Search Results (30846 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-44249 1 Totolink 2 Lr350, Lr350 Firmware 2025-04-25 9.8 Critical
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.
CVE-2022-44139 1 Apartment Visitors Management System Project 1 Apartment Visitors Management System 2025-04-25 9.8 Critical
Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php.
CVE-2022-44120 1 Dedebiz 1 Dedecmsv6 2025-04-25 9.8 Critical
dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.
CVE-2022-36784 1 Elsight 2 Halo, Halo Firmware 2025-04-25 9.8 Critical
Elsight – Elsight Halo  Remote Code Execution (RCE) Elsight Halo web panel allows us to perform connection validation. through the POST request : /api/v1/nics/wifi/wlan0/ping we can abuse DESTINATION parameter and leverage it to remote code execution.
CVE-2021-3942 1 Hp 5400 Color Laserjet Cm4540 Mfp Cc419a, Color Laserjet Cm4540 Mfp Cc419a Firmware, Color Laserjet Cm4540 Mfp Cc420a and 5397 more 2025-04-25 9.8 Critical
Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR.
CVE-2020-23584 1 Optilinknetwork 2 Op-xt71000n, Op-xt71000n Firmware 2025-04-25 9.8 Critical
Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute commands on " /diag_tracert_admin.asp " in the "PingTest" parameter that leads to command execution.
CVE-2020-23583 1 Optilinknetwork 2 Op-xt71000n, Op-xt71000n Firmware 2025-04-25 9.8 Critical
OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that leads to COMMAND EXECUTION. An attacker can successfully trigger the COMMAND and can compromise full system.
CVE-2022-36787 1 Webvendome Project 1 Webvendome 2025-04-25 9.8 Critical
webvendome - webvendome SQL Injection. SQL Injection in the Parameter " DocNumber" Request : Get Request : /webvendome/showfiles.aspx?jobnumber=nullDoc Number=HERE.
CVE-2022-45909 1 Drachtio 1 Drachtio-server 2025-04-25 9.1 Critical
drachtio-server before 0.8.19 has a heap-based buffer over-read via a long Request-URI in an INVITE request.
CVE-2022-45908 1 Paddlepaddle 1 Paddlepaddle 2025-04-25 9.8 Critical
In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on a user-supplied winstr. This may lead to arbitrary code execution.
CVE-2022-45907 1 Linuxfoundation 1 Pytorch 2025-04-25 9.8 Critical
In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
CVE-2022-45276 1 Eyunjing 1 Yjcms 2025-04-25 9.8 Critical
An issue in the /index/user/user_edit.html component of YJCMS v1.0.9 allows unauthenticated attackers to obtain the Administrator account password.
CVE-2022-44400 1 Purchase Order Management System Project 1 Purchase Order Management System 2025-04-25 9.8 Critical
Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info.
CVE-2022-44399 1 Poultry Farm Management System Project 1 Poultry Farm Management System 2025-04-25 9.8 Critical
Poultry Farm Management System v1.0 contains a SQL injection vulnerability via the del parameter at /Redcock-Farm/farm/category.php.
CVE-2022-44283 1 Avs4you 1 Avs Audio Converter 2025-04-25 9.8 Critical
AVS Audio Converter 10.3 is vulnerable to Buffer Overflow.
CVE-2022-44255 1 Totolink 2 Lr350, Lr350 Firmware 2025-04-25 9.8 Critical
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main function via long post data.
CVE-2022-43705 1 Botan Project 1 Botan 2025-04-25 9.1 Critical
In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was introduced in Botan 1.11.34 (November 2016).
CVE-2022-3603 1 Piwebsolution 1 Export Customers List Csv For Woocommerce 2025-04-25 9.8 Critical
The Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list WordPress plugin before 2.0.69 does not validate data when outputting it back in a CSV file, which could lead to CSV injection.
CVE-2022-36193 1 Lahirudanushka 1 School Management System 2025-04-25 9.8 Critical
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
CVE-2022-45872 1 Iterm2 1 Iterm2 2025-04-25 9.8 Critical
iTerm2 before 3.4.18 mishandles a DECRQSS response.