Medium · CVSS 4.8
Employee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via adding new entries under the Departments and Designations module.
Published Dec 19, 2022 · Updated Jul 9, 2026
Critical · CVSS 9.8
Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.
Published Dec 19, 2022 · Updated Jul 9, 2026
High · CVSS 8.8
mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PNG file.
Published Sep 30, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx. This vulnerability allows authenticated attackers to read arbitrary files in the system.
Published Oct 3, 2022 · Updated Jul 9, 2026
Critical · CVSS 9.8
An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page.
Published Oct 17, 2022 · Updated Jul 9, 2026
High · CVSS 7.2
Flatpress v1.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the Upload File function.
Published Sep 29, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Flatpress v1.2.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the page parameter at /flatpress/admin.php.
Published Oct 11, 2022 · Updated Jul 9, 2026
Critical · CVSS 9.8
SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at changeStatus.php.
Published Sep 21, 2022 · Updated Jul 9, 2026
Medium · CVSS 4.8
SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component newProjectValidation.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the shortName parameter.
Published Sep 21, 2022 · Updated Jul 9, 2026
Medium · CVSS 4.8
SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component newProjectValidation.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fullName parameter.
Published Sep 21, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.1
SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component newTask.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the shortName parameter.
Published Sep 21, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.1
Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then used at a victim's origin.
Published Dec 23, 2022 · Updated Jul 9, 2026
Medium · CVSS 4.3
The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before update 35 does not check user permission before showing the preview of a "Content Page" type page, allowing attackers to view unpublished "Content Page" pages via URL manipulation.
Published Sep 21, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.4
A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic.
Published Oct 13, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.4
A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the description field of uploaded svg file.
Published Oct 19, 2022 · Updated Jul 9, 2026
Critical · CVSS 9.8
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf.
Published Sep 20, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/country_group.jsf.
Published Sep 19, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at /SVFE2/pages/audit/voiceaudit.jsf.
Published Sep 19, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /feegroups/tgrt_group.jsf.
Published Sep 13, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/service_group.jsf.
Published Sep 9, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files via modifying the PATH parameter.
Published Sep 9, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system.
Published Sep 9, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.5
Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user/get-role-list web interface.
Published Dec 8, 2022 · Updated Jul 9, 2026
High · CVSS 7.8
On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or "Client Server Network" configuration, a low-privileged Sage 300 workstation user could abuse their access to the "SharedData" folder on the connected Sage 300 server to view and/or modify the credentials associated with Sage 300 users and SQL accounts to impersonate users and/or access the SQL database as a system administrator. With system administrator-level access to the Sage 300 MS SQL database it would be possible to create, update, and delete all records associated with the program and, depending on the configuration, execute code on the underlying database server.
Published Apr 28, 2023 · Updated Jul 9, 2026
Critical · CVSS 9.8
Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
Published Oct 24, 2022 · Updated Jul 9, 2026
High · CVSS 8.8
ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators.
Published Sep 19, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.
Published Aug 28, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.1
Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.
Published Sep 26, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.5
The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via crafted URL.
Published Sep 22, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Interway a.s WebJET CMS 8.6.896 is vulnerable to Cross Site Scripting (XSS).
Published Oct 19, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Genesys PureConnect Interaction Web Tools Chat Service (up to at least 26- September- 2019) allows XSS within the Printable Chat History via the participant -> name JSON POST parameter.
Published Sep 16, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.3
There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a preview is proposed by the application. This preview generates a URL including an md5 hash of the file accessed. The document's URL (https://{url}/tmp/{MD5 hash of the document}) is then accessible without authentication.
Published Nov 22, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.5
An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the filter parameter, allows the complete disclosure of all databases.
Published Nov 22, 2022 · Updated Jul 9, 2026
High · CVSS 7.5
Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the application. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to compromised accounts.
Published Nov 23, 2022 · Updated Jul 9, 2026
Critical · CVSS 9
PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation.
Published Nov 25, 2022 · Updated Jul 9, 2026
Critical · CVSS 9
Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation when the malicious blog post is loaded in the victim's browser.
Published Nov 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Zentao Demo15 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: URL : view-source:https://demo15.zentao.pm/user-login.html/zentao/index.php?mode=getconfig.
Published Sep 19, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js.
Published Sep 15, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.
Published Sep 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability which allows attackers to remove the Wi-Fi password and force the device into open security mode via a crafted packet sent to goform/setWizard.
Published Aug 30, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentication provider. Login attempts for valid, unlocked users configured to use PlexTrac as their authentication provider take significantly longer than those for invalid users, allowing for valid users to be enumerated by an unauthenticated remote attacker. Note that the lockout policy implemented in Plextrac version 1.17.0 makes it impossible to distinguish between valid, locked user accounts and user accounts that do not exist, but does not prevent valid, unlocked users from being enumerated.
Published Sep 8, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTrac authentication provider. An unauthenticated remote attacker could perform a bruteforce attack on the login page with no time or attempt limitation in an attempt to obtain valid credentials for the platform users configured to use the PlexTrac authentication provider.
Published Sep 8, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
The PlexTrac platform prior to API version 1.17.0 does not restrict excessive MFA TOTP submission attempts. An unauthenticated remote attacker in possession of a valid username and password can bruteforce their way past MFA protections to login as the targeted user.
Published Sep 8, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.
Published Aug 28, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If InfluxDB is being deployed on a publicly accessible endpoint, we strongly recommend authentication be enabled. Otherwise the data will be publicly available to any unauthenticated user. The default settings do NOT enable authentication and authorization."
Published Sep 2, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do.
Published Oct 7, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a crafted HTTP request.
Published Oct 7, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which allows attackers to steal all data such as source code and system files via a crafted GET request.
Published Aug 30, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authenticated user to access arbitrary files on the system. Furthermore, self-registration is enabled by default in these versions of Label Studio enabling a remote attacker to create a new account and then exploit the SSRF.
Published Oct 3, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens.
Published Sep 16, 2022 · Updated Jul 9, 2026