CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-39039

    Last Modified: 10 Apr 2025

    aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch Server-Side Request Forgery (SSRF) attack, to perform arbitrary system command or disrupt service.

    Published: 3 Jan 2023
    7.5
    High

    CVE-2022-39040

    Last Modified: 10 Apr 2025

    aEnrich a+HRD log read function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.

    Published: 3 Jan 2023
    7.8
    High

    CVE-2022-41645

    Last Modified: 10 Apr 2025

    Out-of-bounds read vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code by having a user to open a specially crafted project file.

    Published: 3 Jan 2023
    7.8
    High

    CVE-2022-43448

    Last Modified: 10 Apr 2025

    Out-of-bounds write vulnerability in V-SFT v6.1.7.0 and earlier and TELLUS v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code by having a user to open a specially crafted image file.

    Published: 3 Jan 2023
    7.2
    High

    CVE-2022-44036

    Last Modified: 21 Nov 2024

    In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execution. NOTE: the vendor's position is that this is "very obviously a feature not an issue and if you don't like that feature it is very obvious how to disable it."

    Published: 3 Jan 2023
    7.2
    High

    CVE-2022-45867

    Last Modified: 10 Apr 2025

    MyBB before 1.8.33 allows Directory Traversal. The Admin CP Languages module allows remote authenticated users, with high privileges, to achieve local file inclusion and execution.

    Published: 3 Jan 2023
    6.5
    Medium

    CVE-2022-46305

    Last Modified: 10 Apr 2025

    ChangingTec ServiSign component has a path traversal vulnerability. An unauthenticated LAN attacker can exploit this vulnerability to bypass authentication and access arbitrary system files.

    Published: 3 Jan 2023
    8.8
    High

    CVE-2022-46306

    Last Modified: 10 Apr 2025

    ChangingTec ServiSign component has a path traversal vulnerability due to insufficient filtering for special characters in the DLL file path. An unauthenticated remote attacker can host a malicious website for the component user to access, which triggers the component to load malicious DLL files under arbitrary file path and allows the attacker to perform arbitrary system operation and disrupt of service.

    Published: 3 Jan 2023
    6.5
    Medium

    CVE-2022-46309

    Last Modified: 10 Apr 2025

    Vitals ESP upload function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to access arbitrary system files.

    Published: 3 Jan 2023
    7.8
    High

    CVE-2022-47317

    Last Modified: 10 Apr 2025

    Out-of-bounds write vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code by having a user to open a specially crafted project file.

    Published: 3 Jan 2023
    9.8
    Critical

    CVE-2022-47618

    Last Modified: 10 Apr 2025

    Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can use these credentials to log in administrator page, to manipulate system or disrupt service.

    Published: 3 Jan 2023
    8.1
    High

    CVE-2022-36943

    Last Modified: 28 Jan 2026

    SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item.

    Published: 3 Jan 2023
    7.8
    High

    CVE-2023-0054

    Last Modified: 3 Nov 2025

    Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145.

    Published: 3 Jan 2023
    6.7
    Medium

    CVE-2022-32623

    Last Modified: 10 Apr 2025

    In mdp, there is a possible out of bounds write due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07342114; Issue ID: ALPS07342114.

    Published: 3 Jan 2023
    6.4
    Medium

    CVE-2022-32638

    Last Modified: 10 Apr 2025

    In isp, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494449; Issue ID: ALPS07494449.

    Published: 3 Jan 2023
    6.7
    Medium

    CVE-2022-32640

    Last Modified: 10 Apr 2025

    In meta wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441652; Issue ID: ALPS07441652.

    Published: 3 Jan 2023
    6.4
    Medium

    CVE-2022-32644

    Last Modified: 10 Apr 2025

    In vow, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494473; Issue ID: ALPS07494473.

    Published: 3 Jan 2023
    6.7
    Medium

    CVE-2022-32646

    Last Modified: 10 Apr 2025

    In gpu drm, there is a possible stack overflow due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363501; Issue ID: ALPS07363501.

    Published: 3 Jan 2023
    6.7
    Medium

    CVE-2022-32657

    Last Modified: 10 Apr 2025

    In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220705042; Issue ID: GN20220705042.

    Published: 3 Jan 2023
    9.8
    Critical

    CVE-2022-32665

    Last Modified: 10 Apr 2025

    In Boa, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20220026; Issue ID: OSBNB00144124.

    Published: 3 Jan 2023
    9.8
    Critical

    CVE-2022-39042

    Last Modified: 10 Apr 2025

    aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access API function to perform arbitrary system command or disrupt service.

    Published: 3 Jan 2023
    8.8
    High

    CVE-2022-43437

    Last Modified: 10 Apr 2025

    The Download function’s parameter of EasyTest has insufficient validation for user input. A remote attacker authenticated as a general user can inject arbitrary SQL command to access, modify or delete database.

    Published: 3 Jan 2023
    7.5
    High

    CVE-2022-45143

    Last Modified: 21 Nov 2024

    The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.

    Published: 3 Jan 2023
    4.4
    Medium

    CVE-2022-32639

    Last Modified: 10 Apr 2025

    In watchdog, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494487; Issue ID: ALPS07494487.

    Published: 3 Jan 2023
    6.7
    Medium

    CVE-2022-32636

    Last Modified: 10 Apr 2025

    In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07510064; Issue ID: ALPS07510064.

    Published: 3 Jan 2023
    8.8
    High

    CVE-2022-3860

    Last Modified: 10 Apr 2025

    The Visual Email Designer for WooCommerce WordPress plugin before 1.7.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author.

