Export limit exceeded: 375239 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (375239 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-26627 | 1 Online Project Time Management System Project | 1 Online Project Time Management System | 2024-11-21 | 8.8 High |
| Online Project Time Management System v1.0 was discovered to contain an arbitrary file write vulnerability which allows attackers to execute arbitrary code via a crafted HTML file. | ||||
| CVE-2022-26624 | 1 Ecommerce Codeigniter Bootstrap Project | 1 Ecommerce Codeigniter Bootstrap | 2024-11-21 | 6.1 Medium |
| Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title parameter in /vendor/views/add_product.php. | ||||
| CVE-2022-26619 | 1 Halo | 1 Halo | 2024-11-21 | 7.5 High |
| Halo Blog CMS v1.4.17 was discovered to allow attackers to upload arbitrary files via the Attachment Upload function. | ||||
| CVE-2022-26616 | 1 Public Knowledge Project | 1 Open Journal Systems | 2024-11-21 | 6.1 Medium |
| PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers. | ||||
| CVE-2022-26615 | 1 College Website Content Management System Project | 1 College Website Content Management System | 2024-11-21 | 5.4 Medium |
| A cross-site scripting (XSS) vulnerability in College Website Content Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User Profile Name text fields. | ||||
| CVE-2022-26613 | 1 Php-cms Project | 1 Php-cms | 2024-11-21 | 9.8 Critical |
| PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability via the category parameter in categorymenu.php. | ||||
| CVE-2022-26612 | 2 Apache, Microsoft | 2 Hadoop, Windows | 2024-11-21 | 9.8 Critical |
| In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR entry may create a symlink under the expected extraction directory which points to an external directory. A subsequent TAR entry may extract an arbitrary file into the external directory using the symlink name. This however would be caught by the same targetDirPath check on Unix because of the getCanonicalPath call. However on Windows, getCanonicalPath doesn't resolve symbolic links, which bypasses the check. unpackEntries during TAR extraction follows symbolic links which allows writing outside expected base directory on Windows. This was addressed in Apache Hadoop 3.2.3 | ||||
| CVE-2022-26607 | 1 Baigo | 1 Baigo Cms | 2024-11-21 | 7.2 High |
| A remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbitrary code via uploading a crafted PHP file. | ||||
| CVE-2022-26605 | 1 Dascomsoft | 1 Eziosuite | 2024-11-21 | 8.8 High |
| eZiosuite v2.0.7 contains an authenticated arbitrary file upload via the Avatar upload functionality. | ||||
| CVE-2022-26595 | 1 Liferay | 2 Digital Experience Platform, Liferay Portal | 2024-11-21 | 4.3 Medium |
| Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permission when accessing a list of sites/groups, which allows remote authenticated users to view sites/groups via the user's site membership assignment UI. | ||||
| CVE-2022-26594 | 1 Liferay | 1 Liferay Portal | 2024-11-21 | 6.1 Medium |
| Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote attackers to inject arbitrary web script or HTML via a form field's help text to (1) Forms module's form builder, or (2) App Builder module's object form view's form builder. | ||||
| CVE-2022-26593 | 1 Liferay | 2 Digital Experience Platform, Liferay Portal | 2024-11-21 | 5.4 Medium |
| Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the name of a asset category. | ||||
| CVE-2022-26592 | 1 Sass-lang | 1 Libsass | 2024-11-21 | 8.8 High |
| Stack Overflow vulnerability in libsass 3.6.5 via the CompoundSelector::has_real_parent_ref function. | ||||
| CVE-2022-26591 | 1 Fantec | 2 Mwid25-ds, Mwid25-ds Firmware | 2024-11-21 | 7.5 High |
| FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows unauthenticated attackers to access and download arbitrary files via a crafted GET request. | ||||
| CVE-2022-26589 | 1 Pluck-cms | 1 Pluck | 2024-11-21 | 6.5 Medium |
| A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages. | ||||
| CVE-2022-26588 | 1 Icehrm | 1 Icehrm | 2024-11-21 | 6.5 Medium |
| A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account takeover via the app/service.php URI. | ||||
| CVE-2022-26585 | 1 Mingsoft | 1 Mcms | 2024-11-21 | 9.8 Critical |
| Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list. | ||||
| CVE-2022-26582 | 1 Paxtechnology | 2 A930, Paydroid | 2024-11-21 | 7.8 High |
| PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an attacker to gain root access through command injection in systool client. The attacker must have shell access to the device in order to exploit this vulnerability. | ||||
| CVE-2022-26581 | 2 Pax, Paxtechnology | 3 A930, A930, Paydroid | 2024-11-21 | 5.2 Medium |
| PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an unauthorized attacker to perform privileged actions through the execution of specific binaries listed in ADB daemon. The attacker must have physical USB access to the device in order to exploit this vulnerability. | ||||
| CVE-2022-26580 | 1 Paxtechnology | 2 A930, Paydroid | 2024-11-21 | 6.8 Medium |
| PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow the execution of specific command injections on selected binaries in the ADB daemon shell service. The attacker must have physical USB access to the device in order to exploit this vulnerability. | ||||