CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2023-0077

    Last Modified: 9 Apr 2025

    Integer overflow or wraparound vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to overflow buffers via unspecified vectors.

    Published: 5 Jan 2023
    7.5
    High

    CVE-2022-43932

    Last Modified: 10 Apr 2025

    Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 5 Jan 2023
    2
    Low

    CVE-2021-4303

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, has been found in shannah Xataface up to 2.x. Affected by this issue is the function testftp of the file install/install_form.js.php of the component Installer. The manipulation leads to cross site scripting. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. Upgrading to version 3.0.0 is able to address this issue. The patch is identified as 94143a4299e386f33bf582139cd4702571d93bde. It is recommended to upgrade the affected component. VDB-217442 is the identifier assigned to this vulnerability. NOTE: Installer is disabled by default.

    Published: 5 Jan 2023
    3.5
    Low

    CVE-2016-15010

    Last Modified: 21 Nov 2024

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in University of Cambridge django-ucamlookup up to 1.9.1. Affected by this vulnerability is an unknown functionality of the component Lookup Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 1.9.2 is able to address this issue. The identifier of the patch is 5e25e4765637ea4b9e0bf5fcd5e9a922abee7eb3. It is recommended to upgrade the affected component. The identifier VDB-217441 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 5 Jan 2023
    3.5
    Low

    CVE-2016-15009

    Last Modified: 25 Nov 2024

    A vulnerability classified as problematic has been found in OpenACS bug-tracker. Affected is an unknown function of the file lib/nav-bar.adp of the component Search. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The name of the patch is aee43e5714cd8b697355ec3bf83eefee176d3fc3. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217440.

    Published: 5 Jan 2023
    3.5
    Low

    CVE-2018-25064

    Last Modified: 21 Nov 2024

    A vulnerability was found in OSM Lab show-me-the-way. It has been rated as problematic. This issue affects some unknown processing of the file js/site.js. The manipulation leads to cross site scripting. The attack may be initiated remotely. The patch is named 4bed3b34dcc01fe6661f39c0e5d2285b340f7cac. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217439.

    Published: 5 Jan 2023
    3.5
    Low

    CVE-2022-4869

    Last Modified: 21 Nov 2024

    A vulnerability was found in Evolution Events Artaxerxes. It has been declared as problematic. This vulnerability affects unknown code of the file arta/common/middleware.py of the component POST Parameter Handler. The manipulation of the argument password leads to information disclosure. The attack can be initiated remotely. The patch is identified as 022111407d34815c16c6eada2de69ca34084dc0d. It is recommended to apply a patch to fix this issue. VDB-217438 is the identifier assigned to this vulnerability.

    Published: 5 Jan 2023
    5.5
    Medium

    CVE-2019-25098

    Last Modified: 21 Nov 2024

    A vulnerability was found in soerennb eXtplorer up to 2.1.12. It has been classified as critical. This affects an unknown part of the file include/archive.php of the component Archive Handler. The manipulation leads to path traversal. Upgrading to version 2.1.13 is able to address this issue. The identifier of the patch is b8fcb888f4ff5e171c16797a4b075c6c6f50bf46. It is recommended to upgrade the affected component. The identifier VDB-217437 was assigned to this vulnerability.

    Published: 5 Jan 2023
    5.5
    Medium

    CVE-2019-25097

    Last Modified: 21 Nov 2024

    A vulnerability was found in soerennb eXtplorer up to 2.1.12 and classified as critical. Affected by this issue is some unknown functionality of the component Directory Content Handler. The manipulation leads to path traversal. Upgrading to version 2.1.13 is able to address this issue. The name of the patch is b8fcb888f4ff5e171c16797a4b075c6c6f50bf46. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217436.

    Published: 5 Jan 2023
    3.5
    Low

    CVE-2019-25096

    Last Modified: 21 Nov 2024

    A vulnerability has been found in soerennb eXtplorer up to 2.1.12 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 2.1.13 is able to address this issue. The patch is named b8fcb888f4ff5e171c16797a4b075c6c6f50bf46. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217435.

    Published: 5 Jan 2023
    3.5
    Low

    CVE-2019-25095

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, was found in kakwa LdapCherry up to 0.x. Affected is an unknown function of the component URL Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.0.0 is able to address this issue. The patch is identified as 6f98076281e9452fdb1adcd1bcbb70a6f968ade9. It is recommended to upgrade the affected component. VDB-217434 is the identifier assigned to this vulnerability.

