Common Vulnerabilities and Exposures (CVE) is a critical tool for maintaining software security, providing a standardized way to track and manage vulnerabilities across systems. Organizations should regularly monitor CVE databases, assess the impact of vulnerabilities, and apply patches promptly to reduce the risk of exploitation.
CVE (Common Vulnerabilities and Exposures) is a public database that provides a standardized method for identifying, tracking, and referencing publicly disclosed security vulnerabilities in software and hardware.
Each vulnerability receives a unique identifier called a CVE ID (e.g., CVE-2023-12345), making it easier to reference specific vulnerabilities across different tools and databases.
Total Search Results: 158437
CVE ID | Description | Severity | Published Date | Affected Vendor | Action |
---|---|---|---|---|---|
CVE-2022-28443 | UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability. | Unknown | N/A | n/a | |
CVE-2022-28444 | UCMS v1.6 was discovered to contain an arbitrary file read vulnerability. | Unknown | N/A | n/a | |
CVE-2022-28445 | KiteCMS v1.1.1 was discovered to contain an arbitrary file read vulnerability via the background management module. | Unknown | N/A | n/a | |
CVE-2022-28448 | nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info. | Unknown | N/A | n/a | |
CVE-2022-28449 | nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upload an arbitrary file to the system. | Unknown | N/A | n/a | |
CVE-2022-2845 | Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218. | Unknown | N/A | vim | |
CVE-2022-28450 | nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new post, which allows a remote attacker to execute arbitrary JavaScript code at client browser. | Unknown | N/A | n/a | |
CVE-2022-28451 | nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature. | Unknown | N/A | n/a | |
CVE-2022-28452 | Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection. | Unknown | N/A | n/a | |
CVE-2022-28454 | Limbas 4.3.36.1319 is vulnerable to Cross Site Scripting (XSS). | Unknown | N/A | n/a | |
CVE-2022-2846 | The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields. This could allow unauthenticated attackers to create arbitrary events and put Cross-Site Scripting payloads in it. | Unknown | N/A | Unknown | |
CVE-2022-28461 | mingyuefusu Library Management System all versions as of 03-27-2022 is vulnerable to SQL Injection. | Unknown | N/A | n/a | |
CVE-2022-28462 | novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability. | Unknown | N/A | n/a | |
CVE-2022-28463 | ImageMagick 7.1.0-27 is vulnerable to Buffer Overflow. | Unknown | N/A | n/a | |
CVE-2022-28464 | Apifox through 2.1.6 is vulnerable to Cross Site Scripting (XSS) which can lead to remote code execution. | Unknown | N/A | n/a | |
CVE-2022-28467 | Online Student Admission v1.0 was discovered to contain a SQL injection vulnerability via the txtapplicationID parameter. | Unknown | N/A | n/a | |
CVE-2022-28468 | Payroll Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter. | Unknown | N/A | n/a | |
CVE-2022-2847 | A vulnerability, which was classified as critical, has been found in SourceCodester Guest Management System. This issue affects some unknown processing of the file /guestmanagement/front.php. The manipulation of the argument rid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206489 was assigned to this vulnerability. | Unknown | N/A | SourceCodester | |
CVE-2022-28470 | marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor. | Unknown | N/A | n/a | |
CVE-2022-28471 | In ffjpeg (commit hash: caade60), the function bmp_load() in bmp.c contains an integer overflow vulnerability, which eventually results in the heap overflow in jfif_encode() in jfif.c. This is due to the incomplete patch for issue 38 | Unknown | N/A | n/a | |
CVE-2022-28477 | WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS). | Unknown | N/A | n/a | |
CVE-2022-28478 | SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files management" menu does not sanitize user input allowing attackers with admin privileges to delete arbitrary files on the remote system. | Unknown | N/A | n/a | |
CVE-2022-28479 | SeedDMS versions 6.0.18 and 5.1.25 and below are vulnerable to stored XSS. An attacker with admin privileges can inject the payload inside the "Role management" menu and then trigger the payload by loading the "Users management" menu | Unknown | N/A | n/a | |
CVE-2022-2848 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-16486. | Unknown | N/A | Kepware | |
CVE-2022-28480 | ALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe. | Unknown | N/A | n/a | |
CVE-2022-28481 | CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection. | Unknown | N/A | n/a | |
CVE-2022-28487 | Tcpreplay version 4.4.1 contains a memory leakage flaw in fix_ipv6_checksums() function. The highest threat from this vulnerability is to data confidentiality. | Unknown | N/A | n/a | |
CVE-2022-28488 | The function wav_format_write in libwav.c in libwav through 2017-04-20 has an Use of Uninitialized Variable vulnerability. | Unknown | N/A | n/a | |
CVE-2022-2849 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220. | Unknown | N/A | vim | |
CVE-2022-28491 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 contains a command injection vulnerability in the NTPSyncWithHost function via the host_name parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | Unknown | N/A | n/a | |
