Search Results (331181 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-35000 1 Bitbanksoftware 1 Jpegdec 2024-11-21 5.5 Medium
JPEGDEC commit be4843c was discovered to contain a segmentation fault via fseek at /libio/fseek.c.
CVE-2022-34999 1 Bitbanksoftware 1 Jpegdec 2024-11-21 5.5 Medium
JPEGDEC commit be4843c was discovered to contain a FPE via DecodeJPEG at /src/jpeg.inl.
CVE-2022-34998 1 Bitbanksoftware 1 Jpegdec 2024-11-21 7.8 High
JPEGDEC commit be4843c was discovered to contain a global buffer overflow via JPEGDecodeMCU at /src/jpeg.inl.
CVE-2022-34993 1 Totolink 2 A3600r, A3600r Firmware 2024-11-21 9.8 Critical
Totolink A3600R_Firmware V4.1.2cu.5182_B20201102 contains a hard code password for root in /etc/shadow.sample.
CVE-2022-34992 1 Luadec Project 1 Luadec 2024-11-21 7.8 High
Luadec v0.9.9 was discovered to contain a heap-buffer overflow via the function UnsetPending.
CVE-2022-34991 1 Techvill 1 Paymoney 2024-11-21 5.4 Medium
Paymoney v3.3 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the first_name and last_name parameters.
CVE-2022-34989 1 Fruits Bazar Project 1 Fruits Bazar 2024-11-21 9.8 Critical
Fruits Bazar v1.0 was discovered to contain a SQL injection vulnerability via the recover_email parameter at user_password_recover.php.
CVE-2022-34988 1 Inoutscripts 1 Blockchain Altexchanger 2024-11-21 5.4 Medium
Inout Blockchain AltExchanger v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/js.
CVE-2022-34983 1 Scu-captcha Project 1 Scu-captcha 2024-11-21 9.8 Critical
The scu-captcha package in PyPI v0.0.1 to v0.0.4 included a code execution backdoor inserted by a third party.
CVE-2022-34982 1 Eziod Project 1 Eziod 2024-11-21 9.8 Critical
The eziod package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party.
CVE-2022-34981 1 Pycrowdtangle Project 1 Pycrowdtangle 2024-11-21 9.8 Critical
The PyCrowdTangle package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party.
CVE-2022-34972 1 So Filter Shop By Project 1 So Filter Shop By 2024-11-21 9.8 Critical
So Filter Shop v3.x was discovered to contain multiple blind SQL injection vulnerabilities via the att_value_id , manu_value_id , opt_value_id , and subcate_value_id parameters at /index.php?route=extension/module/so_filter_shop_by/filter_data.
CVE-2022-34971 1 Feehi 1 Feehi Cms 2024-11-21 8.8 High
An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-34970 1 Crowcpp 1 Crow 2024-11-21 9.8 Critical
Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitation this vulnerability allows attackers to remotely execute arbitrary code in the context of the vulnerable service.
CVE-2022-34969 1 Pingcap 1 Tidb 2024-11-21 7.5 High
PingCAP TiDB v6.1.0 was discovered to contain a NULL pointer dereference.
CVE-2022-34968 1 Percona 1 Percona Server 2024-11-21 7.5 High
An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL query.
CVE-2022-34967 1 Monetdb 1 Monetdb 2024-11-21 7.5 High
The assertion `stmt->Dbc->FirstStmt' failed in MonetDB Database Server v11.43.13.
CVE-2022-34966 1 Openteknik 1 Open Source Social Network 2024-11-21 7.5 High
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an HTML injection vulnerability via the location parameter at http://ip_address/:port/ossn/home.
CVE-2022-34965 1 Openteknik 1 Open Source Social Network 2024-11-21 7.2 High
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an arbitrary file upload vulnerability via the component /ossn/administrator/com_installer. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. Note: The project owner believes this is intended behavior of the application as it only allows authenticated admins to upload files.
CVE-2022-34964 1 Openteknik 1 Open Source Social Network 2024-11-21 4.8 Medium
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the SitePages module.