LIVE FEED
1777 events · 4 sources · newest first
Events in view
1777
all sources
Critical
1499
severity
Active sources
4
collectors
Last sync
2026-08-27 06:00
UTC
2022-12-22
NVD CVE
CVE-2022-26486: An unexpected message in the WebGPU IPC framework could lead to a use-after-free
CRITICAL
◈ 2 sources · orig. NVD CVE
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox <...
2022-12-19
NVD CVE
CVE-2022-40434: Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field
CRITICAL
Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.
2022-12-14
NVD CVE
CVE-2022-31358: A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environm
CRITICAL
A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/.
2022-12-02
NVD CVE
CVE-2022-44290: webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the
CRITICAL
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.
2022-12-02
NVD CVE
CVE-2022-44945: Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via t
CRITICAL
Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter.
2022-12-02
NVD CVE
CVE-2022-44291: webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the
CRITICAL
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
2022-11-25
NVD CVE
CVE-2022-37721: PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low priv
CRITICAL
PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or...
2022-11-25
NVD CVE
CVE-2022-37720: Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). W
CRITICAL
Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payload in a blog post, leading to full...
2022-11-25
NVD CVE
CVE-2022-45207: Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via th
CRITICAL
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.
2022-11-25
NVD CVE
CVE-2022-45206: Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via th
CRITICAL
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.
2022-11-22
NVD CVE
CVE-2022-40842: ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side req
CRITICAL
ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php.
2022-11-22
NVD CVE
CVE-2022-36180: Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirec
CRITICAL
Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection],...
2022-11-22
NVD CVE
Fusiondirectory 1.3 suffers from Improper Session Handling.
2022-11-22
NVD CVE
CVE-2022-44194: Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_d
CRITICAL
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_dns1_pri and apmode_dns1_sec.
2022-11-22
NVD CVE
CVE-2022-42989: ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XS
CRITICAL
ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa de Entrada.
2022-11-15
NVD CVE
CVE-2022-42120: A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 thr
CRITICAL
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a...
2022-11-15
NVD CVE
CVE-2022-42122: A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7
CRITICAL
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into...
2022-11-10
NVD CVE
CVE-2022-44089: ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulne
CRITICAL
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.
2022-11-10
NVD CVE
CVE-2022-44087: ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulne
CRITICAL
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT.
2022-11-10
NVD CVE
CVE-2022-44088: ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulne
CRITICAL
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.
2022-10-25
NVD CVE
CVE-2022-38580: Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
CRITICAL
Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
2022-10-19
NVD CVE
CVE-2022-41415: Acer Altos W2000h-W570h F4 R01.03.0018 was discovered to contain a stack overflo
CRITICAL
Acer Altos W2000h-W570h F4 R01.03.0018 was discovered to contain a stack overflow in the RevserveMem component. This vulnerability allows attackers to cause a Denial of Service (DoS) via injecting crafted shellcode...
2022-10-18
NVD CVE
CVE-2022-40684: An authentication bypass using an alternate path or channel [CWE-288] in Fortine
CRITICAL
◈ 2 sources · orig. NVD CVE
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and...
2022-10-17
NVD CVE
CVE-2022-40055: An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to
CRITICAL
An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page.
2022-10-12
NVD CVE
CVE-2022-33106: WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit atta
CRITICAL
WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit attack, allowing the attacker to brute force the admin password leading to Account Take Over.
2022-09-30
NVD CVE
CVE-2022-35156: Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnera
CRITICAL
Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..
2022-09-21
NVD CVE
CVE-2022-38619: SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability
CRITICAL
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf.
2022-09-21
NVD CVE
CVE-2022-40030: SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL
CRITICAL
SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at changeStatus.php.
2022-09-16
NVD CVE
CVE-2022-36536: An issue in the component post_applogin.php of Super Flexible Software GmbH & Co
CRITICAL
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens.
2022-09-15
NVD CVE
CVE-2022-37257: Prototype pollution vulnerability in function convertLater in npm-convert.js in
CRITICAL
Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js.
2022-09-02
NVD CVE
CVE-2022-36640: influxData influxDB before v1.8.10 contains no authentication mechanism or contr
CRITICAL
influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's...
2022-08-31
NVD CVE
CVE-2022-36202: Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edo
CRITICAL
Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter.
2022-08-30
NVD CVE
CVE-2022-37176: Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability
CRITICAL
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability which allows attackers to remove the Wi-Fi password and force the device into open security mode via a crafted packet sent to goform/setWizard.
2022-08-29
NVD CVE
CVE-2022-32993: TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue vi
CRITICAL
TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh.
2022-08-28
NVD CVE
CVE-2022-38555: Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.
CRITICAL
Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.
2022-08-28
NVD CVE
CVE-2022-37053: TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpin
CRITICAL
TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.
2022-08-23
NVD CVE
CVE-2021-42232: TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vul
CRITICAL
TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command....
2022-08-23
NVD CVE
CVE-2021-42627: The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.
CRITICAL
The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage...
2022-08-19
NVD CVE
CVE-2022-35201: Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RC
CRITICAL
Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.
2022-08-15
NVD CVE
CVE-2022-36262: An issue was discovered in taocms 3.0.2. in the website settings that allows arb
CRITICAL
An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying config.php.