Search

Search Results (19877 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-30914 1 H3c 2 Magic R100, Magic R100 Firmware 2024-11-21 9.8 Critical
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the UpdateMacClone parameter at /goform/aspForm.
CVE-2022-30913 1 H3c 2 Magic R100, Magic R100 Firmware 2024-11-21 9.8 Critical
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the ipqos_set_bandwidth parameter at /goform/aspForm.
CVE-2022-30912 1 H3c 2 Magic R100, Magic R100 Firmware 2024-11-21 9.8 Critical
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the UpdateWanParams parameter at /goform/aspForm.
CVE-2022-30910 1 H3c 2 Magic R100, Magic R100 Firmware 2024-11-21 9.8 Critical
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the GO parameter at /goform/aspForm.
CVE-2022-30909 1 H3c 2 Magic R100, Magic R100 Firmware 2024-11-21 9.8 Critical
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the CMD parameter at /goform/aspForm.
CVE-2022-30899 1 Partkeepr 1 Partkeepr 2024-11-21 4.8 Medium
A Cross Site Scripting vulnerabilty exists in PartKeepr 1.4.0 via the 'name' field in /api/part_categories.
CVE-2022-30898 1 Chshcms 1 Cscms 2024-11-21 6.5 Medium
A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password.
CVE-2022-30882 1 Pyanxdns Project 1 Pyanxdns 2024-11-21 9.8 Critical
pyanxdns package in PyPI version 0.2 is vulnerable to code execution backdoor. The impact is: execute arbitrary code (remote). When installing the pyanxdns package of version 0.2, the request package will be installed.
CVE-2022-30877 1 Keep Project 1 Keep 2024-11-21 9.8 Critical
The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2.
CVE-2022-30875 1 Dolibarr 1 Dolibarr Erp\/crm 2024-11-21 6.1 Medium
Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.
CVE-2022-30782 1 Openmoney Api Project 1 Openmoney Api 2024-11-21 7.5 High
Openmoney API through 2020-06-29 uses the JavaScript Math.random function, which does not provide cryptographically secure random numbers.
CVE-2022-30781 1 Gitea 1 Gitea 2024-11-21 7.5 High
Gitea before 1.16.7 does not escape git fetch remote.
CVE-2022-30777 1 Parallels 1 H-sphere 2024-11-21 6.1 Medium
Parallels H-Sphere 3.6.1713 allows XSS via the index_en.php from parameter.
CVE-2022-30776 1 Atmail 1 Atmail 2024-11-21 6.1 Medium
atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.
CVE-2022-30775 1 Xpdfreader 1 Xpdf 2024-11-21 5.5 Medium
xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafted PDF document to the pdftoppm binary. It is most easily reproduced with the DCMAKE_CXX_COMPILER=afl-clang-fast++ option.
CVE-2022-30770 1 Terminalfour 1 Terminalfour 2024-11-21 6.1 Medium
Terminalfour versions 8.3.7, 8.3.x versions prior to version 8.3.8 and r 8.2.x versions prior to version 8.2.18.5 or 8.2.18.2.1 are vulnerable to (XSS) vulnerability that could be exploited by an attacker to mislead an administrator and steal their credentials.
CVE-2022-30765 1 Janeczku 1 Calibre-web 2024-11-21 9.8 Critical
Calibre-Web before 0.6.18 allows user table SQL Injection.
CVE-2022-30763 1 Janet-lang 1 Janet 2024-11-21 7.5 High
Janet before 1.22.0 mishandles arrays.
CVE-2022-30760 1 Ihb-eg 1 Fn2web 2024-11-21 4.3 Medium
An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authenticated attackers to obtain sensitive student information (final grades, study courses, degrees) by changing the student ID parameter in the HTTP POST request to the FrontControllerSS endpoint.
CVE-2022-30746 1 Samsung 1 Smartthings 2024-11-21 7.5 High
Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API.