Export limit exceeded: 363899 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (363899 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-37133 | 1 Dlink | 2 Dir-816, Dir-816 Firmware | 2024-11-21 | 7.5 High |
| D-link DIR-816 A2_v1.10CNB04.img reboots the router without authentication via /goform/doReboot. No authentication is required, and reboot is executed when the function returns at the end. | ||||
| CVE-2022-37130 | 1 Dlink | 2 Dir-816, Dir-816 Firmware | 2024-11-21 | 9.8 Critical |
| In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is met, setnum will be spliced into v10 by snprintf, and the system will be executed, resulting in a command injection vulnerability | ||||
| CVE-2022-37129 | 1 Dlink | 2 Dir-816, Dir-816 Firmware | 2024-11-21 | 8.8 High |
| D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in the command parameter, it will be spliced into byte_4836B0 by snprintf, and finally doSystem(&byte_4836B0); will be executed, resulting in a command injection. | ||||
| CVE-2022-37128 | 1 Dlink | 2 Dir-816, Dir-816 Firmware | 2024-11-21 | 9.8 Critical |
| In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end. | ||||
| CVE-2022-37125 | 1 Dlink | 2 Dir-816, Dir-816 Firmware | 2024-11-21 | 9.8 Critical |
| D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost. | ||||
| CVE-2022-37123 | 1 Dlink | 2 Dir-816, Dir-816 Firmware | 2024-11-21 | 8.8 High |
| D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi. | ||||
| CVE-2022-37122 | 1 Carel | 4 Applica, Pcoweb Card, Pcoweb Card Firmware and 1 more | 2024-11-21 | 7.5 High |
| Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' GET parameter through the 'logdownload.cgi' Bash script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks. | ||||
| CVE-2022-37113 | 1 Bluecms Project | 1 Bluecms | 2024-11-21 | 9.8 Critical |
| Bluecms 1.6 has SQL injection in line 132 of admin/area.php | ||||
| CVE-2022-37112 | 1 Bluecms Project | 1 Bluecms | 2024-11-21 | 9.8 Critical |
| BlueCMS 1.6 has SQL injection in line 55 of admin/model.php | ||||
| CVE-2022-37111 | 1 Bluecms Project | 1 Bluecms | 2024-11-21 | 9.8 Critical |
| BlueCMS 1.6 has SQL injection in line 132 of admin/article.php | ||||
| CVE-2022-37108 | 1 Securonix | 1 Snypr | 2024-11-21 | 8.7 High |
| An injection vulnerability in the syslog-ng configuration wizard in Securonix Snypr 6.4 allows an application user with the "Manage Ingesters" permission to execute arbitrary code on remote ingesters by appending arbitrary text to text files that are executed by the system, such as users' crontab files. The patch for this was present in SNYPR version 6.4 Jun 2022 R3_[06170871], but may have been introduced sooner. | ||||
| CVE-2022-37100 | 1 H3c | 2 H200, H200 Firmware | 2024-11-21 | 9.8 Critical |
| H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateMacClone. | ||||
| CVE-2022-37099 | 1 H3c | 2 H200, H200 Firmware | 2024-11-21 | 9.8 Critical |
| H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateSnat. | ||||
| CVE-2022-37098 | 1 H3c | 2 H200, H200 Firmware | 2024-11-21 | 9.8 Critical |
| H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateIpv6Params. | ||||
| CVE-2022-37097 | 1 H3c | 2 H200, H200 Firmware | 2024-11-21 | 9.8 Critical |
| H3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetAPInfoById. | ||||
| CVE-2022-37096 | 1 H3c | 2 H200, H200 Firmware | 2024-11-21 | 9.8 Critical |
| H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EnableIpv6. | ||||
| CVE-2022-37095 | 1 H3c | 2 H200, H200 Firmware | 2024-11-21 | 9.8 Critical |
| H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateWanParams. | ||||
| CVE-2022-37094 | 1 H3c | 2 H200, H200 Firmware | 2024-11-21 | 9.8 Critical |
| H3C H200 H200V100R004 was discovered to contain a stack overflow via the function Edit_BasicSSID_5G. | ||||
| CVE-2022-37093 | 1 H3c | 2 H200, H200 Firmware | 2024-11-21 | 9.8 Critical |
| H3C H200 H200V100R004 was discovered to contain a stack overflow via the function AddMacList. | ||||
| CVE-2022-37092 | 1 H3c | 2 H200, H200 Firmware | 2024-11-21 | 9.8 Critical |
| H3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetAPWifiorLedInfoById. | ||||