Export limit exceeded: 360814 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 360814 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 360814 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (360814 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-24239 | 1 Aceware | 1 Aceweb Online Portal | 2024-11-21 | 9.8 Critical |
| ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file upload vulnerability via attachments.awp. | ||||
| CVE-2022-24238 | 1 Aceware | 1 Aceweb Online Portal | 2024-11-21 | 6.1 Medium |
| ACEweb Online Portal 3.5.065 was discovered to contain a cross-site scripting (XSS) vulnerability via the txtNmName1 parameter in person.awp. | ||||
| CVE-2022-24237 | 1 Snapt | 1 Aria | 2024-11-21 | 8.8 High |
| The snaptPowered2 component of Snapt Aria v12.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated attackers to execute arbitrary commands. | ||||
| CVE-2022-24236 | 1 Snapt | 1 Aria | 2024-11-21 | 3.5 Low |
| An insecure permissions vulnerability in Snapt Aria v12.8 allows unauthenticated attackers to send e-mails from spoofed users' accounts. | ||||
| CVE-2022-24235 | 1 Snapt | 1 Aria | 2024-11-21 | 8.8 High |
| A Cross-Site Request Forgery (CSRF) in the management portal of Snapt Aria v12.8 allows attackers to escalate privileges and execute arbitrary code via unspecified vectors. | ||||
| CVE-2022-24232 | 1 Hospital\'s Patient Records Management System Project | 1 Hospital\'s Patient Records Management System | 2024-11-21 | 7.8 High |
| A local file inclusion in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | ||||
| CVE-2022-24231 | 1 Simple Student Information System Project | 1 Simple Student Information System | 2024-11-21 | 9.8 Critical |
| Simple Student Information System v1.0 was discovered to contain a SQL injection vulnerability via add/Student. | ||||
| CVE-2022-24229 | 1 Onlyoffice | 1 Document Server | 2024-11-21 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in ONLYOFFICE Document Server Example before v7.0.0 allows remote attackers inject arbitrary HTML or JavaScript through /example/editor. | ||||
| CVE-2022-24226 | 1 Phpgurukul | 1 Hospital Management System | 2024-11-21 | 7.5 High |
| Hospital Management System v4.0 was discovered to contain a blind SQL injection vulnerability via the register function in func2.php. | ||||
| CVE-2022-24223 | 1 Thedigitalcraft | 1 Atomcms | 2024-11-21 | 9.8 Critical |
| AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php. | ||||
| CVE-2022-24222 | 1 Elitecms | 1 Elite Cms | 2024-11-21 | 9.8 Critical |
| eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php. | ||||
| CVE-2022-24221 | 1 Elitecms | 1 Elite Cms | 2024-11-21 | 9.8 Critical |
| eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php. | ||||
| CVE-2022-24220 | 1 Elitecms | 1 Elite Cms | 2024-11-21 | 9.8 Critical |
| eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php. | ||||
| CVE-2022-24219 | 1 Elitecms | 1 Elite Cms | 2024-11-21 | 9.8 Critical |
| eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php. | ||||
| CVE-2022-24218 | 1 Elitecms | 1 Elite Cms | 2024-11-21 | 9.1 Critical |
| An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files. | ||||
| CVE-2022-24206 | 1 Tongda2000 | 1 Tongda Office Anywhere | 2024-11-21 | 9.8 Critical |
| Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in /mobile_seal/get_seal.php via the DEVICE_LIST parameter. | ||||
| CVE-2022-24198 | 1 Itextpdf | 1 Itext | 2024-11-21 | 6.5 Medium |
| iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. NOTE: Vendor does not view this as a vulnerability and has not found it to be exploitable. | ||||
| CVE-2022-24197 | 1 Itextpdf | 1 Itext | 2024-11-21 | 6.5 Medium |
| iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. | ||||
| CVE-2022-24196 | 1 Itextpdf | 1 Itext | 2024-11-21 | 6.5 Medium |
| iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component readStreamBytesRaw, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. | ||||
| CVE-2022-24193 | 1 Icewhale | 1 Casaos | 2024-11-21 | 9.8 Critical |
| CasaOS before v0.2.7 was discovered to contain a command injection vulnerability. | ||||