Search Results (330039 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-33055 1 Online Railway Reservation System Project 1 Online Railway Reservation System 2024-11-21 7.2 High
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/trains/manage_train.php.
CVE-2022-33049 1 Online Railway Reservation System Project 1 Online Railway Reservation System 2024-11-21 7.2 High
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/?page=user/manage_user.
CVE-2022-33048 1 Online Railway Reservation System Project 1 Online Railway Reservation System 2024-11-21 7.2 High
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/reservations/view_details.php.
CVE-2022-33047 1 Otfcc Project 1 Otfcc 2024-11-21 9.8 Critical
OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c.
CVE-2022-33043 1 Urtracker 1 Urtracker 2024-11-21 5.4 Medium
A cross-site scripting (XSS) vulnerability in the batch add function of Urtracker Premium v4.0.1.1477 allows attackers to execute arbitrary web scripts or HTML via a crafted excel file.
CVE-2022-33042 1 Online Railway Reservation System Project 1 Online Railway Reservation System 2024-11-21 7.2 High
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/inquiries/view_details.php.
CVE-2022-33037 1 Orwell-dev-cpp Project 1 Orwell-dev-cpp 2024-11-21 7.8 High
A binary hijack in Orwell-Dev-Cpp v5.11 allows attackers to execute arbitrary code via a crafted .exe file.
CVE-2022-33036 1 Embarcadero 1 Dev-c\+\+ 2024-11-21 7.8 High
A binary hijack in Embarcadero Dev-CPP v6.3 allows attackers to execute arbitrary code via a crafted .exe file.
CVE-2022-33035 1 Netsarang 1 Xlpd 2024-11-21 7.8 High
XLPD v7.0.0094 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.
CVE-2022-33034 1 Gnu 1 Libredwg 2024-11-21 7.8 High
LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at decode_r2007.c.
CVE-2022-33033 1 Gnu 1 Libredwg 2024-11-21 7.8 High
LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c.
CVE-2022-33032 1 Gnu 1 Libredwg 2024-11-21 7.8 High
LibreDWG v0.12.4.4608 was discovered to contain a heap-buffer-overflow via the function decode_preR13_section_hdr at decode_r11.c.
CVE-2022-33028 1 Gnu 1 Libredwg 2024-11-21 7.8 High
LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function dwg_add_object at decode.c.
CVE-2022-33027 1 Gnu 1 Libredwg 2024-11-21 7.8 High
LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function dwg_add_handleref at dwg.c.
CVE-2022-33026 1 Gnu 1 Libredwg 2024-11-21 7.8 High
LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c.
CVE-2022-33025 1 Gnu 1 Libredwg 2024-11-21 7.8 High
LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function decode_preR13_section at decode_r11.c.
CVE-2022-33024 1 Gnu 1 Libredwg 2024-11-21 7.5 High
There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dwg2dxf: decode.c:5801 in libredwg v0.12.4.4608.
CVE-2022-33023 1 Openhwgroup 1 Cva6 2024-11-21 7.5 High
CVA6 commit 909d85a gives incorrect permission to use special multiplication units when the format of instructions is wrong.
CVE-2022-33021 1 Openhwgroup 1 Cva6 2024-11-21 7.5 High
CVA6 commit 909d85a accesses invalid memory when reading the value of MHPMCOUNTER30.
CVE-2022-33011 1 Withknown 1 Known 2024-11-21 8.8 High
Known v1.3.1+2020120201 was discovered to allow attackers to perform an account takeover via a host header injection attack.