Export limit exceeded: 96477 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (96477 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-28113 | 1 Fantec | 2 Mwid25-ds, Mwid25-ds Firmware | 2024-11-21 | 7.2 High |
| An issue in upload.csp of FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows attackers to write files and reset the user passwords without having a valid session cookie. | ||||
| CVE-2022-28109 | 1 Selenium | 1 Selenium Grid | 2024-11-21 | 8.8 High |
| Selenium Selenium Grid (formerly Selenium Standalone Server) Fixed in 4.0.0-alpha-7 is affected by: DNS rebinding. The impact is: execute arbitrary code (remote). The component is: WebDriver endpoint of Selenium Grid / Selenium Standalone Server. The attack vector is: Triggered by browsing to to a malicious remote web server. The WebDriver endpoint of Selenium Server (Grid) is vulnerable to DNS rebinding. This can be used to execute arbitrary code on the machine. | ||||
| CVE-2022-28108 | 1 Selenium | 1 Selenium Grid | 2024-11-21 | 8.8 High |
| Selenium Server (Grid) before 4 allows CSRF because it permits non-JSON content types such as application/x-www-form-urlencoded, multipart/form-data, and text/plain. | ||||
| CVE-2022-28099 | 1 Poultry Farm Management System Project | 1 Poultry Farm Management System | 2024-11-21 | 8.8 High |
| Poultry Farm Management System v1.0 was discovered to contain a SQL injection vulnerability via the Item parameter at /farm/store.php. | ||||
| CVE-2022-28096 | 1 Skycaiji | 1 Skycaiji | 2024-11-21 | 7.2 High |
| Skycaiji v2.4 was discovered to contain a remote code execution (RCE) vulnerability via /SkycaijiApp/admin/controller/Develop.php. | ||||
| CVE-2022-28080 | 1 Event Management System Project | 1 Event Management System | 2024-11-21 | 8.8 High |
| Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter. | ||||
| CVE-2022-28079 | 1 College Management System Project | 1 College Management System | 2024-11-21 | 8.8 High |
| College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter. | ||||
| CVE-2022-28076 | 1 Seacms | 1 Seacms | 2024-11-21 | 7.2 High |
| Seacms v11.6 was discovered to contain a remote command execution (RCE) vulnerability via the Mail Server Settings. | ||||
| CVE-2022-28073 | 1 Radare | 1 Radare2 | 2024-11-21 | 7.5 High |
| A use after free in r_reg_set_value function in radare2 5.4.2 and 5.4.0. | ||||
| CVE-2022-28072 | 1 Radare | 1 Radare2 | 2024-11-21 | 7.5 High |
| A heap buffer overflow in r_read_le32 function in radare25.4.2 and 5.4.0. | ||||
| CVE-2022-28071 | 1 Radare | 1 Radare2 | 2024-11-21 | 7.5 High |
| A use after free in r_reg_get_name_idx function in radare2 5.4.2 and 5.4.0. | ||||
| CVE-2022-28070 | 1 Radare | 1 Radare2 | 2024-11-21 | 7.5 High |
| A null pointer deference in __core_anal_fcn function in radare2 5.4.2 and 5.4.0. | ||||
| CVE-2022-28069 | 1 Radare | 1 Radare2 | 2024-11-21 | 7.5 High |
| A heap buffer overflow in vax_opfunction in radare2 5.4.2 and 5.4.0. | ||||
| CVE-2022-28068 | 1 Radare | 1 Radare2 | 2024-11-21 | 7.5 High |
| A heap buffer overflow in r_sleb128 function in radare2 5.4.2 and 5.4.0. | ||||
| CVE-2022-28067 | 1 Sandboxie | 1 Sandboxie | 2024-11-21 | 8.6 High |
| An incorrect access control issue in Sandboxie Classic v5.55.13 allows attackers to cause a Denial of Service (DoS) in the Sandbox via a crafted executable. | ||||
| CVE-2022-28062 | 1 Online Car Rental System Project | 1 Online Car Rental System | 2024-11-21 | 8.8 High |
| Car Rental System v1.0 contains an arbitrary file upload vulnerability via the Add Car component which allows attackers to upload a webshell and execute arbitrary code. | ||||
| CVE-2022-28060 | 1 Victor Cms Project | 1 Victor Cms | 2024-11-21 | 7.5 High |
| SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php. | ||||
| CVE-2022-28059 | 1 Verydows | 1 Verydows | 2024-11-21 | 8.1 High |
| Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\database_controller.php. | ||||
| CVE-2022-28058 | 1 Verydows | 1 Verydows | 2024-11-21 | 8.1 High |
| Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\file_controller.php. | ||||
| CVE-2022-28053 | 1 Typemill | 1 Typemill | 2024-11-21 | 8.8 High |
| Typemill v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | ||||