Search Results (374604 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-26655 1 Pexip 1 Pexip Infinity 2024-11-21 7.5 High
Pexip Infinity 27.x before 27.3 has Improper Input Validation. The client API allows remote attackers to trigger a software abort via a gateway call into Teams.
CVE-2022-26654 1 Pexip 1 Pexip Infinity 2024-11-21 7.5 High
Pexip Infinity before 27.3 allows remote attackers to force a software abort via HTTP.
CVE-2022-26653 1 Zohocorp 1 Manageengine Remote Access Plus 2024-11-21 5.3 Medium
Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator).
CVE-2022-26651 2 Debian, Digium 3 Debian Linux, Asterisk, Certified Asterisk 2024-11-21 9.8 Critical
An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escaping functionality for backslash characters in SQL queries, resulting in user-provided data creating a broken SQL query or possibly a SQL injection. This is fixed in 16.25.2, 18.11.2, and 19.3.2, and 16.8-cert14.
CVE-2022-26650 1 Apache 1 Shenyu 2024-11-21 7.5 High
In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular expressions and characters causing a resource exhaustion. This issue affects Apache ShenYu (incubating) 2.4.0, 2.4.1 and 2.4.2 and is fixed in 2.4.3.
CVE-2022-26643 1 Johnsoncontrols 1 Easyio Cpt Graphics 2024-11-21 5.3 Medium
An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application.
CVE-2022-26642 1 Tp-link 2 Tl-wr840n, Tl-wr840n Firmware 2024-11-21 7.2 High
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the X_TP_ClonedMACAddress parameter.
CVE-2022-26641 1 Tp-link 2 Tl-wr840n, Tl-wr840n Firmware 2024-11-21 7.2 High
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the httpRemotePort parameter.
CVE-2022-26640 1 Tp-link 2 Tl-wr840n, Tl-wr840n Firmware 2024-11-21 7.2 High
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the minAddress parameter.
CVE-2022-26639 1 Tp-link 2 Tl-wr840n, Tl-wr840n Firmware 2024-11-21 7.2 High
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the DNSServers parameter.
CVE-2022-26635 1 Php 1 Memcached 2024-11-21 9.8 Critical
PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. Note: Third parties have disputed this as not affecting PHP-Memcached directly.
CVE-2022-26634 1 Hma 1 Hidemyass 2024-11-21 7.8 High
HMA VPN v5.3.5913.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
CVE-2022-26633 1 Simple Student Quarterly Result\/grade System Project 1 Simple Student Quarterly Result\/grade System 2024-11-21 9.8 Critical
Simple Student Quarterly Result/Grade System v1.0 was discovered to contain a SQL injection vulnerability via /sqgs/Actions.php.
CVE-2022-26632 1 Multi-vendor Online Groceries Management System Project 1 Multi-vendor Online Groceries Management System 2024-11-21 9.8 Critical
Multi-Vendor Online Groceries Management System v1.0 was discovered to contain a blind SQL injection vulnerability via the id parameter in /products/view_product.php.
CVE-2022-26631 1 Automatic Question Paper Generator Project 1 Automatic Question Paper Generator 2024-11-21 9.8 Critical
Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter.
CVE-2022-26630 1 Jellycms 1 Jellycms 2024-11-21 8.8 High
Jellycms v3.8.1 and below was discovered to contain an arbitrary file upload vulnerability via \app.\admin\Controllers\db.php.
CVE-2022-26629 3 Linux, Microsoft, Splus 3 Linux Kernel, Windows, Soroushplus 2024-11-21 9.1 Critical
An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function.
CVE-2022-26628 1 Matrimony Project 1 Matrimony 2024-11-21 9.8 Critical
Matrimony v1.0 was discovered to contain a SQL injection vulnerability via the Password parameter.
CVE-2022-26627 1 Online Project Time Management System Project 1 Online Project Time Management System 2024-11-21 8.8 High
Online Project Time Management System v1.0 was discovered to contain an arbitrary file write vulnerability which allows attackers to execute arbitrary code via a crafted HTML file.
CVE-2022-26624 1 Ecommerce Codeigniter Bootstrap Project 1 Ecommerce Codeigniter Bootstrap 2024-11-21 6.1 Medium
Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title parameter in /vendor/views/add_product.php.