Latest CVE Feed
-
9.8
CRITICALCVE-2022-44808
A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can proces... Read more
- Published: Nov. 22, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44252
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.... Read more
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44251
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.... Read more
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44250
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.... Read more
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44249
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.... Read more
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44139
Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php.... Read more
Affected Products : apartment_visitors_management_system- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44120
dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.... Read more
Affected Products : dedecmsv6- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
4.8
MEDIUMCVE-2022-42985
The ScratchLogin extension through 1.1 for MediaWiki does not escape verification failure messages, which allows users with administrator privileges to perform cross-site scripting (XSS).... Read more
Affected Products : scratch_login- Published: Nov. 17, 2022
- Modified: Apr. 25, 2025
-
7.2
HIGHCVE-2022-39833
FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported API endpoints via a crafted HTTP request.... Read more
Affected Products : filecloud- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
6.3
MEDIUMCVE-2022-38753
This update resolves a multi-factor authentication bypass attack... Read more
Affected Products : netiq_advanced_authentication- Published: Nov. 28, 2022
- Modified: Apr. 25, 2025
-
5.4
MEDIUMCVE-2022-38147
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3).... Read more
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
5.4
MEDIUMCVE-2022-38145
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta description and get it executed in the versioned history compare view.... Read more
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
7.5
HIGHCVE-2022-37772
Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the application. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to compromised... Read more
Affected Products : maarch_rm- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
5.4
MEDIUMCVE-2022-37430
Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2).... Read more
Affected Products : framework- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
5.4
MEDIUMCVE-2022-37429
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a javascript URL with white space characters.... Read more
Affected Products : framework- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
5.4
MEDIUMCVE-2022-37421
Silverstripe silverstripe/cms through 4.11.0 allows XSS.... Read more
Affected Products : silverstripe- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-36784
Elsight – Elsight Halo Remote Code Execution (RCE) Elsight Halo web panel allows us to perform connection validation. through the POST request : /api/v1/nics/wifi/wlan0/ping we can abuse DESTINATION parameter and leverage it to remote code execution. ... Read more
- Published: Nov. 17, 2022
- Modified: Apr. 25, 2025
-
8.2
HIGHCVE-2022-36337
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the MebxConfiguration driver leads to arbitrary code execution. Control of a UEFI variable under the OS can cause this overflow when read by ... Read more
Affected Products : kernel- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2021-3942
Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR.... Read more
Affected Products : laserjet_managed_flow_mfp_e52545c_firmware pagewide_managed_color_flow_mfp_e58650z_firmware pagewide_managed_color_flow_mfp_e77660z_firmware pagewide_pro_577dw_d3q21a_firmware pagewide_pro_477dn_d3q19a_firmware pagewide_pro_477dw_d3q20a_firmware pagewide_377dw_j9v80a_firmware officejet_pro_6960_j7k33a_firmware officejet_pro_6960_t0f30a_firmware officejet_pro_6960_t0f32a_firmware +5390 more products- Published: Dec. 12, 2022
- Modified: Apr. 25, 2025
-
4.3
MEDIUMCVE-2020-23588
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to "Enable or Disable Ports" and to "Change port number" t... Read more
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025