Latest CVE Feed
-
9.8
CRITICALCVE-2022-36978
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The sp... Read more
Affected Products : avalanche- Published: Mar. 29, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-54383
Incorrect Privilege Assignment vulnerability in wpweb WooCommerce PDF Vouchers allows Privilege Escalation.This issue affects WooCommerce PDF Vouchers: from n/a before 4.9.9.... Read more
Affected Products :- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
9.8
CRITICALCVE-2022-36977
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The sp... Read more
Affected Products : avalanche- Published: Mar. 29, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36934
An integer overflow in WhatsApp could result in remote code execution in an established video call.... Read more
- Published: Sep. 22, 2022
- Modified: Sep. 03, 2025
-
9.8
CRITICALCVE-2022-36976
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exists within the GroupDaoImpl class. A crafted request can trigger execution of SQL queries composed from a us... Read more
Affected Products : avalanche- Published: Mar. 29, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-54367
Deserialization of Untrusted Data vulnerability in ForumWP ForumWP allows Object Injection.This issue affects ForumWP: from n/a through 2.1.0.... Read more
Affected Products : forumwp- Published: Dec. 16, 2024
- Modified: Feb. 05, 2025
-
9.8
CRITICALCVE-2022-36681
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_account.... Read more
Affected Products : simple_task_scheduling_system- Published: Aug. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36669
Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.... Read more
Affected Products : hospital_information_system- Published: Sep. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36606
Ywoa before v6.1 was discovered to contain a SQL injection vulnerability via /oa/setup/checkPool?database.... Read more
Affected Products : ywoa- Published: Aug. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36588
In D-Link DAP1650 v1.04 firmware, the fileaccess.cgi program in the firmware has a buffer overflow vulnerability caused by strncpy.... Read more
- Published: Sep. 08, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36715
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/search.php.... Read more
Affected Products : library_management_system- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36586
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by strcpy in function 0x869f4 in the httpd binary.... Read more
- Published: Sep. 08, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36560
Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers are able to access the passcodes at /etc/srapi/config/system.conf and /usr/sbin/ssol-sshd.sh.... Read more
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36555
Hytec Inter HWL-2511-SS v1.05 and below implements a SHA512crypt hash for the root account which can be easily cracked via a brute-force attack.... Read more
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36728
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /staff/delstu.php.... Read more
Affected Products : library_management_system- Published: Aug. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36557
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers to execute arbitrary code via a crafted html file.... Read more
Affected Products : skybridge_mb-a110_firmware skybridge_mb-a100_firmware skybridge_mb-a100 skybridge_mb-a110- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36678
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.... Read more
Affected Products : simple_task_scheduling_system- Published: Aug. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36697
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_waste.... Read more
Affected Products : ingredients_stock_management_system- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36519
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function AddWlanMacList.... Read more
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36444
An issue was discovered in Atos Unify OpenScape SBC 9 and 10 before 10R2.2.1, Atos Unify OpenScape Branch 9 and 10 before version 10R2.1.1, and Atos Unify OpenScape BCF 10 before 10R9.12.1. A remote code execution vulnerability may allow an unauthenticate... Read more
Affected Products : unify_openscape_bcf unify_openscape_branch unify_openscape_session_border_controller- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024