βΌ CVE-2022-3385 βΌ
π Read
via "National Vulnerability Database".
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stack buffer and enable remote code execution.π Read
via "National Vulnerability Database".
βΌ CVE-2022-41773 βΌ
π Read
via "National Vulnerability Database".
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckDIACloud. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.π Read
via "National Vulnerability Database".
βΌ CVE-2022-41701 βΌ
π Read
via "National Vulnerability Database".
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutShift API.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0074 βΌ
π Read
via "National Vulnerability Database".
Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server Container allows Privilege Escalation. This affects versions from 1.6.15 before 1.7.16.1.π Read
via "National Vulnerability Database".
βΌ CVE-2022-43340 βΌ
π Read
via "National Vulnerability Database".
A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and grant Administrator rights to regular users.π Read
via "National Vulnerability Database".
βΌ CVE-2022-41627 βΌ
π Read
via "National Vulnerability Database".
The physical IoT device of the AliveCor's KardiaMobile, a smartphone-based personal electrocardiogram (EKG) has no encryption for its data-over-sound protocols. Exploiting this vulnerability could allow an attacker to read patient EKG results or create a denial-of-service condition by emitting sounds at similar frequencies as the device, disrupting the smartphone microphoneΓ’β¬β’s ability to accurately read the data. To carry out this attack, the attacker must be close (less than 5 feet) to pick up and emit sound waves.π Read
via "National Vulnerability Database".
βΌ CVE-2022-3386 βΌ
π Read
via "National Vulnerability Database".
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename to overflow the stack buffer and enable remote code execution.π Read
via "National Vulnerability Database".
βΌ CVE-2022-41133 βΌ
π Read
via "National Vulnerability Database".
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in GetDIAE_line_message_settingsListParameters. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.π Read
via "National Vulnerability Database".
βΌ CVE-2022-39976 βΌ
π Read
via "National Vulnerability Database".
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /modules/announcement/index.php?view=edit&id=.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40876 βΌ
π Read
via "National Vulnerability Database".
In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can cause a stack overflow and enable remote code execution (RCE).π Read
via "National Vulnerability Database".
βΌ CVE-2022-39977 βΌ
π Read
via "National Vulnerability Database".
Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in the User module. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file uploaded through the picture upload point.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40965 βΌ
π Read
via "National Vulnerability Database".
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PostEnergyType API.π Read
via "National Vulnerability Database".
βΌ CVE-2022-41651 βΌ
π Read
via "National Vulnerability Database".
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the SetPF API.π Read
via "National Vulnerability Database".
βΌ CVE-2022-41702 βΌ
π Read
via "National Vulnerability Database".
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the InsertReg API.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40967 βΌ
π Read
via "National Vulnerability Database".
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckIoTHubNameExisted. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0073 βΌ
π Read
via "National Vulnerability Database".
Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server Dashboard allows Command Injection. This affects 1.7.0 versions before 1.7.16.1.π Read
via "National Vulnerability Database".
βΌ CVE-2022-3387 βΌ
π Read
via "National Vulnerability Database".
Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks. An unauthorized attacker could remotely exploit vulnerable PHP code to delete .PDF files.π Read
via "National Vulnerability Database".
βΌ CVE-2021-38395 βΌ
π Read
via "National Vulnerability Database".
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.π Read
via "National Vulnerability Database".
βΌ CVE-2021-38399 βΌ
π Read
via "National Vulnerability Database".
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauthorized files and directories.π Read
via "National Vulnerability Database".
βΌ CVE-2022-37914 βΌ
π Read
via "National Vulnerability Database".
Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to bypass authentication. Successful exploitation of these vulnerabilities could allow an attacker to gain administrative privileges leading to a complete compromise of the Aruba EdgeConnect Enterprise Orchestrator with versions 9.1.2.40051 and below, 9.0.7.40108 and below, 8.10.23.40009 and below, and any older branches of Orchestrator not specifically mentioned.π Read
via "National Vulnerability Database".
βΌ CVE-2022-31678 βΌ
π Read
via "National Vulnerability Database".
VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.π Read
via "National Vulnerability Database".
π1