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/members/view_member.php?id=.
CVE-2022-30375 1 Simple Social Networking Site Project 1 Simple Social Networking Site 2024-11-21 6.5 Medium
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to file deletion via /sns/classes/Master.php?f=delete_img.
CVE-2022-30374 1 Air Cargo Management System Project 1 Air Cargo Management System 2024-11-21 7.2 High
Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/?page=transactions/manage_transaction&id=.
CVE-2022-30373 1 Air Cargo Management System Project 1 Air Cargo Management System 2024-11-21 7.2 High
Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/cargo_types/manage_cargo_type.php?id=.
CVE-2022-30372 1 Air Cargo Management System Project 1 Air Cargo Management System 2024-11-21 7.2 High
Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo.
CVE-2022-30371 1 Air Cargo Management System Project 1 Air Cargo Management System 2024-11-21 7.2 High
Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/cargo_types/view_cargo_type.php?id=.
CVE-2022-30370 1 Air Cargo Management System Project 1 Air Cargo Management System 2024-11-21 9.8 Critical
Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo_type.
CVE-2022-30367 1 Air Cargo Management System Project 1 Air Cargo Management System 2024-11-21 6.5 Medium
Air Cargo Management System v1.0 is vulnerable to file deletion via /acms/classes/Master.php?f=delete_img.
CVE-2022-30352 1 Phpabook Project 1 Phpabook 2024-11-21 9.8 Critical
phpABook 0.9i is vulnerable to SQL Injection due to insufficient sanitization of user-supplied data in the "auth_user" parameter in index.php script.
CVE-2022-30349 1 Sscms 1 Siteserver Cms 2024-11-21 6.1 Medium
siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).
CVE-2022-30335 1 Wealth 1 Bonanza Wealth Management System 2024-11-21 9.8 Critical
Bonanza Wealth Management System (BWM) 7.3.2 allows SQL injection via the login form. Users who supply the application with a SQL injection payload in the User Name textbox could collect all passwords in encrypted format from the Microsoft SQL Server component.
CVE-2022-30334 1 Brave 1 Brave 2024-11-21 5.3 Medium
Brave before 1.34, when a Private Window with Tor Connectivity is used, leaks .onion URLs in Referer and Origin headers. NOTE: although this was fixed by Brave, the Brave documentation still advises "Note that Private Windows with Tor Connectivity in Brave are just regular private windows that use Tor as a proxy. Brave does NOT implement most of the privacy protections from Tor Browser."
CVE-2022-30331 1 Tigergraph 1 Tigergraph 2024-11-21 8.8 High
The User-Defined Functions (UDF) feature in TigerGraph 3.6.0 allows installation of a query (in the GSQL query language) without proper validation. Consequently, an attacker can execute arbitrary C++ code. NOTE: the vendor's position is "GSQL was behaving as expected."