Critical
|
11 Dec 2022 |
11 Dec 2022 |
CPAI-2022-1019
|
|
CVE-2022-25434 CVE-2022-25435 CVE-2022-25437 CVE-2022-25439 CVE-2022-25440 CVE-2022-26278 CVE-2022-27016 CVE-2022-27022
|
Tenda AC9 Stack Overflow (CVE-2022-25434; CVE-2022-25435; CVE-2022-25437; CVE-2022-25439; CVE-2022-25440; CVE-2022-26278; CVE-2022-27016; CVE-2022-27022)
|
Critical
|
11 Dec 2022 |
11 Dec 2022 |
CPAI-2022-1005
|
|
CVE-2022-28021
|
Purchase Order Management System Remote Code Execution (CVE-2022-28021)
|
Critical
|
13 Nov 2022 |
11 Dec 2022 |
CPAI-2022-0797
|
|
CVE-2022-27268 CVE-2022-27269 CVE-2022-27270 CVE-2022-27271 CVE-2022-27273 CVE-2022-27275 CVE-2022-27276
|
InHand Networks InRouter 900 Command Injection (CVE-2022-27268; CVE-2022-27269; CVE-2022-27270; CVE-2022-27271; CVE-2022-27273; CVE-2022-27275; CVE-2022-27276)
|
Critical
|
11 Dec 2022 |
11 Dec 2022 |
CPAI-2022-0452
|
|
CVE-2022-33107
|
ThinkPHP Remote Code Execution (CVE-2022-33107)
|
Critical
|
11 Dec 2022 |
11 Dec 2022 |
CPAI-2021-1481
|
|
CVE-2021-30180
|
Apache Dubbo Remote Code Execution (CVE-2021-30180)
|
Critical
|
11 Dec 2022 |
11 Dec 2022 |
CPAI-2022-1048
|
|
CVE-2022-32994
|
Halo CMS Arbitrary File Upload (CVE-2022-32994)
|
Medium
|
8 Dec 2022 |
8 Dec 2022 |
CPAI-2021-1472
|
|
CVE-2021-28662
|
Squid Proxy Denial of Service (CVE-2021-28662)
|
Critical
|
8 Dec 2022 |
8 Dec 2022 |
CPAI-2021-1471
|
|
CVE-2021-28958
|
Zoho ManageEngine ADSelfService Plus Command Injection (CVE-2021-28958)
|
Medium
|
8 Dec 2022 |
8 Dec 2022 |
CPAI-2021-1470
|
|
CVE-2021-31813
|
Zoho ManageEngine Applications Manager Cross-Site Scripting (CVE-2021-31813)
|
Critical
|
8 Dec 2022 |
8 Dec 2022 |
CPAI-2021-1469
|
|
CVE-2021-32608
|
SmartStore SmartStoreNET Cross-Site Scripting (CVE-2021-32608)
|
Critical
|
8 Dec 2022 |
8 Dec 2022 |
CPAI-2021-1468
|
|
CVE-2021-32607
|
SmartStore SmartStoreNET Cross-Site Scripting (CVE-2021-32607)
|
Critical
|
8 Dec 2022 |
8 Dec 2022 |
CPAI-2021-1466
|
|
CVE-2021-37918
|
Zoho ManageEngine ADManager Plus ModifyPhotoAction File Upload (CVE-2021-37918)
|
High
|
8 Dec 2022 |
8 Dec 2022 |
CPAI-2021-1465
|
|
CVE-2021-43829
|
Patrowl PatrowlManager Unrestricted File Upload (CVE-2021-43829)
|
Critical
|
8 Dec 2022 |
8 Dec 2022 |
CPAI-2022-1040
|
|
CVE-2022-23329
|
UJCMS Jspxcms Command Injection (CVE-2022-23329)
|
Critical
|
8 Dec 2022 |
8 Dec 2022 |
CPAI-2022-1038
|
|
CVE-2022-28531
|
Covid-19 Directory on Vaccination System SQL Injection (CVE-2022-28531)
|
Critical
|
8 Dec 2022 |
8 Dec 2022 |
