Search Results (359350 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-23906 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 7.2 High
CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. This vulnerability is exploited via a crafted image file.
CVE-2022-23904 1 Rainworx 1 Auctionworx 2024-11-21 8.0 High
Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack that allows an authenticated user to upgrade his account to admin and gain access to the auctionworx admin control panel. This vulnerability affects AuctionWorx Enterprise and AuctionWorx: Events Edition.
CVE-2022-23903 1 Pearadmin 1 Pear Admin Think 2024-11-21 5.4 Medium
A Cross Site Scripting (XSS) vulnerability exists in pearadmin pear-admin-think <=5.0.6, which allows a login account to access arbitrary functions and cause stored XSS through a fake User-Agent.
CVE-2022-23902 1 Tongda2000 1 Tongda Office Anywhere 2024-11-21 9.8 Critical
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in export_data.php via the d_name parameter.
CVE-2022-23901 1 Re2c 1 Re2c 2024-11-21 9.8 Critical
A stack overflow re2c 2.2 exists due to infinite recursion issues in src/dfa/dead_rules.cc.
CVE-2022-23900 1 Wavlink 2 Wl-wn531p3, Wl-wn531p3 Firmware 2024-11-21 9.8 Critical
A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve unauthorized remote code execution via a malicious POST request through /cgi-bin/adm.cgi.
CVE-2022-23899 1 Mingsoft 1 Mcms 2024-11-21 9.8 Critical
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java.
CVE-2022-23898 1 Mingsoft 1 Mcms 2024-11-21 9.8 Critical
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.
CVE-2022-23896 1 Admidio 1 Admidio 2024-11-21 5.4 Medium
Admidio 4.1.2 version is affected by stored cross-site scripting (XSS).
CVE-2022-23889 1 Yzmcms 1 Yzmcms 2024-11-21 5.3 Medium
The comment function in YzmCMS v6.3 was discovered as being able to be operated concurrently, allowing attackers to create an unusually large number of comments.
CVE-2022-23888 1 Yzmcms 1 Yzmcms 2024-11-21 8.8 High
YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.html.
CVE-2022-23887 1 Yzmcms 1 Yzmcms 2024-11-21 6.5 Medium
YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete user accounts via /admin/admin_manage/delete.
CVE-2022-23884 1 Minecraft 1 Bedrock Server 2024-11-21 9.8 Critical
Mojang Bedrock Dedicated Server 1.18.2 is affected by an integer overflow leading to a bound check bypass caused by PurchaseReceiptPacket::_read (packet deserializer).
CVE-2022-23882 1 Tuzicms 1 Tuzicms 2024-11-21 9.8 Critical
TuziCMS 2.0.6 is affected by SQL injection in \App\Manage\Controller\BannerController.class.php.
CVE-2022-23881 1 Zzzcms 1 Zzzphp 2024-11-21 9.8 Critical
ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.
CVE-2022-23880 1 Taogogo 1 Taocms 2024-11-21 9.8 Critical
An arbitrary file upload vulnerability in the File Management function module of taoCMS v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-23878 1 Seacms 1 Seacms 2024-11-21 9.8 Critical
seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.
CVE-2022-23873 1 Victor Cms Project 1 Victor Cms 2024-11-21 8.8 High
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary commands via 'user_firstname' parameter.
CVE-2022-23872 1 Emlog 1 Emlog 2024-11-21 4.8 Medium
Emlog pro v1.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /admin/configure.php via the parameter footer_info.
CVE-2022-23871 1 Gibbonedu 1 Gibbon 2024-11-21 5.4 Medium
Multiple cross-site scripting (XSS) vulnerabilities in the component outcomes_addProcess.php of Gibbon CMS v22.0.01 allow attackers to execute arbitrary web scripts or HTML via a crafted payload insterted into the name, category, description parameters.