‼ CVE-2022-1664 ‼
📖 Read
via "National Vulnerability Database".
Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially crafted orig.tar and debian.tar tarballs.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29663 ‼
📖 Read
via "National Vulnerability Database".
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/hy.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29662 ‼
📖 Read
via "National Vulnerability Database".
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/news/save.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29660 ‼
📖 Read
via "National Vulnerability Database".
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29681 ‼
📖 Read
via "National Vulnerability Database".
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Links/del.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29686 ‼
📖 Read
via "National Vulnerability Database".
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/lists/zhuan.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29688 ‼
📖 Read
via "National Vulnerability Database".
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/hy.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-34360 ‼
📖 Read
via "National Vulnerability Database".
A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later QuTS hero h5.0.0: Proxy Server 1.4.3 ( 2022/01/18 ) and later QuTScloud c4.5.6: Proxy Server 1.4.2 ( 2021/12/30 ) and later📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29669 ‼
📖 Read
via "National Vulnerability Database".
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/lists/zhuan.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-1886 ‼
📖 Read
via "National Vulnerability Database".
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29666 ‼
📖 Read
via "National Vulnerability Database".
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29667 ‼
📖 Read
via "National Vulnerability Database".
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via /admin.php/pic/admin/pic/hy. This vulnerability is exploited via restoring deleted photos.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29665 ‼
📖 Read
via "National Vulnerability Database".
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/topic/save.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-20809 ‼
📖 Read
via "National Vulnerability Database".
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-22577 ‼
📖 Read
via "National Vulnerability Database".
An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30785 ‼
📖 Read
via "National Vulnerability Database".
A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-24422 ‼
📖 Read
via "National Vulnerability Database".
Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access to the VNC Console.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-24418 ‼
📖 Read
via "National Vulnerability Database".
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29091 ‼
📖 Read
via "National Vulnerability Database".
Dell Unity, Dell UnityVSA, and Dell UnityXT versions prior to 5.2.0.0.5.173 contain a Reflected Cross-Site Scripting Vulnerability in Unisphere GUI. An Unauthenticated Remote Attacker could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript code in a victim user's web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-27777 ‼
📖 Read
via "National Vulnerability Database".
A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to inject content if able to control input into specific attributes.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30473 ‼
📖 Read
via "National Vulnerability Database".
Tenda AC Series Router AC18_V15.03.05.19(6318) has a stack-based buffer overflow vulnerability in function form_fast_setting_wifi_set📖 Read
via "National Vulnerability Database".