Export limit exceeded: 371214 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (371214 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-28557 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-11-21 | 9.8 Critical |
| There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arbitrary command execution | ||||
| CVE-2022-28556 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-11-21 | 7.5 High |
| Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin is vulnerable to Buffer Overflow. The stack overflow vulnerability lies in the /goform/setpptpservercfg interface of the web. The sent post data startip and endip are copied to the stack using the sanf function, resulting in stack overflow. Similarly, this vulnerability can be used together with CVE-2021-44971 | ||||
| CVE-2022-28552 | 1 Chshcms | 1 Cscms | 2024-11-21 | 8.8 High |
| Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin. | ||||
| CVE-2022-28545 | 1 Fudforum | 1 Fudforum | 2024-11-21 | 5.4 Medium |
| FUDforum 3.1.1 is vulnerable to Stored XSS. | ||||
| CVE-2022-28544 | 1 Samsung | 1 Galaxy Store | 2024-11-21 | 6.2 Medium |
| Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allows attacker to access the file of Galaxy store. | ||||
| CVE-2022-28543 | 1 Samsung | 1 Samsung Flow | 2024-11-21 | 4 Medium |
| Path traversal vulnerability in Samsung Flow prior to version 4.8.07.4 allows local attackers to read arbitrary files as Samsung Flow permission. | ||||
| CVE-2022-28542 | 1 Samsung | 1 Galaxy Store | 2024-11-21 | 6.8 Medium |
| Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access privileged content providers as Galaxy Store permission. | ||||
| CVE-2022-28541 | 1 Samsung | 1 Update | 2024-11-21 | 5.9 Medium |
| Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as Samsung Update permission. | ||||
| CVE-2022-28533 | 1 Medical Hub Directory Site Project | 1 Medical Hub Directory Site | 2024-11-21 | 9.8 Critical |
| Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php. | ||||
| CVE-2022-28531 | 1 Covid-19 Directory On Vaccination System Project | 1 Covid-19 Directory On Vaccination System | 2024-11-21 | 9.8 Critical |
| Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtusername (aka Username) field. | ||||
| CVE-2022-28530 | 1 Covid-19 Directory On Vaccination System Project | 1 Covid-19 Directory On Vaccination System | 2024-11-21 | 9.8 Critical |
| Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory. | ||||
| CVE-2022-28528 | 1 Bloofox | 1 Bloofoxcms | 2024-11-21 | 8.8 High |
| bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit. | ||||
| CVE-2022-28527 | 1 Dhcms Project | 1 Dhcms | 2024-11-21 | 8.1 High |
| dhcms v20170919 was discovered to contain an arbitrary folder deletion vulnerability via /admin.php?r=admin/AdminBackup/del. | ||||
| CVE-2022-28525 | 1 Ed01-cms Project | 1 Ed01-cms | 2024-11-21 | 8.8 High |
| ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_user&id=1. | ||||
| CVE-2022-28524 | 1 Ed01-cms Project | 1 Ed01-cms | 2024-11-21 | 9.8 Critical |
| ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php. | ||||
| CVE-2022-28523 | 1 Hongcms Project | 1 Hongcms | 2024-11-21 | 8.1 High |
| HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete. | ||||
| CVE-2022-28522 | 1 Zcms Project | 1 Zcms | 2024-11-21 | 5.4 Medium |
| ZCMS v20170206 was discovered to contain a stored cross-site scripting (XSS) vulnerability via index.php?m=home&c=message&a=add. | ||||
| CVE-2022-28521 | 1 Zcms Project | 1 Zcms | 2024-11-21 | 9.8 Critical |
| ZCMS v20170206 was discovered to contain a file inclusion vulnerability via index.php?m=home&c=home&a=sp_set_config. | ||||
| CVE-2022-28512 | 1 Fantastic Blog Project | 1 Fantastic Blog | 2024-11-21 | 9.8 Critical |
| A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantasticblog/single.php" via the "id=5" parameters. | ||||
| CVE-2022-28508 | 1 Mantisbt | 1 Mantisbt | 2024-11-21 | 6.1 Medium |
| An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field. | ||||