CPAI-2022-1022
|
|
CVE-2022-4116
|
Java Quarkus Framework Remote Code Execution (CVE-2022-4116)
|
Critical
|
8 Dec 2022 |
8 Dec 2022 |
CPAI-2022-1018
|
|
CVE-2022-31830
|
Baidu Kity Minder Server-Side Request Forgery (CVE-2022-31830)
|
Critical
|
8 Dec 2022 |
8 Dec 2022 |
CPAI-2022-1017
|
|
CVE-2022-29632
|
Roncoo Education Arbitrary File Upload (CVE-2022-29632)
|
Critical
|
8 Dec 2022 |
8 Dec 2022 |
CPAI-2022-1007
|
|
CVE-2022-37113
|
BlueCMS SQL Injection (CVE-2022-37113)
|
Critical
|
8 Dec 2022 |
8 Dec 2022 |
CPAI-2022-0998
|
|
CVE-2022-28082
|
Tenda AX12 Stack Overflow (CVE-2022-28082)
|
Critical
|
8 Dec 2022 |
8 Dec 2022 |
CPAI-2022-0995
|
|
CVE-2022-25414 CVE-2022-25417 CVE-2022-25418 CVE-2022-25427 CVE-2022-25428 CVE-2022-25429 CVE-2022-25431 CVE-2022-25433 CVE-2022-28560
|
Tenda AC9 Stack Overflow (CVE-2022-25414; CVE-2022-25417; CVE-2022-25418; CVE-2022-25427; CVE-2022-25428; CVE-2022-25429; CVE-2022-25431; CVE-2022-25433; CVE-2022-28560)
|
Critical
|
8 Dec 2022 |
8 Dec 2022 |
CPAI-2022-0980
|
|
CVE-2022-40851
|
Tenda AC15 Stack Overflow (CVE-2022-40851)
|
Critical
|
8 Dec 2022 |
8 Dec 2022 |
CPAI-2022-0970
|
|
CVE-2022-29328
|
D-Link DAP-1330 Stack Overflow (CVE-2022-29328)
|
Critical
|
8 Dec 2022 |
8 Dec 2022 |
CPAI-2022-0863
|
|
CVE-2022-35555
|
Tenda W6 Command Injection (CVE-2022-35555)
|
Critical
|
8 Dec 2022 |
8 Dec 2022 |
CPAI-2022-0859
|
|
CVE-2022-40855
|
Tenda W20E Stack Overflow (CVE-2022-40855)
|
Critical
|
7 Dec 2022 |
7 Dec 2022 |
CPAI-2020-3621
|
|
CVE-2020-4211
|
IBM Spectrum Protect Plus Command Injection (CVE-2020-4211)
|
Critical
|
7 Dec 2022 |
7 Dec 2022 |
CPAI-2019-2703
|
|
CVE-2019-12815
|
ProFTPD Authentication Bypass (CVE-2019-12815)
|
High
|
7 Dec 2022 |
7 Dec 2022 |
CPAI-2022-1054
|
|
|
Dridex Manager Phishing Attempt
|
Medium
|
7 Dec 2022 |
7 Dec 2022 |
CPAI-2021-1463
|
|
CVE-2021-38428
|
Delta Industrial Automation DIALink Cross-Site Scripting (CVE-2021-38428)
|
Critical
|
7 Dec 2022 |
7 Dec 2022 |
CPAI-2022-1006
|
|
CVE-2022-25438 CVE-2022-25441 CVE-2022-36273
|
Tenda AC9 Command Injection (CVE-2022-25438; CVE-2022-25441; CVE-2022-36273)
|
High
|
22 Sep 2022 |
7 Dec 2022 |
CPAI-2018-2113
|
|
CVE-2018-6458
|
Easy Hosting Control Panel Cross-Site Request Forgery (CVE-2018-6458)
|
Critical
|
6 Dec 2022 |
6 Dec 2022 |
CPAI-2019-2702
|
|
CVE-2019-12196
|
Zoho ManageEngine NetFlow Analyzer SQL Injection (CVE-2019-12196)
|
High
|
6 Dec 2022 |
6 Dec 2022 |
CPAI-2022-1030
|
|
|
LibreOffice Macro Event OS Command Injection
