Vulnerabilities (CVE)

Total 291749 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-44801 1 Dlink 2 Dir-878, Dir-878 Firmware 2025-04-29 N/A 9.8 CRITICAL
D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control.
CVE-2022-44202 1 Dlink 2 Dir-878, Dir-878 Firmware 2025-04-29 N/A 9.8 CRITICAL
D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow.
CVE-2022-44172 1 Tenda 2 Ac18, Ac18 Firmware 2025-04-29 N/A 9.8 CRITICAL
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function R7WebsSecurityHandler.
CVE-2022-44171 1 Tenda 2 Ac18, Ac18 Firmware 2025-04-29 N/A 9.8 CRITICAL
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function form_fast_setting_wifi_set.
CVE-2022-44169 1 Tenda 2 Ac15, Ac15 Firmware 2025-04-29 N/A 7.5 HIGH
Tenda AC15 V15.03.05.18 is vulnerable to Buffer Overflow via function formSetVirtualSer.
CVE-2022-43179 1 Online Leave Management System Project 1 Online Leave Management System 2025-04-29 N/A 7.2 HIGH
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/?page=user/manage_user&id=.
CVE-2022-43143 1 Beekeeperstudio 1 Beekeeper-studio 2025-04-29 N/A 9.6 CRITICAL
A cross-site scripting (XSS) vulnerability in Beekeeper Studio v3.6.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error modal container.
CVE-2022-43117 1 Password Storage Application Project 1 Password Storage Application 2025-04-29 N/A 5.4 MEDIUM
Sourcecodester Password Storage Application in PHP/OOP and MySQL 1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Name, Username, Description and Site Feature parameters.
CVE-2022-42891 1 Siemens 1 Syngo Dynamics Cardiovascular Imaging And Information System 2025-04-29 N/A 7.5 HIGH
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the website’s application pool.
CVE-2022-42734 1 Siemens 1 Syngo Dynamics Cardiovascular Imaging And Information System 2025-04-29 N/A 7.5 HIGH
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the website’s application pool.
CVE-2022-42733 1 Siemens 1 Syngo Dynamics Cardiovascular Imaging And Information System 2025-04-29 N/A 7.5 HIGH
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any folder accessible to the account assigned to the website’s application pool.
CVE-2022-42096 1 Backdropcms 1 Backdrop Cms 2025-04-29 N/A 4.8 MEDIUM
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.
CVE-2022-40470 1 Phpgurukul 1 Blood Donor Management System 2025-04-29 N/A 4.8 MEDIUM
Phpgurukul Blood Donor Management System 1.0 allows Cross Site Scripting via Add Blood Group Name Feature.
CVE-2022-3561 1 Librenms 1 Librenms 2025-04-29 N/A 6.1 MEDIUM
Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.
CVE-2022-37197 1 Iobit 1 Iotransfer 2025-04-29 N/A 7.8 HIGH
IOBit IOTransfer V4 is vulnerable to Unquoted Service Path.
CVE-2022-36786 1 Dlink 2 Dsl-224, Dsl-224 Firmware 2025-04-29 N/A 9.9 CRITICAL
DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router.
CVE-2022-34827 1 Carel 2 Boss Mini, Boss Mini Firmware 2025-04-29 N/A 9.9 CRITICAL
Carel Boss Mini 1.5.0 has Improper Access Control.
CVE-2021-31739 1 Seppmail 1 Seppmail 2025-04-29 N/A 6.1 MEDIUM
The SEPPmail solution is vulnerable to a Cross-Site Scripting vulnerability (XSS), because user input is not correctly encoded in HTML attributes when returned by the server.SEPPmail 11.1.10 allows XSS via a recipient address.
CVE-2021-22141 1 Elastic 1 Kibana 2025-04-29 N/A 6.1 MEDIUM
An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in Kibana redirecting the user to an arbitrary website.
CVE-2024-13207 1 Patelmilap 1 Widget For Social Page Feeds 2025-04-29 N/A 4.8 MEDIUM
The Widget for Social Page Feeds WordPress plugin before 6.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).