Export limit exceeded: 375438 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (375438 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-28481 | 1 Csv-safe Project | 1 Csv-safe | 2024-11-21 | 9.8 Critical |
| CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection. | ||||
| CVE-2022-28480 | 1 Allmediaserver | 1 Allmediaserver | 2024-11-21 | 9.8 Critical |
| ALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe. | ||||
| CVE-2022-28479 | 1 Seeddms | 1 Seeddms | 2024-11-21 | 4.8 Medium |
| SeedDMS versions 6.0.18 and 5.1.25 and below are vulnerable to stored XSS. An attacker with admin privileges can inject the payload inside the "Role management" menu and then trigger the payload by loading the "Users management" menu | ||||
| CVE-2022-28478 | 1 Seeddms | 1 Seeddms | 2024-11-21 | 6.5 Medium |
| SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files management" menu does not sanitize user input allowing attackers with admin privileges to delete arbitrary files on the remote system. | ||||
| CVE-2022-28477 | 1 Wbce | 1 Wbce Cms | 2024-11-21 | 6.1 Medium |
| WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS). | ||||
| CVE-2022-28471 | 1 Rockcarry | 1 Ffjpeg | 2024-11-21 | 6.5 Medium |
| In ffjpeg (commit hash: caade60), the function bmp_load() in bmp.c contains an integer overflow vulnerability, which eventually results in the heap overflow in jfif_encode() in jfif.c. This is due to the incomplete patch for issue 38 | ||||
| CVE-2022-28470 | 1 Python | 1 Pypi | 2024-11-21 | 9.8 Critical |
| marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor. | ||||
| CVE-2022-28468 | 1 Payroll Management System Project | 1 Payroll Management System | 2024-11-21 | 9.8 Critical |
| Payroll Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter. | ||||
| CVE-2022-28467 | 1 Online Student Admission Project | 1 Online Student Admission | 2024-11-21 | 9.8 Critical |
| Online Student Admission v1.0 was discovered to contain a SQL injection vulnerability via the txtapplicationID parameter. | ||||
| CVE-2022-28464 | 1 Apifox | 1 Apifox | 2024-11-21 | 9.0 Critical |
| Apifox through 2.1.6 is vulnerable to Cross Site Scripting (XSS) which can lead to remote code execution. | ||||
| CVE-2022-28462 | 1 Xxyopen | 1 Novel-plus | 2024-11-21 | 7.5 High |
| novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability. | ||||
| CVE-2022-28461 | 1 Mingyuefusu Project | 1 Mingyuefusu | 2024-11-21 | 9.8 Critical |
| mingyuefusu Library Management System all versions as of 03-27-2022 is vulnerable to SQL Injection. | ||||
| CVE-2022-28454 | 1 Limbas | 1 Limbas | 2024-11-21 | 6.1 Medium |
| Limbas 4.3.36.1319 is vulnerable to Cross Site Scripting (XSS). | ||||
| CVE-2022-28452 | 1 Redplanetcomputers | 1 Laundry Management System | 2024-11-21 | 9.8 Critical |
| Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection. | ||||
| CVE-2022-28451 | 1 Nopcommerce | 1 Nopcommerce | 2024-11-21 | 7.5 High |
| nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature. | ||||
| CVE-2022-28450 | 1 Nopcommerce | 1 Nopcommerce | 2024-11-21 | 5.4 Medium |
| nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new post, which allows a remote attacker to execute arbitrary JavaScript code at client browser. | ||||
| CVE-2022-28449 | 1 Nopcommerce | 1 Nopcommerce | 2024-11-21 | 6.1 Medium |
| nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upload an arbitrary file to the system. | ||||
| CVE-2022-28448 | 1 Nopcommerce | 1 Nopcommerce | 2024-11-21 | 5.4 Medium |
| nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info. | ||||
| CVE-2022-28445 | 1 Kitesky | 1 Kitecms | 2024-11-21 | 6.5 Medium |
| KiteCMS v1.1.1 was discovered to contain an arbitrary file read vulnerability via the background management module. | ||||
| CVE-2022-28444 | 1 Ucms Project | 1 Ucms | 2024-11-21 | 7.5 High |
| UCMS v1.6 was discovered to contain an arbitrary file read vulnerability. | ||||