Export limit exceeded: 37225 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 37225 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (37225 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-41378 | 1 Online Pet Shop We App Project | 1 Online Pet Shop We App | 2024-11-21 | 7.2 High |
| Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/admin/?page=inventory/manage_inventory. | ||||
| CVE-2022-41377 | 1 Online Pet Shop We App Project | 1 Online Pet Shop We App | 2024-11-21 | 7.2 High |
| Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/admin/?page=maintenance/manage_category. | ||||
| CVE-2022-41355 | 1 Online Leave Management System Project | 1 Online Leave Management System | 2024-11-21 | 7.2 High |
| Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /leave_system/classes/Master.php?f=delete_department. | ||||
| CVE-2022-41294 | 2 Ibm, Microsoft | 2 Robotic Process Automation, Windows | 2024-11-21 | 6.5 Medium |
| IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api. IBM X-Force ID: 236807. | ||||
| CVE-2022-41291 | 3 Ibm, Linux, Microsoft | 4 Aix, Infosphere Information Server, Linux Kernel and 1 more | 2024-11-21 | 6.5 Medium |
| IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 236699. | ||||
| CVE-2022-40922 | 1 Lief-project | 1 Lief | 2024-11-21 | 6.5 Medium |
| A vulnerability in the LIEF::MachO::BinaryParser::init_and_parse function of LIEF v0.12.1 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted MachO file. | ||||
| CVE-2022-40895 | 1 Nedi | 1 Nedi | 2024-11-21 | 9.1 Critical |
| In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to affect the integrity of a device via a User Enumeration vulnerability. The vulnerability is due to insecure design, where a difference in forgot password utility could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. This affects NeDi 1.0.7 for OS X 1.0.7 <= and NeDi for Suse 1.0.7 <= and NeDi for FreeBSD 1.0.7 <=. | ||||
| CVE-2022-40886 | 1 Dedecms | 1 Dedecms | 2024-11-21 | 7.2 High |
| DedeCMS 5.7.98 has a file upload vulnerability in the background. | ||||
| CVE-2022-40835 | 1 Codeigniter | 1 Codeigniter | 2024-11-21 | 9.8 Critical |
| B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php. Note: Multiple third parties have disputed this as not a valid vulnerability | ||||
| CVE-2022-40834 | 1 Codeigniter | 1 Codeigniter | 2024-11-21 | 9.8 Critical |
| B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_not_like() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | ||||
| CVE-2022-40833 | 1 Codeigniter | 1 Codeigniter | 2024-11-21 | 9.8 Critical |
| B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | ||||
| CVE-2022-40832 | 1 Codeigniter | 1 Codeigniter | 2024-11-21 | 9.8 Critical |
| B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php having() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | ||||
| CVE-2022-40831 | 1 Codeigniter | 1 Codeigniter | 2024-11-21 | 9.8 Critical |
| B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php like() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | ||||
| CVE-2022-40830 | 1 Codeigniter | 1 Codeigniter | 2024-11-21 | 9.8 Critical |
| B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_not_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | ||||
| CVE-2022-40829 | 1 Codeigniter | 1 Codeigniter | 2024-11-21 | 9.8 Critical |
| B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_like() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | ||||
| CVE-2022-40826 | 2 Bcit-ci, Codeigniter | 2 Codeigniter, Codeigniter | 2024-11-21 | 9.8 Critical |
| B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_having() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | ||||
| CVE-2022-40825 | 1 Codeigniter | 1 Codeigniter | 2024-11-21 | 9.8 Critical |
| B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | ||||
| CVE-2022-40824 | 2 Bcit-ci, Codeigniter | 2 Codeigniter, Codeigniter | 2024-11-21 | 9.8 Critical |
| B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | ||||
| CVE-2022-40764 | 1 Snyk | 2 Cli, Golang Cli | 2024-11-21 | 7.8 High |
| Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the common practice of viewing untrusted files in the Visual Studio Code editor, for example. The original demonstration was with shell metacharacters in the vendor.json ignore field, affecting snyk-go-plugin before 1.19.1. This affects, for example, the Snyk TeamCity plugin (which does not update automatically) before 20220930.142957. | ||||
| CVE-2022-40721 | 1 Creativedream File Uploader Project | 1 Creativedream File Uploader | 2024-11-21 | 9.8 Critical |
| Arbitrary file upload vulnerability in php uploader | ||||