Search Results (348231 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-27367 1 Chshcms 1 Cscms 2024-11-21 7.2 High
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Topic.php_del.
CVE-2022-27366 1 Chshcms 1 Cscms 2024-11-21 7.2 High
Cscms Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the component dance_Dance.php_hy.
CVE-2022-27365 1 Chshcms 1 Cscms 2024-11-21 7.2 High
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Dance.php_del.
CVE-2022-27360 1 Bladex 1 Springblade 2024-11-21 9.8 Critical
SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.
CVE-2022-27359 1 Foxit 2 Pdf Editor, Pdf Reader 2024-11-21 5.5 Medium
Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a this.maildoc NULL pointer dereference.
CVE-2022-27357 1 Ecommerce-website Project 1 Ecommerce-website 2024-11-21 9.8 Critical
Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-27352 1 Simple House Rental System Project 1 Simple House Rental System 2024-11-21 8.8 High
Simple House Rental System v1 was discovered to contain an arbitrary file upload vulnerability via /app/register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-27351 1 Phpgurukul 1 Zoo Management System 2024-11-21 9.8 Critical
Zoo Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /public_html/apply_vacancy. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-27349 1 Socialcodia 1 Social Codia Sms 2024-11-21 7.2 High
Social Codia SMS v1 was discovered to contain an arbitrary file upload vulnerability via addteacher.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-27348 1 Socialcodia 1 Social Codia Sms 2024-11-21 4.8 Medium
Social Codia SMS v1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field.
CVE-2022-27346 1 Ecommerce-website Project 1 Ecommerce-website 2024-11-21 8.8 High
Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-27342 1 Link-admin Project 1 Link-admin 2024-11-21 9.8 Critical
Link-Admin v0.0.1 was discovered to contain a SQL injection vulnerability via DictRest.ResponseResult().
CVE-2022-27341 1 Jfinalcms Project 1 Jfinalcms 2024-11-21 9.8 Critical
JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function.
CVE-2022-27340 1 Mingsoft 1 Mcms 2024-11-21 8.8 High
MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attackers to escalate privileges and modify data.
CVE-2022-27337 4 Debian, Fedoraproject, Freedesktop and 1 more 4 Debian Linux, Fedora, Poppler and 1 more 2024-11-21 6.5 Medium
A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
CVE-2022-27336 1 Seacms 1 Seacms 2024-11-21 9.8 Critical
Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.
CVE-2022-27332 1 Zammad 1 Zammad 2024-11-21 9.1 Critical
An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).
CVE-2022-27331 1 Zammad 1 Zammad 2024-11-21 4.3 Medium
An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active application instance, including settings that should only be visible to authenticated users.
CVE-2022-27330 1 E-commerce Website Project 1 E-commerce Website 2024-11-21 5.4 Medium
A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_product of E-Commerce Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Title text field.
CVE-2022-27313 1 Gitea 1 Gitea 2024-11-21 7.5 High
An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Service (DoS) via deleting the configuration file.