Latest CVE Feed
-
9.8
CRITICALCVE-2022-28346
An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the ... Read more
- EPSS Score: %2.04
- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28104
Foxit PDF Editor v11.3.1 was discovered to contain an arbitrary file upload vulnerability.... Read more
- EPSS Score: %0.58
- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28022
Purchase Order Management System v1.0 was discovered to contain a SQL injection vulnerability via /purchase_order/classes/Master.php?f=delete_item.... Read more
Affected Products : purchase_order_management_system- EPSS Score: %8.16
- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27984
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.... Read more
Affected Products : cuppacms- EPSS Score: %24.64
- Published: Apr. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28005
An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse improperly secured access to arbitrary files on the server (via /Electron/download directory traversal in conjun... Read more
Affected Products : 3cx- EPSS Score: %4.68
- Published: May. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27982
RG-NBR-E Enterprise Gateway RG-NBR2100G-E was discovered to contain a remote code execution (RCE) vulnerability via the fileName parameter at /guest_auth/cfg/upLoadCfg.php.... Read more
- EPSS Score: %3.02
- Published: May. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28034
AtomCMS 2.0 is vulnerabie to SQL Injection via Atom.CMS_admin_ajax_list-sort.php... Read more
Affected Products : atomcms- EPSS Score: %0.48
- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-53915
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24405. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.... Read more
Affected Products : enterprise_vault- Published: Nov. 24, 2024
- Modified: Nov. 29, 2024
-
9.8
CRITICALCVE-2022-28044
Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control.... Read more
- EPSS Score: %0.23
- Published: Apr. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28025
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=school_year.... Read more
Affected Products : student_grading_system- EPSS Score: %0.29
- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27919
Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configuration allows certain anonymous access to administration and an API.... Read more
Affected Products : enterprise- EPSS Score: %2.15
- Published: Mar. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28026
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=student_p&id=.... Read more
Affected Products : student_grading_system- EPSS Score: %0.29
- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28029
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_type.... Read more
Affected Products : simple_real_estate_portal_system- EPSS Score: %0.29
- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27805
An authentication bypass vulnerability exists in the GHOME control functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted network request can lead to arbitrary XCMD execution. An attacker can send a malicious ... Read more
- EPSS Score: %0.18
- Published: Oct. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27804
An os command injection vulnerability exists in the web interface util_set_abode_code functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker ca... Read more
- EPSS Score: %0.43
- Published: Oct. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28024
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=grade.... Read more
Affected Products : student_grading_system- EPSS Score: %0.29
- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27631
A memory corruption vulnerability exists in the httpd unescape functionality of DD-WRT Revision 32270 - Revision 48599. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.... Read more
Affected Products : dd-wrt- EPSS Score: %2.39
- Published: Aug. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27516
User login brute force protection functionality bypass ... Read more
Affected Products : gateway application_delivery_controller_firmware application_delivery_controller- EPSS Score: %0.03
- Published: Nov. 08, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27586
Password recovery vulnerability in SICK SIM1004 Partnumber 1098148 with firmware version <2.0.0 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. Th... Read more
- EPSS Score: %2.26
- Published: Nov. 01, 2022
- Modified: May. 06, 2025
-
9.8
CRITICALCVE-2022-27468
Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to the web server.... Read more
Affected Products : monsta_ftp- EPSS Score: %0.95
- Published: Apr. 26, 2022
- Modified: Nov. 21, 2024