Unknown · CVSS Not scored
SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.
Published Mar 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings.
Published Jun 21, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file.
Published Mar 18, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in the upload function of /admin/show.php allows attackers to execute arbitrary web scripts or HTML via a crafted image file.
Published Mar 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.
Published Mar 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
NUUO v03.11.00 was discovered to contain access control issue.
Published Mar 29, 2022 · Updated Jul 9, 2026
High · CVSS 7.8
Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows writing to kernel memory beyond the SystemBuffer of the IRP.
Published Jul 2, 2024 · Updated Jul 9, 2026
Medium · CVSS 6.1
Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows for the leakage of kernel memory from both the stack and the heap.
Published Jul 2, 2024 · Updated Jul 9, 2026
High · CVSS 7.8
Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 provides read and write access to the PCI configuration space of the device.
Published Jul 2, 2024 · Updated Jul 9, 2026
Medium · CVSS 5.5
Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 leaks driver logs that contain addresses of kernel mode objects, weakening KASLR.
Published Jul 2, 2024 · Updated Jul 9, 2026
Unknown · CVSS Not scored
The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 before update 5 does not check if the origin of event messages it receives matches the origin of the Remote App, allowing attackers to exfiltrate the CSRF token via a crafted event message.
Published Mar 2, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure permissions, leading to privilege escalation because of a race condition.
Published Mar 9, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.PersistentRegistryData.
Published Mar 2, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.
Published Feb 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain an integer overflow via the function dm_checkString. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
Published Feb 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
Published Feb 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
Published Feb 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in the content field of a blog post.
Published Mar 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the thumbnail path of a blog post.
Published Mar 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.
Published Mar 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A vulnerability in the component process.php of QR Code Generator v5.2.7 allows attackers to perform directory traversal.
Published Jul 25, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Authenticated stored cross-site scripting (XSS) vulnerability in "Field Server Address" field in INTELBRAS ATA 200 Firmware 74.19.10.21 allows attackers to inject JavaScript code through a crafted payload.
Published Aug 15, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
ZZ Inc. KeyMouse Windows 3.08 and prior is affected by a remote code execution vulnerability during an unauthenticated update. To exploit this vulnerability, a user must trigger an update of an affected installation of KeyMouse.
Published Mar 7, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier has insecure permissions, which allows unprivileged local users to elevate privileges to SYSTEM via the "Browse For Folder" window accessible by triggering a "Repair" on the MSI package located in C:\Windows\Installer.
Published Mar 9, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Denial of Service (DoS) in the Z-Wave S0 NonceGet protocol specification in Silicon Labs Z-Wave 500 series allows local attackers to block S0/S2 protected Z-Wave network via crafted S0 NonceGet Z-Wave packages, utilizing included but absent NodeIDs.
Published May 17, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce the victim server to disclose the username and password hash of the user executing the ACEweb Online software.
Published May 27, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability in the admin interface in Element-IT HTTP Commander 7.0.0 allows unauthenticated users to get admin access by injecting a malicious script in the User-Agent field.
Published Mar 3, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.
Published Jun 16, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.
Published Mar 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted ZIP file.
Published Mar 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.
Published Mar 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file.
Published Mar 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function.
Published Mar 1, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
ACEweb Online Portal 3.5.065 was discovered to contain an External Controlled File Path and Name vulnerability via the txtFilePath parameter in attachments.awp.
Published May 27, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp.
Published May 27, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file upload vulnerability via attachments.awp.
Published May 27, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
ACEweb Online Portal 3.5.065 was discovered to contain a cross-site scripting (XSS) vulnerability via the txtNmName1 parameter in person.awp.
Published May 27, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
The iTopVPNmini.exe component of iTop VPN 3.2 will try to connect to datastate_iTopVPN_Pipe_Server on a loop. An attacker that opened a named pipe with the same name can use it to gain the token of another user by listening for connections and abusing ImpersonateNamedPipeClient().
Published Jul 6, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP requests in their update procedure in order to download a config file. After downloading the config file, the products will parse the HTTP location of the update from the file and will try to install the update automatically with ADMIN privileges. An attacker Intercepting this communication can supply the product a fake config file with malicious locations for the updates thus gaining a remote code execution on an endpoint.
Published Jul 6, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
In IOBit Advanced System Care (AscService.exe) 15, an attacker with SEImpersonatePrivilege can create a named pipe with the same name as one of ASCService's named pipes. ASCService first tries to connect before trying to create the named pipes, because of that during login the service will try to connect to the attacker which will lead to either escalation of privileges (through token manipulation and ImpersonateNamedPipeClient() ) from ADMIN -> SYSTEM or from Local ADMIN-> Domain ADMIN depending on the user and named pipe that is used.
Published Jul 6, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramData folder, ProgramData folder has "rwx" permissions for unprivileged users. Low privilege users can use SetOpLock to wait for CreateProcess and switch the genuine component with a malicious executable thus gaining code execution as a high privilege user (Low Privilege -> high integrity ADMIN).
Published Jul 6, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home pages through the non login status because real authentication is not carried out.
Published Mar 7, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
An issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS).
Published Mar 21, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
BigAnt Software BigAnt Server v5.6.06 was discovered to contain a cross-site scripting (XSS) vulnerability.
Published Mar 21, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF).
Published Mar 21, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.
Published Mar 21, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.
Published Mar 21, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.
Published Mar 21, 2022 · Updated Jul 9, 2026
Unknown · CVSS Not scored
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.
Published Mar 21, 2022 · Updated Jul 9, 2026
Critical · CVSS 9.8
The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries, allowing attackers to have write access and escalate privileges via replacing NEWTESTREMOTEMANAGER.EXE.
Published Jan 30, 2023 · Updated Jul 9, 2026