More than 60 organizations, including M&S, Microsoft UK and Vodafone, have signed the UK government's Cyber Resilience Pledge, a new initiative aimed at boosting cyber security and resilience across British businesses
A vulnerability has been found in SmartVista SVFE2 2.2.22 and classified as critical. This vulnerability affects unknown code of the file /SVFE2/pages/feegroups/service_group.jsf. The manipulation of the argument UserForm:j_id88/UserForm:j_id90/UserForm:j_id92 leads to sql injection.
This vulnerability is documented as CVE-2022-38615. The attack can be initiated remotely. There is not any exploit available.
A vulnerability was found in SmartVista Cardgen 3.28.0. It has been classified as critical. This vulnerability affects unknown code. This manipulation causes path traversal.
This vulnerability is registered as CVE-2022-38613. The attack requires access to the local network. No exploit is available.
A vulnerability was found in SmartVista Cardgen 3.28.0. It has been declared as problematic. This issue affects some unknown processing of the component OutfileService. Such manipulation of the argument PATH leads to information disclosure.
This vulnerability is documented as CVE-2022-38614. The attack requires being on the local network. There is not any exploit available.
A vulnerability has been found in Micro-Star International MSI Feature Nagivator 1.0.1808.0901 and classified as problematic. This affects an unknown part of the component Image File Handler. This manipulation causes denial of service.
The identification of this vulnerability is CVE-2022-34108. The attack needs to be done within the local network. There is no exploit available.
A vulnerability was found in Micro-Star International MSI Feature Navigator 1.0.1808.0901 and classified as critical. This vulnerability affects unknown code of the file \PromoPhoto\. Such manipulation leads to improper access controls.
This vulnerability is referenced as CVE-2022-34109. The attack needs to be initiated within the local network. No exploit is available.
A vulnerability was found in Micro-Star International MSI Feature Navigator 1.0.1808.0901. It has been classified as problematic. This issue affects some unknown processing of the component File Download Handler. Performing a manipulation results in information disclosure.
This vulnerability is identified as CVE-2022-34110. The attack can only be performed from the local network. There is not any exploit available.
A vulnerability described as critical has been identified in SmartVista SVFE2 2.2.22. This issue affects the function UserForm of the file /feegroups/tgrt_group.jsf. Such manipulation of the argument j_id90 leads to sql injection.
This vulnerability is listed as CVE-2022-38616. The attack may be performed from remote. There is no available exploit.
A vulnerability marked as critical has been reported in stealjs 2.2.4. This vulnerability affects the function convertLater of the file npm-convert.js. Performing a manipulation of the argument requestedVersion results in improperly controlled modification of object prototype attributes.
This vulnerability is known as CVE-2022-37257. Access to the local network is required for this attack. No exploit is available.
A vulnerability classified as problematic has been found in Qsmart Next 4.1.2. Impacted is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2022-29649. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability marked as critical has been reported in Bolt CMS up to 5.1.12. This impacts an unknown function of the component File Handler. This manipulation causes unrestricted upload.
This vulnerability appears as CVE-2022-36532. The attack may be initiated remotely. There is no available exploit.
CERT/CC warns an unpatched backdoor in several Tenda routers lets attackers bypass login and gain full admin access with a hidden password. CERT/CC published an alert documenting an undocumented authentication backdoor in multiple Tenda firmware versions, tracked as CVE-2026-11405. The flaw gives anyone who knows the right password full administrative access to the device’s web […]
Microsoft says the Windows settings backup and restore tool will be enabled by default on Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems after upgrading to Windows 11 26H2. [...]