CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2022-4814

    Last Modified: 10 Apr 2025

    Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

    Published: 28 Dec 2022
    5.3
    Medium

    CVE-2022-4801

    Last Modified: 10 Apr 2025

    Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.

    Published: 28 Dec 2022
    8.8
    High

    CVE-2022-4803

    Last Modified: 10 Apr 2025

    Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

    Published: 28 Dec 2022
    5.3
    Medium

    CVE-2022-4804

    Last Modified: 10 Apr 2025

    Improper Authorization in GitHub repository usememos/memos prior to 0.9.1.

    Published: 28 Dec 2022
    5.3
    Medium

    CVE-2022-4806

    Last Modified: 10 Apr 2025

    Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

    Published: 28 Dec 2022
    8.8
    High

    CVE-2022-4809

    Last Modified: 10 Apr 2025

    Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

    Published: 28 Dec 2022
    4.3
    Medium

    CVE-2022-4810

    Last Modified: 10 Apr 2025

    Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

    Published: 28 Dec 2022
    8.3
    High

    CVE-2022-4811

    Last Modified: 10 Apr 2025

    Authorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/memos before 0.9.1.

    Published: 28 Dec 2022
    7.8
    High

    CVE-2022-44564

    Last Modified: 11 Apr 2025

    Huawei Aslan Children's Watch has a path traversal vulnerability. Successful exploitation may allow attackers to access or modify protected system resources.

    Published: 28 Dec 2022
    5.3
    Medium

    CVE-2022-4798

    Last Modified: 10 Apr 2025

    Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

    Published: 28 Dec 2022
    6.5
    Medium

    CVE-2022-4800

    Last Modified: 10 Apr 2025

    Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

    Published: 28 Dec 2022
    4.3
    Medium

    CVE-2022-4805

    Last Modified: 10 Apr 2025

    Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1.

    Published: 28 Dec 2022
    8.8
    High

    CVE-2022-4808

    Last Modified: 10 Apr 2025

    Improper Privilege Management in GitHub repository usememos/memos prior to 0.9.1.

    Published: 28 Dec 2022
    7.5
    High

    CVE-2022-39012

    Last Modified: 11 Apr 2025

    Huawei Aslan Children's Watch has an improper input validation vulnerability. Successful exploitation may cause the watch's application service abnormal.

    Published: 28 Dec 2022
    6.5
    Medium

    CVE-2022-41579

    Last Modified: 11 Apr 2025

    There is an insufficient authentication vulnerability in some Huawei band products. Successful exploit could allow the attacker to spoof then connect to the band.

    Published: 28 Dec 2022
    2.6
    Low

    CVE-2021-4294

    Last Modified: 21 Nov 2024

    A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is 8612686d6dda34ae9ef6b5a974e4b7accb4fea29. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216987.

    Published: 28 Dec 2022
    5.5
    Medium

    CVE-2022-45874

    Last Modified: 11 Apr 2025

    Huawei Aslan Children's Watch has an improper authorization vulnerability. Successful exploit could allow the attacker to access certain file.

    Published: 28 Dec 2022
    6.5
    Medium

    CVE-2022-46740

    Last Modified: 11 Apr 2025

    There is a denial of service vulnerability in the Wi-Fi module of the HUAWEI WS7100-20 Smart WiFi Router.Successful exploit could cause a denial of service (DoS) condition.

    Published: 28 Dec 2022
    8.1
    High

    CVE-2022-4796

    Last Modified: 10 Apr 2025

    Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1.

    Published: 28 Dec 2022
    4.3
    Medium

    CVE-2022-4797

    Last Modified: 10 Apr 2025

    Improper Restriction of Excessive Authentication Attempts in GitHub repository usememos/memos prior to 0.9.1.

    Published: 28 Dec 2022
    6.5
    Medium

    CVE-2022-4799

    Last Modified: 10 Apr 2025

    Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

    Published: 28 Dec 2022
    4.3
    Medium

    CVE-2022-4807

    Last Modified: 10 Apr 2025

    Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

    Published: 28 Dec 2022
    —
    Unknown

    CVE-2023-22369

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-25011. Reason: This candidate is a duplicate of CVE-2023-25011. Notes: All CVE users should reference CVE-2023-25011 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 28 Dec 2022
    7.5
    High

    CVE-2022-38202

    Last Modified: 10 Apr 2025

    There is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and below. Successful exploitation may allow a remote, unauthenticated attacker traverse the file system to access files outside of the intended directory on ArcGIS Server. This could lead to the disclosure of sensitive site configuration information (not user datasets).

    Published: 28 Dec 2022
    7.2
    High

    CVE-2022-23544

    Last Modified: 11 Apr 2025

    MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions prior to 2.5.0 are subject to a Server-Side Request Forgery that leads to Cross-Site Scripting. A Server-Side request forgery in `IssueProxyResourceService::getMdImageByUrl` allows an attacker to access internal resources, as well as executing JavaScript code in the context of Metersphere's origin by a victim of a reflected XSS. This vulnerability has been fixed in v2.5.0. There are no known workarounds.

