Export limit exceeded: 375260 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (375260 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-27441 | 1 Tpcms Project | 1 Tpcms | 2024-11-21 | 4.8 Medium |
| A stored cross-site scripting (XSS) vulnerability in TPCMS v3.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Phone text box. | ||||
| CVE-2022-27438 | 29 3cx, Boom, Caphyon and 26 more | 99 Call Flow Designer, Crm Template Generator, Boomtv Streamer Portal and 96 more | 2024-11-21 | 8.1 High |
| Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check. | ||||
| CVE-2022-27436 | 1 Ecommerce-website Project | 1 Ecommerce-website | 2024-11-21 | 4.8 Medium |
| A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username text field. | ||||
| CVE-2022-27435 | 1 Ecommerce-website Project | 1 Ecommerce-website | 2024-11-21 | 8.8 High |
| An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component. | ||||
| CVE-2022-27434 | 1 Unit4 | 1 Teta | 2024-11-21 | 9.8 Critical |
| UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in the errorReporting page. | ||||
| CVE-2022-27432 | 1 Pluck-cms | 1 Pluck | 2024-11-21 | 8.8 High |
| A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover. | ||||
| CVE-2022-27429 | 1 Jizhicms | 1 Jizhicms | 2024-11-21 | 9.8 Critical |
| Jizhicms v1.9.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via /admin.php/Plugins/update.html. | ||||
| CVE-2022-27428 | 1 Gallerycms Project | 1 Gallerycms | 2024-11-21 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in /index.php/album/add of GalleryCMS v2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the album_name parameter. | ||||
| CVE-2022-27426 | 1 Chamilo | 1 Chamilo Lms | 2024-11-21 | 8.8 High |
| A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and execute arbitrary system commands via a crafted Phar file. | ||||
| CVE-2022-27425 | 1 Chamilo | 1 Chamilo | 2024-11-21 | 6.1 Medium |
| Chamilo LMS v1.11.13 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /blog/blog.php. | ||||
| CVE-2022-27423 | 1 Chamilo | 1 Chamilo Lms | 2024-11-21 | 9.8 Critical |
| Chamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php. | ||||
| CVE-2022-27422 | 1 Chamilo | 1 Chamilo Lms | 2024-11-21 | 6.1 Medium |
| A reflected cross-site scripting (XSS) vulnerability in Chamilo LMS v1.11.13 allows attackers to execute arbitrary web scripts or HTML via user interaction with a crafted URL. | ||||
| CVE-2022-27421 | 1 Chamilo | 1 Chamilo Lms | 2024-11-21 | 7.2 High |
| Chamilo LMS v1.11.13 lacks validation on the user modification form, allowing attackers to escalate privileges to Platform Admin. | ||||
| CVE-2022-27420 | 1 Hospital Management System Project | 1 Hospital Management System | 2024-11-21 | 9.8 Critical |
| Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php. | ||||
| CVE-2022-27419 | 1 Rtl 433 Project | 1 Rtl 433 | 2024-11-21 | 5.5 Medium |
| rtl_433 21.12 was discovered to contain a stack overflow in the function acurite_00275rm_decode at /devices/acurite.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file. | ||||
| CVE-2022-27418 | 1 Broadcom | 1 Tcpreplay | 2024-11-21 | 7.8 High |
| Tcpreplay v4.4.1 has a heap-based buffer overflow in do_checksum_math at /tcpedit/checksum.c. | ||||
| CVE-2022-27416 | 1 Broadcom | 1 Tcpreplay | 2024-11-21 | 7.8 High |
| Tcpreplay v4.4.1 was discovered to contain a double-free via __interceptor_free. | ||||
| CVE-2022-27413 | 1 Hospital Management System Project | 1 Hospital Management System | 2024-11-21 | 9.8 Critical |
| Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in admin.php. | ||||
| CVE-2022-27412 | 1 Exploreit | 1 Explore Cms | 2024-11-21 | 9.8 Critical |
| Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request. | ||||
| CVE-2022-27411 | 1 Totolink | 2 N600r, N600r Firmware | 2024-11-21 | 9.8 Critical |
| TOTOLINK N600R v5.3c.5507_B20171031 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter in the "Main" function. | ||||