‼ CVE-2022-28262 ‼
📖 Read
via "National Vulnerability Database".
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-28265 ‼
📖 Read
via "National Vulnerability Database".
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30048 ‼
📖 Read
via "National Vulnerability Database".
Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30047 ‼
📖 Read
via "National Vulnerability Database".
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-28269 ‼
📖 Read
via "National Vulnerability Database".
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of Annotation objects that could result in a memory leak in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-28240 ‼
📖 Read
via "National Vulnerability Database".
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29845 ‼
📖 Read
via "National Vulnerability Database".
In Progress Ipswitch WhatsUp Gold 21.1.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would allow them to read the contents of a local file.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-28245 ‼
📖 Read
via "National Vulnerability Database".
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29846 ‼
📖 Read
via "National Vulnerability Database".
In Progress Ipswitch WhatsUp Gold 16.1 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to obtain the WhatsUp Gold installation serial number.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30449 ‼
📖 Read
via "National Vulnerability Database".
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in room.php.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30062 ‼
📖 Read
via "National Vulnerability Database".
ftcms <=2.1 was discovered to be vulnerable to Arbitrary File Read via tp.php📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30057 ‼
📖 Read
via "National Vulnerability Database".
Shopwind <=v3.4.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30448 ‼
📖 Read
via "National Vulnerability Database".
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrecord.php.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-28255 ‼
📖 Read
via "National Vulnerability Database".
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30063 ‼
📖 Read
via "National Vulnerability Database".
ftcms <=2.1 was discovered to be vulnerable to code execution attacks .📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30453 ‼
📖 Read
via "National Vulnerability Database".
ShopWind <= 3.4.2 has a RCE vulnerability in Database.php📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30060 ‼
📖 Read
via "National Vulnerability Database".
ftcms <=2.1 was discovered to be vulnerable to Arbitrary File Write via admin/controllers/tp.php📖 Read
via "National Vulnerability Database".
🕴 PlainID Debuts Authorization-as-a-Service Platform 🕴
📖 Read
via "Dark Reading".
Platform powered by policy-based access control (PBAC).📖 Read
via "Dark Reading".
Darkreading
PlainID Debuts Authorization-as-a-Service Platform
Platform powered by policy-based access control (PBAC).
‼ CVE-2022-30557 ‼
📖 Read
via "National Vulnerability Database".
Foxit PDF Reader and PDF Editor before 11.2.2 have a Type Confusion issue that causes a crash because of Unsigned32 mishandling during JavaScript execution.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29596 ‼
📖 Read
via "National Vulnerability Database".
MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../../../../../../../windows/win.ini%00.jpg&Pwd=_any_password_&ConnMode=1&3054=Login substring for directory traversal.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29855 ‼
📖 Read
via "National Vulnerability Database".
Mitel 6800 and 6900 Series SIP phone devices through 2022-04-27 have "undocumented functionality." A vulnerability in Mitel 6800 Series and 6900 Series SIP phones excluding 6970, versions 5.1 SP8 (5.1.0.8016) and earlier, and 6.0 (6.0.0.368) through 6.1 HF4 (6.1.0.165), could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system startup. A successful exploit could allow access to sensitive information and code execution.📖 Read
via "National Vulnerability Database".