Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2022-31383 |
|
SQL Injection in sqli (CVE-2022-31383)
SQL injection in sqli (CVE-2022-31383). Successful exploitation can lead to full system takeover.
|
| CVE-2021-42675 |
|
Unrestricted File Upload in kreado (CVE-2021-42675)
vulnerability in kreado (CVE-2021-42675). Successful exploitation can lead to full system takeover.
|
| CVE-2022-32511 |
|
Unsafe Deserialization in jmespath (CVE-2022-32511)
vulnerability in jmespath (CVE-2022-32511). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.6.1` or later.
|
| CVE-2021-42875 |
|
OS Command Injection in totolink (CVE-2021-42875)
OS command injection in totolink (CVE-2021-42875). Successful exploitation can lead to full system takeover.
|
| CVE-2022-29704 |
|
BrowsBox CMS v4.0 was discovered to contain a SQL injection vulnerability.
BrowsBox CMS v4.0 was discovered to contain a SQL injection vulnerability.
|
| CVE-2022-31340 |
|
Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php.
Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php.
|
| CVE-2022-30490 |
|
SQL Injection in sqli (CVE-2022-30490)
SQL injection in sqli (CVE-2022-30490). Successful exploitation can lead to full system takeover.
|
| CVE-2022-28945 |
|
Path Traversal in path-traversal (CVE-2022-28945)
path traversal in path-traversal (CVE-2022-28945). Successful exploitation can lead to full system takeover.
|
| CVE-2022-24239 |
|
Unrestricted File Upload in aceware (CVE-2022-24239)
vulnerability in aceware (CVE-2022-24239). Successful exploitation can lead to full system takeover.
|
| CVE-2022-24240 |
|
SQL Injection in sqli (CVE-2022-24240)
SQL injection in sqli (CVE-2022-24240). Successful exploitation can lead to full system takeover.
|
| CVE-2021-42872 |
|
OS Command Injection in totolink (CVE-2021-42872)
OS command injection in totolink (CVE-2021-42872). Successful exploitation can lead to full system takeover.
|
| CVE-2012-1710 KEV |
|
[KEV] Vulnerability in Oracle fusion-middleware (CVE-2012-1710)
vulnerability in Oracle fusion-middleware (CVE-2012-1710). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-7489 |
|
Vulnerability in schneider-electric (CVE-2020-7489)
vulnerability in schneider-electric (CVE-2020-7489). Successful exploitation can lead to full system takeover.
|
| CVE-2021-41653 |
|
Code Injection in tp-link (CVE-2021-41653)
code injection in tp-link (CVE-2021-41653). Successful exploitation can lead to full system takeover.
|
| CVE-2020-25368 |
|
OS Command Injection in dlink (CVE-2020-25368)
OS command injection in dlink (CVE-2020-25368). Successful exploitation can lead to full system takeover.
|
| CVE-2020-25912 |
|
XXE (XML External Entity) in dos (CVE-2020-25912)
vulnerability in dos (CVE-2020-25912). Confidential information can be exposed externally.
|
| CVE-2021-3825 |
|
Vulnerability in pardus (CVE-2021-3825)
vulnerability in pardus (CVE-2021-3825). Successful exploitation can lead to full system takeover.
|
| CVE-2021-41326 |
|
Vulnerability in misp-project (CVE-2021-41326)
vulnerability in misp-project (CVE-2021-41326). Successful exploitation can lead to full system takeover.
|
| CVE-2021-36582 |
|
Unrestricted File Upload in kooboo (CVE-2021-36582)
vulnerability in kooboo (CVE-2021-36582). Successful exploitation can lead to full system takeover.
|
| CVE-2021-36581 |
|
Unrestricted File Upload in kooboo (CVE-2021-36581)
vulnerability in kooboo (CVE-2021-36581). Successful exploitation can lead to full system takeover.
|
| CVE-2021-39302 |
|
SQL Injection in sqli (CVE-2021-39302)
SQL injection in sqli (CVE-2021-39302). Successful exploitation can lead to full system takeover.
|
| CVE-2021-33485 |
|
CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.
CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.
|
| CVE-2021-22779 |
|
Vulnerability in schneider-electric (CVE-2021-22779)
vulnerability in schneider-electric (CVE-2021-22779). Confidential information can be exposed externally.
|
| CVE-2021-30120 |
|
Kaseya VSA through 9.5.7 allows attackers to bypass the 2FA requirement.
