CVE Feed

    Dashboard / CVE

    6.2
    Medium

    CVE-2022-42284

    Last Modified: 7 Apr 2025

    NVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This may lead to a credentials exposure.

    Published: 13 Jan 2023
    6.4
    Medium

    CVE-2022-42283

    Last Modified: 7 Apr 2025

    NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service or gain code execution.

    Published: 13 Jan 2023
    6.5
    Medium

    CVE-2022-42282

    Last Modified: 7 Apr 2025

    NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can access arbitrary files, which may lead to information disclosure.

    Published: 13 Jan 2023
    6.7
    Medium

    CVE-2022-42281

    Last Modified: 7 Apr 2025

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the FsRecovery, which may allow a highly privileged local attacker to cause an out-of-bounds write, which may lead to code execution, denial of service, compromised integrity, and information disclosure.

    Published: 13 Jan 2023
    7.1
    High

    CVE-2022-42280

    Last Modified: 7 Apr 2025

    NVIDIA BMC contains a vulnerability in SPX REST auth handler, where an un-authorized attacker can exploit a path traversal, which may lead to authentication bypass.

    Published: 13 Jan 2023
    7.2
    High

    CVE-2022-42279

    Last Modified: 7 Apr 2025

    NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.

    Published: 13 Jan 2023
    7.2
    High

    CVE-2022-42278

    Last Modified: 7 Apr 2025

    NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can read and write to arbitrary locations within the memory context of the IPMI server process, which may lead to code execution, denial of service, information disclosure and data tampering.

    Published: 13 Jan 2023
    7.5
    High

    CVE-2022-42277

    Last Modified: 7 Apr 2025

    NVIDIA DGX Station contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.

    Published: 13 Jan 2023
    7.5
    High

    CVE-2022-42276

    Last Modified: 7 Apr 2025

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.

    Published: 13 Jan 2023
    7.8
    High

    CVE-2022-3161

    Last Modified: 16 Jan 2025

    The APDFL.dll contains a memory corruption vulnerability while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.

    Published: 13 Jan 2023
    7.8
    High

    CVE-2022-3160

    Last Modified: 16 Jan 2025

    The APDFL.dll contains an out-of-bounds write past the fixed-length heap-based buffer while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.

    Published: 13 Jan 2023
    7.8
    High

    CVE-2022-3159

    Last Modified: 16 Jan 2025

    The APDFL.dll contains a stack-based buffer overflow vulnerability that could be triggered while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.

    Published: 13 Jan 2023
    7.7
    High

    CVE-2022-42275

    Last Modified: 7 Apr 2025

    NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. This may lead to a loss of integrity and denial of service.

    Published: 13 Jan 2023
    7.8
    High

    CVE-2022-42274

    Last Modified: 7 Apr 2025

    NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service or gain code execution.

    Published: 13 Jan 2023
    7.5
    High

    CVE-2022-3693

    Last Modified: 20 May 2026

    Path Traversal vulnerability in Deytek Informatics FileOrbis File Management System allows Path Traversal. This issue affects FileOrbis File Management System: from unspecified before 10.6.3.

    Published: 13 Jan 2023
    9.8
    Critical

    CVE-2023-23566

    Last Modified: 7 Apr 2025

    A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verification when they try to add an account to any third-party webmail service (or add an account to Outlook or Gmail, etc.) with IMAP or POP3 without any verification code.

    Published: 13 Jan 2023
    5.4
    Medium

    CVE-2023-0289

    Last Modified: 7 Apr 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository craigk5n/webcalendar prior to master.

    Published: 13 Jan 2023
    7.8
    High

    CVE-2021-36204

    Last Modified: 7 Apr 2025

    Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.3 allows API calls to expose credentials in plain text.

    Published: 13 Jan 2023
    9.8
    Critical

    CVE-2022-45299

    Last Modified: 7 Apr 2025

    An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL.

    Published: 13 Jan 2023
    7.5
    High

    CVE-2022-41721

    Last Modified: 4 Apr 2025

    A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead be reading the body of the HTTP request, which could be attacker-manipulated to represent arbitrary HTTP2 requests.

    Published: 13 Jan 2023
    7.2
    High

    CVE-2022-46947

    Last Modified: 7 Apr 2025

    Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.

    Published: 13 Jan 2023
    7.5
    High

    CVE-2023-22602

    Last Modified: 21 Nov 2024

    When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an authentication bypass. The authentication bypass occurs when Shiro and Spring Boot are using different pattern-matching techniques. Both Shiro and Spring Boot < 2.6 default to Ant style pattern matching. Mitigation: Update to Apache Shiro 1.11.0, or set the following Spring Boot configuration value: `spring.mvc.pathmatch.matching-strategy = ant_path_matcher`

    Published: 13 Jan 2023
    7.8
    High

    CVE-2023-21597

    Last Modified: 5 Mar 2025

    Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2023
    8.8
    High

    CVE-2022-42136

    Last Modified: 7 Apr 2025

    Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission to access. That action, could lead an attacker to store arbitrary code on that files and execute RCE commands.

