‼ CVE-2022-29983 ‼
📖 Read
via "National Vulnerability Database".
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/view_invoice&id=.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29995 ‼
📖 Read
via "National Vulnerability Database".
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=clients/manage_client&id=.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29981 ‼
📖 Read
via "National Vulnerability Database".
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Users.php?f=delete.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29987 ‼
📖 Read
via "National Vulnerability Database".
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=user/manage_user&id=.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29747 ‼
📖 Read
via "National Vulnerability Database".
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/manage_invoice&id= // Leak place ---> id.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29994 ‼
📖 Read
via "National Vulnerability Database".
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=facilities/manage_facility&id=.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29985 ‼
📖 Read
via "National Vulnerability Database".
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_category.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29538 ‼
📖 Read
via "National Vulnerability Database".
RESI Gemini-Net Web 4.2 is affected by Improper Access Control in authorization logic. An unauthenticated user is able to access some critical resources.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29539 ‼
📖 Read
via "National Vulnerability Database".
resi-calltrace in RESI Gemini-Net 4.2 is affected by OS Command Injection. It does not properly check the parameters sent as input before they are processed on the server. Due to the lack of validation of user input, an unauthenticated attacker can bypass the syntax intended by the software (e.g., concatenate `&|;\r\ commands) and inject arbitrary system commands with the privileges of the application user.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29750 ‼
📖 Read
via "National Vulnerability Database".
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_service.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29748 ‼
📖 Read
via "National Vulnerability Database".
Simple Client Management System 1.0 is vulnerable to SQL Injection via \cms\admin?page=client/manage_client&id=.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29993 ‼
📖 Read
via "National Vulnerability Database".
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/bookings/view_booking.php?id=.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30279 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8. The event logging of the ASQ sofbus lacbus plugin triggers the dereferencing of a NULL pointer, leading to a crash of SNS. An attacker could exploit this vulnerability via forged sofbus lacbus traffic to cause a firmware crash.📖 Read
via "National Vulnerability Database".
🕴 Needs Improvement: Scoring Biden's Cyber Executive Order 🕴
📖 Read
via "Dark Reading".
One year after it was issued, has President Biden's Cyber Executive Order had an impact?📖 Read
via "Dark Reading".
Darkreading
Needs Improvement: Scoring Biden's Cyber Executive Order
One year after it was issued, has President Biden's Cyber Executive Order had an impact?
‼ CVE-2021-33082 ‼
📖 Read
via "National Vulnerability Database".
Sensitive information in resource not removed before reuse in firmware for some Intel(R) SSD and Intel(R) Optane(TM) SSD Products may allow an unauthenticated user to potentially enable information disclosure via physical access.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-33074 ‼
📖 Read
via "National Vulnerability Database".
Protection mechanism failure in firmware for some Intel(R) SSD, Intel(R) SSD DC and Intel(R) Optane(TM) SSD Products may allow an unauthenticated user to potentially enable information disclosure via physical access.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-21136 ‼
📖 Read
via "National Vulnerability Database".
Improper input validation for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable denial of service via local access.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-21182 ‼
📖 Read
via "National Vulnerability Database".
A privilege escalation vulnerability exists in the router configuration import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-33075 ‼
📖 Read
via "National Vulnerability Database".
Race condition in firmware for some Intel(R) Optane(TM) SSD, Intel(R) Optane(TM) SSD DC and Intel(R) SSD DC Products may allow a privileged user to potentially enable denial of service via local access.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-0155 ‼
📖 Read
via "National Vulnerability Database".
Unchecked return value in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-0190 ‼
📖 Read
via "National Vulnerability Database".
Uncaught exception in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.📖 Read
via "National Vulnerability Database".