CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2022-4843

    Last Modified: 9 Apr 2025

    NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.8.2.

    Published: 29 Dec 2022
    5.7
    Medium

    CVE-2022-4848

    Last Modified: 9 Apr 2025

    Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

    Published: 29 Dec 2022
    6.5
    Medium

    CVE-2022-4850

    Last Modified: 10 Apr 2025

    Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

    Published: 29 Dec 2022
    5.3
    Medium

    CVE-2022-4851

    Last Modified: 10 Apr 2025

    Improper Handling of Values in GitHub repository usememos/memos prior to 0.9.1.

    Published: 29 Dec 2022
    —
    Unknown

    CVE-2022-48137

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-26830. Reason: This candidate is a reservation duplicate of CVE-2023-26830. Notes: All CVE users should reference CVE-2023-26830 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 29 Dec 2022
    —
    Unknown

    CVE-2022-48138

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-26829. Reason: This candidate is a reservation duplicate of CVE-2023-26829. Notes: All CVE users should reference CVE-2023-26829 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 29 Dec 2022
    9.1
    Critical

    CVE-2022-36437

    Last Modified: 11 Apr 2025

    The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and 5.1.2. The affected Hazelcast Jet versions are through 4.5.3.

    Published: 29 Dec 2022
    —
    Unknown

    CVE-2022-48187

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 29 Dec 2022
    5.4
    Medium

    CVE-2022-4839

    Last Modified: 9 Apr 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

    Published: 29 Dec 2022
    8.8
    High

    CVE-2022-4844

    Last Modified: 9 Apr 2025

    Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

    Published: 29 Dec 2022
    4.3
    Medium

    CVE-2022-4845

    Last Modified: 10 Apr 2025

    Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

    Published: 29 Dec 2022
    6.5
    Medium

    CVE-2022-4846

    Last Modified: 10 Apr 2025

    Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

    Published: 29 Dec 2022
    6.5
    Medium

    CVE-2022-4847

    Last Modified: 9 Apr 2025

    Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

    Published: 29 Dec 2022
    6.5
    Medium

    CVE-2022-4849

    Last Modified: 9 Apr 2025

    Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

    Published: 29 Dec 2022
    —
    Unknown

    CVE-2022-4852

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 29 Dec 2022
    —
    Unknown

    CVE-2022-4853

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 29 Dec 2022
    6.1
    Medium

    CVE-2022-30519

    Last Modified: 30 Apr 2025

    XSS in signing form in Reprise Software RLM License Administration v14.2BL4 allows remote attacker to inject arbitrary code via password field.

    Published: 29 Dec 2022
    —
    Unknown

    CVE-2023-22498

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 29 Dec 2022
    3.1
    Low

    CVE-2022-4823

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, was found in InSTEDD Nuntium. Affected is an unknown function of the file app/controllers/geopoll_controller.rb. The manipulation of the argument signature leads to observable timing discrepancy. It is possible to launch the attack remotely. The name of the patch is 77236f7fd71a0e2eefeea07f9866b069d612cf0d. It is recommended to apply a patch to fix this issue. VDB-217002 is the identifier assigned to this vulnerability.

    Published: 28 Dec 2022
    2.4
    Low

    CVE-2022-4822

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, has been found in FlatPress. This issue affects some unknown processing of the file setup/lib/main.lib.php of the component Setup. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 5f23b4c2eac294cc0ba5e541f83a6f8a26f9fed1. It is recommended to apply a patch to fix this issue. The identifier VDB-217001 was assigned to this vulnerability.

    Published: 28 Dec 2022
    2.4
    Low

    CVE-2022-4821

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic was found in FlatPress. This vulnerability affects the function onupload of the file admin/panels/uploader/admin.uploader.php of the component XML File Handler/MD File Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The name of the patch is 3cc223dec5260e533a84b5cf5780d3a4fbf21241. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217000.

    Published: 28 Dec 2022
    3.5
    Low

    CVE-2022-4820

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in FlatPress. This affects an unknown part of the file admin/panels/entry/admin.entry.list.php of the component Admin Area. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The name of the patch is 229752b51025e678370298284d42f8ebb231f67f. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216999.

