Search Results (30435 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-37809 1 Tenda 2 Ac1206, Ac1206 Firmware 2024-11-21 9.8 Critical
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the speed_dir parameter in the function formSetSpeedWan.
CVE-2022-37808 1 Tenda 2 Ac1206, Ac1206 Firmware 2024-11-21 9.8 Critical
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the index parameter in the function formWifiWpsOOB.
CVE-2022-37807 1 Tenda 2 Ac1206, Ac1206 Firmware 2024-11-21 9.8 Critical
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function formSetClientState.
CVE-2022-37806 1 Tenda 2 Ac1206, Ac1206 Firmware 2024-11-21 9.8 Critical
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromDhcpListClient.
CVE-2022-37805 1 Tenda 2 Ac1206, Ac1206 Firmware 2024-11-21 9.8 Critical
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromWizardHandle.
CVE-2022-37804 1 Tenda 2 Ac1206, Ac1206 Firmware 2024-11-21 9.8 Critical
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo.
CVE-2022-37803 1 Tenda 2 Ac1206, Ac1206 Firmware 2024-11-21 9.8 Critical
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromAddressNat.
CVE-2022-37802 1 Tenda 2 Ac1206, Ac1206 Firmware 2024-11-21 9.8 Critical
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromNatStaticSetting.
CVE-2022-37801 1 Tenda 2 Ac1206, Ac1206 Firmware 2024-11-21 9.8 Critical
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetQosBand.
CVE-2022-37800 1 Tenda 2 Ac1206, Ac1206 Firmware 2024-11-21 9.8 Critical
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function fromSetRouteStatic.
CVE-2022-37799 1 Tenda 2 Ac1206, Ac1206 Firmware 2024-11-21 9.8 Critical
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter at the function setSmartPowerManagement.
CVE-2022-37798 1 Tenda 2 Ac1206, Ac1206 Firmware 2024-11-21 9.8 Critical
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetVirtualSer.
CVE-2022-37794 1 Library Management System Project 1 Library Management System 2024-11-21 9.8 Critical
In Library Management System 1.0 the /card/in-card.php file id_no parameters are vulnerable to SQL injection.
CVE-2022-37767 1 Pebbletemplates 1 Pebble Templates 2024-11-21 9.8 Critical
Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with springbok. NOTE: the vendor disputes this because input to the Pebble templating engine is intended to include arbitrary Java code, and thus either the input should not arrive from an untrusted source, or else the application using the engine should apply restrictions to the input. The engine is not responsible for validating the input.
CVE-2022-37661 1 Adtran 4 Sr506n, Sr506n Firmware, Sr510n and 1 more 2024-11-21 9.8 Critical
SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature.
CVE-2022-37617 1 Browserify-shim Project 1 Browserify-shim 2024-11-21 9.8 Critical
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the k variable in resolve-shims.js.
CVE-2022-37616 2 Debian, Xmldom Project 2 Debian Linux, Xmldom 2024-11-21 9.8 Critical
A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."
CVE-2022-37609 1 Js-beautify Project 1 Js-beautify 2024-11-21 9.8 Critical
Prototype pollution vulnerability in beautify-web js-beautify 1.13.7 via the name variable in options.js.
CVE-2022-37601 3 Debian, Redhat, Webpack.js 4 Debian Linux, Logging, Migration Toolkit Applications and 1 more 2024-11-21 9.8 Critical
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
CVE-2022-37598 1 Uglifyjs Project 1 Uglifyjs 2024-11-21 9.8 Critical
Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js. NOTE: the vendor considers this an invalid report.