Search Results (336257 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-46494 1 Evershop 1 Evershop 2025-05-27 6.1 Medium
Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafted request to the ProductGrid function in admin/productGrid/Grid.jsx.
CVE-2023-43743 1 Zultys 12 Mx-e, Mx-e Firmware, Mx-se and 9 more 2025-05-27 8.8 High
A SQL injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an authenticated attacker to execute arbitrary SQL queries on the backend database via the filter parameter in requests to the /newapi/ endpoint in the Zultys MX web interface.
CVE-2022-40935 1 Online Pet Shop Web Application Project 1 Online Pet Shop Web Application 2025-05-27 7.2 High
Online Pet Shop We App v1.0 is vulnerable to SQL Injection via /pet_shop/classes/Master.php?f=delete_category,id.
CVE-2022-40934 1 Online Pet Shop Web Application Project 1 Online Pet Shop Web Application 2025-05-27 7.2 High
Online Pet Shop We App v1.0 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_sub_category,id
CVE-2022-40933 1 Online Pet Shop Web Application Project 1 Online Pet Shop Web Application 2025-05-27 7.2 High
Online Pet Shop We App v1.0 by oretnom23 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_order,id.
CVE-2022-40932 1 Phpgurukul 1 Zoo Management System 2025-05-27 7.2 High
In Zoo Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of the "gallery" file of the "Gallery" module in the background management system.
CVE-2022-40447 1 Zzcms 1 Zzcms 2025-05-27 7.2 High
ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php.
CVE-2022-40446 1 Zzcms 1 Zzcms 2025-05-27 7.2 High
ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&groupid=.
CVE-2022-40298 1 Crestron 1 Airmedia 2025-05-27 8.8 High
Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the AirMedia Windows Application, version 4.3.1.39. A low privileged user can initiate a repair of the system and gain a SYSTEM level shell.
CVE-2022-38573 1 10-strike 1 Network Inventory Explorer 2025-05-27 9.8 Critical
10-Strike Network Inventory Explorer v9.3 was discovered to contain a buffer overflow via the Add Computers function.
CVE-2022-35408 1 Insyde 1 Insydeh2o 2025-05-27 8.2 High
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM callout vulnerability in the SMM driver in UsbLegacyControlSmm leads to possible arbitrary code execution in SMM and escalation of privileges. An attacker could overwrite the function pointers in the EFI_BOOT_SERVICES table before the USB SMI handler triggers. (This is not exploitable from code running in the operating system.)
CVE-2022-35039 1 Otfcc Project 1 Otfcc 2025-05-27 6.5 Medium
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e20a0.
CVE-2022-35038 1 Otfcc Project 1 Otfcc 2025-05-27 6.5 Medium
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b064d.
CVE-2022-35037 1 Otfcc Project 1 Otfcc 2025-05-27 6.5 Medium
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6adb1e.
CVE-2022-35036 1 Otfcc Project 1 Otfcc 2025-05-27 6.5 Medium
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e1fc8.
CVE-2022-35035 1 Otfcc Project 1 Otfcc 2025-05-27 6.5 Medium
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b559f.
CVE-2022-35034 1 Otfcc Project 1 Otfcc 2025-05-27 6.5 Medium
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e7e3d.
CVE-2022-35031 1 Otfcc Project 1 Otfcc 2025-05-27 6.5 Medium
OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x703969.
CVE-2022-35030 1 Otfcc Project 1 Otfcc 2025-05-27 6.5 Medium
OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fe954.
CVE-2022-35029 1 Otfcc Project 1 Otfcc 2025-05-27 6.5 Medium
OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6babea.