βΌ CVE-2022-30808 βΌ
π Read
via "National Vulnerability Database".
elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php.π Read
via "National Vulnerability Database".
βΌ CVE-2022-30277 βΌ
π Read
via "National Vulnerability Database".
BD SynapsysΓ’βΒ’, versions 4.20, 4.20 SR1, and 4.30, contain an insufficient session expiration vulnerability. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected health information (ePHI), protected health information (PHI) and personally identifiable information (PII).π Read
via "National Vulnerability Database".
βΌ CVE-2022-30115 βΌ
π Read
via "National Vulnerability Database".
Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by having the trailing dot in the HSTS cache and *not* using thetrailing dot in the URL.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29483 βΌ
π Read
via "National Vulnerability Database".
Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine.π Read
via "National Vulnerability Database".
βΌ CVE-2022-31336 βΌ
π Read
via "National Vulnerability Database".
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/loaddata.php.π Read
via "National Vulnerability Database".
βΌ CVE-2019-12350 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_download.php via an id parameter value with a trailing comma.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36866 βΌ
π Read
via "National Vulnerability Database".
Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) vulnerability in Fatcat Apps Easy Pricing Tables plugin <= 3.1.2 at WordPress.π Read
via "National Vulnerability Database".
βΌ CVE-2022-30809 βΌ
π Read
via "National Vulnerability Database".
elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_page.php?page=.π Read
via "National Vulnerability Database".
βΌ CVE-2022-30834 βΌ
π Read
via "National Vulnerability Database".
Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_manage_account_details.php?booking_id=31&user_id=π Read
via "National Vulnerability Database".
βΌ CVE-2022-31335 βΌ
π Read
via "National Vulnerability Database".
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/index.php?view=edit&id=.π Read
via "National Vulnerability Database".
βΌ CVE-2022-30034 βΌ
π Read
via "National Vulnerability Database".
Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RPC calls or deny service by shutting down Celery task nodes.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29712 βΌ
π Read
via "National Vulnerability Database".
LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and service_param parameters.π Read
via "National Vulnerability Database".
βΌ CVE-2022-31347 βΌ
π Read
via "National Vulnerability Database".
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=delete_vehicle.π Read
via "National Vulnerability Database".
βΌ CVE-2022-1797 βΌ
π Read
via "National Vulnerability Database".
A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix Controllers, resulting in a major nonrecoverable fault. If the target device becomes unavailable, a user would have to clear the fault and redownload the user project file to bring the device back online.π Read
via "National Vulnerability Database".
βΌ CVE-2022-23237 βΌ
π Read
via "National Vulnerability Database".
E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks that could allow an attacker to redirect users to malicious websites.π Read
via "National Vulnerability Database".
βΌ CVE-2022-32201 βΌ
π Read
via "National Vulnerability Database".
In libjpeg 1.63, there is a NULL pointer dereference in Component::SubXOf in component.hpp.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27781 βΌ
π Read
via "National Vulnerability Database".
libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to retrieve thatinformation.π Read
via "National Vulnerability Database".
βΌ CVE-2022-31953 βΌ
π Read
via "National Vulnerability Database".
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incident_reports/view_report.php?id=.π Read
via "National Vulnerability Database".
βΌ CVE-2022-32003 βΌ
π Read
via "National Vulnerability Database".
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/courts/view_court.php?id=.π Read
via "National Vulnerability Database".
βΌ CVE-2022-30831 βΌ
π Read
via "National Vulnerability Database".
Wedding Management System v1.0 is vulnerable to SQL Injection via Wedding-Management/wedding_details.php.π Read
via "National Vulnerability Database".
βΌ CVE-2022-31343 βΌ
π Read
via "National Vulnerability Database".
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/?page=bookings/view_details&id=.π Read
via "National Vulnerability Database".