Unknown · CVSS Not scored
A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.
Published Mar 30, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Online Banking System Protect v1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via parameters on user profile, system_info and accounts management.
Published Mar 30, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application.
Published Apr 13, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbitrary code via uploading a crafted PHP file.
Published Apr 6, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.1.0 through 7.3.3, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 8, allows remote attackers to inject arbitrary web script or HTML via web content template names.
Published Apr 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permission when accessing a list of sites/groups, which allows remote authenticated users to view sites/groups via the user's site membership assignment UI.
Published Apr 19, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote attackers to inject arbitrary web script or HTML via a form field's help text to (1) Forms module's form builder, or (2) App Builder module's object form view's form builder.
Published Apr 15, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the name of a asset category.
Published Apr 19, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.
Published Apr 5, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp.
Published Mar 25, 2022 · Updated Jul 9, 2026
Critical · CVSS 9.8 · CISA KEV
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
Published Mar 27, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
The HTTP interface of Synaman v5.1 and below was discovered to allow authenticated attackers to execute arbitrary code and escalate privileges.
Published Apr 6, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Synaman v5.1 and below was discovered to contain weak file permissions which allows authenticated attackers to escalate privileges.
Published Apr 6, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "special" field.
Published Mar 29, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Joget DX 7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Datalist table.
Published Mar 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which allows attackers to arbitrarily add admin accounts.
Published Jun 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.
Published Mar 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings.
Published Jun 21, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file.
Published Mar 18, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in the upload function of /admin/show.php allows attackers to execute arbitrary web scripts or HTML via a crafted image file.
Published Mar 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.
Published Mar 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
NUUO v03.11.00 was discovered to contain access control issue.
Published Mar 29, 2022 · Updated Jul 9, 2026
High · CVSS 7.8
Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows writing to kernel memory beyond the SystemBuffer of the IRP.
Published Jul 2, 2024 · Updated Jul 9, 2026
Medium · CVSS 6.1
Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows for the leakage of kernel memory from both the stack and the heap.
Published Jul 2, 2024 · Updated Jul 9, 2026
High · CVSS 7.8
Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 provides read and write access to the PCI configuration space of the device.
Published Jul 2, 2024 · Updated Jul 9, 2026
Medium · CVSS 5.5
Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 leaks driver logs that contain addresses of kernel mode objects, weakening KASLR.
Published Jul 2, 2024 · Updated Jul 9, 2026
Unknown · CVSS Not scored
The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 before update 5 does not check if the origin of event messages it receives matches the origin of the Remote App, allowing attackers to exfiltrate the CSRF token via a crafted event message.
Published Mar 2, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure permissions, leading to privilege escalation because of a race condition.
Published Mar 9, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.PersistentRegistryData.
Published Mar 2, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.
Published Feb 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain an integer overflow via the function dm_checkString. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
Published Feb 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
Published Feb 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
Published Feb 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in the content field of a blog post.
Published Mar 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the thumbnail path of a blog post.
Published Mar 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.
Published Mar 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A vulnerability in the component process.php of QR Code Generator v5.2.7 allows attackers to perform directory traversal.
Published Jul 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Authenticated stored cross-site scripting (XSS) vulnerability in "Field Server Address" field in INTELBRAS ATA 200 Firmware 74.19.10.21 allows attackers to inject JavaScript code through a crafted payload.
Published Aug 15, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
ZZ Inc. KeyMouse Windows 3.08 and prior is affected by a remote code execution vulnerability during an unauthenticated update. To exploit this vulnerability, a user must trigger an update of an affected installation of KeyMouse.
Published Mar 7, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier has insecure permissions, which allows unprivileged local users to elevate privileges to SYSTEM via the "Browse For Folder" window accessible by triggering a "Repair" on the MSI package located in C:\Windows\Installer.
Published Mar 9, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Denial of Service (DoS) in the Z-Wave S0 NonceGet protocol specification in Silicon Labs Z-Wave 500 series allows local attackers to block S0/S2 protected Z-Wave network via crafted S0 NonceGet Z-Wave packages, utilizing included but absent NodeIDs.
Published May 17, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce the victim server to disclose the username and password hash of the user executing the ACEweb Online software.
Published May 27, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in the admin interface in Element-IT HTTP Commander 7.0.0 allows unauthenticated users to get admin access by injecting a malicious script in the User-Agent field.
Published Mar 3, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.
Published Jun 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.
Published Mar 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted ZIP file.
Published Mar 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.
Published Mar 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file.
Published Mar 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function.
Published Mar 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
ACEweb Online Portal 3.5.065 was discovered to contain an External Controlled File Path and Name vulnerability via the txtFilePath parameter in attachments.awp.
Published May 27, 2022 · Updated Jul 9, 2026