βΌ CVE-2022-23768 βΌ
π Read
via "National Vulnerability Database".
This Vulnerability in NIS-HAP11AC is caused by an exposed external port for the telnet service. Remote attackers use this vulnerability to induce all attacks such as source code hijacking, remote control of the device.π Read
via "National Vulnerability Database".
βΌ CVE-2022-28204 βΌ
π Read
via "National Vulnerability Database".
A denial-of-service issue was discovered in MediaWiki 1.37.x before 1.37.2. Rendering of w/index.php?title=Special%3AWhatLinksHere&target=Property%3AP31&namespace=1&invert=1 can take more than thirty seconds. There is a DDoS risk.π Read
via "National Vulnerability Database".
βΌ CVE-2022-23767 βΌ
π Read
via "National Vulnerability Database".
This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform various attacks such as obtaining privileges and executing remote code, thereby taking over the victimΓ’β¬β’s system.π Read
via "National Vulnerability Database".
βΌ CVE-2022-23766 βΌ
π Read
via "National Vulnerability Database".
An improper input validation vulnerability leading to arbitrary file execution was discovered in BigFileAgent. In order to cause arbitrary files to be executed, the attacker makes the victim access a web page d by them or inserts a script using XSS into a general website.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35066 βΌ
π Read
via "National Vulnerability Database".
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e41b8.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35069 βΌ
π Read
via "National Vulnerability Database".
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b544e.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35063 βΌ
π Read
via "National Vulnerability Database".
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e41a8.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35061 βΌ
π Read
via "National Vulnerability Database".
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e412a.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38550 βΌ
π Read
via "National Vulnerability Database".
A stored cross-site scripting (XSS) vulnerability in the /weibo/list component of Jeesns v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35070 βΌ
π Read
via "National Vulnerability Database".
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x65fc97.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35060 βΌ
π Read
via "National Vulnerability Database".
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c0a32.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35064 βΌ
π Read
via "National Vulnerability Database".
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x4adcdb in __asan_memset.π Read
via "National Vulnerability Database".
βΌ CVE-2022-28321 βΌ
π Read
via "National Vulnerability Database".
The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user tries to connect from an IP address that is not resolvable via DNS. In such conditions, a user with denied access to a machine can still get access. NOTE: the relevance of this issue is largely limited to openSUSE Tumbleweed and openSUSE Factory; it does not affect Linux-PAM upstream.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35065 βΌ
π Read
via "National Vulnerability Database".
OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x65f724.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38545 βΌ
π Read
via "National Vulnerability Database".
Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38509 βΌ
π Read
via "National Vulnerability Database".
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budget.php.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38532 βΌ
π Read
via "National Vulnerability Database".
Micro-Star International Co., Ltd MSI Center 1.0.50.0 was discovered to contain a vulnerability in the component C_Features of MSI.CentralServer.exe. This vulnerability allows attackers to escalate privileges via running a crafted executable.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35062 βΌ
π Read
via "National Vulnerability Database".
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c0bc3.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38527 βΌ
π Read
via "National Vulnerability Database".
UCMS v1.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Import function under the Site Management page.π Read
via "National Vulnerability Database".
βΌ CVE-2022-35068 βΌ
π Read
via "National Vulnerability Database".
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e420d.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0143 βΌ
π Read
via "National Vulnerability Database".
When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Server (RCS)π Read
via "National Vulnerability Database".