Export limit exceeded: 37187 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 37187 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (37187 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-36657 1 Library Management System Project 1 Library Management System 2024-11-21 4.8 Medium
Library Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /librarian/edit_book_details.php.
CVE-2022-36634 1 Zkteco 1 Zkbiosecurity V5000 2024-11-21 8.8 High
An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a crafted HTTP request.
CVE-2022-36622 1 Samsung 1 Mtower 2024-11-21 7.5 High
Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_GetObjectInfo1.
CVE-2022-36621 1 Samsung 1 Mtower 2024-11-21 7.5 High
Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_AllocateTransientObject.
CVE-2022-36619 1 Dlink 2 Dir-816, Dir-816 Firmware 2024-11-21 7.5 High
In D-link DIR-816 A2_v1.10CNB04.img,the network can be reset without authentication via /goform/setMAC.
CVE-2022-36616 1 Totolink 2 A810r, A810r Firmware 2024-11-21 7.8 High
TOTOLINK A810R V4.1.2cu.5182_B20201026 and V5.9c.4050_B20190424 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
CVE-2022-36615 1 Totolink 2 A3000ru, A3000ru Firmware 2024-11-21 7.8 High
TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
CVE-2022-36614 1 Totolink 2 A860r, A860r Firmware 2024-11-21 7.8 High
TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
CVE-2022-36613 1 Totolink 2 N600r, N600r Firmware 2024-11-21 7.8 High
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
CVE-2022-36612 1 Totolink 2 A950rg, A950rg Firmware 2024-11-21 7.8 High
TOTOLINK A950RG V4.1.2cu.5204_B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
CVE-2022-36611 1 Totolink 2 A800r, A800r Firmware 2024-11-21 7.8 High
TOTOLINK A800R V4.1.2cu.5137_B20200730 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
CVE-2022-36610 1 Totolink 2 A720r, A720r Firmware 2024-11-21 7.8 High
TOTOLINK A720R V4.1.5cu.532_B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
CVE-2022-36604 1 Canaan 2 Avalon Asic Miner, Avalon Asic Miner Firmware 2024-11-21 7.5 High
An access control issue in Canaan Avalon ASIC Miner 2020.3.30 and below allows unauthenticated attackers to arbitrarily change user passwords via a crafted POST request.
CVE-2022-36603 1 Innosilicon 2 T3t\+, T3t\+ Firmware 2024-11-21 8.8 High
InnoSilicon T3T+ t2t+_soc_20190911_151433.swu was discovered to contain a remote code execution (RCE) vulnerability in the checkUrl function.
CVE-2022-36602 1 Innosilicon 2 A10, A10 Firmware 2024-11-21 8.8 High
InnoSilicon A10 a10_20200924_120556 was discovered to contain a remote code execution (RCE) vulnerability in the setPlatformAPI function.
CVE-2022-36601 1 Jinglemining 2 Jasminer X4 Server, Jasminer X4 Server Firmware 2024-11-21 9.8 Critical
The Eclipse TCF debug interface in JasMiner-X4-Server-20220621-090907 and below is open on port 1534. This issue allows unauthenticated attackers to gain root privileges on the affected device and access sensitive data or execute arbitrary commands.
CVE-2022-36583 1 Dedecms 1 Dedecms 2024-11-21 6.1 Medium
DedeCMS V5.7.97 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/co_do.php via the dopost, rpok, and aid parameters.
CVE-2022-36582 1 Garage Management System Project 1 Garage Management System 2024-11-21 7.2 High
An arbitrary file upload vulnerability in the component /php_action/createProduct.php of Garage Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-36581 1 Online Ordering System Project 1 Online Ordering System 2024-11-21 7.5 High
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /admin/login.php.
CVE-2022-36580 1 Online Ordering System Project 1 Online Ordering System 2024-11-21 7.2 High
An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering System v2.3.2 allows attackers to execute arbitrary code via a crafted PHP file.