Export limit exceeded: 380896 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (380896 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-31507 | 1 Ganga Project | 1 Ganga | 2024-11-21 | 9.3 Critical |
| The ganga-devs/ganga repository before 8.5.10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||||
| CVE-2022-31506 | 1 Cmu | 1 Opendiamond | 2024-11-21 | 9.3 Critical |
| The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||||
| CVE-2022-31505 | 1 Mercadoenlineaback Project | 1 Mercadoenlineaback | 2024-11-21 | 9.3 Critical |
| The cheo0/MercadoEnLineaBack repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||||
| CVE-2022-31504 | 1 Baiduwenkuspider Flaskweb Project | 1 Baiduwenkuspider Flaskweb | 2024-11-21 | 9.3 Critical |
| The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||||
| CVE-2022-31503 | 1 Orchest | 1 Orchest | 2024-11-21 | 9.3 Critical |
| The orchest/orchest repository before 2022.05.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||||
| CVE-2022-31502 | 1 Wormnest Project | 1 Wormnest | 2024-11-21 | 9.3 Critical |
| The operatorequals/wormnest repository through 0.4.7 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||||
| CVE-2022-31501 | 1 Onyxforum Project | 1 Onyxforum | 2024-11-21 | 9.3 Critical |
| The ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||||
| CVE-2022-31500 | 1 Knime | 1 Knime Analytics Platform | 2024-11-21 | 7.8 High |
| In KNIME Analytics Platform below 4.6.0, the Windows installer sets improper filesystem permissions. | ||||
| CVE-2022-31499 | 1 Nortekcontrol | 2 Emerge E3, Emerge E3 Firmware | 2024-11-21 | 9.8 Critical |
| Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256. | ||||
| CVE-2022-31498 | 1 Librehealth | 1 Librehealth Ehr | 2024-11-21 | 6.1 Medium |
| LibreHealth EHR Base 2.0.0 allows interface/orders/patient_match_dialog.php key XSS. | ||||
| CVE-2022-31497 | 1 Librehealth | 1 Librehealth Ehr | 2024-11-21 | 6.1 Medium |
| LibreHealth EHR Base 2.0.0 allows interface/main/finder/finder_navigation.php patient XSS. | ||||
| CVE-2022-31496 | 1 Librehealth | 1 Librehealth Ehr | 2024-11-21 | 8.8 High |
| LibreHealth EHR Base 2.0.0 allows incorrect interface/super/manage_site_files.php access. | ||||
| CVE-2022-31495 | 1 Librehealth | 1 Librehealth Ehr | 2024-11-21 | 6.1 Medium |
| LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS. | ||||
| CVE-2022-31494 | 1 Librehealth | 1 Librehealth Ehr | 2024-11-21 | 6.1 Medium |
| LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php action XSS. | ||||
| CVE-2022-31493 | 1 Librehealth | 1 Librehealth Ehr | 2024-11-21 | 6.1 Medium |
| LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php acl_id XSS. | ||||
| CVE-2022-31492 | 1 Librehealth | 1 Librehealth Ehr | 2024-11-21 | 6.1 Medium |
| Cross Site scripting (XSS) vulnerability inLibreHealth EHR Base 2.0.0 via interface/usergroup/usergroup_admin_add.php Username. | ||||
| CVE-2022-31489 | 1 Inoutscripts | 1 Blockchain Altexchanger | 2024-11-21 | 7.5 High |
| Inout Blockchain AltExchanger 1.2.1 allows index.php/home/about inoutio_language cookie SQL injection. | ||||
| CVE-2022-31488 | 1 Inoutscripts | 1 Blockchain Altexchanger | 2024-11-21 | 7.5 High |
| Inout Blockchain AltExchanger 1.2.1 allows index.php/coins/update_marketboxslider marketcurrency SQL injection. | ||||
| CVE-2022-31487 | 1 Inoutscripts | 2 Blockchain Altexchanger, Blockchain Fiatexchanger | 2024-11-21 | 7.5 High |
| Inout Blockchain AltExchanger 1.2.1 and Inout Blockchain FiatExchanger 2.2.1 allow Chart/TradingView/chart_content/master.php symbol SQL injection. | ||||
| CVE-2022-31486 | 2 Carrier, Hidglobal | 28 Lenels2 Lnl-4420, Lenels2 Lnl-4420 Firmware, Lenels2 Lnl-x2210 and 25 more | 2024-11-21 | 8.8 High |
| An authenticated attacker can send a specially crafted route to the “edit_route.cgi” binary and have it execute shell commands. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.303 for the LP series and 1.297 for the EP series. An attacker with this level of access on the device can monitor all communications sent to and from this device, modify onboard relays, change configuration files, or cause the device to become unstable. | ||||