    Published: 13 Jan 2023
    9.8
    Critical

    CVE-2022-46478

    Last Modified: 7 Apr 2025

    The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary commands via crafted Hessian serialized data.

    Published: 13 Jan 2023
    9.8
    Critical

    CVE-2022-46502

    Last Modified: 7 Apr 2025

    Online Student Enrollment System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /student_enrollment/admin/login.php.

    Published: 13 Jan 2023
    8.2
    High

    CVE-2022-46093

    Last Modified: 7 Apr 2025

    Hospital Management System v1.0 is vulnerable to SQL Injection. Attackers can gain administrator privileges without the need for a password.

    Published: 13 Jan 2023
    6.5
    Medium

    CVE-2022-48090

    Last Modified: 7 Apr 2025

    Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to SQL Injection via /app/dao/CustomerDAO.php.

    Published: 13 Jan 2023
    5.4
    Medium

    CVE-2022-48091

    Last Modified: 7 Apr 2025

    Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to Cross Site Scripting (XSS) via process_update_profile.php.

    Published: 13 Jan 2023
    7.4
    High

    CVE-2022-21191

    Last Modified: 4 Apr 2025

    Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function.

    Published: 13 Jan 2023
    7.2
    High

    CVE-2022-46950

    Last Modified: 7 Apr 2025

    Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=delete_window.

    Published: 13 Jan 2023
    7.2
    High

    CVE-2022-46951

    Last Modified: 7 Apr 2025

    Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=delete_uploads.

    Published: 13 Jan 2023
    7.2
    High

    CVE-2022-46952

    Last Modified: 7 Apr 2025

    Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=delete_user.

    Published: 13 Jan 2023
    7.2
    High

    CVE-2022-46953

    Last Modified: 7 Apr 2025

    Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=save_window.

    Published: 13 Jan 2023
    9.8
    Critical

    CVE-2022-46954

    Last Modified: 7 Apr 2025

    Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=delete_transaction.

    Published: 13 Jan 2023
    9.8
    Critical

    CVE-2022-46955

    Last Modified: 7 Apr 2025

    Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=save_queue.

    Published: 13 Jan 2023
    7.2
    High

    CVE-2022-46956

    Last Modified: 7 Apr 2025

    Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php.

    Published: 13 Jan 2023
    6.1
    Medium

    CVE-2021-46872

    Last Modified: 7 Apr 2025

    An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other products, permits the javascript: URI scheme and thus can lead to XSS in some applications. (Nim versions 1.6.2 and later are fixed; there may be backports of the fix to some earlier versions. NimForum 2.2.0 is fixed.)

    Published: 13 Jan 2023
    7.8
    High

    CVE-2023-21587

    Last Modified: 5 Mar 2025

    Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2023
    5.5
    Medium

    CVE-2023-21591

    Last Modified: 5 Mar 2025

    Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2023
    5.5
    Medium

    CVE-2023-21592

    Last Modified: 5 Mar 2025

    Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2023
    5.5
    Medium

    CVE-2023-21598

    Last Modified: 5 Mar 2025

    Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2023
    9.8
    Critical

    CVE-2022-46471

    Last Modified: 7 Apr 2025

    Online Health Care System v1.0 was discovered to contain a SQL injection vulnerability via the consulting_id parameter at /healthcare/Admin/consulting_detail.php.

    Published: 13 Jan 2023
    7.2
    High

    CVE-2022-46946

    Last Modified: 7 Apr 2025

    Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_brand.

    Published: 13 Jan 2023
    7.2
    High

    CVE-2022-46949

    Last Modified: 7 Apr 2025

    Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_helmet.

    Published: 13 Jan 2023
    7.5
    High

    CVE-2022-48256

    Last Modified: 7 Apr 2025

    Technitium DNS Server before 10.0 allows a self-CNAME denial-of-service attack in which a CNAME loop causes an answer to contain hundreds of records.

    Published: 13 Jan 2023
    —
    Unknown

    CVE-2023-0269

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 13 Jan 2023
    7.8
    High

    CVE-2023-21588

    Last Modified: 5 Mar 2025

    Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2023
    7.8
    High

    CVE-2023-21589

    Last Modified: 5 Mar 2025

    Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2023
    7.8
    High

    CVE-2023-21590

    Last Modified: 5 Mar 2025

    Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 Jan 2023