CVE-2022-35537
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameters: mac_5g and Newname, which leads to command injection in page /wifi_mesh.shtml.
Read morePage 9/27.
CVEs without a recognized CWE (not present in the CWE map or marked as N/A).
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameters: mac_5g and Newname, which leads to command injection in page /wifi_mesh.shtml.
Read moreWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 qos.cgi has no filtering on parameters: qos_bandwith and qos_dat, which leads to command injection in page /qos.shtml.
Read moreWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameter macAddr, which leads to command injection in page /wifi_mesh.shtml.
Read moreWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameter hiddenSSID32g and SSID2G2, which leads to command injection in page /wifi_multi_ssid.shtml.
Read moreWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 qos.cgi has no filtering on parameters: cli_list and cli_num, which leads to command injection in page /qos.shtml.
Read moreWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 login.cgi has no filtering on parameter key, which leads to command injection in page /login.shtml.
Read moreWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameter led_switch, which leads to command injection in page /ledonoff.shtml.
Read moreWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: wlan_signal, web_pskValue, sel_EncrypTyp, sel_Automode, wlan_bssid, wlan_ssid and wlan_channel, which lead…
Read moreWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameter del_mac and parameter flag, which leads to command injection in page /cli_black_list.shtml.
Read moreWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: ppp_username, ppp_passwd, rwan_gateway, rwan_mask and rwan_ip, which leads to command injection in page /w…
Read moreWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameters: remoteManagementEnabled, blockPortScanEnabled, pingFrmWANFilterEnabled and blockSynFloodEnabled, whic…
Read moreWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 api.cgi has no filtering on parameter ufconf, and this is a hidden parameter which doesn't appear in POST body, but exist in cgi binary. This lead…
Read moreWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameter add_mac, which leads to command injection in page /cli_black_list.shtml.
Read moreWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 nas.cgi has no filtering on parameters: User1Passwd and User1, which leads to command injection in page /nas_disk.shtml.
Read moreWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: web_pskValue, wl_Method, wlan_ssid, EncrypType, rwan_ip, rwan_mask, rwan_gateway, ppp_username, ppp_passwd…
Read moreA too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.
Read moreImproper exposure of client IP addresses in net/http before Go 1.17.12 and Go 1.18.4 can be triggered by calling httputil.ReverseProxy.ServeHTTP with a Request.Header map containing a nil value for t…
Read moreVMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malicious actor with network access may be able to create a user with administrative privileges.
Read moreVMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can create and leak hex dumps, leading to information disclosure. Suc…
Read moreVMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network access can escalate privileges to root.
Read moreA Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the aerdl.dll component used in certain WithSecure products unpacker function crashes which leads to scanning engine…
Read moreLinux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less than 4.7.0 are susceptible to a vulnerability which could a…
Read moreIn btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth Standard. This could lead to remote escalation of privilege wi…
Read moreIn onDefaultNetworkChanged of Vpn.java, there is a possible way to disable VPN due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileg…
Read moreIn onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no a…
Read moreVulnerability of writing data to an arbitrary address in the HW_KEYMASTER module. Successful exploitation of this vulnerability may affect confidentiality.
Read moreThe video framework has the memory overwriting vulnerability caused by addition overflow. Successful exploitation of this vulnerability may affect the availability.
Read moreThe My HUAWEI app has a defect in the design. Successful exploitation of this vulnerability may affect data confidentiality.
Read moreIn Task.java, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i…
Read moreIBM Workload Scheduler 9.4 and 9.5 could allow a local user to overwrite key system files which would cause the system to crash. IBM X-Force ID: 221187.
