Search Results (356099 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-34570 1 Wavlink 2 Wl-wn579x3, Wl-wn579x3 Firmware 2024-11-21 7.5 High
WAVLINK WN579 X3 M79X3.V5030.191012/M79X3.V5030.191012 contains an information leak which allows attackers to obtain the key information via accessing the messages.txt page.
CVE-2022-34568 1 Libsdl 1 Simple Directmedia Layer 2024-11-21 7.5 High
SDL v1.2 was discovered to contain a use-after-free via the XFree function at /src/video/x11/SDL_x11yuv.c.
CVE-2022-34567 1 Uthscsa 1 Multi-image Analysis Gui 2024-11-21 8.8 High
An issue in \Roaming\Mango\Plugins of University of Texas Multi-image Analysis GUI (Mango) 4.1 allows attackers to escalate privileges via crafted plugins.
CVE-2022-34558 4 Global-workqueue Project, Reqmgr2 Project, Reqmon Project and 1 more 4 Global-workqueue, Reqmgr2, Reqmon and 1 more 2024-11-21 9.8 Critical
WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr 2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows attackers to execute arbitrary code via a crafted dbs-client package.
CVE-2022-34557 1 Barangay Management System Project 1 Barangay Management System 2024-11-21 8.8 High
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /pages/permit/permit.php.
CVE-2022-34556 1 Picoc Project 1 Picoc 2024-11-21 5.5 Medium
PicoC v3.2.2 was discovered to contain a NULL pointer dereference at variable.c.
CVE-2022-34555 1 Tp-link 2 Tl-r473g, Tl-r473g Firmware 2024-11-21 9.8 Critical
TP-LINK TL-R473G 2.0.1 Build 220529 Rel.65574n was discovered to contain a remote code execution vulnerability which is exploited via a crafted packet.
CVE-2022-34551 1 Sims Project 1 Sims 2024-11-21 6.5 Medium
Sims v1.0 was discovered to allow path traversal when downloading attachments.
CVE-2022-34550 1 Student Information Management System Project 1 Student Information Management System 2024-11-21 5.4 Medium
Sims v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /addNotifyServlet. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the notifyInfo parameter.
CVE-2022-34549 1 Sims Project 1 Sims 2024-11-21 8.8 High
Sims v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /uploadServlet. This vulnerability allows attackers to escalate privileges and execute arbitrary commands via a crafted file.
CVE-2022-34540 1 Dw 2 Megapix, Megapix Firmware 2024-11-21 8.8 High
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/license/license_tok.cgi. This vulnerability is exploitable via a crafted POST request.
CVE-2022-34539 1 Dw 2 Megapix, Megapix Firmware 2024-11-21 8.8 High
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/curltest.cgi. This vulnerability is exploitable via a crafted POST request.
CVE-2022-34538 1 Dw 2 Megapix, Megapix Firmware 2024-11-21 8.8 High
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/bia/addacph.cgi. This vulnerability is exploitable via a crafted POST request.
CVE-2022-34537 1 Dw 2 Megapix, Megapix Firmware 2024-11-21 5.4 Medium
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a cross-site scripting (XSS) vulnerability via the component bia_oneshot.cgi.
CVE-2022-34536 1 Dw 2 Megapix, Megapix Firmware 2024-11-21 7.5 High
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows attackers to access the core log file and perform session hijacking via a crafted session token.
CVE-2022-34535 1 Dw 2 Megapix, Megapix Firmware 2024-11-21 7.5 High
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows unauthenticated attackers to view internal paths and scripts via web files.
CVE-2022-34534 1 Dw 2 Spectrum Server, Spectrum Server Firmware 2024-11-21 7.5 High
Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.
CVE-2022-34531 1 Dedecms 1 Dedecms 2024-11-21 9.8 Critical
DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.
CVE-2022-34530 1 Backdropcms 1 Backdrop Cms 2024-11-21 5.3 Medium
An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.
CVE-2022-34529 1 Wasm3 Project 1 Wasm3 2024-11-21 5.5 Medium
WASM3 v0.5.0 was discovered to contain a segmentation fault via the component Compile_Memory_CopyFill.