Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-36484 1 Totolink 2 N350rt, N350rt Firmware 2022-08-25 N/A 7.8 HIGH
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the function setDiagnosisCfg.
CVE-2022-36482 1 Totolink 2 N350rt, N350rt Firmware 2022-08-25 N/A 7.8 HIGH
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the lang parameter in the function setLanguageCfg.
CVE-2022-36479 1 Totolink 2 N350rt, N350rt Firmware 2022-08-25 N/A 7.8 HIGH
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the host_time parameter in the function NTPSyncWithHost.
CVE-2022-36466 1 Totolink 2 A3700r, A3700r Firmware 2022-08-25 N/A 7.8 HIGH
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the ip parameter in the function setDiagnosisCfg.
CVE-2022-36465 1 Totolink 2 A3700r, A3700r Firmware 2022-08-25 N/A 7.8 HIGH
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the pppoeUser parameter.
CVE-2022-36481 1 Totolink 2 N350rt, N350rt Firmware 2022-08-25 N/A 7.8 HIGH
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the ip parameter in the function setDiagnosisCfg.
CVE-2022-36480 1 Totolink 2 N350rt, N350rt Firmware 2022-08-25 N/A 7.8 HIGH
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the command parameter in the function setTracerouteCfg.
CVE-2022-36463 1 Totolink 2 A3700r, A3700r Firmware 2022-08-25 N/A 7.8 HIGH
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the command parameter in the function setTracerouteCfg.
CVE-2022-36488 1 Totolink 2 N350rt, N350rt Firmware 2022-08-25 N/A 7.8 HIGH
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the sPort parameter in the function setIpPortFilterRules.
CVE-2022-36483 1 Totolink 2 N350rt, N350rt Firmware 2022-08-25 N/A 7.8 HIGH
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the pppoeUser parameter.
CVE-2022-36464 1 Totolink 2 A3700r, A3700r Firmware 2022-08-25 N/A 7.8 HIGH
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the sPort parameter in the function setIpPortFilterRules.
CVE-2022-36456 1 Totolink 2 A720r, A720r Firmware 2022-08-25 N/A 7.8 HIGH
TOTOLink A720R V4.1.5cu.532_B20210610 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.
CVE-2022-37074 1 H3c 2 Gr-1200w Firmware, Gr-120w 2022-08-25 N/A 7.8 HIGH
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function switch_debug_info_set.
CVE-2022-37241 1 Altn 1 Security Gateway For Email Servers 2022-08-25 N/A 5.4 MEDIUM
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the data_leak_list_ajax endpoint.
CVE-2022-37239 1 Altn 1 Security Gateway For Email Servers 2022-08-25 N/A 5.4 MEDIUM
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the rulles_list_ajax endpoint.
CVE-2022-37245 1 Altn 1 Security Gateway For Email Servers 2022-08-25 N/A 5.4 MEDIUM
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the Blacklist endpoint.
CVE-2022-37243 1 Altn 1 Security Gateway For Email Servers 2022-08-25 N/A 5.4 MEDIUM
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the whitelist endpoint.
CVE-2022-35235 1 Xplodedthemes 1 Wpide - File Manager \& Code Editor 2022-08-25 N/A 4.9 MEDIUM
Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
CVE-2022-35726 1 Yotuwp 1 Video Gallery 2022-08-25 N/A 9.8 CRITICAL
Broken Authentication vulnerability in yotuwp Video Gallery plugin <= 1.3.4.5 at WordPress.
CVE-2022-36282 1 Search Exclude Project 1 Search Exclude 2022-08-25 N/A 5.4 MEDIUM
Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Roman Pronskiy's Search Exclude plugin <= 1.2.6 at WordPress.