Search Results (326435 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-28068 1 Radare 1 Radare2 2024-11-21 7.5 High
A heap buffer overflow in r_sleb128 function in radare2 5.4.2 and 5.4.0.
CVE-2022-28067 1 Sandboxie 1 Sandboxie 2024-11-21 8.6 High
An incorrect access control issue in Sandboxie Classic v5.55.13 allows attackers to cause a Denial of Service (DoS) in the Sandbox via a crafted executable.
CVE-2022-28063 1 Simple Bakery Shop Management System Project 1 Simple Bakery Shop Management System 2024-11-21 4.9 Medium
Simple Bakery Shop Management System v1.0 contains a file disclosure via /bsms/?page=products.
CVE-2022-28062 1 Online Car Rental System Project 1 Online Car Rental System 2024-11-21 8.8 High
Car Rental System v1.0 contains an arbitrary file upload vulnerability via the Add Car component which allows attackers to upload a webshell and execute arbitrary code.
CVE-2022-28060 1 Victor Cms Project 1 Victor Cms 2024-11-21 7.5 High
SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php.
CVE-2022-28059 1 Verydows 1 Verydows 2024-11-21 8.1 High
Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\database_controller.php.
CVE-2022-28058 1 Verydows 1 Verydows 2024-11-21 8.1 High
Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\file_controller.php.
CVE-2022-28056 1 Shopxo 1 Shopxo 2024-11-21 9.8 Critical
ShopXO v2.2.5 and below was discovered to contain a system re-install vulnerability via the Add function in app/install/controller/Index.php.
CVE-2022-28055 1 Fusionpbx 1 Fusionpbx 2024-11-21 9.8 Critical
Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.
CVE-2022-28054 2 Microsoft, Vandyke 2 Windows, Vshell 2024-11-21 9.8 Critical
Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted value.
CVE-2022-28053 1 Typemill 1 Typemill 2024-11-21 8.8 High
Typemill v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-28052 1 Roothub 1 Roothub 2024-11-21 8.0 High
Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege to arbitrarily upload files via /common/upload API, which could lead to remote arbitrary code execution.
CVE-2022-28051 1 Seeddms 1 Seeddms 2024-11-21 5.4 Medium
The "Add category" functionality inside the "Global Keywords" menu in "SeedDMS" version 6.0.18 and 5.1.25, is prone to stored XSS which allows an attacker to inject malicious javascript code.
CVE-2022-28049 1 F5 1 Njs 2024-11-21 5.5 Medium
NGINX NJS 0.7.2 was discovered to contain a NULL pointer dereference via the component njs_vmcode_array at /src/njs_vmcode.c.
CVE-2022-28048 2 Fedoraproject, Stb Project 2 Fedora, Stb 2024-11-21 8.8 High
STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.
CVE-2022-28044 2 Debian, Irzip Project 2 Debian Linux, Irzip 2024-11-21 9.8 Critical
Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control.
CVE-2022-28042 3 Debian, Fedoraproject, Nothings 3 Debian Linux, Fedora, Stb Image.h 2024-11-21 8.8 High
stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode.
CVE-2022-28041 3 Debian, Fedoraproject, Nothings 3 Debian Linux, Fedora, Stb Image.h 2024-11-21 6.5 Medium
stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
CVE-2022-28036 1 Thedigitalcraft 1 Atomcms 2024-11-21 9.8 Critical
AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_navigation.php
CVE-2022-28035 1 Thedigitalcraft 1 Atomcms 2024-11-21 9.8 Critical
Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_blur-save.php