Export limit exceeded: 46854 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (46854 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-30899 | 1 Partkeepr | 1 Partkeepr | 2024-11-21 | 4.8 Medium |
| A Cross Site Scripting vulnerabilty exists in PartKeepr 1.4.0 via the 'name' field in /api/part_categories. | ||||
| CVE-2022-30898 | 1 Chshcms | 1 Cscms | 2024-11-21 | 6.5 Medium |
| A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password. | ||||
| CVE-2022-30887 | 1 Pharmacy Management System Project | 1 Pharmacy Management System | 2024-11-21 | 9.8 Critical |
| Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file. | ||||
| CVE-2022-30886 | 1 School Dormitory Management System Project | 1 School Dormitory Management System | 2024-11-21 | 9.8 Critical |
| School Dormitory Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /dms/admin/reports/daily_collection_report.php. | ||||
| CVE-2022-30882 | 1 Pyanxdns Project | 1 Pyanxdns | 2024-11-21 | 9.8 Critical |
| pyanxdns package in PyPI version 0.2 is vulnerable to code execution backdoor. The impact is: execute arbitrary code (remote). When installing the pyanxdns package of version 0.2, the request package will be installed. | ||||
| CVE-2022-30877 | 1 Keep Project | 1 Keep | 2024-11-21 | 9.8 Critical |
| The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2. | ||||
| CVE-2022-30875 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2024-11-21 | 6.1 Medium |
| Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page. | ||||
| CVE-2022-30843 | 1 Room Rent Portal Site Project | 1 Room Rent Portal Site | 2024-11-21 | 8.8 High |
| Room-rent-portal-site v1.0 is vulnerable to SQL Injection via /rrps/classes/Master.php?f=delete_category, id. | ||||
| CVE-2022-30842 | 1 Covid 19 Travel Pass Management System Project | 1 Covid 19 Travel Pass Management System | 2024-11-21 | 5.4 Medium |
| Covid-19 Travel Pass Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /ctpms/classes/Users.php?f=save, firstname. | ||||
| CVE-2022-30839 | 1 Room Rent Portal Site Project | 1 Room Rent Portal Site | 2024-11-21 | 6.1 Medium |
| Room-rent-portal-site v1.0 is vulnerable to Cross Site Scripting (XSS) via /rrps/classes/Master.php?f=save_category, vehicle_name. | ||||
| CVE-2022-30838 | 1 Covid 19 Travel Pass Management System Project | 1 Covid 19 Travel Pass Management System | 2024-11-21 | 9.8 Critical |
| Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=update_application_status | ||||
| CVE-2022-30782 | 1 Openmoney Api Project | 1 Openmoney Api | 2024-11-21 | 7.5 High |
| Openmoney API through 2020-06-29 uses the JavaScript Math.random function, which does not provide cryptographically secure random numbers. | ||||
| CVE-2022-30781 | 1 Gitea | 1 Gitea | 2024-11-21 | 7.5 High |
| Gitea before 1.16.7 does not escape git fetch remote. | ||||
| CVE-2022-30777 | 1 Parallels | 1 H-sphere | 2024-11-21 | 6.1 Medium |
| Parallels H-Sphere 3.6.1713 allows XSS via the index_en.php from parameter. | ||||
| CVE-2022-30776 | 1 Atmail | 1 Atmail | 2024-11-21 | 6.1 Medium |
| atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter. | ||||
| CVE-2022-30775 | 1 Xpdfreader | 1 Xpdf | 2024-11-21 | 5.5 Medium |
| xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafted PDF document to the pdftoppm binary. It is most easily reproduced with the DCMAKE_CXX_COMPILER=afl-clang-fast++ option. | ||||
| CVE-2022-30770 | 1 Terminalfour | 1 Terminalfour | 2024-11-21 | 6.1 Medium |
| Terminalfour versions 8.3.7, 8.3.x versions prior to version 8.3.8 and r 8.2.x versions prior to version 8.2.18.5 or 8.2.18.2.1 are vulnerable to (XSS) vulnerability that could be exploited by an attacker to mislead an administrator and steal their credentials. | ||||
| CVE-2022-30765 | 1 Janeczku | 1 Calibre-web | 2024-11-21 | 9.8 Critical |
| Calibre-Web before 0.6.18 allows user table SQL Injection. | ||||
| CVE-2022-30763 | 1 Janet-lang | 1 Janet | 2024-11-21 | 7.5 High |
| Janet before 1.22.0 mishandles arrays. | ||||
| CVE-2022-30760 | 1 Ihb-eg | 1 Fn2web | 2024-11-21 | 4.3 Medium |
| An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authenticated attackers to obtain sensitive student information (final grades, study courses, degrees) by changing the student ID parameter in the HTTP POST request to the FrontControllerSS endpoint. | ||||