Search Results (324464 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-24615 1 Zip4j Project 1 Zip4j 2024-11-21 5.5 Medium
zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result in an application crash. This could be used to mount a denial of service attack against services that use zip4j library.
CVE-2022-24612 1 Eyesofnetwork 1 Eyesofnetwork 2024-11-21 5.4 Medium
An authenticated user can upload an XML file containing an XSS via the ITSM module of EyesOfNetwork 5.3.11, resulting in a stored XSS.
CVE-2022-24611 1 Silabs 10 Sd3502, Sd3502 Firmware, Sd3503 and 7 more 2024-11-21 6.5 Medium
Denial of Service (DoS) in the Z-Wave S0 NonceGet protocol specification in Silicon Labs Z-Wave 500 series allows local attackers to block S0/S2 protected Z-Wave network via crafted S0 NonceGet Z-Wave packages, utilizing included but absent NodeIDs.
CVE-2022-24610 1 Alecto 2 Dvc-215ip, Dvc-215ip Firmware 2024-11-21 8.6 High
Settings/network settings/wireless settings on the Alecto DVC-215IP camera version 63.1.1.173 and below shows the Wi-Fi passphrase hidden, but by editing/removing the style of the password field the password becomes visible which grants access to an internal network connected to the camera.
CVE-2022-24609 1 Luocms Project 1 Luocms 2024-11-21 9.8 Critical
Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file.
CVE-2022-24608 1 Luocms Project 1 Luocms 2024-11-21 6.1 Medium
Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php.
CVE-2022-24607 1 Luocms Project 1 Luocms 2024-11-21 9.8 Critical
Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php.
CVE-2022-24606 1 Luocms Project 1 Luocms 2024-11-21 9.8 Critical
Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php.
CVE-2022-24605 1 Luocms Project 1 Luocms 2024-11-21 9.8 Critical
Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php.
CVE-2022-24604 1 Luocms Project 1 Luocms 2024-11-21 9.8 Critical
Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php.
CVE-2022-24603 1 Luocms Project 1 Luocms 2024-11-21 9.8 Critical
Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php.
CVE-2022-24602 1 Luocms Project 1 Luocms 2024-11-21 9.8 Critical
Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.
CVE-2022-24601 1 Luocms Project 1 Luocms 2024-11-21 7.5 High
Luocms v2.0 is affected by SQL Injection in /admin/manager/admin_mod.php. An attacker can obtain sensitive information through SQL injection statements.
CVE-2022-24600 1 Luocms Project 1 Luocms 2024-11-21 9.8 Critical
Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL injection statements.
CVE-2022-24595 1 Automotivelinux 1 Kooky Koi 2024-11-21 9.8 Critical
Automotive Grade Linux Kooky Koi 11.0.0, 11.0.1, 11.0.2, 11.0.3, 11.0.4, and 11.0.5 is affected by Incorrect Access Control in usr/bin/afb-daemon. To exploit the vulnerability, an attacker should send a well-crafted HTTP (or WebSocket) request to the socket listened by the afb-daemon process. No credentials nor user interactions are required.
CVE-2022-24594 1 Waline 1 Waline 2024-11-21 5.3 Medium
In waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address.
CVE-2022-24590 1 Backdropcms 1 Backdrop 2024-11-21 5.4 Medium
A stored cross-site scripting (XSS) vulnerability in the Add Link function of BackdropCMS v1.21.1 allows attackers to execute arbitrary web scripts or HTML.
CVE-2022-24589 1 Burden Project 1 Burden 2024-11-21 6.1 Medium
Burden v3.0 was discovered to contain a stored cross-site scripting (XSS) in the Add Category function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the task parameter.
CVE-2022-24588 1 Flatpress 1 Flatpress 2024-11-21 5.4 Medium
Flatpress v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability in the Upload SVG File function.
CVE-2022-24587 1 Pluxml 1 Pluxml 2024-11-21 5.4 Medium
A stored cross-site scripting (XSS) vulnerability in the component core/admin/medias.php of PluXml v5.8.7 allows attackers to execute arbitrary web scripts or HTML.