    Published: 28 Dec 2022
    2.4
    Low

    CVE-2022-4819

    Last Modified: 21 Nov 2024

    A vulnerability was found in HotCRP. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The attack may be launched remotely. The name of the patch is d4ffdb0ef806453c54ddca7fdda3e5c60356285c. It is recommended to apply a patch to fix this issue. VDB-216998 is the identifier assigned to this vulnerability.

    Published: 28 Dec 2022
    5.5
    Medium

    CVE-2022-4818

    Last Modified: 9 Apr 2025

    A vulnerability was found in Talend Open Studio for MDM. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file org.talend.mdm.core/src/com/amalto/core/storage/SystemStorageWrapper.java. The manipulation leads to xml external entity reference. Upgrading to version 20221220_1938 is able to address this issue. The name of the patch is 95590db2ad6a582c371273ceab1a73ad6ed47853. It is recommended to upgrade the affected component. The identifier VDB-216997 was assigned to this vulnerability.

    Published: 28 Dec 2022
    5.5
    Medium

    CVE-2018-25057

    Last Modified: 21 Nov 2024

    A vulnerability was found in simple_php_link_shortener. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument $link["id"] leads to sql injection. The name of the patch is b26ac6480761635ed94ccb0222ba6b732de6e53f. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216996.

    Published: 28 Dec 2022
    5.5
    Medium

    CVE-2017-20150

    Last Modified: 21 Nov 2024

    A vulnerability was found in challenge website. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to sql injection. The name of the patch is f1644b1d3502e5aa5284f31ea80d2623817f4d42. It is recommended to apply a patch to fix this issue. The identifier VDB-216989 was assigned to this vulnerability.

    Published: 28 Dec 2022
    3.1
    Low

    CVE-2022-4817

    Last Modified: 10 Apr 2025

    A vulnerability was found in centic9 jgit-cookbook. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to insecure temporary file. The attack can be initiated remotely. The name of the patch is b8cb29b43dc704708d598c60ac1881db7cf8e9c3. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216988.

    Published: 28 Dec 2022
    6.5
    Medium

    CVE-2022-23554

    Last Modified: 10 Apr 2025

    Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows Authentication Filter bypass. The AuthenticationFilter relies on the request URI to evaluate if the user is accessing the swagger endpoint. By accessing a URL with a path such as /api/foo;%2fapi%2fswagger the contains condition will hold and will return from the authentication filter without aborting the request. Note that the principal object will not be assigned and therefore the issue wont allow user impersonation. This issue has been fixed in version 1.10.4. There are no known workarounds.

    Published: 28 Dec 2022
    7.5
    High

    CVE-2022-23553

    Last Modified: 10 Apr 2025

    Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows URL access filter bypass. This issue has been fixed in version 1.10.4. There are no known workarounds.

    Published: 28 Dec 2022
    4.5
    Medium

    CVE-2022-4780

    Last Modified: 10 Apr 2025

    ISOS firmwares from versions 1.81 to 2.00 contain hardcoded credentials from embedded StreamX installer that integrators are not forced to change.

    Published: 28 Dec 2022
    7.5
    High

    CVE-2022-4779

    Last Modified: 10 Apr 2025

    StreamX applications from versions 6.02.01 to 6.04.34 are affected by a logic bug that allows to bypass the implemented authentication scheme. StreamX applications using StreamView HTML component with the public web server feature activated are affected.

    Published: 28 Dec 2022
    6.5
    Medium

    CVE-2022-4778

    Last Modified: 9 Apr 2025

    StreamX applications from versions 6.02.01 to 6.04.34 are affected by a path traversal vulnerability that allows authenticated users to get unauthorized access to files on the server's filesystem. StreamX applications using StreamView HTML component with the public web server feature activated are affected.

    Published: 28 Dec 2022
    3.5
    Low

    CVE-2018-25056

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, was found in yolapi. Affected is the function render_description of the file yolapi/pypi/metadata.py. The manipulation of the argument text leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is a0fe129055a99f429133a5c40cb13b44611ff796. It is recommended to apply a patch to fix this issue. VDB-216966 is the identifier assigned to this vulnerability.