CVE-2022-28492 | TOTOLINK Technology CPE with firmware V6.3c.566 ,allows remote attackers to bypass Login. | Unknown | N/A | n/a | |
CVE-2022-28493 | A vulnerability in TOTOLINK CP900 V6.3c.566 allows attackers to start the Telnet service, | Unknown | N/A | n/a | |
CVE-2022-28494 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setUpgradeFW function via the filename parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | Unknown | N/A | n/a | |
CVE-2022-28495 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | Unknown | N/A | n/a | |
CVE-2022-28496 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 discovered to contain a command injection vulnerability in the setPasswordCfg function via the adminuser and adminpassparameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | Unknown | N/A | n/a | |
CVE-2022-28497 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_write_bootloader function via the filename parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | Unknown | N/A | n/a | |
CVE-2022-2850 | A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514. | Unknown | N/A | n/a | |
CVE-2022-28505 | Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java. | Unknown | N/A | n/a | |
CVE-2022-28506 | There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45. | Unknown | N/A | n/a | |
CVE-2022-28507 | Dragon Path Technologies Bharti Airtel Routers Hardware BDT-121 version 1.0 is vulnerable to Cross Site Scripting (XSS) via Dragon path router admin page. | Unknown | N/A | n/a | |
CVE-2022-28508 | An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field. | Unknown | N/A | n/a | |
CVE-2022-28512 | A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantasticblog/single.php" via the "id=5" parameters. | Unknown | N/A | n/a | |
CVE-2022-2852 | Use after free in FedCM in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Unknown | N/A | ||
CVE-2022-28521 | ZCMS v20170206 was discovered to contain a file inclusion vulnerability via index.php?m=home&c=home&a=sp_set_config. | Unknown | N/A | n/a | |
CVE-2022-28522 | ZCMS v20170206 was discovered to contain a stored cross-site scripting (XSS) vulnerability via index.php?m=home&c=message&a=add. | Unknown | N/A | n/a | |
CVE-2022-28523 | HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete. | Unknown | N/A | n/a | |
CVE-2022-28524 | ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php. | Unknown | N/A | n/a | |
CVE-2022-28525 | ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_user&id=1. | Unknown | N/A | n/a | |
CVE-2022-28527 | dhcms v20170919 was discovered to contain an arbitrary folder deletion vulnerability via /admin.php?r=admin/AdminBackup/del. | Unknown | N/A | n/a | |
CVE-2022-28528 | bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit. | Unknown | N/A | n/a | |
CVE-2022-2853 | Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | Unknown | N/A | ||
CVE-2022-28530 | Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory. | Unknown | N/A | n/a | |
CVE-2022-28531 | Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtusername (aka Username) field. | Unknown | N/A | n/a | |
CVE-2022-28533 | Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php. | Unknown | N/A | n/a | |
CVE-2022-2854 | Use after free in SwiftShader in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Unknown | N/A | ||
CVE-2022-28541 | Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as Samsung Update permission. | Unknown | N/A | Samsung Mobile | |
CVE-2022-28542 | Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access privileged content providers as Galaxy Store permission. | Unknown | N/A | Samsung Mobile | |
CVE-2022-28543 | Path traversal vulnerability in Samsung Flow prior to version 4.8.07.4 allows local attackers to read arbitrary files as Samsung Flow permission. | Unknown | N/A | Samsung Mobile | |
CVE-2022-28544 | Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allows attacker to access the file of Galaxy store. | Unknown | N/A | Samsung Mobile | |
CVE-2022-28545 | FUDforum 3.1.1 is vulnerable to Stored XSS. | Unknown | N/A | n/a | |
CVE-2022-2855 | Use after free in ANGLE in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Unknown | N/A | ||
CVE-2022-28550 | Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead. jhead copies strings to a stack buffer when it detects a &i or &o. However, jhead does not check the boundary of the stack buffer. As a result, there will be a stack buffer overflow problem when multiple `&i` or `&o` are given. | Unknown | N/A | n/a | |
CVE-2022-28552 | Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin. | Unknown | N/A | n/a | |
CVE-2022-28556 | Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin is vulnerable to Buffer Overflow. The stack overflow vulnerability lies in the /goform/setpptpservercfg interface of the web. The sent post data startip and endip are copied to the stack using the sanf function, resulting in stack overflow. Similarly, this vulnerability can be used together with CVE-2021-44971 | Unknown | N/A | n/a | |
CVE-2022-28557 | There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arbitrary command execution | Unknown | N/A | n/a | |
CVE-2022-2856 | Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page. | Unknown | N/A | ||
CVE-2022-28560 | There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 15.03.2.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload | Unknown | N/A | n/a | |
