Search Results (325104 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-25506 1 Freetakserver-ui Project 1 Freetakserver-ui 2024-11-21 6.5 Medium
FreeTAKServer-UI v1.9.8 was discovered to contain a SQL injection vulnerability via the API endpoint /AuthenticateUser.
CVE-2022-25505 1 Taogogo 1 Taocms 2024-11-21 9.8 Critical
Taocms v3.0.2 was discovered to contain a SQL injection vulnerability via the id parameter in \include\Model\Category.php.
CVE-2022-25498 1 Cuppacms 1 Cuppacms 2024-11-21 9.8 Critical
CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.
CVE-2022-25497 1 Cuppacms 1 Cuppacms 2024-11-21 5.3 Medium
CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.
CVE-2022-25495 1 Cuppacms 1 Cuppacms 2024-11-21 9.8 Critical
The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a crafted PHP file.
CVE-2022-25494 1 Online Banking System Project 1 Online Banking System 2024-11-21 9.8 Critical
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via staff_login.php.
CVE-2022-25493 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 6.1 Medium
HMS v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via treatmentrecord.php.
CVE-2022-25492 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 9.8 Critical
HMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php.
CVE-2022-25491 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 7.5 High
HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in appointment.php.
CVE-2022-25490 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 9.8 Critical
HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php.
CVE-2022-25489 1 Thedigitalcraft 1 Atomcms 2024-11-21 5.4 Medium
Atom CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "A" parameter in /widgets/debug.php.
CVE-2022-25488 1 Thedigitalcraft 1 Atomcms 2024-11-21 9.8 Critical
Atom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php.
CVE-2022-25487 1 Thedigitalcraft 1 Atomcms 2024-11-21 9.8 Critical
Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.
CVE-2022-25486 1 Cuppacms 1 Cuppacms 2024-11-21 7.8 High
CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php.
CVE-2022-25485 1 Cuppacms 1 Cuppacms 2024-11-21 7.8 High
CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.
CVE-2022-25484 1 Broadcom 1 Tcpreplay 2024-11-21 5.5 Medium
tcpprep v4.4.1 has a reachable assertion (assert(l2len > 0)) in packet2tree() at tree.c in tcpprep v4.4.1.
CVE-2022-25481 1 Thinkphp 1 Thinkphp 2024-11-21 7.5 High
ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the debugging mode.
CVE-2022-25479 1 Realtek 4 Rtsper, Rtsper Pcie Card Reader Driver, Rtsper Usb Card Reader Driver and 1 more 2024-11-21 6.1 Medium
Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows for the leakage of kernel memory from both the stack and the heap.
CVE-2022-25478 1 Realtek 2 Rtsper, Rtsuer 2024-11-21 7.8 High
Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 provides read and write access to the PCI configuration space of the device.
CVE-2022-25477 1 Realtek 2 Rtsper, Rtsuer 2024-11-21 5.5 Medium
Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 leaks driver logs that contain addresses of kernel mode objects, weakening KASLR.