Export limit exceeded: 387425 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (387425 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-26269 | 1 Globalsuzuki | 1 Suzuki Connect | 2024-11-21 | 4.6 Medium |
| Suzuki Connect v1.0.15 allows attackers to tamper with displayed messages via spoofed CAN messages. | ||||
| CVE-2022-26268 | 1 Xiaohuanxiong Project | 1 Xiaohuanxiong | 2024-11-21 | 9.8 Critical |
| Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books.php. | ||||
| CVE-2022-26267 | 1 Piwigo | 1 Piwigo | 2024-11-21 | 7.5 High |
| Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php. | ||||
| CVE-2022-26266 | 1 Piwigo | 1 Piwigo | 2024-11-21 | 8.8 High |
| Piwigo v12.2.0 was discovered to contain a SQL injection vulnerability via pwg.users.php. | ||||
| CVE-2022-26265 | 1 Contao | 1 Contao | 2024-11-21 | 9.8 Critical |
| Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter. | ||||
| CVE-2022-26263 | 1 Yonyou | 1 U8\+ | 2024-11-21 | 6.1 Medium |
| Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp. | ||||
| CVE-2022-26260 | 1 Simple-plist Project | 1 Simple-plist | 2024-11-21 | 9.8 Critical |
| Simple-Plist v1.3.0 was discovered to contain a prototype pollution vulnerability via .parse(). | ||||
| CVE-2022-26259 | 1 Xiongmaitech | 20 Ahb80n16t-gs, Ahb80n16t-gs Firmware, Ahb80n32f4-lme and 17 more | 2024-11-21 | 7.8 High |
| A buffer over flow in Xiongmai DVR devices NBD80X16S-KL, NBD80X09S-KL, NBD80X08S-KL, NBD80X09RA-KL, AHB80X04R-MH, AHB80X04R-MH-V2, AHB80X04-R-MH-V3, AHB80N16T-GS, AHB80N32F4-LME, and NBD90S0VT-QW allows attackers to cause a Denial of Service (DoS) via a crafted RSTP request. | ||||
| CVE-2022-26255 | 1 Clash Project | 1 Clash | 2024-11-21 | 9.8 Critical |
| Clash for Windows v0.19.8 was discovered to allow arbitrary code execution via a crafted payload injected into the Proxies name column. | ||||
| CVE-2022-26254 | 1 Wowonder | 1 Wowonder | 2024-11-21 | 5.3 Medium |
| WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to arbitrarily change group ID names. | ||||
| CVE-2022-26252 | 1 Aapanel | 1 Aapanel | 2024-11-21 | 6.5 Medium |
| aaPanel v6.8.21 was discovered to be vulnerable to directory traversal. This vulnerability allows attackers to obtain the root user private SSH key(id_rsa). | ||||
| CVE-2022-26251 | 1 Synametrics | 1 Synaman | 2024-11-21 | 7.2 High |
| The HTTP interface of Synaman v5.1 and below was discovered to allow authenticated attackers to execute arbitrary code and escalate privileges. | ||||
| CVE-2022-26250 | 1 Synametrics | 1 Synaman | 2024-11-21 | 7.8 High |
| Synaman v5.1 and below was discovered to contain weak file permissions which allows authenticated attackers to escalate privileges. | ||||
| CVE-2022-26249 | 1 Surveyking Project | 1 Surveyking | 2024-11-21 | 9.8 Critical |
| Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitive information via a CSV injection attack. | ||||
| CVE-2022-26247 | 1 Teamwork Management System Project | 1 Teamwork Management System | 2024-11-21 | 5.9 Medium |
| TMS v2.28.0 contains an insecure permissions vulnerability via the component /TMS/admin/user/Update2. This vulnerability allows attackers to modify the administrator account and password. | ||||
| CVE-2022-26246 | 1 Tms Project | 1 Tms | 2024-11-21 | 6.1 Medium |
| TMS v2.28.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /TMS/admin/setting/mail/createorupdate. | ||||
| CVE-2022-26245 | 1 Open-falcon | 1 Falcon-plus | 2024-11-21 | 9.8 Critical |
| Falcon-plus v0.3 was discovered to contain a SQL injection vulnerability via the parameter grpName in /config/service/host.go. | ||||
| CVE-2022-26244 | 1 Hospital\'s Patient Records Management System Project | 1 Hospital\'s Patient Records Management System | 2024-11-21 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "special" field. | ||||
| CVE-2022-26243 | 1 Tendacn | 2 Ac10, Ac10 Firmware | 2024-11-21 | 7.5 High |
| Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow in the setSmartPowerManagement function. | ||||
| CVE-2022-26240 | 2 Beckmancoulter, Microsoft | 2 Remisol Advance, Windows | 2024-11-21 | 6.5 Medium |
| The default privileges for the running service Normand Message Buffer in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data. | ||||