Search Results (42958 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-29856 1 Automationanywhere 1 Automation 360 2024-11-21 7.5 High
A hardcoded cryptographic key in Automation360 22 allows an attacker to decrypt exported RPA packages.
CVE-2022-29817 1 Jetbrains 1 Intellij Idea 2024-11-21 3.9 Low
In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible
CVE-2022-29816 1 Jetbrains 1 Intellij Idea 2024-11-21 2.8 Low
In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible
CVE-2022-29811 1 Jetbrains 1 Hub 2024-11-21 6.1 Medium
In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible.
CVE-2022-29778 2 D-link, Dlink 3 Dir-890l Firmware, Dir-890l, Dir-890l Firmware 2024-11-21 8.8 High
D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the parameter 'descriptor' at SetVirtualServerSettings.php
CVE-2022-29770 1 Xuxueli 1 Xxl-job 2024-11-21 5.4 Medium
XXL-Job v2.3.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /xxl-job-admin/jobinfo.
CVE-2022-29734 1 Ict 2 Protege Gx, Protege Wx 2024-11-21 5.4 Medium
A cross-site scripting (XSS) vulnerability in ICT Protege GX/WX v2.08 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.
CVE-2022-29732 1 Deltacontrols 2 Entelitouch, Entelitouch Firmware 2024-11-21 6.1 Medium
Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to contain a cross-site scripting (XSS) vulnerability via the Username parameter. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2022-29730 1 Usr 10 Usr-g800v2, Usr-g800v2 Firmware, Usr-g806 and 7 more 2024-11-21 9.8 Critical
USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 was discovered to contain hard-coded credentials for its highest privileged account. The credentials cannot be altered through normal operation of the device.
CVE-2022-29728 1 Surveysparrow 1 Enterprise Survey Software 2024-11-21 6.1 Medium
Survey Sparrow Enterprise Survey Software 2022 has a Reflected cross-site scripting (XSS) vulnerability in the test parameter.
CVE-2022-29727 1 Surveysparrow 1 Enterprise Survey Software 2024-11-21 5.4 Medium
Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter.
CVE-2022-29711 1 Librenms 1 Librenms 2024-11-21 6.1 Medium
LibreNMS v22.3.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Table/GraylogController.php.
CVE-2022-29710 1 Limesurvey 1 Limesurvey 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execute arbitrary web scripts or HTML via a crafted plugin.
CVE-2022-29653 1 Ofcms Project 1 Ofcms 2024-11-21 6.1 Medium
OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json.
CVE-2022-29649 1 Qsmart Next Project 1 Qsmart Next 2024-11-21 6.1 Medium
Qsmart Next v4.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2022-29648 1 Jflyfox 1 Jfinal Cms 2024-11-21 5.4 Medium
A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request.
CVE-2022-29645 1 Totolink 2 A3100r, A3100r Firmware 2024-11-21 9.8 Critical
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for root stored in the component /etc/shadow.sample.
CVE-2022-29644 1 Totolink 2 A3100r, A3100r Firmware 2024-11-21 9.8 Critical
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for the telnet service stored in the component /web_cste/cgi-bin/product.ini.
CVE-2022-29628 1 Online Market Place Site Project 1 Online Market Place Site 2024-11-21 5.4 Medium
A cross-site scripting (XSS) vulnerability in /omps/seller of Online Market Place Site v1.0 allows attackers to execute arbitrary web cripts or HTML via a crafted payload injected into the Page parameter.
CVE-2022-29618 1 Sap 1 Netweaver Development Infrastructure 2024-11-21 6.1 Medium
Due to insufficient input validation, SAP NetWeaver Development Infrastructure (Design Time Repository) - versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to inject script into the URL and execute code in the user’s browser. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.