Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2022-45510

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the mit_ssid_index parameter at /goform/AdvSetWrlsafeset.... Read more

    Affected Products : w30e_firmware w30e
    • Published: Dec. 08, 2022
    • Modified: Apr. 23, 2025
  • 7.5

    HIGH
    CVE-2022-45509

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the account parameter at /goform/addUserName.... Read more

    Affected Products : w30e_firmware w30e
    • Published: Dec. 08, 2022
    • Modified: Apr. 23, 2025
  • 7.5

    HIGH
    CVE-2022-45508

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the new_account parameter at /goform/editUserName.... Read more

    Affected Products : w30e_firmware w30e
    • Published: Dec. 08, 2022
    • Modified: Apr. 23, 2025
  • 7.5

    HIGH
    CVE-2022-45507

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the editNameMit parameter at /goform/editFileName.... Read more

    Affected Products : w30e_firmware w30e
    • Published: Dec. 08, 2022
    • Modified: Apr. 23, 2025
  • 9.8

    CRITICAL
    CVE-2022-45506

    Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /goform/delFileName.... Read more

    Affected Products : w30e_firmware w30e
    • Published: Dec. 08, 2022
    • Modified: Apr. 23, 2025
  • 7.5

    HIGH
    CVE-2022-45505

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the cmdinput parameter at /goform/exeCommand.... Read more

    Affected Products : w30e_firmware w30e
    • Published: Dec. 08, 2022
    • Modified: Apr. 23, 2025
  • 7.5

    HIGH
    CVE-2022-45504

    An issue in the component tpi_systool_handle(0) (/goform/SysToolRestoreSet) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to arbitrarily reboot the device.... Read more

    Affected Products : w6-s_firmware w6-s
    • Published: Dec. 08, 2022
    • Modified: Apr. 23, 2025
  • 7.5

    HIGH
    CVE-2022-45503

    Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the linkEn parameter at /goform/setAutoPing.... Read more

    Affected Products : w6-s_firmware w6-s
    • Published: Dec. 08, 2022
    • Modified: Apr. 23, 2025
  • 7.5

    HIGH
    CVE-2022-45501

    Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/wifiSSIDset.... Read more

    Affected Products : w6-s_firmware w6-s
    • Published: Dec. 08, 2022
    • Modified: Apr. 23, 2025
  • 7.5

    HIGH
    CVE-2022-45499

    Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/WifiMacFilterGet.... Read more

    Affected Products : w6-s_firmware w6-s
    • Published: Dec. 08, 2022
    • Modified: Apr. 23, 2025
  • 7.5

    HIGH
    CVE-2022-45498

    An issue in the component tpi_systool_handle(0) (/goform/SysToolReboot) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to arbitrarily reboot the device.... Read more

    Affected Products : w6-s_firmware w6-s
    • Published: Dec. 08, 2022
    • Modified: Apr. 23, 2025
  • 9.8

    CRITICAL
    CVE-2022-45497

    Tenda W6-S v1.0.0.4(510) was discovered to contain a command injection vulnerability in the tpi_get_ping_output function at /goform/exeCommand.... Read more

    Affected Products : w6-s_firmware w6-s
    • Published: Dec. 08, 2022
    • Modified: Apr. 23, 2025
  • 4.9

    MEDIUM
    CVE-2022-45326

    An XML external entity (XXE) injection vulnerability in Kwoksys Kwok Information Server before v2.9.5.SP31 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks.... Read more

    Affected Products : information_server
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 9.8

    CRITICAL
    CVE-2022-45010

    Simple Phone Book/Directory Web App v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at /PhoneBook/edit.php.... Read more

    • Published: Dec. 07, 2022
    • Modified: Apr. 23, 2025
  • 9.1

    CRITICAL
    CVE-2022-44900

    A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z file.... Read more

    Affected Products : py7zr
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 7.2

    HIGH
    CVE-2022-44838

    Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /services/view_service.php.... Read more

    Affected Products : automotive_shop_management_system
    • Published: Dec. 09, 2022
    • Modified: Apr. 23, 2025
  • 7.5

    HIGH
    CVE-2022-44790

    Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could successfully perform an attack to extract potentially sensitive information from the database if the survey id exists.... Read more

    Affected Products : email_marketer
    • Published: Dec. 09, 2022
    • Modified: Apr. 23, 2025
  • 8.8

    HIGH
    CVE-2022-44289

    Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.... Read more

    Affected Products : thinkphp
    • Published: Dec. 06, 2022
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2022-43509

    Out-of-bounds write vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.... Read more

    Affected Products : cx-programmer
    • Published: Dec. 07, 2022
    • Modified: Apr. 23, 2025
  • 7.8

    HIGH
    CVE-2022-43508

    Use-after free vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.... Read more

    Affected Products : cx-programmer
    • Published: Dec. 07, 2022
    • Modified: Apr. 23, 2025
Showing 20 of 293609 Results