Latest CVE Feed
-
9.8
CRITICALCVE-2022-37003
The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause permission escalation and unauthorized access to files.... Read more
- Published: Aug. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37437
When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS certificate validation is not correctly performed and tested for the destination. The vulnerability only affects connections between... Read more
Affected Products : splunk- Published: Aug. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37130
In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is met, setnum will be spliced into v10 by snprintf, and the system will be executed, resulting in a command ... Read more
- Published: Aug. 31, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37069
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateSnat.... Read more
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36950
In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may be able to perform remote command execution through a Java classloader manipulation. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.... Read more
Affected Products : netbackup- Published: Jul. 27, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37149
WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi. This vulnerability allows attackers to execute arbitrary commands via the username parameter.... Read more
- Published: Aug. 30, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37125
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.... Read more
- Published: Aug. 31, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36979
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The spe... Read more
Affected Products : avalanche- Published: Mar. 29, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37067
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateWanParamsMulti.... Read more
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36978
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The sp... Read more
Affected Products : avalanche- Published: Mar. 29, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-54383
Incorrect Privilege Assignment vulnerability in wpweb WooCommerce PDF Vouchers allows Privilege Escalation.This issue affects WooCommerce PDF Vouchers: from n/a before 4.9.9.... Read more
Affected Products :- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
9.8
CRITICALCVE-2022-36977
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The sp... Read more
Affected Products : avalanche- Published: Mar. 29, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36934
An integer overflow in WhatsApp could result in remote code execution in an established video call.... Read more
- Published: Sep. 22, 2022
- Modified: Sep. 03, 2025
-
9.8
CRITICALCVE-2022-36976
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exists within the GroupDaoImpl class. A crafted request can trigger execution of SQL queries composed from a us... Read more
Affected Products : avalanche- Published: Mar. 29, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-54367
Deserialization of Untrusted Data vulnerability in ForumWP ForumWP allows Object Injection.This issue affects ForumWP: from n/a through 2.1.0.... Read more
Affected Products : forumwp- Published: Dec. 16, 2024
- Modified: Feb. 05, 2025
-
9.8
CRITICALCVE-2022-36681
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_account.... Read more
Affected Products : simple_task_scheduling_system- Published: Aug. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36669
Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.... Read more
Affected Products : hospital_information_system- Published: Sep. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36606
Ywoa before v6.1 was discovered to contain a SQL injection vulnerability via /oa/setup/checkPool?database.... Read more
Affected Products : ywoa- Published: Aug. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36588
In D-Link DAP1650 v1.04 firmware, the fileaccess.cgi program in the firmware has a buffer overflow vulnerability caused by strncpy.... Read more
- Published: Sep. 08, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36715
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/search.php.... Read more
Affected Products : library_management_system- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024