Latest CVE Feed
-
9.8
CRITICALCVE-2022-36557
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers to execute arbitrary code via a crafted html file.... Read more
Affected Products : skybridge_mb-a110_firmware skybridge_mb-a100_firmware skybridge_mb-a100 skybridge_mb-a110- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36678
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.... Read more
Affected Products : simple_task_scheduling_system- Published: Aug. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36697
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_waste.... Read more
Affected Products : ingredients_stock_management_system- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36519
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function AddWlanMacList.... Read more
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36444
An issue was discovered in Atos Unify OpenScape SBC 9 and 10 before 10R2.2.1, Atos Unify OpenScape Branch 9 and 10 before version 10R2.1.1, and Atos Unify OpenScape BCF 10 before 10R9.12.1. A remote code execution vulnerability may allow an unauthenticate... Read more
Affected Products : unify_openscape_bcf unify_openscape_branch unify_openscape_session_border_controller- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36558
Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able to access the passcord via the file /etc/ciel.cfg.... Read more
Affected Products : skybridge_mb-a110_firmware skybridge_mb-a100_firmware skybridge_mb-a100 skybridge_mb-a110- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36418
Missing Authorization vulnerability in Vagary Digital HREFLANG Tags Lite.This issue affects HREFLANG Tags Lite: from n/a through 2.0.0. ... Read more
Affected Products : hreflang_tags_lite- Published: Jan. 17, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36344
An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted fi... Read more
Affected Products : ichitaro_government_8 ichitaro_pro_3 just_jump_class atok_medical_2 atok_medical_3 atok_pro_3 atok_pro_4 atok_pro_5 hanako_police_5 hanako_police_6 +51 more products- Published: Aug. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36692
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.... Read more
Affected Products : ingredients_stock_management_system- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36749
RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php. This vulnerability is exploited via a crafted payload injected into the file name of an uploaded file.... Read more
Affected Products : rpi-jukebox-rfid- Published: Aug. 30, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36361
A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA1) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA1) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA1) (All versions), LOGO! 24CE... Read more
- Published: Oct. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36585
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, in httpd binary, the addDhcpRule function has a buffer overflow caused by sscanf.... Read more
- Published: Sep. 07, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36387
Broken Access Control vulnerability in Alessio Caiazza's About Me plugin <= 1.0.12 at WordPress.... Read more
Affected Products : about-me- Published: Sep. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36227
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 rema... Read more
- Published: Nov. 22, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36202
Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter.... Read more
Affected Products : doctor\'s_appointment_system- Published: Aug. 31, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36327
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to write files to locations with certain critical filesystem types leading to remote code execution was discovered in Western Digital... Read more
Affected Products : my_cloud_os_5 my_cloud_home_firmware my_cloud_home_duo_firmware sandisk_ibi_firmware my_cloud my_cloud_dl2100 my_cloud_dl4100 my_cloud_ex2_ultra my_cloud_ex2100 my_cloud_ex4100 +7 more products- Published: May. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36193
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.... Read more
- Published: Nov. 28, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-36270
Clinic's Patient Management System v1.0 has arbitrary code execution via url: ip/pms/users.php.... Read more
- Published: Aug. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36425
Broken Access Control vulnerability in Beaver Builder plugin <= 2.5.4.3 at WordPress.... Read more
Affected Products : beaver_builder- Published: Sep. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36085
Open Policy Agent (OPA) is an open source, general-purpose policy engine. The Rego compiler provides a (deprecated) `WithUnsafeBuiltins` function, which allows users to provide a set of built-in functions that should be deemed unsafe — and as such rejecte... Read more
Affected Products : open_policy_agent- Published: Sep. 08, 2022
- Modified: Nov. 21, 2024