CVE Vulnerabilities
CVE vulnerability database enriched with CISA KEV and NVD data
| CVE ID | CVSS | Severity | KEV | Sightings |
|---|---|---|---|---|
| CVE-2022-43351 Sanitization Management System v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /classes/Master.php?f=delete_img. | 6.5 | MEDIUM | — | 0 |
| CVE-2022-43352 Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_quote. | 7.2 | HIGH | — | 0 |
| CVE-2022-44048 The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44049 The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democrit... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44050 The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the demo... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44051 The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritu... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44052 The d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritu... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44053 The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the demo... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44054 The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-43050 Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component update_profile.php. This vulnerability allows attackers to execute arbit... | 7.2 | HIGH | — | 0 |
| CVE-2022-43051 Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete_test. | 7.2 | HIGH | — | 0 |
| CVE-2022-43052 Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete. | 7.2 | HIGH | — | 0 |
| CVE-2022-3872 An off-by-one read/write issue was found in the SDHCI device of QEMU. It occurs when reading/writing the Buffer Data Port Register in sdhci_read_dataport and sdhci_write_dataport, respectively, if dat... | 8.6 | HIGH | — | 0 |
| CVE-2022-43046 Food Ordering Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /foms/place-order.php. | 4.8 | MEDIUM | — | 0 |
| CVE-2022-43049 Canteen Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the component /youthappam/add-food.php. | 7.2 | HIGH | — | 0 |
| CVE-2022-43359 Gifdec commit 1dcbae19363597314f6623010cc80abad4e47f7c was discovered to contain an out-of-bounds read in the function read_image_data. This vulnerability is triggered when parsing a crafted Gif file. | 7.8 | HIGH | — | 0 |
| CVE-2020-35473 An information leakage vulnerability in the Bluetooth Low Energy advertisement scan response in Bluetooth Core Specifications 4.0 through 5.2, and extended scan response in Bluetooth Core Specificatio... | 4.3 | MEDIUM | — | 0 |
| CVE-2022-44457 A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.0 < V1.17.2), Mendix SAML (Mendix 8 compatib... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-41757 An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to obtain write access to read-only memory, or obtain access to already fre... | 8.8 | HIGH | — | 0 |
| CVE-2022-43343 N-Prolog v1.91 was discovered to contain a global buffer overflow vulnerability in the function gettoken() at Main.c. | 7.5 | HIGH | — | 0 |
| CVE-2022-44311 html2xhtml v1.3 was discovered to contain an Out-Of-Bounds read in the function static void elm_close(tree_node_t *nodo) at procesador.c. This vulnerability allows attackers to access sensitive files ... | 8.1 | HIGH | — | 0 |
| CVE-2022-44312 PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceInteger function in expression.c when called from ExpressionInfixOperator. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-44313 PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceUnsignedInteger function in expression.c when called from ExpressionParseFunctionCall. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-44314 PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StringStrncpy function in cstdlib/string.c when called from ExpressionParseFunctionCall. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-44315 PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionAssign function in expression.c when called from ExpressionParseFunctionCall. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-44316 PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the LexGetStringConstant function in lex.c when called from LexScanGetToken. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-44317 PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StdioOutPutc function in cstdlib/stdio.c when called from ExpressionParseFunctionCall. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-44318 PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StringStrcat function in cstdlib/string.c when called from ExpressionParseFunctionCall. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-44319 PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StdioBasePrintf function in cstdlib/string.c when called from ExpressionParseFunctionCall. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-44320 PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceFP function in expression.c when called from ExpressionParseFunctionCall. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-44556 Missing parameter type validation in the DRM module. Successful exploitation of this vulnerability may affect availability. | 7.5 | HIGH | — | 0 |
| CVE-2022-33321 Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONIT... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-33322 Cross-site scripting vulnerability in Mitsubishi Electric consumer electronics products (Air Conditioning, Wi-Fi Interface, Refrigerator, HEMS adapter, Remote control with Wi-Fi Interface, BATHROOM TH... | 6.1 | MEDIUM | — | 0 |
| CVE-2022-21778 In vpu, there is a possible information disclosure due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not n... | 6.7 | MEDIUM | — | 0 |
| CVE-2022-26446 In Modem 4G RRC, there is a possible system crash due to improper input validation. This could lead to remote denial of service, when concatenating improper SIB12 (CMAS message), with no additional ex... | 7.5 | HIGH | — | 0 |
| CVE-2022-44196 Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_push1. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44197 Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_server_ip. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44198 Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_push1. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44199 Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_server_ip. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44200 Netgear R7000P V1.3.0.8, V1.3.1.64 is vulnerable to Buffer Overflow via parameters: stamode_dns1_pri and stamode_dns1_sec. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44184 Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_sec. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44201 D-Link DIR823G 1.02B05 is vulnerable to Commad Injection. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44202 D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44801 D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44804 D-Link DIR-882 1.10B02 and1.20B06 is vulnerable to Buffer Overflow via the websRedirect function. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44806 D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44807 D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow via webGetVarString. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44808 A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-39066 There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phonebook interface, an authenticated attacker could use the vulnerability to execut... | 8.8 | HIGH | — | 0 |
| CVE-2022-39067 There is a buffer overflow vulnerability in ZTE MF286R. Due to lack of input validation on parameters of the wifi interface, an authenticated attacker could use the vulnerability to perform a denial o... | 6.5 | MEDIUM | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.