Search Results (30312 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-27332 1 Zammad 1 Zammad 2024-11-21 9.1 Critical
An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).
CVE-2022-27311 1 Gibbon Project 1 Gibbon 2024-11-21 9.8 Critical
Gibbon v3.4.4 and below allows attackers to execute a Server-Side Request Forgery (SSRF) via a crafted URL.
CVE-2022-27299 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 9.8 Critical
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php.
CVE-2022-27277 1 Inhandnetworks 2 Inrouter 900, Inrouter 900 Firmware 2024-11-21 9.1 Critical
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain an arbitrary file deletion vulnerability via the function sub_17C08.
CVE-2022-27276 1 Inhandnetworks 2 Inrouter 900, Inrouter 900 Firmware 2024-11-21 9.8 Critical
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_10F2C. This vulnerability is triggered via a crafted packet.
CVE-2022-27275 1 Inhandnetworks 2 Inrouter 900, Inrouter 900 Firmware 2024-11-21 9.8 Critical
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_122D0. This vulnerability is triggered via a crafted packet.
CVE-2022-27274 1 Inhandnetworks 2 Inrouter 900, Inrouter 900 Firmware 2024-11-21 9.8 Critical
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_12028. This vulnerability is triggered via a crafted packet.
CVE-2022-27273 1 Inhandnetworks 2 Inrouter 900, Inrouter 900 Firmware 2024-11-21 9.8 Critical
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_12168. This vulnerability is triggered via a crafted packet.
CVE-2022-27272 1 Inhandnetworks 2 Inrouter 900, Inrouter 900 Firmware 2024-11-21 9.8 Critical
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_1791C. This vulnerability is triggered via a crafted packet.
CVE-2022-27271 1 Inhandnetworks 2 Inrouter 900, Inrouter 900 Firmware 2024-11-21 9.8 Critical
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component python-lib. This vulnerability is triggered via a crafted packet.
CVE-2022-27270 1 Inhandnetworks 2 Inrouter 900, Inrouter 900 Firmware 2024-11-21 9.8 Critical
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component ipsec_secrets. This vulnerability is triggered via a crafted packet.
CVE-2022-27269 1 Inhandnetworks 2 Inrouter 900, Inrouter 900 Firmware 2024-11-21 9.8 Critical
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component config_ovpn. This vulnerability is triggered via a crafted packet.
CVE-2022-27268 1 Inhandnetworks 2 Inrouter 900, Inrouter 900 Firmware 2024-11-21 9.8 Critical
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component get_cgi_from_memory. This vulnerability is triggered via a crafted packet.
CVE-2022-27263 1 Strapi 1 Strapi 2024-11-21 9.8 Critical
An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.
CVE-2022-27262 1 Sailsjs 1 Skipper 2024-11-21 9.8 Critical
An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file.
CVE-2022-27260 1 Buttercms 1 Buttercms 2024-11-21 9.8 Critical
An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.
CVE-2022-27255 1 Realtek 4 Ecos Msdk, Ecos Msdk Firmware, Ecos Rsdk and 1 more 2024-11-21 9.8 Critical
In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. This allows an attacker to remotely execute code without authentication via a crafted SIP packet that contains malicious SDP data.
CVE-2022-27250 1 Unisoc 1 Unisoc Chipset 2024-11-21 9.8 Critical
The UNISOC chipset through 2022-03-15 allows attackers to obtain remote control of a mobile phone, e.g., to obtain sensitive information from text messages or the device's screen, record video of the device's physical environment, or modify data.
CVE-2022-27240 1 Glewlwyd Sso Server Project 1 Glewlwyd Sso Server 2024-11-21 9.8 Critical
scheme/webauthn.c in Glewlwyd SSO server 2.x before 2.6.2 has a buffer overflow associated with a webauthn assertion.
CVE-2022-27228 1 Bitrix24 1 Bitrix24 2024-11-21 9.8 Critical
In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code.