Search Results (327132 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-29321 1 Dlink 2 Dir-816, Dir-816 Firmware 2024-11-21 9.8 Critical
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the lanip parameter in /goform/setNetworkLan.
CVE-2022-29320 1 Minitool 1 Partition Wizard 2024-11-21 7.8 High
MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
CVE-2022-29318 1 Car Rental Management System Project 1 Car Rental Management System 2024-11-21 7.2 High
An arbitrary file upload vulnerability in the New Entry module of Car Rental Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-29317 1 Simple Bus Ticket Booking System Project 1 Simple Bus Ticket Booking System 2024-11-21 9.8 Critical
Simple Bus Ticket Booking System v1.0 was discovered to contain multiple SQL injection vulnerbilities via the username and password parameters at /assets/partials/_handleLogin.php.
CVE-2022-29316 1 Complete Online Job Search System Project 1 Complete Online Job Search System 2024-11-21 9.8 Critical
Complete Online Job Search System v1.0 was discovered to contain a SQL injection vulnerability via /eris/index.php?q=result&searchfor=advancesearch.
CVE-2022-29315 1 Invicti 1 Acunetix 2024-11-21 8.8 High
Invicti Acunetix before 14 allows CSV injection via the Description field on the Add Targets page, if the Export CSV feature is used.
CVE-2022-29307 1 Ionizecms 1 Ionize 2024-11-21 9.8 Critical
IonizeCMS v1.0.8.1 was discovered to contain a command injection vulnerability via the function copy_lang_content in application/models/lang_model.php.
CVE-2022-29306 1 Ionizecms 1 Ionize 2024-11-21 9.8 Critical
IonizeCMS v1.0.8.1 was discovered to contain a SQL injection vulnerability via the id_page parameter in application/models/article_model.php.
CVE-2022-29305 1 Imgurl Project 1 Imgurl 2024-11-21 8.1 High
imgurl v2.31 was discovered to contain a Blind SQL injection vulnerability via /upload/localhost.
CVE-2022-29304 1 Online Sports Complex Booking System Project 1 Online Sports Complex Booking System 2024-11-21 8.8 High
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /classes/master.php?f=delete_ Facility.
CVE-2022-29302 1 Contec 2 Sv-cpt-mc310, Sv-cpt-mc310 Firmware 2024-11-21 5.5 Medium
SolarView Compact ver.6.00 was discovered to contain a local file disclosure via /html/Solar_Ftp.php.
CVE-2022-29298 1 Contec 2 Sv-cpt-mc310, Sv-cpt-mc310 Firmware 2024-11-21 7.5 High
SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.
CVE-2022-29296 1 Avantune 1 Genialcloud Proj 2024-11-21 6.1 Medium
A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2022-29286 1 Pexip 1 Pexip Infinity 2024-11-21 7.5 High
Pexip Infinity 27 before 28.0 allows remote attackers to trigger excessive resource consumption and termination because of registrar resource mishandling.
CVE-2022-29281 1 Notable 1 Notable 2024-11-21 8.8 High
Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link. There is improper validation of the file URI scheme. A hyperlink to an SMB share could lead to execution of an arbitrary program (or theft of NTLM credentials via an SMB relay attack, because the application resolves UNC paths).
CVE-2022-29272 1 Nagios 1 Nagios Xi 2024-11-21 6.1 Medium
In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
CVE-2022-29271 1 Nagios 1 Nagios Xi 2024-11-21 6.5 Medium
In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.
CVE-2022-29270 1 Nagios 1 Nagios Xi 2024-11-21 4.3 Medium
In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.
CVE-2022-29269 1 Nagios 1 Nagios Xi 2024-11-21 6.5 Medium
In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.
CVE-2022-29266 1 Apache 1 Apisix 2024-11-21 7.5 High
In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information.