Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in /index.php/?p=report of Online Fire Reporting System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "Contac #" text field.
Published Jul 27, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.
Published Aug 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to download arbitrary files regardless of file type or size.
Published Sep 12, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to write arbitrary files to the directory \PromoPhoto\, regardless of file type or size.
Published Sep 12, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in the Feature Navigator of Micro-Star International MSI Feature Nagivator v1.0.1808.0901 allows attackers to cause a Denial of Service (DoS) via a crafted image or video file.
Published Sep 12, 2022 · Updated Jul 9, 2026
High · CVSS 7.5
ICEcoder v8.1 allows attackers to execute a directory traversal.
Published Sep 22, 2022 · Updated Jul 9, 2026
Critical · CVSS 9.8
WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit attack, allowing the attacker to brute force the admin password leading to Account Take Over.
Published Oct 12, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted SVG document, with JavaScript, for a profile picture.
Published Jul 7, 2022 · Updated Jul 9, 2026
High · CVSS 7.5
An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint.
Published Oct 19, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in the Add Classification function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via unspecified vectors.
Published Jul 5, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c.
Published Jul 6, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts or HTML via uploading a crafted PDF file.
Published Jun 27, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh.
Published Aug 29, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM when writing chat-room data there.
Published Jul 18, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan.
Published Jul 6, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the execution of arbitrary code (remote).
Published Jul 6, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda AC23 v16.03.07.44 was discovered to contain a stack overflow via the security_5g parameter in the function formWifiBasicSet.
Published Jul 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Arox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo function at photogalleries.inc.php and the import staff excel function at 1finance_master.inc.php.
Published Jul 15, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
EGT-Kommunikationstechnik UG Mediacenter before v2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Online_Update.php.
Published Jul 11, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.5
Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().
Published Feb 1, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via public_html/register_visitor?msg=.
Published Jun 29, 2022 · Updated Jul 9, 2026
High · CVSS 8.8
An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet.
Published Nov 28, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.
Published Jun 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.
Published Jun 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.
Published Jun 16, 2022 · Updated Jul 9, 2026
High · CVSS 7.2
An arbitrary file upload vulnerability in the apiImportLabs function in api_labs.php of EVE-NG 2.0.3-112 Community allows attackers to execute arbitrary code via a crafted UNL file.
Published Oct 20, 2022 · Updated Jul 9, 2026
Critical · CVSS 9
A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/.
Published Dec 14, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeration or cause a Denial of Service (DoS) via a crafted input.
Published Aug 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php.
Published Jun 1, 2022 · Updated Jul 9, 2026
High · CVSS 7.8
There is a stack buffer overflow vulnerability, which could lead to arbitrary code execution in UEFI DXE driver on some Acer products. An attack could exploit this vulnerability to escalate privilege from ring 3 to ring 0, and hijack control flow during UEFI DXE execution. This affects Altos T110 F3 firmware version <= P13 (latest) and AP130 F2 firmware version <= P04 (latest) and Aspire 1600X firmware version <= P11.A3L (latest) and Aspire 1602M firmware version <= P11.A3L (latest) and Aspire 7600U firmware version <= P11.A4 (latest) and Aspire MC605 firmware version <= P11.A4L (latest) and Aspire TC-105 firmware version <= P12.B0L (latest) and Aspire TC-120 firmware version <= P11-A4 (latest) and Aspire U5-620 firmware version <= P11.A1 (latest) and Aspire X1935 firmware version <= P11.A3L (latest) and Aspire X3475 firmware version <= P11.A3L (latest) and Aspire X3995 firmware version <= P11.A3L (latest) and Aspire XC100 firmware version <= P11.B3 (latest) and Aspire XC600 firmware version <= P11.A4 (latest) and Aspire Z3-615 firmware version <= P11.A2L (latest) and Veriton E430G firmware version <= P21.A1 (latest) and Veriton B630_49 firmware version <= AAP02SR (latest) and Veriton E430 firmware version <= P11.A4 (latest) and Veriton M2110G firmware version <= P21.A3 (latest) and Veriton M2120G fir.
Published Sep 22, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Command injection vulnerability was discovered in Netgear R6200 v2 firmware through R6200v2-V1.0.3.12 via binary /sbin/acos_service that could allow remote authenticated attackers the ability to modify values in the vulnerable parameter.
Published Sep 8, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
NETGEAR R6200_V2 firmware versions through R6200v2-V1.0.3.12_10.1.11 and R6300_V2 firmware versions through R6300v2-V1.0.4.52_10.0.93 allow remote authenticated attackers to execute arbitrary command via shell metacharacters in the ipv6_fix.cgi ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, or ipv6_lan_length parameters.
Published Sep 7, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to improper validation.
Published Jun 9, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RPC calls or deny service by shutting down Celery task nodes.
Published May 31, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the System Tools of the Wi-Fi network. This affects TL-WR841 V12 TL-WR841N(EU)_V12_160624 and TL-WR841 V11 TL-WR841N(EU)_V11_160325 , TL-WR841N_V11_150616 and TL-WR841 V10 TL-WR841N_V10_150310 are also affected.
Published Jul 14, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.
Published Jun 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover admin/moderater account.
Published May 23, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the username and password parameters.
Published Jul 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
BrowsBox CMS v4.0 was discovered to contain a SQL injection vulnerability.
Published Jun 2, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Qsmart Next v4.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability.
Published Sep 15, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the startTime and endTime parameters in the function setParentalRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Published May 18, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file. Note: The vendor argues that this is not a legitimate issue and there is no vulnerability here.
Published May 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.
Published May 4, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file.
Published May 24, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to access the PJSIP and SIP extension credentials, cryptographic keys and voicemails files via unspecified vectors.
Published Jun 24, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters.
Published May 23, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.
Published May 23, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone number of other user accounts.
Published May 10, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.1
A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v7.3 before service pack 3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name of a tag.
Published Sep 21, 2022 · Updated Jul 9, 2026
High · CVSS 7.5
Path traversal vulnerability in the Hypermedia REST APIs module in Liferay Portal 7.4.0 through 7.4.2 allows remote attackers to access files outside of com.liferay.headless.discovery.web/META-INF/resources via the `parameter` parameter.
Published Sep 22, 2022 · Updated Jul 9, 2026