Medium · CVSS 6.1
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal v7.4.3.4 and Liferay DXP v7.4 GA allows attackers to execute arbitrary web scripts or HTML via parameters with the filter_ prefix.
Published Sep 22, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.1
Liferay Portal v7.1.0 through v7.4.2 and Liferay DXP 7.1 before fix pack 26, 7.2 before fix pack 15, and 7.3 before service pack 3 was discovered to contain a cross-site scripting (XSS) vulnerability in the Portal Search module's Custom Facet widget. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Parameter Name text field.
Published Sep 21, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.4
Stored cross-site scripting (XSS) vulnerability in the Site module's user membership administration page in Liferay Portal 7.0.1 through 7.4.1, and Liferay DXP 7.0 before fix pack 102, 7.1 before fix pack 26, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the a user's name.
Published Sep 21, 2022 · Updated Jul 9, 2026
Medium · CVSS 6.1
HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack 17 through 25, 7.2 fix pack 5 through 14, and 7.3 before service pack 3 can be circumvented by using multiple forward slashes, which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, and (3) others parameters that rely on HtmlUtil.escapeRedirect.
Published Sep 22, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.4
A stored cross-site scripting (XSS) vulnerability in Infoblox NIOS v8.5.2-409296 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the VLAN View Name field.
Published Jan 9, 2024 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traversal via a crafted ZIP file.
Published May 31, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan 2.0.8 and Network Inventory for Windows 5.8.22 and Network Software Scanner for Windows 2.0.8 and UnLock IT for Windows 6.1.1. The impact is: execute arbitrary code (remote). The component is: Updater. The attack vector is: To exploit this vulnerability, a user must trigger an update of an affected installation of EMCO Software. ¶¶ Multiple products from EMCO Software are affected by a remote code execution vulnerability during the update process.
Published May 23, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.
Published May 23, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users.
Published Aug 22, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.
Published May 4, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and published by trusted users, this is intentional.
Published Apr 12, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.
Published May 3, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected at /edit-db.php.
Published Apr 28, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php.
Published Apr 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file.
Published Apr 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['page'] parameter.
Published May 11, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['s'] parameter.
Published May 11, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
Published Apr 26, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.
Published Apr 26, 2022 · Updated Jul 9, 2026
Medium · CVSS 5.4
A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment Body component.
Published Apr 26, 2023 · Updated Jul 9, 2026
High · CVSS 7.5
Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP request.
Published Apr 26, 2023 · Updated Jul 9, 2026
Unknown · CVSS Not scored
In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce page by clicking on a crafted link.
Published May 4, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.
Published Jun 6, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the function FT_Request_Size.
Published Apr 22, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.
Published Apr 22, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.
Published May 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file.
Published Apr 12, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.
Published Apr 12, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function. Local users could get remote code execution.
Published May 10, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remote code execution.
Published May 10, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Online Banking System Protect v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the pages parameter.
Published Mar 30, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.
Published Mar 30, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Online Banking System Protect v1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via parameters on user profile, system_info and accounts management.
Published Mar 30, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application.
Published Apr 13, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbitrary code via uploading a crafted PHP file.
Published Apr 6, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.1.0 through 7.3.3, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 8, allows remote attackers to inject arbitrary web script or HTML via web content template names.
Published Apr 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permission when accessing a list of sites/groups, which allows remote authenticated users to view sites/groups via the user's site membership assignment UI.
Published Apr 19, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote attackers to inject arbitrary web script or HTML via a form field's help text to (1) Forms module's form builder, or (2) App Builder module's object form view's form builder.
Published Apr 15, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the name of a asset category.
Published Apr 19, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.
Published Apr 5, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp.
Published Mar 25, 2022 · Updated Jul 9, 2026
Critical · CVSS 9.8 · CISA KEV
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
Published Mar 27, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
The HTTP interface of Synaman v5.1 and below was discovered to allow authenticated attackers to execute arbitrary code and escalate privileges.
Published Apr 6, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Synaman v5.1 and below was discovered to contain weak file permissions which allows authenticated attackers to escalate privileges.
Published Apr 6, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "special" field.
Published Mar 29, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Joget DX 7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Datalist table.
Published Mar 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which allows attackers to arbitrarily add admin accounts.
Published Jun 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.
Published Mar 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings.
Published Jun 21, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file.
Published Mar 18, 2022 · Updated Jul 9, 2026