Read moreVisual Studio Remote Code Execution Vulnerability
Read moreVisual Studio Remote Code Execution Vulnerability
Read moreVisual Studio Remote Code Execution Vulnerability
Read moreAzure Site Recovery Remote Code Execution Vulnerability
Read moreAzure Sphere Information Disclosure Vulnerability
Read moreWindows Bluetooth Driver Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure RTOS GUIX Studio Remote Code Execution Vulnerability
Read moreSMB Client and Server Remote Code Execution Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreWindows Hello Security Feature Bypass Vulnerability
Read moreWindows Error Reporting Service Elevation of Privilege Vulnerability
Read moreWindows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Read moreWindows Print Spooler Elevation of Privilege Vulnerability
Read moreStorage Spaces Direct Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreAzure Site Recovery Elevation of Privilege Vulnerability
Read moreMicrosoft ATA Port Driver Elevation of Privilege Vulnerability
Read moreMicrosoft Office Remote Code Execution Vulnerability
Read moreMicrosoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Read moreWindows Fax Service Elevation of Privilege Vulnerability
Read moreAzure RTOS GUIX Studio Remote Code Execution Vulnerability
Read moreAzure RTOS GUIX Studio Information Disclosure Vulnerability
Read moreAzure RTOS GUIX Studio Information Disclosure Vulnerability
Read moreWindows Partition Management Driver Elevation of Privilege Vulnerability
Read moreMicrosoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Read moreMicrosoft Excel Remote Code Execution Vulnerability
Read moreWindows Bluetooth Service Remote Code Execution Vulnerability
Read moreMicrosoft Exchange Server Information Disclosure Vulnerability
Read moreWindows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
Read moreMicrosoft Exchange Server Elevation of Privilege Vulnerability
Read moreMicrosoft Exchange Server Elevation of Privilege Vulnerability
Read moreMicrosoft Exchange Server Elevation of Privilege Vulnerability
Read moreMicrosoft Exchange Server Information Disclosure Vulnerability
Read moreThe ftlserver component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, TIBCO FTL - Enterprise Edition, TIBCO FTL - Enterprise Edition, TIBCO eFTL - Community E…
Read moreThe ftlserver component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, TIBCO FTL - Enterprise Edition, and TIBCO FTL - Enterprise Edition contains an easily ex…
Read morewolfSSL before 5.4.0 allows remote attackers to cause a denial of service via DTLS because a check for return-routability can be skipped.
Read moreIn Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can be called without user authentication when crafti…
Read moreIn Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Hidden system command web page. After performing a reverse engineering of the firmware, it was discovered that a hidden page not lis…
Read moreIn Zammad 5.2.0, customers who have secondary organizations assigned were able to see all organizations of the system rather than only those to which they are assigned.
Read moreIn Zammad 5.2.0, an attacker could manipulate the rate limiting in the 'forgot password' feature of Zammad, and thereby send many requests for a known account to cause Denial Of Service by many gener…
Read moreThe WPDating WordPress plugin before 7.4.0 does not properly escape user input before concatenating it to certain SQL queries, leading to multiple SQL injection vulnerabilities exploitable by unauthe…
Read moreGo Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-c…
Read moreAn issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled
Read moreA Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files it is possible that can crash the scanning engine. The…
Read moreKaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its 'Delete All Service Data And Reports' feature by the local authenticated atta…
Read moreVMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
Read moreVMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalation vulnerabilities. A malicious actor with local access can escalate privileges to 'root'.
Read moreVMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
Read moreVMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may…
Read moreAn issue has been discovered in GitLab CE/EE affecting all versions starting from 14.6 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1, allowed a project member to filter issues by co…
Read moreAn issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitL…
Read moreAn issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. Mem…
Read moreAn issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. A m…
Read moreAn issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for…
Read moreMultiple Improper Access Control vulnerabilities in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress.
Read moreIttiam libmpeg2 before 2022-07-27 uses memcpy with overlapping memory blocks in impeg2_mc_fullx_fully_8x8.
Read moreThe package @acrontum/filesystem-template before 0.0.2 are vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input.
Read moreA vulnerability in the lua parser of TscanCode tsclua v2.15.01 allows attackers to cause a Denial of Service (DoS) via a crafted lua script.
Read moreD-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the function binary.soapcgi_main.
Read moreD-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the function ssdpcgi_main.
Read moreAn improper access control vulnerability [CWE-284] in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8 and 7.0.0 through 7.0.5 may allow an authenticated attacker with a restricted user pro…
Read moreAn issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and…
Read moreAn issue was discovered in the Arm Mali GPU Kernel Driver (Valhall r29p0 through r38p0). A non-privileged user can make improper GPU processing operations to gain access to already freed memory.
Read moreAn issue in \Roaming\Mango\Plugins of University of Texas Multi-image Analysis GUI (Mango) 4.1 allows attackers to escalate privileges via crafted plugins.
Read moreIn scp, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not neede…
Read moreIBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to elevate their privilege to platform administrator through manipulation of APIs. IBM X-Force ID: 227978.
Read moreIBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow IBM tenant credentials to be exposed. IBM X-Force ID: 227288.
Read more