CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2021-4141

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 25 Aug 2022
    —
    Unknown

    CVE-2021-20192

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 25 Aug 2022
    —
    Unknown

    CVE-2021-20258

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 25 Aug 2022
    —
    Unknown

    CVE-2021-20287

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 25 Aug 2022
    —
    Unknown

    CVE-2021-20301

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 25 Aug 2022
    —
    Unknown

    CVE-2018-5494

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 25 Aug 2022
    —
    Unknown

    CVE-2018-5483

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 25 Aug 2022
    5.4
    Medium

    CVE-2022-37160

    Last Modified: 21 Nov 2024

    Claroline 13.5.7 and prior allows an authenticated attacker to elevate privileges via the arbitrary creation of a privileged user. By combining the XSS vulnerability present in several upload forms and a javascript request to the present API, it is possible to trigger the creation of a user with administrative rights by opening an SVG file as an administrator user.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37159

    Last Modified: 21 Nov 2024

    Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.

    Published: 25 Aug 2022
    6.1
    Medium

    CVE-2022-37161

    Last Modified: 21 Nov 2024

    Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS) via SVG file upload.

    Published: 25 Aug 2022
    5.4
    Medium

    CVE-2022-37162

    Last Modified: 21 Nov 2024

    Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution by adding arbitrary javascript code in the 'Location' field of a calendar event.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37158

    Last Modified: 21 Nov 2024

    RuoYi v3.8.3 has a Weak password vulnerability in the management system.

    Published: 25 Aug 2022
    5.5
    Medium

    CVE-2022-37292

    Last Modified: 21 Nov 2024

    Tenda AX12 V22.03.01.21_CN is vulnerable to Buffer Overflow. This overflow is triggered in the sub_42FDE4 function, which satisfies the request of the upper-level interface function sub_430124, that is, handles the post request under /goform/SetIpMacBind.

    Published: 25 Aug 2022
    5.4
    Medium

    CVE-2022-37238

    Last Modified: 21 Nov 2024

    MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the currentRequest parameter.

    Published: 25 Aug 2022
    5.4
    Medium

    CVE-2022-37239

    Last Modified: 21 Nov 2024

    MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the rulles_list_ajax endpoint.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37240

    Last Modified: 21 Nov 2024

    MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter.

    Published: 25 Aug 2022
    5.4
    Medium

    CVE-2022-37241

    Last Modified: 21 Nov 2024

    MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the data_leak_list_ajax endpoint.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37242

    Last Modified: 21 Nov 2024

    MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter.

    Published: 25 Aug 2022
    5.4
    Medium

    CVE-2022-37243

    Last Modified: 21 Nov 2024

    MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the whitelist endpoint.

    Published: 25 Aug 2022
    5.4
    Medium

    CVE-2022-37244

    Last Modified: 21 Nov 2024

    MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest parameter. after login leads to inject malicious tag leads to IFRAME injection.

    Published: 25 Aug 2022
    5.4
    Medium

    CVE-2022-37245

    Last Modified: 21 Nov 2024

    MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the Blacklist endpoint.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-37822

    Last Modified: 21 Nov 2024

    Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetRouteStatic.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37816

    Last Modified: 21 Nov 2024

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetIpMacBind.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-37820

    Last Modified: 21 Nov 2024

    Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ddnsEn parameter in the function formSetSysToolDDNS.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37814

    Last Modified: 21 Nov 2024

    Tenda AC1206 V15.03.06.23 was discovered to contain multiple stack overflows via the deviceMac and the device_id parameters in the function addWifiMacFilter.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-37824

    Last Modified: 21 Nov 2024

    Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGusetBasic.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-37817

    Last Modified: 21 Nov 2024

    Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetIpMacBind.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37815

    Last Modified: 21 Nov 2024

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the PPPOEPassword parameter in the function formQuickIndex.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-37818

    Last Modified: 21 Nov 2024

    Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the list parameter at the function formSetQosBand.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37813

    Last Modified: 21 Nov 2024

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetSysTime.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37809

    Last Modified: 21 Nov 2024

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the speed_dir parameter in the function formSetSpeedWan.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37810

    Last Modified: 21 Nov 2024

    Tenda AC1206 V15.03.06.23 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37808

    Last Modified: 21 Nov 2024

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the index parameter in the function formWifiWpsOOB.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-37823

    Last Modified: 21 Nov 2024

    Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function formSetVirtualSer.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-37821

    Last Modified: 21 Nov 2024

    Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ProvinceCode parameter in the function formSetProvince.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-37819

    Last Modified: 21 Nov 2024

    Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the timezone parameter in the function fromSetSysTime.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36455

    Last Modified: 21 Nov 2024

    TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37807

    Last Modified: 21 Nov 2024

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function formSetClientState.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37806

    Last Modified: 21 Nov 2024

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromDhcpListClient.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37805

    Last Modified: 21 Nov 2024

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromWizardHandle.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37811

    Last Modified: 21 Nov 2024

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the startIp parameter in the function formSetPPTPServer.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37812

    Last Modified: 21 Nov 2024

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the firewallEn parameter in the function formSetFirewallCfg.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37803

    Last Modified: 21 Nov 2024

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromAddressNat.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37800

    Last Modified: 21 Nov 2024

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function fromSetRouteStatic.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37804

    Last Modified: 21 Nov 2024

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37801

    Last Modified: 21 Nov 2024

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetQosBand.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37802

    Last Modified: 21 Nov 2024

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromNatStaticSetting.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37798

    Last Modified: 21 Nov 2024

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetVirtualSer.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37799

    Last Modified: 21 Nov 2024

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter at the function setSmartPowerManagement.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-37100

    Last Modified: 21 Nov 2024

    H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateMacClone.

    Published: 25 Aug 2022