Search Results (359893 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-26641 1 Tp-link 2 Tl-wr840n, Tl-wr840n Firmware 2024-11-21 7.2 High
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the httpRemotePort parameter.
CVE-2022-26640 1 Tp-link 2 Tl-wr840n, Tl-wr840n Firmware 2024-11-21 7.2 High
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the minAddress parameter.
CVE-2022-26639 1 Tp-link 2 Tl-wr840n, Tl-wr840n Firmware 2024-11-21 7.2 High
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the DNSServers parameter.
CVE-2022-26635 1 Php 1 Memcached 2024-11-21 9.8 Critical
PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. Note: Third parties have disputed this as not affecting PHP-Memcached directly.
CVE-2022-26634 1 Hma 1 Hidemyass 2024-11-21 7.8 High
HMA VPN v5.3.5913.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
CVE-2022-26633 1 Simple Student Quarterly Result\/grade System Project 1 Simple Student Quarterly Result\/grade System 2024-11-21 9.8 Critical
Simple Student Quarterly Result/Grade System v1.0 was discovered to contain a SQL injection vulnerability via /sqgs/Actions.php.
CVE-2022-26632 1 Multi-vendor Online Groceries Management System Project 1 Multi-vendor Online Groceries Management System 2024-11-21 9.8 Critical
Multi-Vendor Online Groceries Management System v1.0 was discovered to contain a blind SQL injection vulnerability via the id parameter in /products/view_product.php.
CVE-2022-26631 1 Automatic Question Paper Generator Project 1 Automatic Question Paper Generator 2024-11-21 9.8 Critical
Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter.
CVE-2022-26630 1 Jellycms 1 Jellycms 2024-11-21 8.8 High
Jellycms v3.8.1 and below was discovered to contain an arbitrary file upload vulnerability via \app.\admin\Controllers\db.php.
CVE-2022-26629 3 Linux, Microsoft, Splus 3 Linux Kernel, Windows, Soroushplus 2024-11-21 9.1 Critical
An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function.
CVE-2022-26628 1 Matrimony Project 1 Matrimony 2024-11-21 9.8 Critical
Matrimony v1.0 was discovered to contain a SQL injection vulnerability via the Password parameter.
CVE-2022-26627 1 Online Project Time Management System Project 1 Online Project Time Management System 2024-11-21 8.8 High
Online Project Time Management System v1.0 was discovered to contain an arbitrary file write vulnerability which allows attackers to execute arbitrary code via a crafted HTML file.
CVE-2022-26624 1 Ecommerce Codeigniter Bootstrap Project 1 Ecommerce Codeigniter Bootstrap 2024-11-21 6.1 Medium
Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title parameter in /vendor/views/add_product.php.
CVE-2022-26619 1 Halo 1 Halo 2024-11-21 7.5 High
Halo Blog CMS v1.4.17 was discovered to allow attackers to upload arbitrary files via the Attachment Upload function.
CVE-2022-26616 1 Public Knowledge Project 1 Open Journal Systems 2024-11-21 6.1 Medium
PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers.
CVE-2022-26615 1 College Website Content Management System Project 1 College Website Content Management System 2024-11-21 5.4 Medium
A cross-site scripting (XSS) vulnerability in College Website Content Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User Profile Name text fields.
CVE-2022-26613 1 Php-cms Project 1 Php-cms 2024-11-21 9.8 Critical
PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability via the category parameter in categorymenu.php.
CVE-2022-26612 2 Apache, Microsoft 2 Hadoop, Windows 2024-11-21 9.8 Critical
In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR entry may create a symlink under the expected extraction directory which points to an external directory. A subsequent TAR entry may extract an arbitrary file into the external directory using the symlink name. This however would be caught by the same targetDirPath check on Unix because of the getCanonicalPath call. However on Windows, getCanonicalPath doesn't resolve symbolic links, which bypasses the check. unpackEntries during TAR extraction follows symbolic links which allows writing outside expected base directory on Windows. This was addressed in Apache Hadoop 3.2.3
CVE-2022-26607 1 Baigo 1 Baigo Cms 2024-11-21 7.2 High
A remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2022-26605 1 Dascomsoft 1 Eziosuite 2024-11-21 8.8 High
eZiosuite v2.0.7 contains an authenticated arbitrary file upload via the Avatar upload functionality.