|
Critical
|
6 Dec 2022 |
6 Dec 2022 |
CPAI-2018-2182
|
|
CVE-2018-7756
|
DEWESoft X3 Remote Command Access (CVE-2018-7756)
|
Critical
|
6 Dec 2022 |
6 Dec 2022 |
CPAI-2022-1016
|
|
CVE-2022-38829 CVE-2022-38830 CVE-2022-38831
|
Tenda RX9 Pro Buffer Overflow (CVE-2022-38829; CVE-2022-38830; CVE-2022-38831)
|
Critical
|
6 Dec 2022 |
6 Dec 2022 |
CPAI-2022-1012
|
|
CVE-2022-32995
|
Halo Server Side Request Forgery (CVE-2022-32995)
|
Critical
|
6 Dec 2022 |
6 Dec 2022 |
CPAI-2022-1002
|
|
CVE-2022-24651 CVE-2022-24652
|
SentCMS Arbitrary File Upload (CVE-2022-24651; CVE-2022-24652)
|
Critical
|
6 Dec 2022 |
6 Dec 2022 |
CPAI-2022-0977
|
|
CVE-2022-30808
|
EliteCMS Remote Code Execution (CVE-2022-30808)
|
Medium
|
6 Dec 2022 |
6 Dec 2022 |
CPAI-2018-2145
|
|
CVE-2018-16833
|
Zoho ManageEngine Desktop Central Cross-site Scripting (CVE-2018-16833)
|
Critical
|
17 Nov 2022 |
6 Dec 2022 |
CPAI-2022-0860
|
|
CVE-2022-26289 CVE-2022-26290 CVE-2022-27078 CVE-2022-27079 CVE-2022-27080 CVE-2022-27081 CVE-2022-27082 CVE-2022-27083
|
Tenda M3 Command Injection (CVE-2022-26289; CVE-2022-26290; CVE-2022-27078; CVE-2022-27079; CVE-2022-27080; CVE-2022-27081; CVE-2022-27082; CVE-2022-27083)
|
High
|
5 Dec 2022 |
5 Dec 2022 |
CPAI-2021-1452
|
|
CVE-2021-2391
|
Oracle Fusion Middleware Business Intelligence Remote Code Execution (CVE-2021-2391)
|
Critical
|
5 Dec 2022 |
5 Dec 2022 |
CPAI-2022-1008
|
|
CVE-2022-38555
|
Linksys E1200 Buffer Overflow (CVE-2022-38555)
|
High
|
5 Dec 2022 |
5 Dec 2022 |
CPAI-2022-0994
|
|
CVE-2022-25048
|
Control WebPanel Command Injection (CVE-2022-25048)
|
High
|
5 Dec 2022 |
5 Dec 2022 |
CPAI-2022-0960
|
|
CVE-2022-36309
|
Airspan AirVelocity 1500 Command Injection (CVE-2022-36309)
|
Critical
|
5 Dec 2022 |
5 Dec 2022 |
CPAI-2021-1319
|
|
CVE-2021-25216
|
ISC BIND Integer Overflow (CVE-2021-25216)
|
Critical
|
4 Dec 2022 |
4 Dec 2022 |
CPAI-2022-1009
|
|
CVE-2022-37159
|
Claroline Arbitrary File Upload (CVE-2022-37159)
|
Critical
|
4 Dec 2022 |
4 Dec 2022 |
CPAI-2022-1003
|
|
CVE-2022-1556
|
WordPress StaffList Plugin SQL Injection (CVE-2022-1556)
|
Critical
|
4 Dec 2022 |
4 Dec 2022 |
CPAI-2022-1000
|
|
CVE-2022-23357
|
MoziloCMS Directory Traversal (CVE-2022-23357)
|
Critical
|
4 Dec 2022 |
4 Dec 2022 |
CPAI-2022-0997
|
|
CVE-2022-29660
|
CSCMS Music Portal System SQL Injection (CVE-2022-29660)
|
Critical
|
4 Dec 2022 |
4 Dec 2022 |
CPAI-2022-0996
|
|
CVE-2022-23881
|
ZZZCMS Command Injection (CVE-2022-23881)
|