    Published: 5 Jan 2023
    6.5
    Medium

    CVE-2022-45857

    Last Modified: 21 Nov 2024

    An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attacker to access a FortiGate without a password via newly created VDOMs after the super_admin account is deleted.

    Published: 5 Jan 2023
    8
    High

    CVE-2022-46648

    Last Modified: 4 Apr 2025

    ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-47318.

    Published: 5 Jan 2023
    9.8
    Critical

    CVE-2022-47523

    Last Modified: 9 Apr 2025

    Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection.

    Published: 5 Jan 2023
    7.8
    High

    CVE-2022-47654

    Last Modified: 10 Apr 2025

    GPAC MP4box 2.1-DEV-rev593-g007bf61a0 is vulnerable to Buffer Overflow in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:8261

    Published: 5 Jan 2023
    7.8
    High

    CVE-2022-47660

    Last Modified: 10 Apr 2025

    GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is has an integer overflow in isomedia/isom_write.c

    Published: 5 Jan 2023
    7.8
    High

    CVE-2022-47093

    Last Modified: 10 Apr 2025

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to heap use-after-free via filters/dmx_m2ts.c:470 in m2tsdmx_declare_pid

    Published: 5 Jan 2023
    —
    Unknown

    CVE-2014-125042

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 5 Jan 2023
    —
    Unknown

    CVE-2014-125043

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 5 Jan 2023
    7.8
    High

    CVE-2022-47091

    Last Modified: 10 Apr 2025

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow in gf_text_process_sub function of filters/load_text.c

    Published: 5 Jan 2023
    7.1
    High

    CVE-2022-47092

    Last Modified: 10 Apr 2025

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is contains an Integer overflow vulnerability in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:8316

    Published: 5 Jan 2023
    7.8
    High

    CVE-2022-47094

    Last Modified: 10 Apr 2025

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Null pointer dereference via filters/dmx_m2ts.c:343 in m2tsdmx_declare_pid

    Published: 5 Jan 2023
    7.8
    High

    CVE-2022-47095

    Last Modified: 9 Apr 2025

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer overflow in hevc_parse_vps_extension function of media_tools/av_parsers.c

    Published: 5 Jan 2023
    8
    High

    CVE-2022-47318

    Last Modified: 4 Apr 2025

    ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-46648.

    Published: 5 Jan 2023
    6.1
    Medium

    CVE-2023-0057

    Last Modified: 9 Apr 2025

    Improper Restriction of Rendered UI Layers or Frames in GitHub repository pyload/pyload prior to 0.5.0b3.dev33.

    Published: 5 Jan 2023
    5.5
    Medium

    CVE-2022-46490

    Last Modified: 10 Apr 2025

    GPAC version 2.1-DEV-rev505-gb9577e6ad-master was discovered to contain a memory leak via the afrt_box_read function at box_code_adobe.c.

    Published: 5 Jan 2023
    7.8
    High

    CVE-2022-47657

    Last Modified: 10 Apr 2025

    GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function hevc_parse_vps_extension of media_tools/av_parsers.c:7662

    Published: 5 Jan 2023
    7.8
    High

    CVE-2022-47658

    Last Modified: 10 Apr 2025

    GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function gf_hevc_read_vps_bs_internal of media_tools/av_parsers.c:8039

    Published: 5 Jan 2023
    7.8
    High

    CVE-2022-47659

    Last Modified: 10 Apr 2025

    GPAC MP4box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to Buffer Overflow in gf_bs_read_data

    Published: 5 Jan 2023
    5.7
    Medium

    CVE-2022-23549

    Last Modified: 10 Mar 2025

    Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-passed` branches, users can create posts with raw body longer than the `max_length` site setting by including html comments that are not counted toward the character limit. This issue is patched in versions 2.8.14 and 2.9.0.beta16. There are no known workarounds.

    Published: 5 Jan 2023
    6.5
    Medium

    CVE-2022-23548

    Last Modified: 10 Mar 2025

    Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-passed` branches, parsing posts can be susceptible to regular expression denial of service (ReDoS) attacks. This issue is patched in versions 2.8.14 and 2.9.0.beta16. There are no known workarounds.

    Published: 5 Jan 2023
    9.1
    Critical

    CVE-2022-31631

    Last Modified: 2 Jul 2025

    In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which may further lead to SQL injection vulnerabilities.

    Published: 5 Jan 2023
    9.8
    Critical

    CVE-2022-45995

    Last Modified: 10 Apr 2025

    There is an unauthorized buffer overflow vulnerability in Tenda AX12 v22.03.01.21 _ cn. This vulnerability can cause the web service not to restart or even execute arbitrary code. It is a different vulnerability from CVE-2022-2414.

