• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2022-31849
2022-06-27
N/A
8.8 HIGH
MERCURY MIPC451-4 1.0.22 Build 220105 Rel.55642n was discovered to contain a remote code execution (RCE) vulnerability which is exploitable via a crafted POST request.
CVE-2022-31847
Wavlink, Wn579x3 Firmware
Wl-wn575a3_firmware, Wl-wn575a3, Wl-wn530hg4_firmware, Wl-wn530hg4, Wl-wn579g3_firmware, Wl-wn579g3, Wn530hg4_firmware, Wn530hg4, Wn531g3_firmware, Wn531g3
2022-06-23
N/A
7.5 HIGH
A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN579 X3 M79X3.V5030.180719 allows attackers to obtain sensitive router information via a crafted POST request.
CVE-2022-31846
Wavlink, Wn535g3 Firmware
Wl-wn575a3_firmware, Wl-wn575a3, Wl-wn530hg4_firmware, Wl-wn530hg4, Wl-wn579g3_firmware, Wl-wn579g3, Wn530hg4_firmware, Wn530hg4, Wn531g3_firmware, Wn531g3
2022-06-23
N/A
7.5 HIGH
A vulnerability in live_mfg.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.
CVE-2022-31845
Wavlink, Wn535g3 Firmware
Wl-wn575a3_firmware, Wl-wn575a3, Wl-wn530hg4_firmware, Wl-wn530hg4, Wl-wn579g3_firmware, Wl-wn579g3, Wn530hg4_firmware, Wn530hg4, Wn531g3_firmware, Wn531g3
2022-06-23
N/A
7.5 HIGH
A vulnerability in live_check.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.
CVE-2022-3184
2022-12-28
N/A
9.8 CRITICAL
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to access an old PHP page vulnerable to directory traversal, which may allow a user to write a file to the webroot directory.
CVE-2022-31836
2023-02-24
N/A
9.8 CRITICAL
The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to cross directory risk.
CVE-2022-31830
2022-06-15
N/A
9.1 CRITICAL
Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class.php.
CVE-2022-3183
2022-12-28
N/A
9.8 CRITICAL
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the user, which may expose the affected to an OS command injection vulnerability.
CVE-2022-31827
2022-06-15
N/A
9.1 CRITICAL
MonstaFTP v2.10.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the function performFetchRequest at HTTPFetcher.php.
CVE-2022-3182
Devolutions, Remote Desktop Manager
Devolutions_gateway, Devolutions_server, Gfwx, Password_hub, Remote_desktop_manager, Workspace
2022-09-20
N/A
7 HIGH
Improper Access Control vulnerability in the Duo SMS two-factor of Devolutions Remote Desktop Manager 2022.2.14 and earlier allows attackers to bypass the application lock. This issue affects: Devolutions Remote Desktop Manager version 2022.2.14 and prior versions.
« Previous 1 … 9,922 9,923 9,924 9,925 9,926 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE