Export limit exceeded: 18671 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 18671 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (18671 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-30898 | 1 Chshcms | 1 Cscms | 2024-11-21 | 6.5 Medium |
| A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password. | ||||
| CVE-2022-30882 | 1 Pyanxdns Project | 1 Pyanxdns | 2024-11-21 | 9.8 Critical |
| pyanxdns package in PyPI version 0.2 is vulnerable to code execution backdoor. The impact is: execute arbitrary code (remote). When installing the pyanxdns package of version 0.2, the request package will be installed. | ||||
| CVE-2022-30877 | 1 Keep Project | 1 Keep | 2024-11-21 | 9.8 Critical |
| The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2. | ||||
| CVE-2022-30875 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2024-11-21 | 6.1 Medium |
| Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page. | ||||
| CVE-2022-30782 | 1 Openmoney Api Project | 1 Openmoney Api | 2024-11-21 | 7.5 High |
| Openmoney API through 2020-06-29 uses the JavaScript Math.random function, which does not provide cryptographically secure random numbers. | ||||
| CVE-2022-30781 | 1 Gitea | 1 Gitea | 2024-11-21 | 7.5 High |
| Gitea before 1.16.7 does not escape git fetch remote. | ||||
| CVE-2022-30777 | 1 Parallels | 1 H-sphere | 2024-11-21 | 6.1 Medium |
| Parallels H-Sphere 3.6.1713 allows XSS via the index_en.php from parameter. | ||||
| CVE-2022-30776 | 1 Atmail | 1 Atmail | 2024-11-21 | 6.1 Medium |
| atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter. | ||||
| CVE-2022-30775 | 1 Xpdfreader | 1 Xpdf | 2024-11-21 | 5.5 Medium |
| xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafted PDF document to the pdftoppm binary. It is most easily reproduced with the DCMAKE_CXX_COMPILER=afl-clang-fast++ option. | ||||
| CVE-2022-30770 | 1 Terminalfour | 1 Terminalfour | 2024-11-21 | 6.1 Medium |
| Terminalfour versions 8.3.7, 8.3.x versions prior to version 8.3.8 and r 8.2.x versions prior to version 8.2.18.5 or 8.2.18.2.1 are vulnerable to (XSS) vulnerability that could be exploited by an attacker to mislead an administrator and steal their credentials. | ||||
| CVE-2022-30765 | 1 Janeczku | 1 Calibre-web | 2024-11-21 | 9.8 Critical |
| Calibre-Web before 0.6.18 allows user table SQL Injection. | ||||
| CVE-2022-30763 | 1 Janet-lang | 1 Janet | 2024-11-21 | 7.5 High |
| Janet before 1.22.0 mishandles arrays. | ||||
| CVE-2022-30760 | 1 Ihb-eg | 1 Fn2web | 2024-11-21 | 4.3 Medium |
| An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authenticated attackers to obtain sensitive student information (final grades, study courses, degrees) by changing the student ID parameter in the HTTP POST request to the FrontControllerSS endpoint. | ||||
| CVE-2022-30746 | 1 Samsung | 1 Smartthings | 2024-11-21 | 7.5 High |
| Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API. | ||||
| CVE-2022-30743 | 1 Samsung | 1 Account | 2024-11-21 | 5.3 Medium |
| Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission. | ||||
| CVE-2022-30739 | 1 Samsung | 1 Account | 2024-11-21 | 4 Medium |
| Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email or phone number with a normal level permission. | ||||
| CVE-2022-30738 | 1 Samsung | 1 Internet | 2024-11-21 | 4.3 Medium |
| Improper check in Loader in Samsung Internet prior to 17.0.1.69 allows attackers to spoof address bar via executing script. | ||||
| CVE-2022-30737 | 1 Samsung | 1 Account | 2024-11-21 | 4 Medium |
| Implicit Intent hijacking vulnerability in Samsung Account prior to version 13.2.00.6 allows attackers to get email ID. | ||||
| CVE-2022-30736 | 1 Samsung | 1 Account | 2024-11-21 | 5.3 Medium |
| Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission. | ||||
| CVE-2022-30735 | 1 Samsung | 1 Account | 2024-11-21 | 5.9 Medium |
| Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_token without permission. | ||||