    Published: 28 Dec 2022
    3.5
    Low

    CVE-2018-25055

    Last Modified: 21 Nov 2024

    A vulnerability was found in FarCry Solr Pro Plugin up to 1.5.x. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file packages/forms/solrProSearch.cfc of the component Search Handler. The manipulation of the argument suggestion leads to cross site scripting. The attack can be launched remotely. Upgrading to version 1.6.0 is able to address this issue. The name of the patch is b8f3d61511c9b02b781ec442bfb803cbff8e08d5. It is recommended to upgrade the affected component. The identifier VDB-216961 was assigned to this vulnerability.

    Published: 28 Dec 2022
    3.5
    Low

    CVE-2018-25054

    Last Modified: 21 Nov 2024

    A vulnerability was found in shred cilla. It has been classified as problematic. Affected is an unknown function of the file cilla-xample/src/main/webapp/WEB-INF/jsp/view/search.jsp of the component Search Handler. The manipulation of the argument details leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is d345e6bc7798bd717a583ec7f545ca387819d5c7. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216960.

    Published: 28 Dec 2022
    4.3
    Medium

    CVE-2018-25053

    Last Modified: 21 Nov 2024

    A vulnerability was found in moappi Json2html up to 1.1.x and classified as problematic. This issue affects some unknown processing of the file json2html.js. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 1.2.0 is able to address this issue. The name of the patch is 2d3d24d971b19a8ed1fb823596300b9835d55801. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216959.

    Published: 28 Dec 2022
    3.5
    Low

    CVE-2018-25052

    Last Modified: 21 Nov 2024

    A vulnerability has been found in Catalyst-Plugin-Session up to 0.40 and classified as problematic. This vulnerability affects the function _load_sessionid of the file lib/Catalyst/Plugin/Session.pm of the component Session ID Handler. The manipulation of the argument sid leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 0.41 is able to address this issue. The name of the patch is 88d1b599e1163761c9bd53bec53ba078f13e09d4. It is recommended to upgrade the affected component. VDB-216958 is the identifier assigned to this vulnerability.

    Published: 28 Dec 2022
    2.4
    Low

    CVE-2018-25051

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, was found in JmPotato Pomash. This affects an unknown part of the file Pomash/theme/clean/templates/editor.html. The manipulation of the argument article.title/content.title/article.tag leads to cross site scripting. It is possible to initiate the attack remotely. The name of the patch is be1914ef0a6808e00f51618b2de92496a3604415. It is recommended to apply a patch to fix this issue. The identifier VDB-216957 was assigned to this vulnerability.

    Published: 28 Dec 2022
    4.8
    Medium

    CVE-2022-3922

    Last Modified: 10 Apr 2025

    The Broken Link Checker WordPress plugin before 1.11.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 28 Dec 2022
    3.5
    Low

    CVE-2018-25050

    Last Modified: 10 Apr 2025

    A vulnerability, which was classified as problematic, has been found in Harvest Chosen up to 1.8.6. Affected by this issue is the function AbstractChosen of the file coffee/lib/abstract-chosen.coffee. The manipulation of the argument group_label leads to cross site scripting. The attack may be launched remotely. Upgrading to version 1.8.7 is able to address this issue. The name of the patch is 77fd031d541e77510268d1041ed37798fdd1017e. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216956.

    Published: 28 Dec 2022
    2.4
    Low

    CVE-2019-25092

    Last Modified: 11 Apr 2025

    A vulnerability classified as problematic was found in Nakiami Mellivora up to 2.1.x. Affected by this vulnerability is the function print_user_ip_log of the file include/layout/user.inc.php of the component Admin Panel. The manipulation of the argument $entry['ip'] leads to cross site scripting. The attack can be launched remotely. Upgrading to version 2.2.0 is able to address this issue. The name of the patch is e0b6965f8dde608a3d2621617c05695eb406cbb9. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216955.

