Export limit exceeded: 373594 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 373594 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 373594 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (373594 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-36612 | 1 Totolink | 2 A950rg, A950rg Firmware | 2024-11-21 | 7.8 High |
| TOTOLINK A950RG V4.1.2cu.5204_B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | ||||
| CVE-2022-36611 | 1 Totolink | 2 A800r, A800r Firmware | 2024-11-21 | 7.8 High |
| TOTOLINK A800R V4.1.2cu.5137_B20200730 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | ||||
| CVE-2022-36610 | 1 Totolink | 2 A720r, A720r Firmware | 2024-11-21 | 7.8 High |
| TOTOLINK A720R V4.1.5cu.532_B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | ||||
| CVE-2022-36609 | 1 Oretnom23 | 1 Clinic\'s Patient Management System | 2024-11-21 | 9.8 Critical |
| Clinic's Patient Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pms/update_patient.php. | ||||
| CVE-2022-36606 | 1 Yimihome | 1 Ywoa | 2024-11-21 | 9.8 Critical |
| Ywoa before v6.1 was discovered to contain a SQL injection vulnerability via /oa/setup/checkPool?database. | ||||
| CVE-2022-36605 | 1 Yimihome | 1 Ywoa | 2024-11-21 | 9.8 Critical |
| Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter. | ||||
| CVE-2022-36604 | 1 Canaan | 2 Avalon Asic Miner, Avalon Asic Miner Firmware | 2024-11-21 | 7.5 High |
| An access control issue in Canaan Avalon ASIC Miner 2020.3.30 and below allows unauthenticated attackers to arbitrarily change user passwords via a crafted POST request. | ||||
| CVE-2022-36603 | 1 Innosilicon | 2 T3t\+, T3t\+ Firmware | 2024-11-21 | 8.8 High |
| InnoSilicon T3T+ t2t+_soc_20190911_151433.swu was discovered to contain a remote code execution (RCE) vulnerability in the checkUrl function. | ||||
| CVE-2022-36602 | 1 Innosilicon | 2 A10, A10 Firmware | 2024-11-21 | 8.8 High |
| InnoSilicon A10 a10_20200924_120556 was discovered to contain a remote code execution (RCE) vulnerability in the setPlatformAPI function. | ||||
| CVE-2022-36601 | 1 Jinglemining | 2 Jasminer X4 Server, Jasminer X4 Server Firmware | 2024-11-21 | 9.8 Critical |
| The Eclipse TCF debug interface in JasMiner-X4-Server-20220621-090907 and below is open on port 1534. This issue allows unauthenticated attackers to gain root privileges on the affected device and access sensitive data or execute arbitrary commands. | ||||
| CVE-2022-36600 | 1 Blogengine | 1 Blogengine.net | 2024-11-21 | 4.8 Medium |
| BlogEngine v3.3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blogengine/api/posts. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field. | ||||
| CVE-2022-36599 | 1 Mingsoft | 1 Mcms | 2024-11-21 | 9.8 Critical |
| Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists. | ||||
| CVE-2022-36594 | 1 Mybatis | 1 Mapper | 2024-11-21 | 9.8 Critical |
| Mapper v4.0.0 to v4.2.0 was discovered to contain a SQL injection vulnerability via the ids parameter at the selectByIds function. | ||||
| CVE-2022-36593 | 1 Keking | 1 Kkfileview | 2024-11-21 | 6.5 Medium |
| kkFileView v4.0.0 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter at /controller/FileController.java. | ||||
| CVE-2022-36588 | 1 Dlink | 2 Dap-1650, Dap-1650 Firmware | 2024-11-21 | 9.8 Critical |
| In D-Link DAP1650 v1.04 firmware, the fileaccess.cgi program in the firmware has a buffer overflow vulnerability caused by strncpy. | ||||
| CVE-2022-36586 | 1 Tenda | 2 G3, G3 Firmware | 2024-11-21 | 9.8 Critical |
| In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by strcpy in function 0x869f4 in the httpd binary. | ||||
| CVE-2022-36585 | 1 Tenda | 2 G3, G3 Firmware | 2024-11-21 | 9.8 Critical |
| In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, in httpd binary, the addDhcpRule function has a buffer overflow caused by sscanf. | ||||
| CVE-2022-36584 | 1 Tenda | 2 G3, G3 Firmware | 2024-11-21 | 9.8 Critical |
| In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, the getsinglepppuser function has a buffer overflow caused by sscanf. | ||||
| CVE-2022-36583 | 1 Dedecms | 1 Dedecms | 2024-11-21 | 6.1 Medium |
| DedeCMS V5.7.97 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/co_do.php via the dopost, rpok, and aid parameters. | ||||
| CVE-2022-36582 | 1 Garage Management System Project | 1 Garage Management System | 2024-11-21 | 7.2 High |
| An arbitrary file upload vulnerability in the component /php_action/createProduct.php of Garage Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | ||||