Latest CVE Feed
-
9.8
CRITICALCVE-2022-31965
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/respondent_types/manage_respondent_type.php?id=.... Read more
Affected Products : rescue_dispatch_management_system- EPSS Score: %0.25
- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31784
A vulnerability in the management interface of MiVoice Business through 9.3 PR1 and MiVoice Business Express through 8.0 SP3 PR3 could allow an unauthenticated attacker (that has network access to the management interface) to conduct a buffer overflow att... Read more
- EPSS Score: %1.67
- Published: Jun. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31691
Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39.0 and below all use Snakeyaml library for YAML editing... Read more
- EPSS Score: %18.84
- Published: Nov. 04, 2022
- Modified: May. 02, 2025
-
9.8
CRITICALCVE-2022-31605
NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.safe_load(). The deserialization of Untrusted Data, may allow an unprivileged network attacker to cause Remote Code... Read more
Affected Products : nvflare- EPSS Score: %2.44
- Published: Jul. 01, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31627
In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.... Read more
Affected Products : php- EPSS Score: %0.13
- Published: Jul. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31383
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.... Read more
- EPSS Score: %0.68
- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31350
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/vehicles/manage_vehicle.php?id=.... Read more
Affected Products : online_car_wash_booking_system- EPSS Score: %0.25
- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31352
Online Car Wash Booking System v1.0 by oretnom23 has SQL injection in /ocwbs/admin/services/manage_service.php?id=.... Read more
Affected Products : online_car_wash_booking_system- EPSS Score: %0.25
- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31348
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/bookings/update_status.php?id=.... Read more
Affected Products : online_car_wash_booking_system- EPSS Score: %0.25
- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31273
An issue in TopIDP3000 Topsec Operating System tos_3.3.005.665b.15_smpidp allows attackers to perform a brute-force attack via a crafted session_id cookie.... Read more
Affected Products : topidp3000_topsec_operating_system- EPSS Score: %0.29
- Published: Jun. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31382
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.... Read more
- EPSS Score: %0.68
- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31249
A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in wrangler of SUSE Rancher allows remote attackers to inject commands in the underlying host via crafted commands passed to Wrangler. This issue af... Read more
- EPSS Score: %1.45
- Published: Feb. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31296
Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php.... Read more
Affected Products : online_discussion_forum- EPSS Score: %6.01
- Published: Jun. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31361
Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer... Read more
Affected Products : docebo- EPSS Score: %0.26
- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31259
The route lookup process in beego before 1.12.9 and 2.x before 2.0.3 allows attackers to bypass access control. When a /p1/p2/:name route is configured, attackers can access it by appending .xml in various places (e.g., p1.xml instead of p1).... Read more
Affected Products : beego- EPSS Score: %0.25
- Published: May. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31199
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the unde... Read more
Affected Products : auditor- Actively Exploited
- EPSS Score: %4.32
- Published: Nov. 08, 2022
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2022-31347
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=delete_vehicle.... Read more
Affected Products : online_car_wash_booking_system- EPSS Score: %0.25
- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31327
Online Ordering System By janobe 2.3.2 is vulneranle to SQL Injection via /ordering/index.php?q=products&id=.... Read more
Affected Products : online_ordering_system- EPSS Score: %0.24
- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31082
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. glpi-inventory-plugin is a plugin for GLPI to handle inventory management. In affected versions a SQL injection ca... Read more
Affected Products : glpi_inventory- EPSS Score: %0.27
- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31180
Shescape is a simple shell escape package for JavaScript. Affected versions were found to have insufficient escaping of white space when interpolating output. This issue only impacts users that use the `escape` or `escapeAll` functions with the `interpola... Read more
Affected Products : shescape- EPSS Score: %1.02
- Published: Aug. 01, 2022
- Modified: Nov. 21, 2024