Export limit exceeded: 18382 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (18382 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-37123 1 Dlink 2 Dir-816, Dir-816 Firmware 2024-11-21 8.8 High
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi.
CVE-2022-37122 1 Carel 4 Applica, Pcoweb Card, Pcoweb Card Firmware and 1 more 2024-11-21 7.5 High
Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' GET parameter through the 'logdownload.cgi' Bash script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks.
CVE-2022-37041 1 Zimbra 1 Collaboration 2024-11-21 7.5 High
An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. The value of the X-Forwarded-Host header overwrites the value of the Host header in proxied requests. The value of X-Forwarded-Host header is not checked against the whitelist of hosts that ZCS is allowed to proxy to (the zimbraProxyAllowedDomains setting).
CVE-2022-37030 1 Grommunio 1 Gromox 2024-11-21 7.8 High
Weak permissions on the configuration file in the PAM module in Grommunio Gromox 0.5 through 1.x before 1.28 allow a local unprivileged user in the gromox group to have the PAM stack execute arbitrary code upon loading the Gromox PAM module.
CVE-2022-37024 1 Zohocorp 7 Manageengine Firewall Analyzer, Manageengine Netflow Analyzer, Manageengine Network Configuration Manager and 4 more 2024-11-21 8.8 High
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allow authenticated users to make database changes that lead to remote code execution.
CVE-2022-37022 1 Apache 1 Geode 2024-11-21 8.8 High
Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11. Any user wishing to protect against deserialization attacks involving JMX or RMI should upgrade to Apache Geode 1.15. Use of 1.15 on Java 11 will automatically protect JMX over RMI against deserialization attacks. This should have no impact on performance since it only affects JMX/RMI which Gfsh uses to communicate with the JMX Manager which is hosted on a Locator.
CVE-2022-37006 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service availability.
CVE-2022-37001 1 Huawei 1 Harmonyos 2024-11-21 7.5 High
The diag-router module has a vulnerability in intercepting excessive long and short instructions. Successful exploitation of this vulnerability will cause the diag-router module to crash.
CVE-2022-36833 2 Google, Samsung 2 Android, Gameoptimizingservice 2024-11-21 7.3 High
Improper Privilege Management vulnerability in Game Optimizing Service prior to versions 3.3.04.0 in Android 10, and 3.5.04.8 in Android 11 and above allows local attacker to execute hidden function for developer by changing package name.
CVE-2022-36773 2 Ibm, Netapp 2 Cognos Analytics, Oncommand Insight 2024-11-21 8.1 High
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 233571.
CVE-2022-36754 1 Oretnom23 1 Expense Management System 2024-11-21 7.2 High
Expense Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Home/debit_credit_p.
CVE-2022-36704 1 Library Management System Project 1 Library Management System 2024-11-21 8.8 High
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /librarian/studentdetails.php.
CVE-2022-36690 1 Ingredient Stock Management System Project 1 Ingredient Stock Management System 2024-11-21 8.8 High
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user&id=.
CVE-2022-36689 1 Ingredient Stock Management System Project 1 Ingredient Stock Management System 2024-11-21 8.8 High
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /admin/?page=reports/waste&month=.
CVE-2022-36688 1 Ingredient Stock Management System Project 1 Ingredient Stock Management System 2024-11-21 8.8 High
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /admin/?page=reports/stockout&month=.
CVE-2022-36686 1 Ingredient Stock Management System Project 1 Ingredient Stock Management System 2024-11-21 8.8 High
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /admin/?page=reports/stockin&month=.
CVE-2022-36676 1 Simple Task Scheduling System Project 1 Simple Task Scheduling System 2024-11-21 7.2 High
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /categories/view_category.php.
CVE-2022-36675 1 Simple Task Scheduling System Project 1 Simple Task Scheduling System 2024-11-21 7.2 High
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /schedules/manage_schedule.php.
CVE-2022-36674 1 Simple Task Scheduling System Project 1 Simple Task Scheduling System 2024-11-21 7.2 High
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /schedules/view_schedule.php.
CVE-2022-36671 1 Xxyopen 1 Novel-plus 2024-11-21 7.5 High
Novel-Plus v3.6.2 was discovered to contain an arbitrary file download vulnerability via the background file download API.