Export limit exceeded: 40807 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (40807 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-23380 | 1 Taogogo | 1 Taocms | 2024-11-21 | 8.8 High |
| There is a SQL injection vulnerability in the background of taocms 3.0.2 in parameter id:action=admin&id=2&ctrl=edit. | ||||
| CVE-2022-23379 | 1 Emlog | 1 Emlog | 2024-11-21 | 9.8 Critical |
| Emlog v6.0 was discovered to contain a SQL injection vulnerability via the $TagID parameter of getblogidsfromtagid(). | ||||
| CVE-2022-23366 | 1 Hms Project | 1 Hms | 2024-11-21 | 9.8 Critical |
| HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php. | ||||
| CVE-2022-23365 | 1 Hms Project | 1 Hms | 2024-11-21 | 9.8 Critical |
| HMS v1.0 was discovered to contain a SQL injection vulnerability via doctorlogin.php. | ||||
| CVE-2022-23364 | 1 Hms Project | 1 Hms | 2024-11-21 | 9.8 Critical |
| HMS v1.0 was discovered to contain a SQL injection vulnerability via adminlogin.php. | ||||
| CVE-2022-23363 | 1 Online Banking System Project | 1 Online Banking System | 2024-11-21 | 9.8 Critical |
| Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via index.php. | ||||
| CVE-2022-23358 | 1 Easycms | 1 Easycms | 2024-11-21 | 9.8 Critical |
| EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php. In the background, search terms provided by the user were not sanitized and were used directly to construct a SQL statement. | ||||
| CVE-2022-23352 | 1 Bigantsoft | 1 Bigant Server | 2024-11-21 | 7.5 High |
| An issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS). | ||||
| CVE-2022-23337 | 1 Dedecms | 1 Dedecms | 2024-11-21 | 9.8 Critical |
| DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter. | ||||
| CVE-2022-23336 | 1 S-cms | 1 S-cms | 2024-11-21 | 9.8 Critical |
| S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter. | ||||
| CVE-2022-23335 | 1 Metinfo | 1 Metinfo | 2024-11-21 | 9.8 Critical |
| Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in language_general.class.php via doModifyParameter. | ||||
| CVE-2022-23314 | 1 Mingsoft | 1 Mcms | 2024-11-21 | 9.8 Critical |
| MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do. | ||||
| CVE-2022-23183 | 1 Advancedcustomfields | 1 Advanced Custom Fields | 2024-11-21 | 6.5 Medium |
| Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro versions prior to 5.12.1 allows a remote authenticated attacker to view the information on the database without the access permission. | ||||
| CVE-2022-23169 | 1 Amodat | 1 Mobile Application Gateway | 2024-11-21 | 5.9 Medium |
| attacker needs to craft a SQL payload. the vulnerable parameter is "agentid" must be authenticated to the admin panel. | ||||
| CVE-2022-23168 | 1 Amodat | 1 Mobile Application Gateway | 2024-11-21 | 5.9 Medium |
| The attacker could get access to the database. The SQL injection is in the username parameter at the login panel: username: admin'-- | ||||
| CVE-2022-23139 | 1 Zte | 2 Zxmp M721, Zxmp M721 Firmware | 2024-11-21 | 8.8 High |
| ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent with the actual permission. It’s easy for?users to?ignore the modification?of?the file permission configuration, so that low-authority accounts could actually obtain higher operating permissions on key files. | ||||
| CVE-2022-23112 | 1 Jenkins | 1 Publish Over Ssh | 2024-11-21 | 6.5 Medium |
| A missing permission check in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers with Overall/Read access to connect to an attacker-specified SSH server using attacker-specified credentials. | ||||
| CVE-2022-23098 | 2 Debian, Intel | 2 Debian Linux, Connman | 2024-11-21 | 7.5 High |
| An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite loop if no data is received. | ||||
| CVE-2022-23055 | 1 Frappe | 1 Erpnext | 2024-11-21 | N/A |
| In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker can also read chat messages of groups that they do not belong to, and of other users. | ||||
| CVE-2022-23046 | 1 Phpipam | 1 Phpipam | 2024-11-21 | 7.2 High |
| PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php | ||||