Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-26536 | 1 Tenda | 2 M3, M3 Firmware | 2022-03-29 | 10.0 HIGH | 9.8 CRITICAL |
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setFixTools. | |||||
CVE-2022-27083 | 1 Tenda | 2 M3, M3 Firmware | 2022-03-29 | 10.0 HIGH | 9.8 CRITICAL |
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadAccessCodePic. | |||||
CVE-2022-26290 | 1 Tenda | 2 M3, M3 Firmware | 2022-03-29 | 10.0 HIGH | 9.8 CRITICAL |
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/WriteFacMac. | |||||
CVE-2022-27082 | 1 Tenda | 2 M3, M3 Firmware | 2022-03-29 | 10.0 HIGH | 9.8 CRITICAL |
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetInternetLanInfo. | |||||
CVE-2022-26289 | 1 Tenda | 2 M3, M3 Firmware | 2022-03-29 | 10.0 HIGH | 9.8 CRITICAL |
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/exeCommand. | |||||
CVE-2020-24772 | 1 Clash Project | 1 Clash | 2022-03-29 | 6.8 MEDIUM | 8.8 HIGH |
In Dreamacro Clash for Windows v0.11.4, an attacker could embed a malicious iframe in a website with a crafted URL that would launch the Clash Windows client and force it to open a remote SMB share. Windows will perform NTLM authentication when opening the SMB share and that request can be relayed (using a tool like responder) for code execution (or captured for hash cracking). | |||||
CVE-2022-24236 | 1 Snapt | 1 Aria | 2022-03-29 | 3.5 LOW | 3.5 LOW |
An insecure permissions vulnerability in Snapt Aria v12.8 allows unauthenticated attackers to send e-mails from spoofed users' accounts. | |||||
CVE-2022-25041 | 1 Open-emr | 1 Openemr | 2022-03-29 | 4.0 MEDIUM | 4.3 MEDIUM |
OpenEMR v6.0.0 was discovered to contain an incorrect access control issue. | |||||
CVE-2022-0859 | 1 Mcafee | 1 Epolicy Orchestrator | 2022-03-29 | 4.4 MEDIUM | 6.4 MEDIUM |
McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to point an ePO server to an arbitrary SQL server during the restoration of the ePO server. To achieve this the attacker would have to be logged onto the server hosting the ePO server (restricted to administrators) and to know the SQL server password. | |||||
CVE-2021-40662 | 1 Chamilo | 1 Chamilo | 2022-03-29 | 6.8 MEDIUM | 8.8 HIGH |
A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a crafted URL. | |||||
CVE-2022-0858 | 1 Mcafee | 1 Epolicy Orchestrator | 2022-03-29 | 4.3 MEDIUM | 6.1 MEDIUM |
A cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the attacker to click on a carefully crafted link. This would lead to limited ability to alter some information in ePO due to the area of the User Interface the vulnerability is present in. | |||||
CVE-2022-0842 | 1 Mcafee | 1 Epolicy Orchestrator | 2022-03-29 | 4.0 MEDIUM | 4.9 MEDIUM |
A blind SQL injection vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote authenticated attacker to potentially obtain information from the ePO database. The data obtained is dependent on the privileges the attacker has and to obtain sensitive data the attacker would require administrator privileges. | |||||
CVE-2022-0857 | 1 Mcafee | 1 Epolicy Orchestrator | 2022-03-29 | 4.3 MEDIUM | 6.1 MEDIUM |
A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the attacker to click on a carefully crafted link. This would lead to limited access to sensitive information and limited ability to alter some information in ePO due to the area of the User Interface the vulnerability is present in. | |||||
CVE-2021-38745 | 1 Chamilo | 1 Chamilo | 2022-03-29 | 4.6 MEDIUM | 6.8 MEDIUM |
Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction with the attacker's profile page. | |||||
CVE-2022-1072 | 2022-03-28 | N/A | N/A | ||
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-26254. Reason: This candidate is a reservation duplicate of CVE-2022-26254. Notes: All CVE users should reference CVE-2022-26254 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. | |||||
CVE-2022-27090 | 1 Chshcms | 1 Cscms | 2022-03-28 | 4.9 MEDIUM | 5.4 MEDIUM |
Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter. | |||||
CVE-2022-24775 | 2 Drupal, Guzzlephp | 2 Drupal, Psr-7 | 2022-03-28 | 5.0 MEDIUM | 7.5 HIGH |
guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There are currently no known workarounds. | |||||
CVE-2021-39384 | 1 Diaowen | 1 Dwsurvey | 2022-03-28 | 7.5 HIGH | 9.8 CRITICAL |
DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.java. | |||||
CVE-2022-25481 | 1 Thinkphp | 1 Thinkphp | 2022-03-28 | 5.0 MEDIUM | 7.5 HIGH |
ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. | |||||
CVE-2022-25505 | 1 Taogogo | 1 Taocms | 2022-03-28 | 7.5 HIGH | 9.8 CRITICAL |
Taocms v3.0.2 was discovered to contain a SQL injection vulnerability via the id parameter in \include\Model\Category.php. |