Latest CVE Feed
-
9.8
CRITICALCVE-2022-31199
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the unde... Read more
Affected Products : auditor- Actively Exploited
- Published: Nov. 08, 2022
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2022-31347
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=delete_vehicle.... Read more
Affected Products : online_car_wash_booking_system- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31327
Online Ordering System By janobe 2.3.2 is vulneranle to SQL Injection via /ordering/index.php?q=products&id=.... Read more
Affected Products : online_ordering_system- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31082
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. glpi-inventory-plugin is a plugin for GLPI to handle inventory management. In affected versions a SQL injection ca... Read more
Affected Products : glpi_inventory- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31180
Shescape is a simple shell escape package for JavaScript. Affected versions were found to have insufficient escaping of white space when interpolating output. This issue only impacts users that use the `escape` or `escapeAll` functions with the `interpola... Read more
Affected Products : shescape- Published: Aug. 01, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31188
CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vulnerability. Validation has been added to urls used in the affected code path... Read more
- Published: Aug. 01, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31207
The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic authentication. They utilize the Omron FINS (9600/TCP) protocol for engineering purposes, including downloading projects and control logic ... Read more
Affected Products : cp1w-cif41_firmware sysmac_cs1_firmware sysmac_cj2m_firmware sysmac_cj2h_firmware sysmac_cp1e_firmware sysmac_cp1h_firmware sysmac_cp1l_firmware sysmac_cs1 sysmac_cj2m sysmac_cj2h +4 more products- Published: Jul. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31031
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions prior to and including 2.12.1 a stack buffer overflow vulnerability affect... Read more
- Published: Jun. 09, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31045
Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configurations can lead to unexpected memory access resulting in undefined behavior or crashing. Users are most likely... Read more
Affected Products : istio- Published: Jun. 09, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31003
Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, when parsing each line of a sdp message, `rest = record + 2` will access the memory behind `\0` and cause an out-of-bounds write. An attacker can se... Read more
- Published: May. 31, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30877
The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2.... Read more
Affected Products : keep- Published: Jun. 08, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30838
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=update_application_status... Read more
Affected Products : covid_19_travel_pass_management_system- Published: May. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30797
Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php.... Read more
Affected Products : online_ordering_system- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30817
Simple Bus Ticket Booking System 1.0 is vulnerable to SQL Injection via /SimpleBusTicket/index.php.... Read more
Affected Products : simple_bus_ticket_booking_system- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30722
Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Account.... Read more
- Published: Jun. 07, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30813
elitecms 1.01 is vulnerable to SQL Injection via /admin/add_post.php.... Read more
Affected Products : elite_cms- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30600
A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.... Read more
- Published: May. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30512
School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31.... Read more
Affected Products : school_dormitory_management_system- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30516
In Hospital-Management-System v1.0, the editid parameter in the doctor.php page is vulnerable to SQL injection attacks.... Read more
Affected Products : hospital_management_system- Published: May. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-20788
libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690.... Read more
- Published: Apr. 23, 2020
- Modified: Nov. 21, 2024