βΌ CVE-2022-30815 βΌ
π Read
via "National Vulnerability Database".
elitecms 1.01 is vulnerable to SQL Injection via admin/edit_sidebar.php?page=2&sidebar=π Read
via "National Vulnerability Database".
βΌ CVE-2022-30349 βΌ
π Read
via "National Vulnerability Database".
siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).π Read
via "National Vulnerability Database".
βΌ CVE-2021-44097 βΌ
π Read
via "National Vulnerability Database".
EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This allows a remote attacker to compromise Application SQL database.π Read
via "National Vulnerability Database".
βΌ CVE-2022-26975 βΌ
π Read
via "National Vulnerability Database".
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication.π Read
via "National Vulnerability Database".
βΌ CVE-2022-30514 βΌ
π Read
via "National Vulnerability Database".
School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.php:126.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27782 βΌ
π Read
via "National Vulnerability Database".
libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.π Read
via "National Vulnerability Database".
βΌ CVE-2022-31354 βΌ
π Read
via "National Vulnerability Database".
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=get_vehicle_service.π Read
via "National Vulnerability Database".
βΌ CVE-2022-31346 βΌ
π Read
via "National Vulnerability Database".
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=delete_service.π Read
via "National Vulnerability Database".
π΄ Building America's Cybersecurity Infrastructure π΄
π Read
via "Dark Reading".
The government is putting the right skills and expertise in place to fight the rising cyber threat.π Read
via "Dark Reading".
Dark Reading
Building America's Cybersecurity Infrastructure
The government is putting the right skills and expertise in place to fight the rising cyber threat.
π U.S. Warns of Karakurt Data Extortion Group π
π Read
via "".
The group reportedly obtains access to organizations either through stolen login credentials or already compromised victims.π Read
via "".
Digital Guardian
U.S. Warns of Karakurt Data Extortion Group
The group reportedly obtains access to organizations either through stolen login credentials or already compromised victims.
βΌ CVE-2022-31992 βΌ
π Read
via "National Vulnerability Database".
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=court_rentals/view_court_rental&id=.π Read
via "National Vulnerability Database".
βΌ CVE-2022-32013 βΌ
π Read
via "National Vulnerability Database".
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via eris/admin/category/index.php?view=edit&id=.π Read
via "National Vulnerability Database".
βΌ CVE-2022-31990 βΌ
π Read
via "National Vulnerability Database".
Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/classes/Master.php?f=delete_product.π Read
via "National Vulnerability Database".
βΌ CVE-2022-31988 βΌ
π Read
via "National Vulnerability Database".
Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/?page=reports/daily_services_report&date=.π Read
via "National Vulnerability Database".
βΌ CVE-2022-32007 βΌ
π Read
via "National Vulnerability Database".
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/company/index.php?view=edit&id=.π Read
via "National Vulnerability Database".
βΌ CVE-2022-32015 βΌ
π Read
via "National Vulnerability Database".
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=category&search=.π Read
via "National Vulnerability Database".
βΌ CVE-2022-31985 βΌ
π Read
via "National Vulnerability Database".
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=reports/daily_sales_report&date=.π Read
via "National Vulnerability Database".
βΌ CVE-2022-32024 βΌ
π Read
via "National Vulnerability Database".
Car Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=.π Read
via "National Vulnerability Database".
βΌ CVE-2022-31991 βΌ
π Read
via "National Vulnerability Database".
Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/classes/Master.php?f=delete_court.π Read
via "National Vulnerability Database".
βΌ CVE-2022-32016 βΌ
π Read
via "National Vulnerability Database".
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=bycompany.π Read
via "National Vulnerability Database".
βΌ CVE-2022-31018 βΌ
π Read
via "National Vulnerability Database".
Play Framework is a web framework for Java and Scala. A denial of service vulnerability has been discovered in verions 2.8.3 through 2.8.15 of Play's forms library, in both the Scala and Java APIs. This can occur when using either the `Form#bindFromRequest` method on a JSON request body or the `Form#bind` method directly on a JSON value. If the JSON data being bound to the form contains a deeply-nested JSON object or array, the form binding implementation may consume all available heap space and cause an `OutOfMemoryError`. If executing on the default dispatcher and `akka.jvm-exit-on-fatal-error` is enabledΓΒ’Γ’β¬Òβ¬οΏ½as it is by defaultΓΒ’Γ’β¬Òβ¬οΏ½then this can crash the application process. `Form.bindFromRequest` is vulnerable when using any body parser that produces a type of `AnyContent` or `JsValue` in Scala, or one that can produce a `JsonNode` in Java. This includes Play's default body parser. This vulnerability been patched in version 2.8.16. There is now a global limit on the depth of a JSON object that can be parsed, which can be configured by the user if necessary. As a workaround, applications that do not need to parse a request body of type `application/json` can switch from the default body parser to another body parser that supports only the specific type of body they expect.π Read
via "National Vulnerability Database".