Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-31941 | 1 Rescue Dispatch Management System Project | 1 Rescue Dispatch Management System | 2022-06-28 | 7.5 HIGH | 9.8 CRITICAL |
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via \rdms\admin?page=user\manage_user&id=. | |||||
CVE-2022-32444 | 1 Yuba | 1 U5cms | 2022-06-28 | 5.8 MEDIUM | 6.1 MEDIUM |
An issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser to be redirected to another site via /loginsave.php. | |||||
CVE-2022-22317 | 5 Hp, Ibm, Linux and 2 more | 7 Hp-ux, Aix, Curam Social Program Management and 4 more | 2022-06-28 | 7.5 HIGH | 9.8 CRITICAL |
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281. | |||||
CVE-2022-22318 | 5 Hp, Ibm, Linux and 2 more | 7 Hp-ux, Aix, Curam Social Program Management and 4 more | 2022-06-28 | 6.5 MEDIUM | 9.8 CRITICAL |
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. | |||||
CVE-2022-30422 | 1 Proietti | 1 Planet Time Enterprise | 2022-06-28 | 10.0 HIGH | 9.8 CRITICAL |
Proietti Tech srl Planet Time Enterprise 4.2.0.1,4.2.0.0,4.1.0.0,4.0.0.0,3.3.1.0,3.3.0.0 is vulnerable to Remote code execution via the Viewstate parameter. | |||||
CVE-2022-22414 | 2 Ibm, Microsoft | 2 Robotic Process Automation, Windows | 2022-06-28 | 2.1 LOW | 5.5 MEDIUM |
IBM Robotic Process Automation 21.0.2 could allow a local user to obtain sensitive web service configuration credentials from system memory. IBM X-Force ID: 223026. | |||||
CVE-2022-2128 | 1 Trudesk Project | 1 Trudesk | 2022-06-28 | 7.5 HIGH | 9.8 CRITICAL |
Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4. | |||||
CVE-2022-31355 | 1 Online Ordering System Project | 1 Online Ordering System | 2022-06-27 | 7.5 HIGH | 9.8 CRITICAL |
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=. | |||||
CVE-2022-31356 | 1 Online Ordering System Project | 1 Online Ordering System | 2022-06-27 | 7.5 HIGH | 9.8 CRITICAL |
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=. | |||||
CVE-2022-31357 | 1 Online Ordering System Project | 1 Online Ordering System | 2022-06-27 | 7.5 HIGH | 9.8 CRITICAL |
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=. | |||||
CVE-2022-31296 | 1 Online Discussion Forum Project | 1 Online Discussion Forum | 2022-06-27 | 7.5 HIGH | 9.8 CRITICAL |
Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php. | |||||
CVE-2021-45026 | 1 Rocketsoftware | 1 Ags-zena | 2022-06-27 | 4.3 MEDIUM | 6.1 MEDIUM |
ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS). | |||||
CVE-2021-45025 | 1 Rocketsoftware | 1 Ags-zena | 2022-06-27 | 5.0 MEDIUM | 7.5 HIGH |
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of Sensitive Information in a Cookie. | |||||
CVE-2021-45024 | 1 Rocketsoftware | 1 Ags-zena | 2022-06-27 | 7.5 HIGH | 9.8 CRITICAL |
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE). | |||||
CVE-2021-41490 | 1 Rice | 1 Open Motion Planning Library | 2022-06-27 | 5.0 MEDIUM | 7.5 HIGH |
Memory leaks in LazyPRM.cpp of OMPL v1.5.0 can cause unexpected behavior. | |||||
CVE-2021-41408 | 1 Voipmonitor | 1 Voipmonitor | 2022-06-27 | 7.5 HIGH | 9.8 CRITICAL |
VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter. | |||||
CVE-2019-12352 | 1 Zzcms | 1 Zzcms | 2022-06-27 | 6.5 MEDIUM | 8.8 HIGH |
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendmail.php (when the attacker has dls_print authority) via a dlid cookie. | |||||
CVE-2018-25040 | 1 Utorrent | 1 Web | 2022-06-27 | 6.8 MEDIUM | 8.8 HIGH |
A vulnerability was found in uTorrent Web. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component HTTP RPC Server. The manipulation leads to privilege escalation. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. | |||||
CVE-2022-30329 | 1 Trendnet | 2 Tew-831dr, Tew-831dr Firmware | 2022-06-27 | 10.0 HIGH | 9.8 CRITICAL |
An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. An OS injection vulnerability exists within the web interface, allowing an attacker with valid credentials to execute arbitrary shell commands. | |||||
CVE-2022-30325 | 1 Trendnet | 2 Tew-831dr, Tew-831dr Firmware | 2022-06-27 | 3.3 LOW | 8.8 HIGH |
An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The default pre-shared key for the Wi-Fi networks is the same for every router except for the last four digits. The device default pre-shared key for both 2.4 GHz and 5 GHz networks can be guessed or brute-forced by an attacker within range of the Wi-Fi network. |