Latest CVE Feed
-
7.5
HIGHCVE-2022-45499
Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/WifiMacFilterGet.... Read more
- Published: Dec. 08, 2022
- Modified: Apr. 23, 2025
-
7.5
HIGHCVE-2022-45498
An issue in the component tpi_systool_handle(0) (/goform/SysToolReboot) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to arbitrarily reboot the device.... Read more
- Published: Dec. 08, 2022
- Modified: Apr. 23, 2025
-
9.8
CRITICALCVE-2022-45497
Tenda W6-S v1.0.0.4(510) was discovered to contain a command injection vulnerability in the tpi_get_ping_output function at /goform/exeCommand.... Read more
- Published: Dec. 08, 2022
- Modified: Apr. 23, 2025
-
4.9
MEDIUMCVE-2022-45326
An XML external entity (XXE) injection vulnerability in Kwoksys Kwok Information Server before v2.9.5.SP31 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks.... Read more
Affected Products : information_server- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
9.8
CRITICALCVE-2022-45010
Simple Phone Book/Directory Web App v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at /PhoneBook/edit.php.... Read more
Affected Products : simple_phone_book\/directory_web_app- Published: Dec. 07, 2022
- Modified: Apr. 23, 2025
-
9.1
CRITICALCVE-2022-44900
A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z file.... Read more
Affected Products : py7zr- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.2
HIGHCVE-2022-44838
Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /services/view_service.php.... Read more
Affected Products : automotive_shop_management_system- Published: Dec. 09, 2022
- Modified: Apr. 23, 2025
-
7.5
HIGHCVE-2022-44790
Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could successfully perform an attack to extract potentially sensitive information from the database if the survey id exists.... Read more
Affected Products : email_marketer- Published: Dec. 09, 2022
- Modified: Apr. 23, 2025
-
8.8
HIGHCVE-2022-44289
Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.... Read more
Affected Products : thinkphp- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-43509
Out-of-bounds write vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.... Read more
Affected Products : cx-programmer- Published: Dec. 07, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-43508
Use-after free vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.... Read more
Affected Products : cx-programmer- Published: Dec. 07, 2022
- Modified: Apr. 23, 2025
-
8.8
HIGHCVE-2022-43464
Hidden functionality vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.... Read more
Affected Products : udr-ja1604_firmware udr-ja1608_firmware udr-ja1616_firmware udr-ja1604 udr-ja1608 udr-ja1616- Published: Dec. 07, 2022
- Modified: Apr. 23, 2025
-
3.3
LOWCVE-2022-42769
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
9.8
CRITICALCVE-2022-42458
Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a remote unauthenticated attacker to upload an arbitrary file. As a result, an arbitrary script may be executed and/or a file may be alte... Read more
Affected Products : bingo\!cms- Published: Dec. 07, 2022
- Modified: Apr. 23, 2025
-
5.5
MEDIUMCVE-2022-42329
Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might result in a dea... Read more
- Published: Dec. 07, 2022
- Modified: Apr. 23, 2025
-
6.2
MEDIUMCVE-2022-42328
Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might result in a dea... Read more
- Published: Dec. 07, 2022
- Modified: Apr. 23, 2025
-
4.8
MEDIUMCVE-2022-41994
Stored cross-site scripting vulnerability in Permission Settings of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.... Read more
Affected Products : basercms- Published: Dec. 07, 2022
- Modified: Apr. 23, 2025
-
7.5
HIGHCVE-2022-3907
The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API keys against the ones stored in the site options.... Read more
Affected Products : clerk.io- Published: Dec. 05, 2022
- Modified: Apr. 23, 2025
-
7.2
HIGHCVE-2022-3858
The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line, WeChat, Email, SMS, Call Button WordPress plugin before 3.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable b... Read more
Affected Products : chaty- Published: Dec. 05, 2022
- Modified: Apr. 23, 2025