Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-30604 | 1 Cybozu | 1 Office | 2022-08-18 | N/A | 6.1 MEDIUM |
Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors. | |||||
CVE-2022-2876 | 1 Student Management System Project | 1 Student Management System | 2022-08-18 | N/A | 9.8 CRITICAL |
A vulnerability, which was classified as critical, was found in SourceCodester Student Management System. Affected is an unknown function of the file index.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-206634 is the identifier assigned to this vulnerability. | |||||
CVE-2022-29891 | 1 Cybozu | 1 Office | 2022-08-18 | N/A | 4.3 MEDIUM |
Browse restriction bypass vulnerability in Custom Ap of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Custom App via unspecified vectors. | |||||
CVE-2022-29487 | 1 Cybozu | 1 Office | 2022-08-18 | N/A | 6.1 MEDIUM |
Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors. | |||||
CVE-2022-28715 | 1 Cybozu | 1 Office | 2022-08-18 | N/A | 6.1 MEDIUM |
Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors. | |||||
CVE-2022-25986 | 1 Cybozu | 1 Office | 2022-08-18 | N/A | 4.3 MEDIUM |
Browse restriction bypass vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Scheduler. | |||||
CVE-2022-36216 | 1 Dedecms | 1 Dedecms | 2022-08-18 | N/A | 7.2 HIGH |
DedeCMS v5.7.94 - v5.7.97 was discovered to contain a remote code execution vulnerability in member_toadmin.php. | |||||
CVE-2022-36215 | 1 Dedebiz | 1 Dedecmsv6 | 2022-08-18 | N/A | 7.2 HIGH |
DedeBIZ v6 was discovered to contain a remote code execution vulnerability in sys_info.php. | |||||
CVE-2022-35516 | 1 Dedecms | 1 Dedecms | 2022-08-18 | N/A | 9.8 CRITICAL |
DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php. | |||||
CVE-2022-35121 | 1 Novel-plus Project | 1 Novel-plus | 2022-08-18 | N/A | 9.8 CRITICAL |
Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java. | |||||
CVE-2022-2335 | 1 Softing | 6 Edgeaggregator, Edgeconnector, Opc and 3 more | 2022-08-18 | N/A | 7.5 HIGH |
A crafted HTTP packet with a -1 content-length header can create a denial-of-service condition in Softing Secure Integration Server V1.22. | |||||
CVE-2022-2337 | 1 Softing | 6 Edgeaggregator, Edgeconnector, Opc and 3 more | 2022-08-18 | N/A | 7.5 HIGH |
A crafted HTTP packet with a missing HTTP URI can create a denial-of-service condition in Softing Secure Integration Server V1.22. | |||||
CVE-2022-2547 | 1 Softing | 6 Edgeaggregator, Edgeconnector, Opc and 3 more | 2022-08-18 | N/A | 7.5 HIGH |
A crafted HTTP packet without a content-type header can create a denial-of-service condition in Softing Secure Integration Server V1.22. | |||||
CVE-2022-2870 | 1 Laravel | 1 Laravel | 2022-08-18 | N/A | 9.8 CRITICAL |
A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206501 was assigned to this vulnerability. | |||||
CVE-2022-35117 | 1 Clinic\'s Patient Management System Project | 1 Clinic\'s Patient Management System | 2022-08-18 | N/A | 4.8 MEDIUM |
Clinic's Patient Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via update_medicine_details.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Packing text box under the Update Medical Details module. | |||||
CVE-2022-35147 | 1 Html-js | 1 Doracms | 2022-08-18 | N/A | 9.8 CRITICAL |
DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request. | |||||
CVE-2022-36191 | 1 Gpac | 1 Gpac | 2022-08-18 | N/A | 5.5 MEDIUM |
A heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isomedia/avc_ext.c:2490, as demonstrated by MP4Box. This vulnerability was fixed in commit fef6242. | |||||
CVE-2022-22455 | 1 Ibm | 1 Security Verify Governance | 2022-08-18 | N/A | 9.8 CRITICAL |
IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 224989. | |||||
CVE-2022-28751 | 1 Zoom | 1 Meetings | 2022-08-18 | N/A | 7.8 HIGH |
The Zoom Client for Meetings for MacOS (Standard and for IT Admin) before version 5.11.3 contains a vulnerability in the package signature validation during the update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root. | |||||
CVE-2022-35133 | 1 Cherrytree Project | 1 Cherrytree | 2022-08-18 | N/A | 6.1 MEDIUM |
A cross-site scripting (XSS) vulnerability in CherryTree v0.99.30 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field when creating a node. |