Unknown · CVSS Not scored
Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RPC calls or deny service by shutting down Celery task nodes.
Published May 31, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the System Tools of the Wi-Fi network. This affects TL-WR841 V12 TL-WR841N(EU)_V12_160624 and TL-WR841 V11 TL-WR841N(EU)_V11_160325 , TL-WR841N_V11_150616 and TL-WR841 V10 TL-WR841N_V10_150310 are also affected.
Published Jul 14, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.
Published Jun 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover admin/moderater account.
Published May 23, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the username and password parameters.
Published Jul 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
BrowsBox CMS v4.0 was discovered to contain a SQL injection vulnerability.
Published Jun 2, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Qsmart Next v4.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability.
Published Sep 15, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the startTime and endTime parameters in the function setParentalRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Published May 18, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file. Note: The vendor argues that this is not a legitimate issue and there is no vulnerability here.
Published May 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.
Published May 4, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file.
Published May 24, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to access the PJSIP and SIP extension credentials, cryptographic keys and voicemails files via unspecified vectors.
Published Jun 24, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters.
Published May 23, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.
Published May 23, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone number of other user accounts.
Published May 10, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.1
A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v7.3 before service pack 3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name of a tag.
Published Sep 21, 2022 · Updated Jul 9, 2026
High · CVSS 7.5
Path traversal vulnerability in the Hypermedia REST APIs module in Liferay Portal 7.4.0 through 7.4.2 allows remote attackers to access files outside of com.liferay.headless.discovery.web/META-INF/resources via the `parameter` parameter.
Published Sep 22, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.1
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal v7.4.3.4 and Liferay DXP v7.4 GA allows attackers to execute arbitrary web scripts or HTML via parameters with the filter_ prefix.
Published Sep 22, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.1
Liferay Portal v7.1.0 through v7.4.2 and Liferay DXP 7.1 before fix pack 26, 7.2 before fix pack 15, and 7.3 before service pack 3 was discovered to contain a cross-site scripting (XSS) vulnerability in the Portal Search module's Custom Facet widget. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Parameter Name text field.
Published Sep 21, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.4
Stored cross-site scripting (XSS) vulnerability in the Site module's user membership administration page in Liferay Portal 7.0.1 through 7.4.1, and Liferay DXP 7.0 before fix pack 102, 7.1 before fix pack 26, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the a user's name.
Published Sep 21, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.1
HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack 17 through 25, 7.2 fix pack 5 through 14, and 7.3 before service pack 3 can be circumvented by using multiple forward slashes, which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, and (3) others parameters that rely on HtmlUtil.escapeRedirect.
Published Sep 22, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.4
A stored cross-site scripting (XSS) vulnerability in Infoblox NIOS v8.5.2-409296 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the VLAN View Name field.
Published Jan 9, 2024 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traversal via a crafted ZIP file.
Published May 31, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan 2.0.8 and Network Inventory for Windows 5.8.22 and Network Software Scanner for Windows 2.0.8 and UnLock IT for Windows 6.1.1. The impact is: execute arbitrary code (remote). The component is: Updater. The attack vector is: To exploit this vulnerability, a user must trigger an update of an affected installation of EMCO Software. ¶¶ Multiple products from EMCO Software are affected by a remote code execution vulnerability during the update process.
Published May 23, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.
Published May 23, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users.
Published Aug 22, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.
Published May 4, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and published by trusted users, this is intentional.
Published Apr 12, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.
Published May 3, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected at /edit-db.php.
Published Apr 28, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php.
Published Apr 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file.
Published Apr 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['page'] parameter.
Published May 11, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['s'] parameter.
Published May 11, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
Published Apr 26, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.
Published Apr 26, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.4
A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment Body component.
Published Apr 26, 2023 · Updated Jul 9, 2026
High · CVSS 7.5
Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP request.
Published Apr 26, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce page by clicking on a crafted link.
Published May 4, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.
Published Jun 6, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the function FT_Request_Size.
Published Apr 22, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.
Published Apr 22, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.
Published May 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file.
Published Apr 12, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.
Published Apr 12, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function. Local users could get remote code execution.
Published May 10, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remote code execution.
Published May 10, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Online Banking System Protect v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the pages parameter.
Published Mar 30, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.
Published Mar 30, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Online Banking System Protect v1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via parameters on user profile, system_info and accounts management.
Published Mar 30, 2022 · Updated Jul 9, 2026