Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-1752 1 Trudesk Project 1 Trudesk 2022-05-26 6.0 MEDIUM 8.0 HIGH
Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.2.
CVE-2022-27095 1 Battleye 1 Battleye 2022-05-26 7.2 HIGH 7.8 HIGH
BattlEye v0.9 contains an unquoted service path which allows attackers to escalate privileges to the system level.
CVE-2022-28995 1 Rengine Project 1 Rengine 2022-05-26 7.5 HIGH 9.8 CRITICAL
Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function.
CVE-2022-28990 1 Wasm3 Project 1 Wasm3 2022-05-26 4.6 MEDIUM 7.8 HIGH
WASM3 v0.5.0 was discovered to contain a heap overflow via the component /wabt/bin/poc.wasm.
CVE-2022-29639 1 Totolink 2 A3100r, A3100r Firmware 2022-05-26 9.3 HIGH 8.1 HIGH
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a command injection vulnerability via the magicid parameter in the function uci_cloudupdate_config.
CVE-2022-28531 1 Covid-19 Directory On Vaccination System Project 1 Covid-19 Directory On Vaccination System 2022-05-26 7.5 HIGH 9.8 CRITICAL
Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtusername (aka Username) field.
CVE-2022-1770 1 Trudesk Project 1 Trudesk 2022-05-26 6.5 MEDIUM 8.8 HIGH
Improper Privilege Management in GitHub repository polonel/trudesk prior to 1.2.2.
CVE-2022-30887 1 Pharmacy Management System Project 1 Pharmacy Management System 2022-05-26 7.5 HIGH 9.8 CRITICAL
Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.
CVE-2022-30886 1 School Dormitory Management System Project 1 School Dormitory Management System 2022-05-26 7.5 HIGH 9.8 CRITICAL
School Dormitory Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /dms/admin/reports/daily_collection_report.php.
CVE-2022-30518 1 Chatbot Application With A Suggestion Feature Project 1 Chatbot Application With A Suggestion Feature 2022-05-26 7.5 HIGH 9.8 CRITICAL
ChatBot Application with a Suggestion Feature 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /simple_chat_bot/admin/responses/view_response.php.
CVE-2022-29320 1 Minitool 1 Partition Wizard 2022-05-26 7.2 HIGH 7.8 HIGH
MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
CVE-2022-30957 1 Jenkins 1 Ssh 2022-05-26 4.0 MEDIUM 4.3 MEDIUM
A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
CVE-2022-30956 1 Jenkins 1 Rundeck 2022-05-26 3.5 LOW 5.4 MEDIUM
Jenkins Rundeck Plugin 3.6.10 and earlier does not restrict URL schemes in Rundeck webhook submissions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to submit crafted Rundeck webhook payloads.
CVE-2022-30955 1 Jenkins 1 Gitlab 2022-05-26 4.0 MEDIUM 6.5 MEDIUM
Jenkins GitLab Plugin 1.5.31 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
CVE-2022-30954 1 Jenkins 1 Blue Ocean 2022-05-26 4.0 MEDIUM 6.5 MEDIUM
Jenkins Blue Ocean Plugin 1.25.3 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP server.
CVE-2022-30953 1 Jenkins 1 Blue Ocean 2022-05-26 4.3 MEDIUM 6.5 MEDIUM
A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.25.3 and earlier allows attackers to connect to an attacker-specified HTTP server.
CVE-2022-29638 1 Totolink 2 A3100r, A3100r Firmware 2022-05-26 7.8 HIGH 7.5 HIGH
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the comment parameter in the function setIpQosRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
CVE-2022-30949 1 Jenkins 3 Git, Mercurial, Repo 2022-05-26 5.0 MEDIUM 5.3 MEDIUM
Jenkins REPO Plugin 1.14.0 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.
CVE-2022-30951 1 Jenkins 1 Wmi Windows Agents 2022-05-26 6.5 MEDIUM 8.8 HIGH
Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library does not implement access control, potentially allowing users to start processes even if they're not allowed to log in.
CVE-2022-30950 1 Jenkins 1 Wmi Windows Agents 2022-05-26 6.5 MEDIUM 8.8 HIGH
Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library which has a buffer overflow vulnerability that may allow users able to connect to a named pipe to execute commands on the Windows agent machine.