Export limit exceeded: 374374 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (374374 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-23902 | 1 Tongda2000 | 1 Tongda Office Anywhere | 2024-11-21 | 9.8 Critical |
| Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in export_data.php via the d_name parameter. | ||||
| CVE-2022-23901 | 1 Re2c | 1 Re2c | 2024-11-21 | 9.8 Critical |
| A stack overflow re2c 2.2 exists due to infinite recursion issues in src/dfa/dead_rules.cc. | ||||
| CVE-2022-23900 | 1 Wavlink | 2 Wl-wn531p3, Wl-wn531p3 Firmware | 2024-11-21 | 9.8 Critical |
| A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve unauthorized remote code execution via a malicious POST request through /cgi-bin/adm.cgi. | ||||
| CVE-2022-23899 | 1 Mingsoft | 1 Mcms | 2024-11-21 | 9.8 Critical |
| MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java. | ||||
| CVE-2022-23898 | 1 Mingsoft | 1 Mcms | 2024-11-21 | 9.8 Critical |
| MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml. | ||||
| CVE-2022-23896 | 1 Admidio | 1 Admidio | 2024-11-21 | 5.4 Medium |
| Admidio 4.1.2 version is affected by stored cross-site scripting (XSS). | ||||
| CVE-2022-23889 | 1 Yzmcms | 1 Yzmcms | 2024-11-21 | 5.3 Medium |
| The comment function in YzmCMS v6.3 was discovered as being able to be operated concurrently, allowing attackers to create an unusually large number of comments. | ||||
| CVE-2022-23888 | 1 Yzmcms | 1 Yzmcms | 2024-11-21 | 8.8 High |
| YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.html. | ||||
| CVE-2022-23887 | 1 Yzmcms | 1 Yzmcms | 2024-11-21 | 6.5 Medium |
| YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete user accounts via /admin/admin_manage/delete. | ||||
| CVE-2022-23884 | 1 Minecraft | 1 Bedrock Server | 2024-11-21 | 9.8 Critical |
| Mojang Bedrock Dedicated Server 1.18.2 is affected by an integer overflow leading to a bound check bypass caused by PurchaseReceiptPacket::_read (packet deserializer). | ||||
| CVE-2022-23882 | 1 Tuzicms | 1 Tuzicms | 2024-11-21 | 9.8 Critical |
| TuziCMS 2.0.6 is affected by SQL injection in \App\Manage\Controller\BannerController.class.php. | ||||
| CVE-2022-23881 | 1 Zzzcms | 1 Zzzphp | 2024-11-21 | 9.8 Critical |
| ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php. | ||||
| CVE-2022-23880 | 1 Taogogo | 1 Taocms | 2024-11-21 | 9.8 Critical |
| An arbitrary file upload vulnerability in the File Management function module of taoCMS v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file. | ||||
| CVE-2022-23878 | 1 Seacms | 1 Seacms | 2024-11-21 | 9.8 Critical |
| seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php. | ||||
| CVE-2022-23873 | 1 Victor Cms Project | 1 Victor Cms | 2024-11-21 | 8.8 High |
| Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary commands via 'user_firstname' parameter. | ||||
| CVE-2022-23872 | 1 Emlog | 1 Emlog | 2024-11-21 | 4.8 Medium |
| Emlog pro v1.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /admin/configure.php via the parameter footer_info. | ||||
| CVE-2022-23871 | 1 Gibbonedu | 1 Gibbon | 2024-11-21 | 5.4 Medium |
| Multiple cross-site scripting (XSS) vulnerabilities in the component outcomes_addProcess.php of Gibbon CMS v22.0.01 allow attackers to execute arbitrary web scripts or HTML via a crafted payload insterted into the name, category, description parameters. | ||||
| CVE-2022-23869 | 1 Ruoyi | 1 Ruoyi | 2024-11-21 | 6.5 Medium |
| In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the password of user test3 can be reset through the /system/user/resetPwd request. | ||||
| CVE-2022-23868 | 1 Ruoyi | 1 Ruoyi | 2024-11-21 | 7.8 High |
| RuoYi v4.7.2 contains a CSV injection vulnerability through ruoyi-admin when a victim opens .xlsx log file. | ||||
| CVE-2022-23865 | 1 Wecul | 1 Nyron | 2024-11-21 | 9.8 Critical |
| Nyron 1.0 is affected by a SQL injection vulnerability through Nyron/Library/Catalog/winlibsrch.aspx. To exploit this vulnerability, an attacker must inject '"> on the thes1 parameter. | ||||