    Published: 28 Dec 2022
    3.5
    Low

    CVE-2021-4293

    Last Modified: 21 Nov 2024

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in gnuboard youngcart5 up to 5.4.5.1. Affected is an unknown function of the file adm/menu_list_update.php. The manipulation of the argument me_link leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 5.4.5.2 is able to address this issue. The name of the patch is 70daa537adfa47b87af12d85f1e698fff01785ff. It is recommended to upgrade the affected component. VDB-216954 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 28 Dec 2022
    9.2
    Critical

    CVE-2022-46179

    Last Modified: 14 Apr 2025

    LiuOS is a small Python project meant to imitate the functions of a regular operating system. Version 0.1.0 and prior of LiuOS allow an attacker to set the GITHUB_ACTIONS environment variable to anything other than null or true and skip authentication checks. This issue is patched in the latest commit (c658b4f3e57258acf5f6207a90c2f2169698ae22) by requiring the var to be set to true, causing a test script to run instead of being able to login. A potential workaround is to check for the GITHUB_ACTIONS environment variable and set it to "" (no quotes) to null the variable and force credential checks.

    Published: 28 Dec 2022
    7.2
    High

    CVE-2022-46173

    Last Modified: 11 Apr 2025

    Elrond-GO is a go implementation for the Elrond Network protocol. Versions prior to 1.3.50 are subject to a processing issue where nodes are affected when trying to process a cross-shard relayed transaction with a smart contract deploy transaction data. The problem was a bad correlation between the transaction caches and the processing component. If the above-mentioned transaction was sent with more gas than required, the smart contract result (SCR transaction) that should have returned the leftover gas, would have been wrongly added to a cache that the processing unit did not consider. The node stopped notarizing metachain blocks. The fix was actually to extend the SCR transaction search in all other caches if it wasn't found in the correct (expected) sharded-cache. There are no known workarounds at this time. This issue has been patched in version 1.3.50.

    Published: 28 Dec 2022
    6.4
    Medium

    CVE-2022-46172

    Last Modified: 11 Apr 2025

    authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, and 2022.11.4, any authenticated user can create an arbitrary number of accounts through the default flows. This would circumvent any policy in a situation where it is undesirable for users to create new accounts by themselves. This may also affect other applications as these new basic accounts would exist throughout the SSO infrastructure. By default the newly created accounts cannot be logged into as no password reset exists by default. However password resets are likely to be enabled by most installations. This vulnerability pertains to the user context used in the default-user-settings-flow, /api/v3/flows/instances/default-user-settings-flow/execute/. This issue has been fixed in versions 2022.10.4 and 2022.11.4.

    Published: 28 Dec 2022
    9.4
    Critical

    CVE-2022-23555

    Last Modified: 11 Apr 2025

    authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 2022.10.4 are vulnerable to Improper Authentication. Token reuse in invitation URLs leads to access control bypass via the use of a different enrollment flow than in the one provided. The vulnerability allows an attacker that knows different invitation flows names (e.g. `enrollment-invitation-test` and `enrollment-invitation-admin`) via either different invite links or via brute forcing to signup via a single invitation url for any valid invite link received (it can even be a url for a third flow as long as it's a valid invite) as the token used in the `Invitations` section of the Admin interface does NOT change when a different `enrollment flow` is selected via the interface and it is NOT bound to the selected flow, so it will be valid for any flow when used. This issue is patched in authentik 2022.11.4,2022.10.4 and 2022.12.0. Only configurations that use invitations and have multiple enrollment flows with invitation stages that grant different permissions are affected. The default configuration is not vulnerable, and neither are configurations with a single enrollment flow. As a workaround, fixed data can be added to invitations which can be checked in the flow to deny requests. Alternatively, an identifier with high entropy (like a UUID) can be used as flow slug, mitigating the attack vector by exponentially decreasing the possibility of discovering other flows.

    Published: 28 Dec 2022
    4.2
    Medium

    CVE-2022-46174

    Last Modified: 11 Apr 2025

    efs-utils is a set of Utilities for Amazon Elastic File System (EFS). A potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. This issue is patched in version v1.34.4. There is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4 or later.

    Published: 28 Dec 2022
    5.4
    Medium

    CVE-2022-4802

    Last Modified: 10 Apr 2025

    Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

    Published: 28 Dec 2022
    6.5
    Medium

    CVE-2022-4812

    Last Modified: 10 Apr 2025

    Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

    Published: 28 Dec 2022
    4.3
    Medium

    CVE-2022-4813

    Last Modified: 10 Apr 2025

    Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.

    Published: 28 Dec 2022