Search Results (84929 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-37175 1 Tenda 2 Ac15, Ac15 Firmware 2024-11-21 9.8 Critical
Tenda ac15 firmware V15.03.05.18 httpd server has stack buffer overflow in /goform/formWifiBasicSet.
CVE-2022-37162 1 Claroline 1 Claroline 2024-11-21 5.4 Medium
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution by adding arbitrary javascript code in the 'Location' field of a calendar event.
CVE-2022-37161 1 Claroline 1 Claroline 2024-11-21 6.1 Medium
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS) via SVG file upload.
CVE-2022-37160 1 Claroline 1 Claroline 2024-11-21 5.4 Medium
Claroline 13.5.7 and prior allows an authenticated attacker to elevate privileges via the arbitrary creation of a privileged user. By combining the XSS vulnerability present in several upload forms and a javascript request to the present API, it is possible to trigger the creation of a user with administrative rights by opening an SVG file as an administrator user.
CVE-2022-37153 1 Articatech 1 Artica Proxy 2024-11-21 6.1 Medium
An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.login.php.
CVE-2022-37150 1 Online Diagnostic Lab Management System Project 1 Online Diagnostic Lab Management System 2024-11-21 5.4 Medium
An issue was discovered in Online Diagnostic Lab Management System 1.0. There is a stored XSS vulnerability via firstname, address, middlename, lastname , gender, email, contact parameters.
CVE-2022-37149 1 Wavlink 2 Wl-wn575a3, Wl-wn575a3 Firmware 2024-11-21 9.8 Critical
WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi. This vulnerability allows attackers to execute arbitrary commands via the username parameter.
CVE-2022-37130 1 Dlink 2 Dir-816, Dir-816 Firmware 2024-11-21 9.8 Critical
In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is met, setnum will be spliced into v10 by snprintf, and the system will be executed, resulting in a command injection vulnerability
CVE-2022-37129 1 Dlink 2 Dir-816, Dir-816 Firmware 2024-11-21 8.8 High
D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in the command parameter, it will be spliced into byte_4836B0 by snprintf, and finally doSystem(&byte_4836B0); will be executed, resulting in a command injection.
CVE-2022-37125 1 Dlink 2 Dir-816, Dir-816 Firmware 2024-11-21 9.8 Critical
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.
CVE-2022-37123 1 Dlink 2 Dir-816, Dir-816 Firmware 2024-11-21 8.8 High
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi.
CVE-2022-37108 1 Securonix 1 Snypr 2024-11-21 8.7 High
An injection vulnerability in the syslog-ng configuration wizard in Securonix Snypr 6.4 allows an application user with the "Manage Ingesters" permission to execute arbitrary code on remote ingesters by appending arbitrary text to text files that are executed by the system, such as users' crontab files. The patch for this was present in SNYPR version 6.4 Jun 2022 R3_[06170871], but may have been introduced sooner.
CVE-2022-37100 1 H3c 2 H200, H200 Firmware 2024-11-21 9.8 Critical
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateMacClone.
CVE-2022-37099 1 H3c 2 H200, H200 Firmware 2024-11-21 9.8 Critical
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateSnat.
CVE-2022-37098 1 H3c 2 H200, H200 Firmware 2024-11-21 9.8 Critical
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateIpv6Params.
CVE-2022-37097 1 H3c 2 H200, H200 Firmware 2024-11-21 9.8 Critical
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetAPInfoById.
CVE-2022-37096 1 H3c 2 H200, H200 Firmware 2024-11-21 9.8 Critical
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EnableIpv6.
CVE-2022-37095 1 H3c 2 H200, H200 Firmware 2024-11-21 9.8 Critical
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateWanParams.
CVE-2022-37094 1 H3c 2 H200, H200 Firmware 2024-11-21 9.8 Critical
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function Edit_BasicSSID_5G.
CVE-2022-37093 1 H3c 2 H200, H200 Firmware 2024-11-21 9.8 Critical
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function AddMacList.