    Published: 5 Jan 2023
    5.5
    Medium

    CVE-2022-46489

    Last Modified: 10 Apr 2025

    GPAC version 2.1-DEV-rev505-gb9577e6ad-master was discovered to contain a memory leak via the gf_isom_box_parse_ex function at box_funcs.c.

    Published: 5 Jan 2023
    5.5
    Medium

    CVE-2022-47086

    Last Modified: 10 Apr 2025

    GPAC MP4Box v2.1-DEV-rev574-g9d5bb184b contains a segmentation violation via the function gf_sm_load_init_swf at scene_manager/swf_parse.c

    Published: 5 Jan 2023
    7.8
    High

    CVE-2022-47087

    Last Modified: 10 Apr 2025

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b has a Buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/av_parsers.c

    Published: 5 Jan 2023
    7.8
    High

    CVE-2022-47088

    Last Modified: 10 Apr 2025

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow.

    Published: 5 Jan 2023
    7.8
    High

    CVE-2022-47089

    Last Modified: 10 Apr 2025

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow via gf_vvc_read_sps_bs_internal function of media_tools/av_parsers.c

    Published: 5 Jan 2023
    5.3
    Medium

    CVE-2022-47543

    Last Modified: 10 Apr 2025

    An issue was discovered in Siren Investigate before 12.1.7. There is an ACL bypass on global objects.

    Published: 5 Jan 2023
    9.8
    Critical

    CVE-2022-47544

    Last Modified: 10 Apr 2025

    An issue was discovered in Siren Investigate before 12.1.7. Script variable whitelisting is insufficiently sandboxed.

    Published: 5 Jan 2023
    7.8
    High

    CVE-2022-47653

    Last Modified: 10 Apr 2025

    GPAC MP4box 2.1-DEV-rev593-g007bf61a0 is vulnerable to Buffer Overflow in eac3_update_channels function of media_tools/av_parsers.c:9113

    Published: 5 Jan 2023
    7.8
    High

    CVE-2022-47655

    Last Modified: 10 Apr 2025

    Libde265 1.0.9 is vulnerable to Buffer Overflow in function void put_qpel_fallback<unsigned short>

    Published: 5 Jan 2023
    7.8
    High

    CVE-2022-47656

    Last Modified: 9 Apr 2025

    GPAC MP4box 2.1-DEV-rev617-g85ce76efd is vulnerable to Buffer Overflow in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:8273

    Published: 5 Jan 2023
    7.8
    High

    CVE-2022-47661

    Last Modified: 10 Apr 2025

    GPAC MP4Box 2.1-DEV-rev649-ga8f438d20 is vulnerable to Buffer Overflow via media_tools/av_parsers.c:4988 in gf_media_nalu_add_emulation_bytes

    Published: 5 Jan 2023
    5.5
    Medium

    CVE-2022-47662

    Last Modified: 10 Apr 2025

    GPAC MP4Box 2.1-DEV-rev649-ga8f438d20 has a segment fault (/stack overflow) due to infinite recursion in Media_GetSample isomedia/media.c:662

    Published: 5 Jan 2023
    7.8
    High

    CVE-2022-47663

    Last Modified: 10 Apr 2025

    GPAC MP4box 2.1-DEV-rev649-ga8f438d20 is vulnerable to buffer overflow in h263dmx_process filters/reframe_h263.c:609

    Published: 5 Jan 2023
    5.4
    Medium

    CVE-2021-32828

    Last Modified: 10 Mar 2025

    The Nuxeo Platform is an open source content management platform for building business applications. In version 11.5.109, the `oauth2` REST API is vulnerable to Reflected Cross-Site Scripting (XSS). This XSS can be escalated to Remote Code Execution (RCE) by levering the automation API.

    Published: 5 Jan 2023
    7.5
    High

    CVE-2023-22626

    Last Modified: 7 Apr 2025

    PgHero before 3.1.0 allows Information Disclosure via EXPLAIN because query results may be present in an error message. (Depending on database user privileges, this may only be information from the database, or may be information from file contents on the database server.)

    Published: 5 Jan 2023
    5.3
    Medium

    CVE-2023-22622

    Last Modified: 7 Apr 2025

    WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.

    Published: 5 Jan 2023
    9.8
    Critical

    CVE-2022-44877

    Last Modified: 3 Nov 2025

    login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.

    Published: 5 Jan 2023