Search Results (325100 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-25549 1 Tenda 2 Ax1806, Ax1806 Firmware 2024-11-21 7.5 High
Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ddnsEn parameter.
CVE-2022-25548 1 Tenda 2 Ax1806, Ax1806 Firmware 2024-11-21 7.5 High
Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the serverName parameter.
CVE-2022-25547 1 Tenda 2 Ax1806, Ax1806 Firmware 2024-11-21 7.5 High
Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter.
CVE-2022-25546 1 Tenda 2 Ax1806, Ax1806 Firmware 2024-11-21 7.5 High
Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ddnsUser parameter.
CVE-2022-25523 1 Typesettercms 1 Typesetter 2024-11-21 8.8 High
TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.
CVE-2022-25521 1 Nuuo 1 Network Video Recorder Firmware 2024-11-21 9.8 Critical
NUUO v03.11.00 was discovered to contain access control issue.
CVE-2022-25518 1 Tecnoteca 1 Cmdbuild 2024-11-21 6.5 Medium
In CMDBuild from version 3.0 to 3.3.2 payload requests are saved in a temporary log table, which allows attackers with database access to read the password of the users who login to the application by querying the database table.
CVE-2022-25517 1 Baomidou 1 Mybatis-plus 2024-11-21 9.8 Critical
MyBatis plus v3.4.3 was discovered to contain a SQL injection vulnerability via the Column parameter in /core/conditions/AbstractWrapper.java. NOTE: the vendor's position is that the reported execution of a SQL statement was intended behavior.
CVE-2022-25516 1 Nothings 1 Stb Truetype.h 2024-11-21 6.5 Medium
stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function stbtt__find_table at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input.
CVE-2022-25515 1 Nothings 1 Stb Truetype.h 2024-11-21 6.5 Medium
stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttULONG() at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input.
CVE-2022-25514 1 Nothings 1 Stb Truetype.h 2024-11-21 7.5 High
stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttUSHORT() at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input.
CVE-2022-25512 1 Freetakserver-ui Project 1 Freetakserver-ui 2024-11-21 7.5 High
FreeTAKServer-UI v1.9.8 was discovered to leak sensitive API and Websocket keys.
CVE-2022-25511 1 Freetakserver-ui Project 1 Freetakserver-ui 2024-11-21 6.5 Medium
An issue in the ?filename= argument of the route /DataPackageTable in FreeTAKServer-UI v1.9.8 allows attackers to place arbitrary files anywhere on the system.
CVE-2022-25510 1 Freetakserver-ui Project 1 Freetakserver-ui 2024-11-21 8.8 High
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges.
CVE-2022-25508 1 Freetakserver-ui Project 1 Freetakserver-ui 2024-11-21 7.5 High
An access control issue in the component /ManageRoute/postRoute of FreeTAKServer v1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users.
CVE-2022-25507 1 Freetakserver-ui Project 1 Freetakserver-ui 2024-11-21 5.4 Medium
FreeTAKServer-UI v1.9.8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Callsign parameter.
CVE-2022-25506 1 Freetakserver-ui Project 1 Freetakserver-ui 2024-11-21 6.5 Medium
FreeTAKServer-UI v1.9.8 was discovered to contain a SQL injection vulnerability via the API endpoint /AuthenticateUser.
CVE-2022-25505 1 Taogogo 1 Taocms 2024-11-21 9.8 Critical
Taocms v3.0.2 was discovered to contain a SQL injection vulnerability via the id parameter in \include\Model\Category.php.
CVE-2022-25498 1 Cuppacms 1 Cuppacms 2024-11-21 9.8 Critical
CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.
CVE-2022-25497 1 Cuppacms 1 Cuppacms 2024-11-21 5.3 Medium
CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.