Show filters
267 Total Results
Displaying 121-130 of 267
Sort by:
Attacker Value
Unknown

CVE-2022-46442

Disclosure Date: December 27, 2022 (last updated February 24, 2025)
dedecms <=V5.7.102 is vulnerable to SQL Injection. In sys_ sql_ n query.php there are no restrictions on the sql query.
Attacker Value
Unknown

CVE-2022-46166

Disclosure Date: December 09, 2022 (last updated February 24, 2025)
Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are affected. Users are advised to upgrade to the most recent releases of Spring Boot Admin 2.6.10 and 2.7.8 to resolve this issue. Users unable to upgrade may disable any notifier or disable write access (POST request) on `/env` actuator endpoint.
Attacker Value
Unknown

CVE-2022-38900

Disclosure Date: November 28, 2022 (last updated February 24, 2025)
decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.
Attacker Value
Unknown

CVE-2022-43192

Disclosure Date: November 17, 2022 (last updated February 24, 2025)
An arbitrary file upload vulnerability in the component /dede/file_manage_control.php of Dedecms v5.7.101 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is related to an incomplete fix for CVE-2022-40886.
Attacker Value
Unknown

CVE-2022-43031

Disclosure Date: November 09, 2022 (last updated February 24, 2025)
DedeCMS v6.1.9 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add Administrator accounts and modify Admin passwords.
Attacker Value
Unknown

CVE-2022-43359

Disclosure Date: November 07, 2022 (last updated February 24, 2025)
Gifdec commit 1dcbae19363597314f6623010cc80abad4e47f7c was discovered to contain an out-of-bounds read in the function read_image_data. This vulnerability is triggered when parsing a crafted Gif file.
Attacker Value
Unknown

CVE-2022-3558

Disclosure Date: November 07, 2022 (last updated February 24, 2025)
The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.
Attacker Value
Unknown

CVE-2022-40921

Disclosure Date: October 12, 2022 (last updated February 24, 2025)
DedeCMS V5.7.99 was discovered to contain an arbitrary file upload vulnerability via the component /dede/file_manage_control.php.
Attacker Value
Unknown

CVE-2022-40886

Disclosure Date: October 03, 2022 (last updated February 24, 2025)
DedeCMS 5.7.98 has a file upload vulnerability in the background.
Attacker Value
Unknown

CVE-2022-36583

Disclosure Date: September 01, 2022 (last updated February 24, 2025)
DedeCMS V5.7.97 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/co_do.php via the dopost, rpok, and aid parameters.