Export limit exceeded: 43080 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 43080 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 43080 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (43080 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-31589 | 1 Sap | 3 Erp Financial Accounting, Erp Localization For Cee Countries, S\/4hana | 2024-11-21 | 6.5 Medium |
| Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than needed authorization to perform certain transaction, which may lead to users getting access to data that would otherwise be restricted. | ||||
| CVE-2022-31497 | 1 Librehealth | 1 Librehealth Ehr | 2024-11-21 | 6.1 Medium |
| LibreHealth EHR Base 2.0.0 allows interface/main/finder/finder_navigation.php patient XSS. | ||||
| CVE-2022-31496 | 1 Librehealth | 1 Librehealth Ehr | 2024-11-21 | 8.8 High |
| LibreHealth EHR Base 2.0.0 allows incorrect interface/super/manage_site_files.php access. | ||||
| CVE-2022-31495 | 1 Librehealth | 1 Librehealth Ehr | 2024-11-21 | 6.1 Medium |
| LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS. | ||||
| CVE-2022-31489 | 1 Inoutscripts | 1 Blockchain Altexchanger | 2024-11-21 | 7.5 High |
| Inout Blockchain AltExchanger 1.2.1 allows index.php/home/about inoutio_language cookie SQL injection. | ||||
| CVE-2022-31488 | 1 Inoutscripts | 1 Blockchain Altexchanger | 2024-11-21 | 7.5 High |
| Inout Blockchain AltExchanger 1.2.1 allows index.php/coins/update_marketboxslider marketcurrency SQL injection. | ||||
| CVE-2022-31487 | 1 Inoutscripts | 2 Blockchain Altexchanger, Blockchain Fiatexchanger | 2024-11-21 | 7.5 High |
| Inout Blockchain AltExchanger 1.2.1 and Inout Blockchain FiatExchanger 2.2.1 allow Chart/TradingView/chart_content/master.php symbol SQL injection. | ||||
| CVE-2022-31473 | 1 F5 | 1 Big-ip Access Policy Manager | 2024-11-21 | 6.8 Medium |
| In BIG-IP Versions 16.1.x before 16.1.1 and 15.1.x before 15.1.4, when running in Appliance mode, an authenticated attacker may be able to bypass Appliance mode restrictions due to a directory traversal vulnerability in an undisclosed page within iApps. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | ||||
| CVE-2022-31447 | 1 Magicpin | 1 Magicpin | 2024-11-21 | 7.5 High |
| An XML external entity (XXE) injection vulnerability in Magicpin v3.4 allows attackers to access sensitive database information via a crafted SVG file. | ||||
| CVE-2022-31446 | 1 Tendacn | 2 Ac18, Ac18 Firmware | 2024-11-21 | 9.8 Critical |
| Tenda AC18 router V15.03.05.19 and V15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac. | ||||
| CVE-2022-31415 | 1 Online Fire Reporting System Project | 1 Online Fire Reporting System | 2024-11-21 | 6.5 Medium |
| Online Fire Reporting System v1.0 was discovered to contain a SQL injection vulnerability via the GET parameter in /report/list.php. | ||||
| CVE-2022-31403 | 1 Combodo | 1 Itop | 2024-11-21 | 6.1 Medium |
| ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/pages/ajax.render.php. | ||||
| CVE-2022-31402 | 1 Combodo | 1 Itop | 2024-11-21 | 6.1 Medium |
| ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php. | ||||
| CVE-2022-31400 | 1 Helpdeskz | 1 Helpdeskz | 2024-11-21 | 4.8 Medium |
| A cross-site scripting (XSS) vulnerability in /staff/setup/email-addresses of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field. | ||||
| CVE-2022-31398 | 1 Helpdeskz | 1 Helpdeskz | 2024-11-21 | 4.8 Medium |
| A cross-site scripting (XSS) vulnerability in /staff/tools/custom-fields of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field. | ||||
| CVE-2022-31393 | 1 Jizhicms | 1 Jizhicms | 2024-11-21 | 9.1 Critical |
| Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Index function in app/admin/c/PluginsController.php. | ||||
| CVE-2022-31390 | 1 Jizhicms | 1 Jizhicms | 2024-11-21 | 9.1 Critical |
| Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Update function in app/admin/c/TemplateController.php. | ||||
| CVE-2022-31386 | 1 Nbnbk Project | 1 Nbnbk | 2024-11-21 | 9.1 Critical |
| A Server-Side Request Forgery (SSRF) in the getFileBinary function of nbnbk cms 3 allows attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the URL parameter. | ||||
| CVE-2022-31325 | 1 Churchcrm | 1 Churchcrm | 2024-11-21 | 7.2 High |
| There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php. | ||||
| CVE-2022-31313 | 1 Api-res-py Project | 1 Api-res-py | 2024-11-21 | 9.8 Critical |
| api-res-py package in PyPI 0.1 is vulnerable to a code execution backdoor in the request package. | ||||