    Published: 2 Jan 2023
    4.8
    Medium

    CVE-2022-4260

    Last Modified: 10 Apr 2025

    The WP-Ban WordPress plugin before 1.69.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 2 Jan 2023
    8.8
    High

    CVE-2022-4237

    Last Modified: 10 Apr 2025

    The Welcart e-Commerce WordPress plugin before 2.8.6 does not validate user input before using it in file_exist() functions via various AJAX actions available to any authenticated users, which could allow users with a role as low as subscriber to perform PHAR deserialisation when they can upload a file and a suitable gadget chain is present on the blog

    Published: 2 Jan 2023
    7.2
    High

    CVE-2022-4372

    Last Modified: 10 Apr 2025

    The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by high privilege users such as admin by default. However, depending on the plugin configuration, other users, such as subscriber could exploit this as well

    Published: 2 Jan 2023
    6.1
    Medium

    CVE-2022-4329

    Last Modified: 10 Apr 2025

    The Product list Widget for Woocommerce WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both unauthenticated and authenticated users (such as high privilege one like admin).

    Published: 2 Jan 2023
    5.3
    Medium

    CVE-2022-4057

    Last Modified: 10 Apr 2025

    The Autoptimize WordPress plugin before 3.1.0 uses an easily guessable path to store plugin's exported settings and logs.

    Published: 2 Jan 2023
    8.8
    High

    CVE-2022-3911

    Last Modified: 10 Apr 2025

    The iubenda WordPress plugin before 3.3.3 does does not have authorisation and CSRF in an AJAX action, and does not ensure that the options to be updated belong to the plugin as long as they are arrays. As a result, any authenticated users, such as subscriber can grant themselves any privileges, such as edit_plugins etc

    Published: 2 Jan 2023
    4.8
    Medium

    CVE-2022-4256

    Last Modified: 10 Apr 2025

    The All-in-One Addons for Elementor WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 2 Jan 2023
    7.2
    High

    CVE-2022-4352

    Last Modified: 10 Apr 2025

    The Qe SEO Handyman WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

    Published: 2 Jan 2023
    4.8
    Medium

    CVE-2022-4200

    Last Modified: 10 Apr 2025

    The Login with Cognito WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 2 Jan 2023
    6.1
    Medium

    CVE-2022-4369

    Last Modified: 10 Apr 2025

    The WP-Lister Lite for Amazon WordPress plugin before 2.4.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which can be used against high-privilege users such as admin.

    Published: 2 Jan 2023
    9.8
    Critical

    CVE-2022-4099

    Last Modified: 10 Apr 2025

    The Joy Of Text Lite WordPress plugin before 2.3.1 does not properly sanitise and escape some parameters before using them in SQL statements accessible to unauthenticated users, leading to unauthenticated SQL injection

    Published: 2 Jan 2023
    9.8
    Critical

    CVE-2022-4298

    Last Modified: 10 Apr 2025

    The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.

    Published: 2 Jan 2023
    2.7
    Low

    CVE-2022-4109

    Last Modified: 10 Apr 2025

    The Wholesale Market for WooCommerce WordPress plugin before 2.0.0 does not validate user input against path traversal attacks, allowing high privilege users such as admin to download arbitrary logs from the server even when they should not be able to (for example in multisite)

    Published: 2 Jan 2023
    6.5
    Medium

    CVE-2022-4236

    Last Modified: 10 Apr 2025

    The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file via an AJAX action available to any authenticated users, which could allow users with a role as low as subscriber to read arbitrary files on the server.

    Published: 2 Jan 2023
    7.2
    High

    CVE-2022-4373

    Last Modified: 10 Apr 2025

    The Quote-O-Matic WordPress plugin through 1.0.5 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

    Published: 2 Jan 2023
    7.2
    High

    CVE-2022-4324

    Last Modified: 10 Apr 2025

    The Custom Field Template WordPress plugin before 2.5.8 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a suitable gadget chain is present on the blog.

    Published: 2 Jan 2023
    5.4
    Medium

    CVE-2022-4114

    Last Modified: 10 Apr 2025

    The Superio WordPress theme does not sanitise and escape some parameters, which could allow users with a role as low as a subscriber to perform Cross-Site Scripting attacks.

    Published: 2 Jan 2023
    5.3
    Medium

    CVE-2022-4417

    Last Modified: 10 Apr 2025

    The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 9.3.3 does not properly block access to the REST API users endpoint when the blog is in a subdirectory, which could allow attackers to bypass the restriction in place and list users

    Published: 2 Jan 2023
    5.4
    Medium

    CVE-2022-4381

    Last Modified: 10 Apr 2025

    The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

    Published: 2 Jan 2023
    5.4
    Medium

    CVE-2022-4362

    Last Modified: 10 Apr 2025

    The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

    Published: 2 Jan 2023
    7.2
    High

    CVE-2022-4358

    Last Modified: 10 Apr 2025

    The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

    Published: 2 Jan 2023
    7.2
    High

    CVE-2022-4359

    Last Modified: 10 Apr 2025

    The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

    Published: 2 Jan 2023
    4.8
    Medium

    CVE-2022-3936

    Last Modified: 10 Apr 2025

    The Team Members WordPress plugin before 5.2.1 does not sanitize and escapes some of its settings, which could allow high-privilege users such as editors to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in a multisite setup).

    Published: 2 Jan 2023
    4.8
    Medium

    CVE-2022-4119

    Last Modified: 10 Apr 2025

    The Image Optimizer, Resizer and CDN WordPress plugin before 6.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 2 Jan 2023