CVE Vulnerabilities
CVE vulnerability database enriched with CISA KEV and NVD data
| CVE ID | CVSS | Severity | KEV | Sightings |
|---|---|---|---|---|
| CVE-2022-26171 Bank Management System v1.o was discovered to contain a SQL injection vulnerability via the email parameter. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-0730 Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-24995 Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-24652 sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in php code execution in /admin/upload/upload. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-0412 The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL stateme... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-24651 sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution through /user/upload/upload. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-0848 OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-24609 Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-24571 Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-24607 Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-0747 The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthent... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-43086 ARM astcenc 3.2.0 is vulnerable to Buffer Overflow. When the compression function of the astc-encoder project with -cl option was used, a stack-buffer-overflow occurred in function encode_ise() in fun... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-24606 Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-24605 Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-24604 Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-24603 Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-24602 Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-46384 https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ΒΆΒΆ MCMS ... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-24193 CasaOS before v0.2.7 was discovered to contain a command injection vulnerability. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-46393 There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v10 variable is directly retrieved from the http request parameter startIp. Th... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-45414 A Remote Code Execution (RCE) vulnerability exists in DataRobot through 2021-10-28 because it allows submission of a Docker environment or Java driver. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-22814 The System Diagnosis service of MyASUS before 3.1.2.0 allows privilege escalation. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-46394 There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v13 variable is directly retrieved from the http request parameter startIp. Th... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-26201 Victor CMS v1.0 was discovered to contain a SQL injection vulnerability. | 9.8 | CRITICAL | β | 0 |
| CVE-2020-12775 Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthenticated remote attacker can exploit this vulnerability to per... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-4045 TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. The exploitation of... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-44632 A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/upgrade_info feature, which allows malicious users to execute arbitrary code on the system via... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-23640 Excel-Streaming-Reader is an easy-to-use implementation of a streaming Excel reader using Apache POI. Prior to xlsx-streamer 2.1.0, the XML parser that was used did apply all the necessary settings to... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-44631 A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/reset_cloud_pwd feature, which allows malicous users to execute arbitrary code on the system v... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-44630 A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/modify_account_pwd feature, which allows malicious users to execute arbitrary code on the syst... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-44629 A Buffer Overflow vulnerabilitiy exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/register feature, which allows malicious users to execute arbitrary code on the system via a ... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-4039 A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-44628 A Buffer Overflow vulnerabiltiy exists in TP-LINK WR-886N 20190826 2.3.8 in thee /cloud_config/router_post/login feature, which allows malicious users to execute arbitrary code on the system via a cra... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-44627 A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/get_reset_pwd_veirfy_code feature, which allows malicious users to execute arbitrary code on t... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-0739 The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_serv... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-44626 A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/get_reg_verify_code feature, which allows malicious users to execute arbitrary code on the sys... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-44625 A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in /cloud_config/cloud_device/info interface, which allows a malicious user to executee arbitrary code on the system via a craf... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-44623 A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 via the /cloud_config/router_post/check_reset_pwd_verify_code interface. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-44622 A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/check_reg_verify_code function which could let a remove malicious user execute arbitrary code ... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-0694 The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (av... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-36166 An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's authentication token by means of the observation of cer... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-42854 It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) PluginServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/plugin/pmx" API. The affected en... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-25394 Medical Store Management System v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter under customer-add.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-41193 wire-avs is the audio visual signaling (AVS) component of Wire, an open-source messenger. A remote format string vulnerability in versions prior to 7.1.12 allows an attacker to cause a denial of servi... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-23878 seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-42786 It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) has Remote Code Execution vulnerabilities in multiple instances of the API requests. The affected endpoints do not hav... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-24720 image_processing is an image processing wrapper for libvips and ImageMagick/GraphicsMagick. Prior to version 1.12.2, using the `#apply` method from image_processing to apply a series of operations tha... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-40050 There is an out-of-bounds read vulnerability in the IFAA module. Successful exploitation of this vulnerability may cause stack overflow. | 9.8 | CRITICAL | β | 0 |
| CVE-2020-14115 A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execu... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-24600 Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL injection statements. | 9.8 | CRITICAL | β | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.