Medium · CVSS 6.5
An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the filter parameter, allows the complete disclosure of all databases.
Published Nov 22, 2022 · Updated Jul 9, 2026
High · CVSS 7.5
Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the application. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to compromised accounts.
Published Nov 23, 2022 · Updated Jul 9, 2026
Critical · CVSS 9
PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation.
Published Nov 25, 2022 · Updated Jul 9, 2026
Critical · CVSS 9
Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation when the malicious blog post is loaded in the victim's browser.
Published Nov 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Zentao Demo15 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: URL : view-source:https://demo15.zentao.pm/user-login.html/zentao/index.php?mode=getconfig.
Published Sep 19, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js.
Published Sep 15, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.
Published Sep 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability which allows attackers to remove the Wi-Fi password and force the device into open security mode via a crafted packet sent to goform/setWizard.
Published Aug 30, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentication provider. Login attempts for valid, unlocked users configured to use PlexTrac as their authentication provider take significantly longer than those for invalid users, allowing for valid users to be enumerated by an unauthenticated remote attacker. Note that the lockout policy implemented in Plextrac version 1.17.0 makes it impossible to distinguish between valid, locked user accounts and user accounts that do not exist, but does not prevent valid, unlocked users from being enumerated.
Published Sep 8, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTrac authentication provider. An unauthenticated remote attacker could perform a bruteforce attack on the login page with no time or attempt limitation in an attempt to obtain valid credentials for the platform users configured to use the PlexTrac authentication provider.
Published Sep 8, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
The PlexTrac platform prior to API version 1.17.0 does not restrict excessive MFA TOTP submission attempts. An unauthenticated remote attacker in possession of a valid username and password can bruteforce their way past MFA protections to login as the targeted user.
Published Sep 8, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.
Published Aug 28, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If InfluxDB is being deployed on a publicly accessible endpoint, we strongly recommend authentication be enabled. Otherwise the data will be publicly available to any unauthenticated user. The default settings do NOT enable authentication and authorization."
Published Sep 2, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do.
Published Oct 7, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a crafted HTTP request.
Published Oct 7, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which allows attackers to steal all data such as source code and system files via a crafted GET request.
Published Aug 30, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authenticated user to access arbitrary files on the system. Furthermore, self-registration is enabled by default in these versions of Label Studio enabling a remote attacker to create a new account and then exploit the SSRF.
Published Oct 3, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens.
Published Sep 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution (RCE) vulnerabilities via the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.php.
Published Sep 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain a cross-site scripting (XSS) vulnerability.
Published Sep 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Bolt CMS contains a vulnerability in version 5.1.12 and below that allows an authenticated user with the ROLE_EDITOR privileges to upload and rename a malicious file to achieve remote code execution.
Published Sep 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue was discovered in rageframe2 2.6.37. There is a XSS vulnerability in the user agent related parameters of the info.php page.
Published Aug 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Authentication Bypass via function phpcgi_main in cgibin.
Published Aug 15, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh.
Published Aug 15, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying config.php.
Published Aug 15, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda AC9 V15.03.2.13 is vulnerable to Buffer Overflow via httpd, form_fast_setting_wifi_set. httpd.
Published Aug 19, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter.
Published Aug 31, 2022 · Updated Jul 9, 2026
Critical · CVSS 9.6
Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout=1&message=[injection]&plug=106.
Published Nov 22, 2022 · Updated Jul 9, 2026
Critical · CVSS 9.8
Fusiondirectory 1.3 suffers from Improper Session Handling.
Published Nov 22, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Multiple reflected XSS vulnerabilities occur when handling error message of BPC SmartVista version 3.28.0 allowing an attacker to execute javascript code at client side.
Published Aug 19, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.4
Stored Cross-site Scripting (XSS) exists in the Amasty Blog Pro 2.10.3 and 2.10.4 plugin for Magento 2 because of the duplicate post function.
Published Nov 23, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.4
Amasty Blog 2.10.3 is vulnerable to Cross Site Scripting (XSS) via leave comment functionality.
Published Nov 23, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system information.
Published Aug 23, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.
Published Aug 19, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via the User parameter or Pwd parameter to Login.asp.
Published Aug 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted HTTP connection request.
Published Aug 22, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Printix Cloud Print Management v1.3.1149.0 for Windows was discovered to contain insecure permissions.
Published Aug 19, 2022 · Updated Jul 9, 2026
Critical · CVSS 9.8
Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..
Published Sep 30, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.1
Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the searchdata parameter.
Published Sep 30, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
Published Jul 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
PyroCMS v3.9 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.
Published Aug 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request.
Published Aug 19, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in /index.php/?p=report of Online Fire Reporting System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "Contac #" text field.
Published Jul 27, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.
Published Aug 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to download arbitrary files regardless of file type or size.
Published Sep 12, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to write arbitrary files to the directory \PromoPhoto\, regardless of file type or size.
Published Sep 12, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in the Feature Navigator of Micro-Star International MSI Feature Nagivator v1.0.1808.0901 allows attackers to cause a Denial of Service (DoS) via a crafted image or video file.
Published Sep 12, 2022 · Updated Jul 9, 2026
High · CVSS 7.5
ICEcoder v8.1 allows attackers to execute a directory traversal.
Published Sep 22, 2022 · Updated Jul 9, 2026
Critical · CVSS 9.8
WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit attack, allowing the attacker to brute force the admin password leading to Account Take Over.
Published Oct 12, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted SVG document, with JavaScript, for a profile picture.
Published Jul 7, 2022 · Updated Jul 9, 2026