CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-36506

    Last Modified: 21 Nov 2024

    H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function SetMacAccessMode.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36499

    Last Modified: 21 Nov 2024

    H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function DEleteusergroup.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36502

    Last Modified: 21 Nov 2024

    H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function UpdateWanParams.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36496

    Last Modified: 21 Nov 2024

    H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function SetMobileAPInfoById.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36498

    Last Modified: 21 Nov 2024

    H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function Asp_SetTimingtimeWifiAndLed.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36500

    Last Modified: 21 Nov 2024

    H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function EditWlanMacList.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36501

    Last Modified: 21 Nov 2024

    H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function UpdateSnat.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36492

    Last Modified: 21 Nov 2024

    H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function AddMacList.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36495

    Last Modified: 21 Nov 2024

    H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function addactionlist.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36497

    Last Modified: 21 Nov 2024

    H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function Edit_BasicSSID_5G.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36490

    Last Modified: 21 Nov 2024

    H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function EditMacList.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36493

    Last Modified: 21 Nov 2024

    H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function SetAPWifiorLedInfoById.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36491

    Last Modified: 21 Nov 2024

    H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function UpdateIpv6Params.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36494

    Last Modified: 21 Nov 2024

    H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function edditactionlist.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36489

    Last Modified: 21 Nov 2024

    H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function EnableIpv6.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36488

    Last Modified: 21 Nov 2024

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the sPort parameter in the function setIpPortFilterRules.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36487

    Last Modified: 21 Nov 2024

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the command parameter in the function setTracerouteCfg.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36486

    Last Modified: 21 Nov 2024

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36485

    Last Modified: 21 Nov 2024

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36484

    Last Modified: 21 Nov 2024

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the function setDiagnosisCfg.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36483

    Last Modified: 21 Nov 2024

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the pppoeUser parameter.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36482

    Last Modified: 21 Nov 2024

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the lang parameter in the function setLanguageCfg.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36481

    Last Modified: 21 Nov 2024

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the ip parameter in the function setDiagnosisCfg.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36480

    Last Modified: 21 Nov 2024

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the command parameter in the function setTracerouteCfg.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36479

    Last Modified: 21 Nov 2024

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the host_time parameter in the function NTPSyncWithHost.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36477

    Last Modified: 21 Nov 2024

    H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function AddWlanMacList.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36478

    Last Modified: 21 Nov 2024

    H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function Edit_BasicSSID.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36474

    Last Modified: 21 Nov 2024

    H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function WlanWpsSet.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36473

    Last Modified: 21 Nov 2024

    H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function Edit_BasicSSID_5G.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36475

    Last Modified: 21 Nov 2024

    H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function AddMacList.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36470

    Last Modified: 21 Nov 2024

    H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function SetAP5GWifiById.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36472

    Last Modified: 21 Nov 2024

    H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function SetMobileAPInfoById.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36469

    Last Modified: 21 Nov 2024

    H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function SetAPWifiorLedInfoById.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36471

    Last Modified: 21 Nov 2024

    H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function SetMacAccessMode.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36467

    Last Modified: 21 Nov 2024

    H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function EditMacList.d.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36468

    Last Modified: 21 Nov 2024

    H3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function Asp_SetTimingtimeWifiAndLed.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36466

    Last Modified: 21 Nov 2024

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the ip parameter in the function setDiagnosisCfg.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36465

    Last Modified: 21 Nov 2024

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the pppoeUser parameter.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36464

    Last Modified: 21 Nov 2024

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the sPort parameter in the function setIpPortFilterRules.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36463

    Last Modified: 21 Nov 2024

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the command parameter in the function setTracerouteCfg.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36462

    Last Modified: 21 Nov 2024

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the lang parameter in the function setLanguageCfg.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36461

    Last Modified: 21 Nov 2024

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36459

    Last Modified: 21 Nov 2024

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the host_time parameter in the function NTPSyncWithHost.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36460

    Last Modified: 21 Nov 2024

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36458

    Last Modified: 21 Nov 2024

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the command parameter in the function setTracerouteCfg.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-36456

    Last Modified: 21 Nov 2024

    TOTOLink A720R V4.1.5cu.532_B20210610 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.

    Published: 25 Aug 2022
    6.3
    Medium

    CVE-2022-2957

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical was found in SourceCodester Simple and Nice Shopping Cart Script. Affected by this vulnerability is an unknown functionality of the file /mkshop/Men/profile.php. The manipulation of the argument mem_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-207001 was assigned to this vulnerability.

    Published: 25 Aug 2022
    8.8
    High

    CVE-2022-36804

    Last Modified: 24 Oct 2025

    Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-34960

    Last Modified: 21 Nov 2024

    The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to locations on the host device. This allows the attacker to mount any arbitrary file to any location on the host.

    Published: 25 Aug 2022
    8.8
    High

    CVE-2022-32427

    Last Modified: 22 Jan 2025

    PrinterLogic Windows Client through 25.0.0.676 allows attackers to execute directory traversal. Authenticated users with prior knowledge of the driver filename could exploit this to escalate privileges or distribute malicious content. This issue has been resolved in PrinterLogic Windows Client 25.0.0688 and all affected are advised to upgrade.

    Published: 25 Aug 2022