Vulnerabilidades CVE
Base de datos de vulnerabilidades CVE enriquecida con datos de CISA KEV y NVD
| CVE ID | CVSS | Severidad | KEV | Avistamientos |
|---|---|---|---|---|
| CVE-2022-28575 It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows attackers to execute arbitrary command... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-27404 FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-30813 elitecms 1.01 is vulnerable to SQL Injection via /admin/add_post.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-29592 Tenda TX9 Pro 22.03.02.10 devices allow OS command injection via set_route (called by doSystemCmd_route). | 9.8 | CRITICAL | β | 0 |
| CVE-2022-29502 SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-27228 In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-27428 GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool β Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of fir... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-28606 An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can be exploited by an attacker to gain control of the server. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-28533 Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-28530 Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-28120 Beijing Runnier Network Technology Co., Ltd Open virtual simulation experiment teaching management platform software 2.0 has a file upload vulnerability, which can be exploited by an attacker to gain ... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-41921 novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-27426 GE UR IED firmware versions prior to version 8.1x with βBasicβ security variant does not allow the disabling of the βFactory Mode,β which is used for servicing the IED by a βFactoryβ user. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-27588 We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.6 build 20220401 and later | 9.8 | CRITICAL | β | 0 |
| CVE-2021-43934 Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate upload requests, enabling a malicious user to potentially upload arbitrary files. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-35104 Possible buffer overflow due to improper parsing of headers while playing the FLAC audio clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Indus... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-43735 CmsWing 1.3.7 is affected by a SQLi vulnerability via parameter: behavior rule. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-27413 Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in admin.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-32337 Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/patients/manage_patient.php?id=. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-20171 Product: AndroidVersions: Android kernelAndroid ID: A-215565667References: N/A | 9.8 | CRITICAL | β | 0 |
| CVE-2021-43736 CmsWing CMS 1.3.7 is affected by a Remote Code Execution (RCE) vulnerability via parameter: log rule | 9.8 | CRITICAL | β | 0 |
| CVE-2022-27668 Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-42675 Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-32352 Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient_admission. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-20170 Product: AndroidVersions: Android kernelAndroid ID: A-209421931References: N/A | 9.8 | CRITICAL | β | 0 |
| CVE-2022-24449 Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-28118 SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in. | 9.8 | CRITICAL | β | 0 |
| CVE-2020-23621 The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow att... | 9.8 | CRITICAL | β | 0 |
| CVE-2020-23620 The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to e... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-41403 flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-29556 The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execute cross-tenant acti... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-29904 The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-29906 The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf9f66) omits a check for the quizadmin user. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-1378 Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_pgHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-1377 Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_rltHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retriev... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-1376 Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_privgrpHandler.ashx. This allows an attacker to inject arbitrary SQL queries, ret... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-1531 SQL injection vulnerability in ARAX-UI Synonym Lookup functionality in GitHub repository rtxteam/rtx prior to checkpoint_2022-04-20 . This vulnerability is critical as it can lead to remote code execu... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-1375 Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_slogHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrie... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-1374 Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_unHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-1372 Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in dlSlog.aspx. This allows an attacker to inject arbitrary SQL queries, retrieve and mod... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-44596 Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "InstallAssistService.exe... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-1371 Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegf. This allows an attacker to inject arbitrary SQL queries, retrieve and modify... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-28452 Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-1370 Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadREGbyID. This allows an attacker to inject arbitrary SQL queries, retrieve and mod... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-1369 Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegIND. This allows an attacker to inject arbitrary SQL queries, retrieve and modi... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-1367 Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve an... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-1366 Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerChart.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve a... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-1281 The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-25651 Memory corruption in bluetooth host due to integer overflow while processing BT HFP-UNIT profile in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon V... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-29317 Simple Bus Ticket Booking System v1.0 was discovered to contain multiple SQL injection vulnerbilities via the username and password parameters at /assets/partials/_handleLogin.php. | 9.8 | CRITICAL | β | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.