Export limit exceeded: 358029 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 358029 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (358029 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-29721 | 1 74cms | 1 74cmsse | 2024-11-21 | 7.5 High |
| 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist. | ||||
| CVE-2022-29720 | 1 74cms | 1 74cmsse | 2024-11-21 | 7.5 High |
| 74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Download.php. | ||||
| CVE-2022-29718 | 1 Caddyserver | 1 Caddy | 2024-11-21 | 6.1 Medium |
| Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links. | ||||
| CVE-2022-29712 | 1 Librenms | 1 Librenms | 2024-11-21 | 9.8 Critical |
| LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and service_param parameters. | ||||
| CVE-2022-29711 | 1 Librenms | 1 Librenms | 2024-11-21 | 6.1 Medium |
| LibreNMS v22.3.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Table/GraylogController.php. | ||||
| CVE-2022-29710 | 1 Limesurvey | 1 Limesurvey | 2024-11-21 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execute arbitrary web scripts or HTML via a crafted plugin. | ||||
| CVE-2022-29709 | 1 Communilink | 1 Clink Office | 2024-11-21 | 7.5 High |
| CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the username and password parameters. | ||||
| CVE-2022-29704 | 1 Browsbox | 1 Brows Box | 2024-11-21 | 9.8 Critical |
| BrowsBox CMS v4.0 was discovered to contain a SQL injection vulnerability. | ||||
| CVE-2022-29701 | 1 Zammad | 1 Zammad | 2024-11-21 | 7.5 High |
| A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | ||||
| CVE-2022-29700 | 1 Zammad | 1 Zammad | 2024-11-21 | 7.5 High |
| A lack of password length restriction in Zammad v5.1.0 allows for the creation of extremely long passwords which can cause a Denial of Service (DoS) during password verification. | ||||
| CVE-2022-29695 | 1 Unicorn-engine | 1 Unicorn Engine | 2024-11-21 | 7.5 High |
| Unicorn Engine v2.0.0-rc7 contains memory leaks caused by an incomplete unicorn engine initialization. | ||||
| CVE-2022-29694 | 1 Unicorn-engine | 1 Unicorn Engine | 2024-11-21 | 7.5 High |
| Unicorn Engine v2.0.0-rc7 and below was discovered to contain a NULL pointer dereference via qemu_ram_free. | ||||
| CVE-2022-29693 | 1 Unicorn-engine | 1 Unicorn Engine | 2024-11-21 | 7.5 High |
| Unicorn Engine v2.0.0-rc7 and below was discovered to contain a memory leak via the function uc_close at /my/unicorn/uc.c. | ||||
| CVE-2022-29692 | 1 Unicorn-engine | 1 Unicorn Engine | 2024-11-21 | 7.8 High |
| Unicorn Engine v1.0.3 was discovered to contain a use-after-free vulnerability via the hook function. | ||||
| CVE-2022-29689 | 1 Chshcms | 1 Cscms Music Portal System | 2024-11-21 | 7.2 High |
| CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/del. | ||||
| CVE-2022-29688 | 1 Chshcms | 1 Cscms Music Portal System | 2024-11-21 | 7.2 High |
| CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/hy. | ||||
| CVE-2022-29687 | 1 Chshcms | 1 Cscms Music Portal System | 2024-11-21 | 7.2 High |
| CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/level_del. | ||||
| CVE-2022-29686 | 1 Chshcms | 1 Cscms Music Portal System | 2024-11-21 | 7.2 High |
| CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/lists/zhuan. | ||||
| CVE-2022-29685 | 1 Chshcms | 1 Cscms Music Portal System | 2024-11-21 | 8.8 High |
| CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/User/level_sort. | ||||
| CVE-2022-29684 | 1 Chshcms | 1 Cscms Music Portal System | 2024-11-21 | 7.2 High |
| CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/js_del. | ||||