CVE-2022-28561 | There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03.01.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload | Unknown | N/A | n/a | |
CVE-2022-28568 | Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored. | Unknown | N/A | n/a | |
CVE-2022-2857 | Use after free in Blink in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Unknown | N/A | ||
CVE-2022-28571 | D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli. | Unknown | N/A | n/a | |
CVE-2022-28572 | Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability in `SetIPv6Status` function | Unknown | N/A | n/a | |
CVE-2022-28573 | D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNTPserverSeting. This vulnerability allows attackers to execute arbitrary commands via the system_time_timezone parameter. | Unknown | N/A | n/a | |
CVE-2022-28575 | It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows attackers to execute arbitrary commands through a carefully constructed payload | Unknown | N/A | n/a | |
CVE-2022-28577 | It is found that there is a command injection vulnerability in the delParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload. | Unknown | N/A | n/a | |
CVE-2022-28578 | It is found that there is a command injection vulnerability in the setOpenVpnCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload. | Unknown | N/A | n/a | |
CVE-2022-28579 | It is found that there is a command injection vulnerability in the setParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload. | Unknown | N/A | n/a | |
CVE-2022-2858 | Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction. | Unknown | N/A | ||
CVE-2022-28580 | It is found that there is a command injection vulnerability in the setL2tpServerCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload. | Unknown | N/A | n/a | |
CVE-2022-28581 | It is found that there is a command injection vulnerability in the setWiFiAdvancedCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload. | Unknown | N/A | n/a | |
CVE-2022-28582 | It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload. | Unknown | N/A | n/a | |
CVE-2022-28583 | It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload. | Unknown | N/A | n/a | |
CVE-2022-28584 | It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload. | Unknown | N/A | n/a | |
CVE-2022-28585 | EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php | Unknown | N/A | n/a | |
CVE-2022-28586 | XSS in edit page of Hoosk 1.8.0 allows attacker to execute javascript code in user browser via edit page with XSS payload bypass filter some special chars. | Unknown | N/A | n/a | |
CVE-2022-28588 | In SpringBootMovie <=1.2 when adding movie names, malicious code can be stored because there are no filtering parameters, resulting in stored XSS. | Unknown | N/A | n/a | |
CVE-2022-28589 | A stored cross-site scripting (XSS) vulnerability in Pixelimity 1.0 allows attackers to execute arbitrary web scripts or HTML via the Title field in admin/pages.php?action=add_new | Unknown | N/A | n/a | |
CVE-2022-2859 | Use after free in Chrome OS Shell in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. | Unknown | N/A | ||
CVE-2022-28590 | A Remote Code Execution (RCE) vulnerability exists in Pixelimity 1.0 via admin/admin-ajax.php?action=install_theme. | Unknown | N/A | n/a | |
CVE-2022-28598 | Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. | Unknown | N/A | n/a | |
CVE-2022-28599 | A stored cross-site scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 that allows an authenticated user to upload a malicious .pdf file which acts as a stored XSS payload. If this stored XSS payload is triggered by an administrator it will trigger a XSS attack. | Unknown | N/A | n/a | |
CVE-2022-2860 | Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to bypass cookie prefix restrictions via a crafted HTML page. | Unknown | N/A | ||
CVE-2022-28601 | A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism. | Unknown | N/A | n/a | |
CVE-2022-28605 | Hardcoded admin token in SoundBar apps in Linkplay SDK 1.00 allows remote attackers to gain admin privilege access in linkplay antifactory | Unknown | N/A | n/a | |
CVE-2022-28606 | An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can be exploited by an attacker to gain control of the server. | Unknown | N/A | n/a | |
CVE-2022-28607 | An issue was discovered in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to gain sensitive information via the action parameter to /system/user/modules/mod_users/controller.php. | Unknown | N/A | n/a | |
CVE-2022-2861 | Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts into WebUI via a crafted HTML page. | Unknown | N/A | ||
CVE-2022-28611 | Improper input validation in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via physical access. | Unknown | N/A | n/a | |
CVE-2022-28612 | Improper Access Control vulnerability leading to multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Muneeb's Custom Popup Builder plugin <= 1.3.1 at WordPress. | Unknown | N/A | Muneeb | |
CVE-2022-28613 | A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is en-abled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500, causing the receiving RTU500 CMU to reboot. The vulnerability is caused by the validation error in the length information carried in MBAP header in the HCI Modbus TCP function. | Unknown | N/A | Hitachi Energy |
vunerability-insight.com © 2023 - 2025. All Rights Reserved.
Vulnerability Data Repositories v