Search Results (347726 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-25427 1 Tenda 2 Ac9, Ac9 Firmware 2024-11-21 9.8 Critical
Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function.
CVE-2022-25420 1 Nttr 1 Goo Blog 2024-11-21 9.8 Critical
NTT Resonant Incorporated goo blog App Web Application 1.0 is vulnerable to CLRF injection. This vulnerability allows attackers to execute arbitrary code via a crafted HTTP request.
CVE-2022-25418 1 Tenda 2 Ac9, Ac9 Firmware 2024-11-21 9.8 Critical
Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function openSchedWifi.
CVE-2022-25417 1 Tenda 2 Ac9, Ac9 Firmware 2024-11-21 9.8 Critical
Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function saveparentcontrolinfo.
CVE-2022-25414 1 Tenda 2 Ac9, Ac9 Firmware 2024-11-21 9.8 Critical
Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR.
CVE-2022-25413 1 Max-3000 1 Maxsite Cms 2024-11-21 5.4 Medium
Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at /admin/page_edit/3.
CVE-2022-25412 1 Max-3000 1 Maxsite Cms 2024-11-21 8.1 High
Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-update-ajax.php via the dir and deletefile parameters.
CVE-2022-25411 1 Max-3000 1 Maxsite Cms 2024-11-21 9.8 Critical
A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-25410 1 Max-3000 1 Maxsite Cms 2024-11-21 5.4 Medium
Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_file_description at /admin/files.
CVE-2022-25409 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 5.4 Medium
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.
CVE-2022-25408 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 5.4 Medium
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dpassword parameter at /admin-panel1.php.
CVE-2022-25407 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 5.4 Medium
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Doctor parameter at /admin-panel1.php.
CVE-2022-25406 1 Tongda2000 1 Tongda2000 2024-11-21 9.8 Critical
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete_query.php via the DELETE_STR parameter.
CVE-2022-25405 1 Tongda2000 1 Tongda2000 2024-11-21 9.8 Critical
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in change_box.php via the DELETE_STR parameter.
CVE-2022-25404 1 Tongda2000 1 Tongda2000 2024-11-21 9.8 Critical
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete.php via the DELETE_STR parameter.
CVE-2022-25403 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 9.8 Critical
HMS v1.0 was discovered to contain a SQL injection vulnerability via the component admin.php.
CVE-2022-25402 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 9.1 Critical
An incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify all PHP files.
CVE-2022-25401 1 Cuppacms 1 Cuppacms 2024-11-21 7.5 High
The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting attackers read access to arbitrary files.
CVE-2022-25399 1 Simple Real Estate Portal System Project 1 Simple Real Estate Portal System 2024-11-21 9.8 Critical
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
CVE-2022-25398 1 Auto Spare Parts Management Project 1 Auto Spare Parts Management 2024-11-21 9.8 Critical
Auto Spare Parts Management v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.