Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-20290 | 1 Google | 1 Android | 2022-08-16 | N/A | 5.5 MEDIUM |
In Midi, there is a possible way to learn about private midi devices due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-203549963 | |||||
CVE-2022-37397 | 1 Yugabyte | 1 Yugabytedb | 2022-08-16 | N/A | 9.8 CRITICAL |
An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password. | |||||
CVE-2022-2804 | 1 Zoo Management System Project | 1 Zoo Management System | 2022-08-16 | N/A | 9.8 CRITICAL |
A vulnerability was found in SourceCodester Zoo Management System. It has been classified as critical. Affected is an unknown function of the file /pages/apply_vacancy.php. The manipulation of the argument filename leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-206250 is the identifier assigned to this vulnerability. | |||||
CVE-2022-2803 | 1 Zoo Management System Project | 1 Zoo Management System | 2022-08-16 | N/A | 9.8 CRITICAL |
A vulnerability was found in SourceCodester Zoo Management System and classified as critical. This issue affects some unknown processing of the file /pages/animals.php. The manipulation of the argument class_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206249 was assigned to this vulnerability. | |||||
CVE-2022-2802 | 1 Gas Agency Management System Project | 1 Gas Agency Management System | 2022-08-16 | N/A | 9.8 CRITICAL |
A vulnerability has been found in SourceCodester Gas Agency Management System and classified as critical. This vulnerability affects unknown code of the file gasmark/login.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-206248. | |||||
CVE-2022-20332 | 1 Google | 1 Android | 2022-08-16 | N/A | 5.5 MEDIUM |
In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-180019130 | |||||
CVE-2022-2801 | 1 Automated Beer Parlour Billing System Project | 1 Automated Beer Parlour Billing System | 2022-08-16 | N/A | 9.8 CRITICAL |
A vulnerability, which was classified as critical, was found in SourceCodester Automated Beer Parlour Billing System. This affects an unknown part of the component Login. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-206247. | |||||
CVE-2022-2800 | 1 Gym Management System Project | 1 Gym Management System | 2022-08-16 | N/A | 6.1 MEDIUM |
A vulnerability, which was classified as problematic, has been found in SourceCodester Gym Management System. Affected by this issue is some unknown functionality. The manipulation leads to clickjacking. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-206246 is the identifier assigned to this vulnerability. | |||||
CVE-2022-35980 | 1 Amazon | 1 Opensearch | 2022-08-16 | N/A | 7.5 HIGH |
OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. Versions 2.0.0.0 and 2.1.0.0 of the security plugin are affected by an information disclosure vulnerability. Requests to an OpenSearch cluster configured with advanced access control features document level security (DLS), field level security (FLS), and/or field masking will not be filtered when the query's search pattern matches an aliased index. OpenSearch Dashboards creates an alias to `.kibana` by default, so filters with the index pattern of `*` to restrict access to documents or fields will not be applied. This issue allows requests to access sensitive information when customer have acted to restrict access that specific information. OpenSearch 2.2.0, which is compatible with OpenSearch Security 2.2.0.0, contains the fix for this issue. There is no recommended work around. | |||||
CVE-2022-20289 | 1 Google | 1 Android | 2022-08-16 | N/A | 5.5 MEDIUM |
In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-203683960 | |||||
CVE-2022-37423 | 1 Neo4j | 1 Awesome Procedures On Cypher | 2022-08-16 | N/A | 7.5 HIGH |
Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to sibling directories via apoc.log.stream. | |||||
CVE-2022-37044 | 1 Zimbra | 1 Collaboration | 2022-08-16 | N/A | 6.1 MEDIUM |
In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/search?action accepts parameters called extra, title, and onload that are partially sanitised and lead to reflected XSS that allows executing arbitrary JavaScript on the victim's machine. | |||||
CVE-2022-37043 | 1 Zimbra | 1 Collaboration | 2022-08-16 | N/A | 5.7 MEDIUM |
An issue was discovered in the webmail component in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. When using preauth, CSRF tokens are not checked on some POST endpoints. Thus, when an authenticated user views an attacker-controlled page, a request will be sent to the application that appears to be intended. The CSRF token is omitted from the request, but the request still succeeds. | |||||
CVE-2022-37041 | 1 Zimbra | 1 Collaboration | 2022-08-16 | N/A | 7.5 HIGH |
An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. The value of the X-Forwarded-Host header overwrites the value of the Host header in proxied requests. The value of X-Forwarded-Host header is not checked against the whitelist of hosts that ZCS is allowed to proxy to (the zimbraProxyAllowedDomains setting). | |||||
CVE-2022-35561 | 1 Tenda | 2 W6, W6 Firmware | 2022-08-16 | N/A | 7.5 HIGH |
A stack overflow vulnerability exists in /goform/WifiMacFilterSet in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter. | |||||
CVE-2022-35560 | 1 Tenda | 2 W6, W6 Firmware | 2022-08-16 | N/A | 7.5 HIGH |
A stack overflow vulnerability exists in /goform/wifiSSIDset in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter. | |||||
CVE-2022-35559 | 1 Tenda | 2 W6, W6 Firmware | 2022-08-16 | N/A | 9.8 CRITICAL |
A stack overflow vulnerability exists in /goform/setAutoPing in Tenda W6 V1.0.0.9(4122), which allows an attacker to construct ping1 parameters and ping2 parameters for a stack overflow attack. An attacker can use this vulnerability to execute arbitrary code execution. | |||||
CVE-2022-35558 | 1 Tenda | 2 W6, W6 Firmware | 2022-08-16 | N/A | 7.5 HIGH |
A stack overflow vulnerability exists in /goform/WifiMacFilterGet in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter. | |||||
CVE-2022-35557 | 1 Tenda | 2 W6, W6 Firmware | 2022-08-16 | N/A | 7.5 HIGH |
A stack overflow vulnerability exists in /goform/wifiSSIDget in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter. | |||||
CVE-2022-35555 | 1 Tenda | 2 W6, W6 Firmware | 2022-08-16 | N/A | 9.8 CRITICAL |
A command injection vulnerability exists in /goform/exeCommand in Tenda W6 V1.0.0.9(4122), which allows attackers to construct cmdinput parameters for arbitrary command execution. |