Kaseya VSA through 9.5.7 allows attackers to bypass the 2FA requirement.
|
| CVE-2021-35502 |
|
Vulnerability in misp-project (CVE-2021-35502)
vulnerability in misp-project (CVE-2021-35502). Successful exploitation can lead to full system takeover.
|
| CVE-2021-27132 |
|
Vulnerability in sercomm (CVE-2021-27132)
vulnerability in sercomm (CVE-2021-27132). Successful exploitation can lead to full system takeover.
|
| CVE-2020-27285 |
|
Vulnerability in redlion (CVE-2020-27285)
vulnerability in redlion (CVE-2020-27285). Confidential information can be exposed externally.
|
| CVE-2020-35276 |
|
SQL Injection in sqli (CVE-2020-35276)
SQL injection in sqli (CVE-2020-35276). Successful exploitation can lead to full system takeover.
|
| CVE-2020-29006 |
|
Vulnerability in misp-project (CVE-2020-29006)
vulnerability in misp-project (CVE-2020-29006). Successful exploitation can lead to full system takeover.
|
| CVE-2020-24881 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2020-24881)
SSRF in ssrf (CVE-2020-24881). Successful exploitation can lead to full system takeover.
|
| CVE-2020-25466 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2020-25466)
SSRF in ssrf (CVE-2020-25466). Successful exploitation can lead to full system takeover.
|
| CVE-2020-26867 |
|
Unsafe Deserialization in deserialization (CVE-2020-26867)
vulnerability in deserialization (CVE-2020-26867). Successful exploitation can lead to full system takeover.
|
| CVE-2018-5353 |
|
Vulnerability in zohocorp (CVE-2018-5353)
vulnerability in zohocorp (CVE-2018-5353). Successful exploitation can lead to full system takeover.
|
| CVE-2020-24193 |
|
SQL Injection in sqli (CVE-2020-24193)
SQL injection in sqli (CVE-2020-24193). Successful exploitation can lead to full system takeover.
|
| CVE-2020-15411 |
|
Privilege Escalation in misp-project (CVE-2020-15411)
vulnerability in misp-project (CVE-2020-15411). Successful exploitation can lead to full system takeover.
|
| CVE-2019-18184 |
|
OS Command Injection in crestron (CVE-2019-18184)
OS command injection in crestron (CVE-2019-18184). Successful exploitation can lead to full system takeover.
|
| CVE-2019-1971 |
|
OS Command Injection in cisco (CVE-2019-1971)
OS command injection in cisco (CVE-2019-1971). Successful exploitation can lead to full system takeover.
|
| CVE-2022-28932 |
|
D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.
D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.
|
| CVE-2017-18362 KEV |
|
[KEV] SQL Injection in Kaseya virtual-systemserver-administrator-vsa (CVE-2017-18362)
SQL injection in Kaseya virtual-systemserver-administrator-vsa (CVE-2017-18362). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2018-19949 KEV |
|
[KEV] Vulnerability in Qnap network-attached-storage-nas (CVE-2018-19949)
vulnerability in Qnap network-attached-storage-nas (CVE-2018-19949). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2015-0987 |
|
Information Disclosure in omron (CVE-2015-0987)
vulnerability in omron (CVE-2015-0987). Confidential information can be exposed externally.
|
| CVE-2022-29351 |
|
Unrestricted File Upload in tiddlywiki (CVE-2022-29351)
vulnerability in tiddlywiki (CVE-2022-29351). Successful exploitation can lead to full system takeover.
|
| CVE-2018-8851 |
|
Vulnerability in echelon (CVE-2018-8851)
vulnerability in echelon (CVE-2018-8851). Successful exploitation can lead to full system takeover.
|
| CVE-2018-11091 |
|
Unrestricted File Upload in mybiz (CVE-2018-11091)
vulnerability in mybiz (CVE-2018-11091). Successful exploitation can lead to full system takeover.
|
| CVE-2018-7790 |
|
Vulnerability in schneider-electric (CVE-2018-7790)
vulnerability in schneider-electric (CVE-2018-7790). Successful exploitation can lead to full system takeover.
|
| CVE-2018-7791 |
|
Authentication Bypass in schneider-electric (CVE-2018-7791)
authentication bypass in schneider-electric (CVE-2018-7791). Successful exploitation can lead to full system takeover.
|
| CVE-2022-28568 |
|
Unrestricted File Upload in simple-doctors-appointment-system-project (CVE-2022-28568)
vulnerability in simple-doctors-appointment-system-project (CVE-2022-28568). Successful exploitation can lead to full system takeover.
|
| CVE-2022-29347 |
|
Unrestricted File Upload in web-at-rchiv-project (CVE-2022-29347)
vulnerability in web-at-rchiv-project (CVE-2022-29347). Successful exploitation can lead to full system takeover.
|
| CVE-2021-43163 |
|
Command Injection in ruijienetworks (CVE-2021-43163)
command injection in ruijienetworks (CVE-2021-43163). Successful exploitation can lead to full system takeover.
|
| CVE-2022-28118 |
|
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.
|