Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-29103 | 1 Microsoft | 10 Windows 10, Windows 11, Windows 7 and 7 more | 2022-05-20 | 4.6 MEDIUM | 7.8 HIGH |
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability. | |||||
CVE-2022-1681 | 1 Requarks | 1 Wiki.js | 2022-05-20 | 9.0 HIGH | 7.2 HIGH |
Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions | |||||
CVE-2022-1044 | 1 Trudesk Project | 1 Trudesk | 2022-05-20 | 4.3 MEDIUM | 6.5 MEDIUM |
Sensitive Data Exposure Due To Insecure Storage Of Profile Image in GitHub repository polonel/trudesk prior to v1.2.1. | |||||
CVE-2022-28269 | 3 Adobe, Apple, Microsoft | 6 Acrobat, Acrobat Dc, Acrobat Reader and 3 more | 2022-05-20 | 4.3 MEDIUM | 3.3 LOW |
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of Annotation objects that could result in a memory leak in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
CVE-2022-29303 | 1 Contec | 2 Sv-cpt-mc310, Sv-cpt-mc310 Firmware | 2022-05-20 | 10.0 HIGH | 9.8 CRITICAL |
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php. | |||||
CVE-2022-29302 | 1 Contec | 2 Sv-cpt-mc310, Sv-cpt-mc310 Firmware | 2022-05-20 | 2.1 LOW | 5.5 MEDIUM |
SolarView Compact ver.6.00 was discovered to contain a local file disclosure via /html/Solar_Ftp.php. | |||||
CVE-2022-30592 | 1 Litespeedtech | 1 Lsquic | 2022-05-20 | 7.5 HIGH | 9.8 CRITICAL |
liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY. | |||||
CVE-2022-26934 | 1 Microsoft | 10 Windows 10, Windows 11, Windows 7 and 7 more | 2022-05-20 | 4.3 MEDIUM | 6.5 MEDIUM |
Windows Graphics Component Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-22011, CVE-2022-29112. | |||||
CVE-2022-30557 | 2 Foxit, Microsoft | 3 Pdf Editor, Pdf Reader, Windows | 2022-05-20 | 5.0 MEDIUM | 7.5 HIGH |
Foxit PDF Reader and PDF Editor before 11.2.2 have a Type Confusion issue that causes a crash because of Unsigned32 mishandling during JavaScript execution. | |||||
CVE-2022-29845 | 1 Ipswitch | 1 Whatsup Gold | 2022-05-20 | 4.0 MEDIUM | 6.5 MEDIUM |
In Progress Ipswitch WhatsUp Gold 21.1.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would allow them to read the contents of a local file. | |||||
CVE-2022-29596 | 1 Microstrategy | 1 Enterprise Manager | 2022-05-20 | 7.5 HIGH | 9.8 CRITICAL |
MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../../../../../../../windows/win.ini%00.jpg&Pwd=_any_password_&ConnMode=1&3054=Login substring for directory traversal. | |||||
CVE-2021-42648 | 1 Coder | 1 Code-server | 2022-05-20 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability exists in Coder Code-Server before 3.12.0, allows attackers to execute arbitrary code via crafted URL. | |||||
CVE-2022-30451 | 1 Waimairencms Project | 1 Waimairencms | 2022-05-20 | 6.5 MEDIUM | 8.8 HIGH |
An authenticated user could execute code via a SQLi vulnerability in waimairenCMS before version 9.1. | |||||
CVE-2022-30450 | 1 Waimairencms Project | 1 Waimairencms | 2022-05-20 | 7.5 HIGH | 9.8 CRITICAL |
A Remote Code Execution (RCE) vulnerability exists in waimairen 9.1 via wx.php | |||||
CVE-2022-30449 | 1 Hospital Management System Project | 1 Hospital Management System | 2022-05-20 | 7.5 HIGH | 9.8 CRITICAL |
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in room.php. | |||||
CVE-2022-30448 | 1 Hospital Management System Project | 1 Hospital Management System | 2022-05-20 | 7.5 HIGH | 9.8 CRITICAL |
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrecord.php. | |||||
CVE-2022-30063 | 1 Ftcms | 1 Ftcms | 2022-05-20 | 7.5 HIGH | 9.8 CRITICAL |
ftcms <=2.1 was discovered to be vulnerable to code execution attacks . | |||||
CVE-2022-30453 | 1 Shopwind | 1 Shopwind | 2022-05-20 | 7.5 HIGH | 9.8 CRITICAL |
ShopWind <= 3.4.2 has a RCE vulnerability in Database.php | |||||
CVE-2022-30452 | 1 Shopwind | 1 Shopwind | 2022-05-20 | 6.5 MEDIUM | 7.2 HIGH |
ShopWind <= v3.4.2 has a Sql injection vulnerability in Database.php | |||||
CVE-2022-30062 | 1 Ftcms | 1 Ftcms | 2022-05-20 | 4.0 MEDIUM | 6.5 MEDIUM |
ftcms <=2.1 was discovered to be vulnerable to Arbitrary File Read via tp.php |