Search Results (360226 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-28108 1 Selenium 1 Selenium Grid 2024-11-21 8.8 High
Selenium Server (Grid) before 4 allows CSRF because it permits non-JSON content types such as application/x-www-form-urlencoded, multipart/form-data, and text/plain.
CVE-2022-28106 1 Online Sports Complex Booking System Project 1 Online Sports Complex Booking System 2024-11-21 9.8 Critical
Online Sports Complex Booking System v1.0 was discovered to allow attackers to take over user accounts via a crafted POST request.
CVE-2022-28105 1 Online Sports Complex Booking System Project 1 Online Sports Complex Booking System 2024-11-21 9.8 Critical
Online Sports Complex Booking System v1.0 was discovered to contain a blind SQL injection vulnerability via the id parameter in /scbs/view_facility.php.
CVE-2022-28104 2 Apple, Foxit 2 Iphone Os, Pdf Editor 2024-11-21 9.8 Critical
Foxit PDF Editor v11.3.1 was discovered to contain an arbitrary file upload vulnerability.
CVE-2022-28102 1 Php Mysql Admin Panel Generator Project 1 Php Mysql Admin Panel Generator 2024-11-21 5.4 Medium
A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected at /edit-db.php.
CVE-2022-28101 1 Lyonbros 1 Turtl 2024-11-21 9.0 Critical
Turtlapp Turtle Note v0.7.2.6 does not filter the <meta> tag during markdown parsing, allowing attackers to execute HTML injection.
CVE-2022-28099 1 Poultry Farm Management System Project 1 Poultry Farm Management System 2024-11-21 8.8 High
Poultry Farm Management System v1.0 was discovered to contain a SQL injection vulnerability via the Item parameter at /farm/store.php.
CVE-2022-28096 1 Skycaiji 1 Skycaiji 2024-11-21 7.2 High
Skycaiji v2.4 was discovered to contain a remote code execution (RCE) vulnerability via /SkycaijiApp/admin/controller/Develop.php.
CVE-2022-28094 1 Online Sports Complex Booking System Project 1 Online Sports Complex Booking System 2024-11-21 6.1 Medium
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php.
CVE-2022-28093 1 Online Sports Complex Booking System Project 1 Online Sports Complex Booking System 2024-11-21 9.8 Critical
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-28090 1 Ujcms 1 Jspxcms 2024-11-21 6.5 Medium
Jspxcms v10.2.0 allows attackers to execute a Server-Side Request Forgery (SSRF) via /cmscp/ext/collect/fetch_url.do?url=.
CVE-2022-28082 1 Tenda 2 Ax12, Ax12 Firmware 2024-11-21 9.8 Critical
Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the list parameter at /goform/SetNetControlList.
CVE-2022-28081 1 Ar-php 1 Arphp 2024-11-21 6.1 Medium
A reflected cross-site scripting (XSS) vulnerability in the component Query.php of arPHP v3.6.0 allows attackers to execute arbitrary web scripts.
CVE-2022-28080 1 Event Management System Project 1 Event Management System 2024-11-21 8.8 High
Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.
CVE-2022-28079 1 College Management System Project 1 College Management System 2024-11-21 8.8 High
College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.
CVE-2022-28078 1 Home Owners Collection Management System Project 1 Home Owners Collection Management System 2024-11-21 6.1 Medium
Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['page'] parameter.
CVE-2022-28077 1 Home Owners Collection Management System Project 1 Home Owners Collection Management System 2024-11-21 6.1 Medium
Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['s'] parameter.
CVE-2022-28076 1 Seacms 1 Seacms 2024-11-21 7.2 High
Seacms v11.6 was discovered to contain a remote command execution (RCE) vulnerability via the Mail Server Settings.
CVE-2022-28074 1 Fit2cloud 1 Halo 2024-11-21 4.8 Medium
Halo-1.5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via \admin\index.html#/system/tools.
CVE-2022-28073 1 Radare 1 Radare2 2024-11-21 7.5 High
A use after free in r_reg_set_value function in radare2 5.4.2 and 5.4.0.