    Published: 27 Dec 2022
    7
    High

    CVE-2022-41967

    Last Modified: 14 Apr 2025

    Dragonfly is a Java runtime dependency management library. Dragonfly v0.3.0-SNAPSHOT does not configure DocumentBuilderFactory to prevent XML external entity (XXE) attacks. This issue is patched in 0.3.1-SNAPSHOT. As a workaround, since Dragonfly only parses XML `SNAPSHOT` versions are being resolved, this vulnerability may be avoided by not trying to resolve `SNAPSHOT` versions.

    Published: 27 Dec 2022
    8.2
    High

    CVE-2022-41966

    Last Modified: 23 May 2025

    XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack overflow error, resulting in a denial of service only via manipulation the processed input stream. The attack uses the hash code implementation for collections and maps to force recursive hash calculation causing a stack overflow. This issue is patched in version 1.4.20 which handles the stack overflow and raises an InputManipulationException instead. A potential workaround for users who only use HashMap or HashSet and whose XML refers these only as default map or set, is to change the default implementation of java.util.Map and java.util per the code example in the referenced advisory. However, this implies that your application does not care about the implementation of the map and all elements are comparable.

    Published: 27 Dec 2022
    2.5
    Low

    CVE-2022-4773

    Last Modified: 21 Nov 2024

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in cloudsync. Affected by this vulnerability is the function getItem of the file src/main/java/cloudsync/connector/LocalFilesystemConnector.java. The manipulation leads to path traversal. It is possible to launch the attack on the local host. The name of the patch is 3ad796833398af257c28e0ebeade68518e0e612a. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216919. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 27 Dec 2022
    3.5
    Low

    CVE-2020-36636

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in OpenMRS Admin UI Module up to 1.4.x. Affected is the function sendErrorMessage of the file omod/src/main/java/org/openmrs/module/adminui/page/controller/systemadmin/accounts/AccountPageController.java of the component Account Setup Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.5.0 is able to address this issue. The name of the patch is 702fbfdac7c4418f23bb5f6452482b4a88020061. It is recommended to upgrade the affected component. VDB-216918 is the identifier assigned to this vulnerability.

    Published: 27 Dec 2022
    3.5
    Low

    CVE-2021-4292

    Last Modified: 21 Nov 2024

    A vulnerability was found in OpenMRS Admin UI Module up to 1.4.x. It has been rated as problematic. This issue affects some unknown processing of the file omod/src/main/webapp/pages/metadata/privileges/privilege.gsp of the component Manage Privilege Page. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 1.5.0 is able to address this issue. The name of the patch is 4f8565425b7c74128dec9ca46dfbb9a3c1c24911. It is recommended to upgrade the affected component. The identifier VDB-216917 was assigned to this vulnerability.

    Published: 27 Dec 2022
    3.5
    Low

    CVE-2021-4291

    Last Modified: 21 Nov 2024

    A vulnerability was found in OpenMRS Admin UI Module up to 1.5.x. It has been declared as problematic. This vulnerability affects unknown code of the file omod/src/main/webapp/pages/metadata/locations/location.gsp. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.6.0 is able to address this issue. The name of the patch is a7eefb5f69f6c50a3bffcb138bb8ea57cb41a9b6. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216916.

    Published: 27 Dec 2022
    3.5
    Low

    CVE-2020-36635

    Last Modified: 11 Apr 2025

    A vulnerability was found in OpenMRS Appointment Scheduling Module up to 1.12.x. It has been classified as problematic. This affects the function validateFieldName of the file api/src/main/java/org/openmrs/module/appointmentscheduling/validator/AppointmentTypeValidator.java. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.13.0 is able to address this issue. The name of the patch is 34213c3f6ea22df427573076fb62744694f601d8. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216915.

    Published: 27 Dec 2022
    4.5
    Medium

    CVE-2022-4772

    Last Modified: 21 Nov 2024

    A vulnerability was found in Widoco and classified as critical. Affected by this issue is the function unZipIt of the file src/main/java/widoco/WidocoUtils.java. The manipulation leads to path traversal. It is possible to launch the attack on the local host. The name of the patch is f2279b76827f32190adfa9bd5229b7d5a147fa92. It is recommended to apply a patch to fix this issue. VDB-216914 is the identifier assigned to this vulnerability.

    Published: 27 Dec 2022
    3.7
    Low

    CVE-2019-25091

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in nsupdate.info. This affects an unknown part of the file src/nsupdate/settings/base.py of the component CSRF Cookie Handler. The manipulation of the argument CSRF_COOKIE_HTTPONLY leads to cookie without 'httponly' flag. It is possible to initiate the attack remotely. The name of the patch is 60a3fe559c453bc36b0ec3e5dd39c1303640a59a. It is recommended to apply a patch to fix this issue. The identifier VDB-216909 was assigned to this vulnerability.

