Search Results (30371 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-34600 1 H3c 2 Magic R200, Magic R200 Firmware 2024-11-21 9.8 Critical
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EditSTList interface at /goform/aspForm.
CVE-2022-34599 1 H3c 2 Magic R200, Magic R200 Firmware 2024-11-21 9.8 Critical
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EdittriggerList interface at /goform/aspForm.
CVE-2022-34598 1 H3c 2 Magic R100, Magic R100 Firmware 2024-11-21 9.8 Critical
The udpserver in H3C Magic R100 V200R004 and V100R005 has the 9034 port opened, allowing attackers to execute arbitrary commands.
CVE-2022-34597 1 Tenda 2 Ax1806, Ax1806 Firmware 2024-11-21 9.8 Critical
Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability via the function WanParameterSetting.
CVE-2022-34596 1 Tenda 2 Ax1803, Ax1803 Firmware 2024-11-21 9.8 Critical
Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function WanParameterSetting.
CVE-2022-34595 1 Tenda 2 Ax1803, Ax1803 Firmware 2024-11-21 9.8 Critical
Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function setipv6status.
CVE-2022-34592 1 Wavlink 2 Wl-wn575a3, Wl-wn575a3 Firmware 2024-11-21 9.8 Critical
Wavlink WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability via the function obtw. This vulnerability allows attackers to execute arbitrary commands via a crafted POST request.
CVE-2022-34577 1 Wavlink 2 Wn535g3, Wn535g3 Firmware 2024-11-21 9.8 Critical
A vulnerability in adm.cgi of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.
CVE-2022-34558 4 Global-workqueue Project, Reqmgr2 Project, Reqmon Project and 1 more 4 Global-workqueue, Reqmgr2, Reqmon and 1 more 2024-11-21 9.8 Critical
WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr 2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows attackers to execute arbitrary code via a crafted dbs-client package.
CVE-2022-34555 1 Tp-link 2 Tl-r473g, Tl-r473g Firmware 2024-11-21 9.8 Critical
TP-LINK TL-R473G 2.0.1 Build 220529 Rel.65574n was discovered to contain a remote code execution vulnerability which is exploited via a crafted packet.
CVE-2022-34531 1 Dedecms 1 Dedecms 2024-11-21 9.8 Critical
DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.
CVE-2022-34509 1 Wikifaces Project 1 Wikifaces 2024-11-21 9.8 Critical
The wikifaces package in PyPI v1.0 included a code execution backdoor inserted by a third party.
CVE-2022-34501 1 Pypi 1 Pypi 2024-11-21 9.8 Critical
The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
CVE-2022-34500 1 Pypi 1 Pypi 2024-11-21 9.8 Critical
The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
CVE-2022-34496 1 Hiby 4 Hiby R3 Pro, Hiby R3 Pro Firmware, Hiby R3 Pro Saber and 1 more 2024-11-21 9.8 Critical
Hiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature.
CVE-2022-34380 1 Dell 1 Cloudlink 2024-11-21 9.3 Critical
Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability. A high privileged local attacker may potentially exploit this vulnerability leading to authentication bypass and access the CloudLink system console. This is critical severity vulnerability as it allows attacker to take control of the system.
CVE-2022-34379 1 Dell 1 Cloudlink 2024-11-21 9.4 Critical
Dell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability. A remote attacker, with the knowledge of the active directory usernames, could potentially exploit this vulnerability to gain unauthorized access to the system.
CVE-2022-34372 1 Dell 1 Powerprotect Cyber Recovery 2024-11-21 9.8 Critical
Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registry API leading to an authentication bypass. The attacker may potentially alter the docker images leading to a loss of integrity and confidentiality
CVE-2022-34294 1 Totd Project 1 Totd 2024-11-21 9.8 Critical
totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.
CVE-2022-34268 1 Rws 1 Worldserver 2024-11-21 9.8 Critical
An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication, leading to command execution on the host.