Unknown · CVSS Not scored
Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution (RCE) vulnerabilities via the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.php.
Published Sep 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain a cross-site scripting (XSS) vulnerability.
Published Sep 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Bolt CMS contains a vulnerability in version 5.1.12 and below that allows an authenticated user with the ROLE_EDITOR privileges to upload and rename a malicious file to achieve remote code execution.
Published Sep 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue was discovered in rageframe2 2.6.37. There is a XSS vulnerability in the user agent related parameters of the info.php page.
Published Aug 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Authentication Bypass via function phpcgi_main in cgibin.
Published Aug 15, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh.
Published Aug 15, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying config.php.
Published Aug 15, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda AC9 V15.03.2.13 is vulnerable to Buffer Overflow via httpd, form_fast_setting_wifi_set. httpd.
Published Aug 19, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter.
Published Aug 31, 2022 · Updated Jul 9, 2026
Critical · CVSS 9.6
Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout=1&message=[injection]&plug=106.
Published Nov 22, 2022 · Updated Jul 9, 2026
Critical · CVSS 9.8
Fusiondirectory 1.3 suffers from Improper Session Handling.
Published Nov 22, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Multiple reflected XSS vulnerabilities occur when handling error message of BPC SmartVista version 3.28.0 allowing an attacker to execute javascript code at client side.
Published Aug 19, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.4
Stored Cross-site Scripting (XSS) exists in the Amasty Blog Pro 2.10.3 and 2.10.4 plugin for Magento 2 because of the duplicate post function.
Published Nov 23, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.4
Amasty Blog 2.10.3 is vulnerable to Cross Site Scripting (XSS) via leave comment functionality.
Published Nov 23, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system information.
Published Aug 23, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.
Published Aug 19, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via the User parameter or Pwd parameter to Login.asp.
Published Aug 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted HTTP connection request.
Published Aug 22, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Printix Cloud Print Management v1.3.1149.0 for Windows was discovered to contain insecure permissions.
Published Aug 19, 2022 · Updated Jul 9, 2026
Critical · CVSS 9.8
Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..
Published Sep 30, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.1
Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the searchdata parameter.
Published Sep 30, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
Published Jul 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
PyroCMS v3.9 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.
Published Aug 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request.
Published Aug 19, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in /index.php/?p=report of Online Fire Reporting System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "Contac #" text field.
Published Jul 27, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.
Published Aug 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to download arbitrary files regardless of file type or size.
Published Sep 12, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to write arbitrary files to the directory \PromoPhoto\, regardless of file type or size.
Published Sep 12, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in the Feature Navigator of Micro-Star International MSI Feature Nagivator v1.0.1808.0901 allows attackers to cause a Denial of Service (DoS) via a crafted image or video file.
Published Sep 12, 2022 · Updated Jul 9, 2026
High · CVSS 7.5
ICEcoder v8.1 allows attackers to execute a directory traversal.
Published Sep 22, 2022 · Updated Jul 9, 2026
Critical · CVSS 9.8
WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit attack, allowing the attacker to brute force the admin password leading to Account Take Over.
Published Oct 12, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted SVG document, with JavaScript, for a profile picture.
Published Jul 7, 2022 · Updated Jul 9, 2026
High · CVSS 7.5
An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint.
Published Oct 19, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in the Add Classification function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via unspecified vectors.
Published Jul 5, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c.
Published Jul 6, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts or HTML via uploading a crafted PDF file.
Published Jun 27, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh.
Published Aug 29, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM when writing chat-room data there.
Published Jul 18, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan.
Published Jul 6, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the execution of arbitrary code (remote).
Published Jul 6, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda AC23 v16.03.07.44 was discovered to contain a stack overflow via the security_5g parameter in the function formWifiBasicSet.
Published Jul 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Arox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo function at photogalleries.inc.php and the import staff excel function at 1finance_master.inc.php.
Published Jul 15, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
EGT-Kommunikationstechnik UG Mediacenter before v2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Online_Update.php.
Published Jul 11, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.5
Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().
Published Feb 1, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via public_html/register_visitor?msg=.
Published Jun 29, 2022 · Updated Jul 9, 2026
High · CVSS 8.8
An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet.
Published Nov 28, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.
Published Jun 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.
Published Jun 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.
Published Jun 16, 2022 · Updated Jul 9, 2026
High · CVSS 7.2
An arbitrary file upload vulnerability in the apiImportLabs function in api_labs.php of EVE-NG 2.0.3-112 Community allows attackers to execute arbitrary code via a crafted UNL file.
Published Oct 20, 2022 · Updated Jul 9, 2026