    Published: 27 Dec 2022
    5.5
    Medium

    CVE-2021-4290

    Last Modified: 14 Apr 2025

    A vulnerability was found in DHBW Fallstudie. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file app/config/passport.js of the component Login. The manipulation of the argument id/email leads to sql injection. The name of the patch is 5c13c6a972ef4c07c5f35b417916e0598af9e123. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216907.

    Published: 27 Dec 2022
    6.3
    Medium

    CVE-2022-4768

    Last Modified: 21 Nov 2024

    A vulnerability was found in Dropbox merou. It has been classified as critical. Affected is the function add_public_key of the file grouper/public_key.py of the component SSH Public Key Handler. The manipulation of the argument public_key_str leads to injection. It is possible to launch the attack remotely. The name of the patch is d93087973afa26bc0a2d0a5eb5c0fde748bdd107. It is recommended to apply a patch to fix this issue. VDB-216906 is the identifier assigned to this vulnerability.

    Published: 27 Dec 2022
    7.5
    High

    CVE-2022-3347

    Last Modified: 14 Apr 2025

    DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. Root DNSSEC public keys are not validated, permitting an attacker to present a self-signed root key and delegation chain.

    Published: 27 Dec 2022
    6.5
    Medium

    CVE-2022-3346

    Last Modified: 14 Apr 2025

    DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. The owner name of RRSIG RRs is not validated, permitting an attacker to present the RRSIG for an attacker-controlled domain in a response for any other domain.

    Published: 27 Dec 2022
    7.5
    High

    CVE-2021-4239

    Last Modified: 14 Apr 2025

    The Noise protocol implementation suffers from weakened cryptographic security after encrypting 2^64 messages, and a potential denial of service attack. After 2^64 (~18.4 quintillion) messages are encrypted with the Encrypt function, the nonce counter will wrap around, causing multiple messages to be encrypted with the same key and nonce. In a separate issue, the Decrypt function increments the nonce state even when it fails to decrypt a message. If an attacker can provide an invalid input to the Decrypt function, this will cause the nonce state to desynchronize between the peers, resulting in a failure to encrypt all subsequent messages.

    Published: 27 Dec 2022
    7.5
    High

    CVE-2022-2584

    Last Modified: 11 Apr 2025

    The dag-pb codec can panic when decoding invalid blocks.

    Published: 27 Dec 2022
    3.7
    Low

    CVE-2022-2583

    Last Modified: 11 Apr 2025

    A race condition can cause incorrect HTTP request routing.

    Published: 27 Dec 2022
    4.3
    Medium

    CVE-2022-2582

    Last Modified: 11 Apr 2025

    The AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field. This hash can be used to brute force the plaintext, if the hash is readable to the attacker. AWS now blocks this metadata field, but older SDK versions still send it.

    Published: 27 Dec 2022
    9.8
    Critical

    CVE-2021-4236

    Last Modified: 11 Apr 2025

    Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the returned UserData pointer is assumed to be non-nil, or authentication bypass. This issue only affects WebSockets with an AuthenticateMethod hook. Request handlers that do not explicitly use WebSockets are not vulnerable.

    Published: 27 Dec 2022
    9.1
    Critical

    CVE-2020-36566

    Last Modified: 11 Apr 2025

    Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.

    Published: 27 Dec 2022
    7.5
    High

    CVE-2020-36564

    Last Modified: 11 Apr 2025

    Due to improper validation of caller input, validation is silently disabled if the provided expected token is malformed, causing any user supplied token to be considered valid.

    Published: 27 Dec 2022
    5.3
    Medium

    CVE-2020-36563

    Last Modified: 11 Apr 2025

    XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions depending on their control over the input.

    Published: 27 Dec 2022
    8.8
    High

    CVE-2016-15005

    Last Modified: 11 Apr 2025

    CSRF tokens are generated using math/rand, which is not a cryptographically secure random number generator, allowing an attacker to predict values and bypass CSRF protections with relatively few requests.

    Published: 27 Dec 2022
    7.5
    High

    CVE-2020-36562

    Last Modified: 11 Apr 2025

    Due to unchecked type assertions, maliciously crafted messages can cause panics, which may be used as a denial of service vector.

    Published: 27 Dec 2022
    7.5
    High

    CVE-2019-25072

    Last Modified: 11 Apr 2025

    Due to support of Gzip compression in request bodies, as well as a lack of limiting response body sizes, a malicious server can cause a client to consume a significant amount of system resources, which may be used as a denial of service vector.

    Published: 27 Dec 2022
    9.1
    Critical

    CVE-2020-36561

    Last Modified: 11 Apr 2025

    Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.

    Published: 27 Dec 2022