Export limit exceeded: 378381 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (378381 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-37299 | 1 Shirne Cms Project | 1 Shirne Cms | 2024-11-21 | 6.5 Medium |
| An issue was discovered in Shirne CMS 1.2.0. There is a Path Traversal vulnerability which could cause arbitrary file read via /static/ueditor/php/controller.php | ||||
| CVE-2022-37292 | 1 Tenda | 2 Ax12, Ax12 Firmware | 2024-11-21 | 5.5 Medium |
| Tenda AX12 V22.03.01.21_CN is vulnerable to Buffer Overflow. This overflow is triggered in the sub_42FDE4 function, which satisfies the request of the upper-level interface function sub_430124, that is, handles the post request under /goform/SetIpMacBind. | ||||
| CVE-2022-37266 | 1 Stealjs | 1 Steal | 2024-11-21 | 9.8 Critical |
| Prototype pollution vulnerability in function extend in babel.js in stealjs steal 2.2.4 via the key variable in babel.js. | ||||
| CVE-2022-37264 | 1 Stealjs | 1 Steal | 2024-11-21 | 9.8 Critical |
| Prototype pollution vulnerability in stealjs steal 2.2.4 via the optionName variable in main.js. | ||||
| CVE-2022-37262 | 1 Stealjs | 1 Steal | 2024-11-21 | 7.5 High |
| A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the source and sourceWithComments variable in main.js. | ||||
| CVE-2022-37260 | 1 Stealjs | 1 Steal | 2024-11-21 | 7.5 High |
| A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the input variable in main.js. | ||||
| CVE-2022-37258 | 1 Stealjs | 1 Steal | 2024-11-21 | 9.8 Critical |
| Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js. | ||||
| CVE-2022-37257 | 1 Stealjs | 1 Steal | 2024-11-21 | 9.8 Critical |
| Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js. | ||||
| CVE-2022-37254 | 1 Dolphinphp Project | 1 Dolphinphp | 2024-11-21 | 5.4 Medium |
| DolphinPHP 1.5.1 is vulnerable to Cross Site Scripting (XSS) via Background - > System - > system function - > configuration management. | ||||
| CVE-2022-37253 | 1 Crime Reporting System Project | 1 Crime Reporting System | 2024-11-21 | 5.4 Medium |
| Persistent cross-site scripting (XSS) in Crime Reporting System 1.0 allows a remote attacker to introduce arbitary Javascript via manipulation of an unsanitized POST parameter | ||||
| CVE-2022-37251 | 1 Craftcms | 1 Craft Cms | 2024-11-21 | 5.4 Medium |
| Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts. | ||||
| CVE-2022-37248 | 1 Craftcms | 1 Craft Cms | 2024-11-21 | 5.4 Medium |
| Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php. | ||||
| CVE-2022-37247 | 1 Craftcms | 1 Craft Cms | 2024-11-21 | 5.4 Medium |
| Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page. | ||||
| CVE-2022-37245 | 1 Altn | 1 Security Gateway For Email Servers | 2024-11-21 | 5.4 Medium |
| MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the Blacklist endpoint. | ||||
| CVE-2022-37244 | 1 Altn | 1 Security Gateway For Email Servers | 2024-11-21 | 5.4 Medium |
| MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest parameter. after login leads to inject malicious tag leads to IFRAME injection. | ||||
| CVE-2022-37243 | 1 Altn | 1 Security Gateway For Email Servers | 2024-11-21 | 5.4 Medium |
| MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the whitelist endpoint. | ||||
| CVE-2022-37242 | 1 Altn | 1 Security Gateway For Email Servers | 2024-11-21 | 9.8 Critical |
| MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter. | ||||
| CVE-2022-37241 | 1 Altn | 1 Security Gateway For Email Servers | 2024-11-21 | 5.4 Medium |
| MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the data_leak_list_ajax endpoint. | ||||
| CVE-2022-37240 | 1 Altn | 1 Security Gateway For Email Servers | 2024-11-21 | 9.8 Critical |
| MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter. | ||||
| CVE-2022-37239 | 1 Altn | 1 Security Gateway For Email Servers | 2024-11-21 | 5.4 Medium |
| MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the rulles_list_ajax endpoint. | ||||