Export limit exceeded: 40332 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (40332 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-34586 1 Advanced School Management System Project 1 Advanced School Management System 2024-11-21 8.8 High
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/view/student_grade_wise.php.
CVE-2022-34540 1 Dw 2 Megapix, Megapix Firmware 2024-11-21 8.8 High
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/license/license_tok.cgi. This vulnerability is exploitable via a crafted POST request.
CVE-2022-34539 1 Dw 2 Megapix, Megapix Firmware 2024-11-21 8.8 High
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/curltest.cgi. This vulnerability is exploitable via a crafted POST request.
CVE-2022-34537 1 Dw 2 Megapix, Megapix Firmware 2024-11-21 5.4 Medium
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a cross-site scripting (XSS) vulnerability via the component bia_oneshot.cgi.
CVE-2022-34536 1 Dw 2 Megapix, Megapix Firmware 2024-11-21 7.5 High
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows attackers to access the core log file and perform session hijacking via a crafted session token.
CVE-2022-34535 1 Dw 2 Megapix, Megapix Firmware 2024-11-21 7.5 High
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows unauthenticated attackers to view internal paths and scripts via web files.
CVE-2022-34534 1 Dw 2 Spectrum Server, Spectrum Server Firmware 2024-11-21 7.5 High
Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.
CVE-2022-34529 1 Wasm3 Project 1 Wasm3 2024-11-21 5.5 Medium
WASM3 v0.5.0 was discovered to contain a segmentation fault via the component Compile_Memory_CopyFill.
CVE-2022-34509 1 Wikifaces Project 1 Wikifaces 2024-11-21 9.8 Critical
The wikifaces package in PyPI v1.0 included a code execution backdoor inserted by a third party.
CVE-2022-34503 1 Qpdf Project 1 Qpdf 2024-11-21 6.5 Medium
QPDF v8.4.2 was discovered to contain a heap buffer overflow via the function QPDF::processXRefStream. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
CVE-2022-34501 1 Pypi 1 Pypi 2024-11-21 9.8 Critical
The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
CVE-2022-34500 1 Pypi 1 Pypi 2024-11-21 9.8 Critical
The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
CVE-2022-34453 1 Dell 2 Xtremio X2, Xtremio X2 Firmware 2024-11-21 7.6 High
Dell XtremIO X2 XMS versions prior to 6-4-1.11 contain an improper access control vulnerability. A remote read only user could potentially exploit this vulnerability to perform add/delete QoS policies which are disabled by default.
CVE-2022-34383 1 Dell 2 Edge Gateway 5200, Edge Gateway 5200 Firmware 2024-11-21 8.1 High
Dell Edge Gateway 5200 (EGW) versions before 1.03.10 contain an operating system command injection vulnerability. A local malicious user may potentially exploit this vulnerability by using an SMI to bypass PMC mitigation and gain arbitrary code execution during SMM.
CVE-2022-34382 1 Dell 3 Alienware Update, Command Update, Update 2024-11-21 7.8 High
Dell Command Update, Dell Update and Alienware Update versions prior to 4.6.0 contains a Local Privilege Escalation Vulnerability in the custom catalog configuration. A local malicious user may potentially exploit this vulnerability in order to elevate their privileges.
CVE-2022-34380 1 Dell 1 Cloudlink 2024-11-21 9.3 Critical
Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability. A high privileged local attacker may potentially exploit this vulnerability leading to authentication bypass and access the CloudLink system console. This is critical severity vulnerability as it allows attacker to take control of the system.
CVE-2022-34379 1 Dell 1 Cloudlink 2024-11-21 9.4 Critical
Dell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability. A remote attacker, with the knowledge of the active directory usernames, could potentially exploit this vulnerability to gain unauthorized access to the system.
CVE-2022-34378 1 Dell 1 Emc Powerscale Onefs 2024-11-21 5.5 Medium
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3, contain a relative path traversal vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to denial of service.
CVE-2022-34375 1 Dell 1 Container Storage Modules 2024-11-21 8.8 High
Dell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to unintentional access to path outside of restricted directory.
CVE-2022-34374 1 Dell 1 Container Storage Modules 2024-11-21 8.8 High
Dell Container Storage Modules 1.2 contains an OS command injection in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to to execute arbitrary OS commands on the affected system.