Search Results (327084 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-29383 1 Netgear 2 Ssl312, Ssl312 Firmware 2024-11-21 9.8 Critical
NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.
CVE-2022-29380 1 Creativeitem 1 Academy Lms 2024-11-21 4.8 Medium
Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel.
CVE-2022-29379 1 F5 1 Njs 2024-11-21 9.8 Critical
Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/njs_module.c. NOTE: multiple third parties dispute this report, e.g., the behavior is only found in unreleased development code that was not part of the 0.7.2, 0.7.3, or 0.7.4 release
CVE-2022-29377 1 Totolink 2 A3600r, A3600r Firmware 2024-11-21 7.5 High
Totolink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a stacker overflow in the fread function at infostat.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via the parameter CONTENT_LENGTH.
CVE-2022-29369 1 F5 1 Njs 2024-11-21 7.5 High
Nginx NJS v0.7.2 was discovered to contain a segmentation violation via njs_lvlhsh_bucket_find at njs_lvlhsh.c.
CVE-2022-29368 1 Moddable 1 Moddable 2024-11-21 7.1 High
Moddable commit before 135aa9a4a6a9b49b60aa730ebc3bcc6247d75c45 was discovered to contain an out-of-bounds read via the function fxUint8Getter at /moddable/xs/sources/xsDataView.c.
CVE-2022-29363 1 Phpok 1 Phpok 2024-11-21 9.8 Critical
Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability allows attackers to getshell via writing arbitrary files.
CVE-2022-29361 1 Palletsprojects 1 Werkzeug 2024-11-21 9.8 Critical
Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body. NOTE: the vendor's position is that this behavior can only occur in unsupported configurations involving development mode and an HTTP server from outside the Werkzeug project
CVE-2022-29360 1 Rainloop 1 Webmail 2024-11-21 5.4 Medium
The Email Viewer in RainLoop through 1.6.0 allows XSS via a crafted email message.
CVE-2022-29359 1 School Club Application System Project 1 School Club Application System 2024-11-21 6.1 Medium
A stored cross-site scripting (XSS) vulnerability in /scas/?page=clubs/application_form&id=7 of School Club Application System v0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter.
CVE-2022-29358 1 Epub2txt2 Project 1 Epub2txt2 2024-11-21 5.5 Medium
epub2txt2 v2.04 was discovered to contain an integer overflow via the function bug in _parse_special_tag at sxmlc.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted XML file.
CVE-2022-29354 1 Keystonejs 1 Keystone 2024-11-21 9.8 Critical
An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrary code via a crafted file.
CVE-2022-29353 1 Graphql-upload Project 1 Graphql-upload 2024-11-21 9.8 Critical
An arbitrary file upload vulnerability in the file upload module of Graphql-upload v13.0.0 allows attackers to execute arbitrary code via a crafted filename.
CVE-2022-29351 1 Tiddlywiki 1 Tiddlywiki5 2024-11-21 9.8 Critical
An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file. Note: The vendor argues that this is not a legitimate issue and there is no vulnerability here.
CVE-2022-29349 1 Keking 1 Kkfileview 2024-11-21 6.1 Medium
kkFileView v4.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/OnlinePreviewController.java.
CVE-2022-29347 1 Web\@rchiv Project 1 Web\@rchiv 2024-11-21 9.8 Critical
An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.
CVE-2022-29340 1 Gpac 1 Gpac 2024-11-21 7.5 High
GPAC 2.1-DEV-rev87-g053aae8-master. has a Null Pointer Dereference vulnerability in gf_isom_parse_movie_boxes_internal due to improper return value handling of GF_SKIP_BOX, which causes a Denial of Service. This vulnerability was fixed in commit 37592ad.
CVE-2022-29339 1 Gpac 1 Gpac 2024-11-21 7.5 High
In GPAC 2.1-DEV-rev87-g053aae8-master, function BS_ReadByte() in utils/bitstream.c has a failed assertion, which causes a Denial of Service. This vulnerability was fixed in commit 9ea93a2.
CVE-2022-29337 1 Cdatatec 2 Fd702xw-x-r430, Fd702xw-x-r430 Firmware 2024-11-21 9.8 Critical
C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter in formlanipv6. This vulnerability allows attackers to execute arbitrary commands via a crafted HTTP request.
CVE-2022-29334 1 H Project 1 H 2024-11-21 9.8 Critical
An issue in H v1.0 allows attackers to bypass authentication via a session replay attack.