Search Results (30311 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-27165 1 Cszcms 1 Csz Cms 2024-11-21 9.8 Critical
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus
CVE-2022-27164 1 Cszcms 1 Csz Cms 2024-11-21 9.8 Critical
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers
CVE-2022-27163 1 Cszcms 1 Csz Cms 2024-11-21 9.8 Critical
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_editUser
CVE-2022-27162 1 Cszcms 1 Csz Cms 2024-11-21 9.8 Critical
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUser
CVE-2022-27161 1 Cszcms 1 Csz Cms 2024-11-21 9.8 Critical
Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUsers
CVE-2022-27158 1 Php 1 Pearweb 2024-11-21 9.8 Critical
pearweb < 1.32 suffers from Deserialization of Untrusted Data.
CVE-2022-27157 1 Php 1 Pearweb 2024-11-21 9.8 Critical
pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.
CVE-2022-27140 1 Express-fileupload Project 1 Express-fileupload 2024-11-21 9.8 Critical
An arbitrary file upload vulnerability in the file upload module of express-fileupload 1.3.1 allows attackers to execute arbitrary code via a crafted PHP file. NOTE: the vendor's position is that the observed behavior can only occur with "intentional misusing of the API": the express-fileupload middleware is not responsible for an application's business logic (e.g., determining whether or how a file should be renamed).
CVE-2022-27139 1 Ghost 1 Ghost 2024-11-21 9.8 Critical
An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file. NOTE: Vendor states that as outlined in Ghost's security documentation, upload of SVGs is only possible by trusted authenticated users. The uploading of SVG files to Ghost does not represent a remote code execution vulnerability. SVGs are not executable on the server, and may only execute javascript in a client's browser - this is expected and intentional functionality
CVE-2022-27133 1 Zbzcms 1 Zbzcms 2024-11-21 9.1 Critical
zbzcms v1.0 was discovered to contain an arbitrary file deletion vulnerability via /include/up.php.
CVE-2022-27131 1 Zbzcms 1 Zbzcms 2024-11-21 9.8 Critical
An arbitrary file upload vulnerability at /zbzedit/php/zbz.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-27129 1 Zbzcms 1 Zbzcms 2024-11-21 9.8 Critical
An arbitrary file upload vulnerability at /admin/ajax.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-27128 1 Zbzcms 1 Zbzcms 2024-11-21 9.8 Critical
An incorrect access control issue at /admin/run_ajax.php in zbzcms v1.0 allows attackers to arbitrarily add administrator accounts.
CVE-2022-27126 1 Zbzcms 1 Zbzcms 2024-11-21 9.8 Critical
zbzcms v1.0 was discovered to contain a SQL injection vulnerability via the art parameter at /include/make.php.
CVE-2022-27123 1 Employee Performance Evaluation Project 1 Employee Performance Evaluation 2024-11-21 9.8 Critical
Employee Performance Evaluation v1.0 was discovered to contain a SQL injection vulnerability via the email parameter.
CVE-2022-27115 2 Microsoft, Std42 2 Windows, Elfinder 2024-11-21 9.8 Critical
In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.
CVE-2022-27104 1 Formalms 1 Formalms 2024-11-21 9.8 Critical
An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3.
CVE-2022-27083 1 Tenda 2 M3, M3 Firmware 2024-11-21 9.8 Critical
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadAccessCodePic.
CVE-2022-27082 1 Tenda 2 M3, M3 Firmware 2024-11-21 9.8 Critical
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetInternetLanInfo.
CVE-2022-27081 1 Tenda 2 M3, M3 Firmware 2024-11-21 9.8 Critical
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetLanInfo.