CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2022-46171

    Last Modified: 15 Apr 2025

    Tauri is a framework for building binaries for all major desktop platforms. The filesystem glob pattern wildcards `*`, `?`, and `[...]` match file path literals and leading dots by default, which unintentionally exposes sub folder content of allowed paths. Scopes without the wildcards are not affected. As `**` allows for sub directories the behavior there is also as expected. The issue has been patched in the latest release and was backported into the currently supported 1.x branches. There are no known workarounds at the time of publication.

    Published: 23 Dec 2022
    —
    Unknown

    CVE-2022-46419

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 23 Dec 2022
    —
    Unknown

    CVE-2022-45878

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 23 Dec 2022
    —
    Unknown

    CVE-2022-42702

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 23 Dec 2022
    —
    Unknown

    CVE-2022-45120

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 23 Dec 2022
    —
    Unknown

    CVE-2022-46735

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 23 Dec 2022
    —
    Unknown

    CVE-2022-46734

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 23 Dec 2022
    —
    Unknown

    CVE-2022-46739

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 23 Dec 2022
    —
    Unknown

    CVE-2022-43659

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 23 Dec 2022
    —
    Unknown

    CVE-2022-43444

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 23 Dec 2022
    —
    Unknown

    CVE-2022-47914

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 23 Dec 2022
    7.5
    High

    CVE-2022-33324

    Last Modified: 21 Nov 2024

    Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series R00/01/02CPU Firmware versions "32" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120(EN)CPU Firmware versions "65" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R08/16/32/120SFCPU Firmware versions "29" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R08/16/32/120PSFCPU Firmware versions "08" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R12CCPU-V Firmware versions "17" and prior, Mitsubishi Electric Corporation MELSEC iQ-L Series L04/08/16/32HCPU Firmware versions "05" and prior and Mitsubishi Electric Corporation MELIPC Series MI5122-VW Firmware versions "07" and prior allows a remote unauthenticated attacker to cause a Denial of Service condition in Ethernet communication on the module by sending specially crafted packets. A system reset of the module is required for recovery.

    Published: 23 Dec 2022
    6.1
    Medium

    CVE-2022-40011

    Last Modified: 23 Feb 2026

    Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then used at a victim's origin.

    Published: 23 Dec 2022
    7.2
    High

    CVE-2022-46560

    Last Modified: 15 Apr 2025

    D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetWan2Settings module.

    Published: 23 Dec 2022
    7.2
    High

    CVE-2022-46561

    Last Modified: 15 Apr 2025

    D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetWanSettings module.

    Published: 23 Dec 2022
    7.2
    High

    CVE-2022-46566

    Last Modified: 15 Apr 2025

    D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetQuickVPNSettings module.

    Published: 23 Dec 2022
    7.2
    High

    CVE-2022-46570

    Last Modified: 15 Apr 2025

    D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetWan3Settings module.

    Published: 23 Dec 2022
    8.8
    High

    CVE-2022-4684

    Last Modified: 9 Apr 2025

    Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.

    Published: 23 Dec 2022
    7.2
    High

    CVE-2022-4722

    Last Modified: 9 Apr 2025

    Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.

    Published: 23 Dec 2022
    9.8
    Critical

    CVE-2022-4686

    Last Modified: 9 Apr 2025

    Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0.

    Published: 23 Dec 2022
    8.8
    High

    CVE-2022-4688

    Last Modified: 9 Apr 2025

    Improper Authorization in GitHub repository usememos/memos prior to 0.9.0.

    Published: 23 Dec 2022
    6.5
    Medium

    CVE-2022-4723

    Last Modified: 9 Apr 2025

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.5.

    Published: 23 Dec 2022
    9.8
    Critical

    CVE-2022-4724

    Last Modified: 9 Apr 2025

    Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5.

    Published: 23 Dec 2022
    7.2
    High

    CVE-2022-46569

    Last Modified: 15 Apr 2025

    D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Key parameter in the SetWLanRadioSecurity module.

    Published: 23 Dec 2022
    9.9
    Critical

    CVE-2022-46641

    Last Modified: 15 Apr 2025

    D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the lan(0)_dhcps_staticlist parameter in the SetIpMacBindSettings function.

    Published: 23 Dec 2022
    9.9
    Critical

    CVE-2022-46642

    Last Modified: 15 Apr 2025

    D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the auto_upgrade_hour parameter in the SetAutoUpgradeInfo function.

    Published: 23 Dec 2022
    6.5
    Medium

    CVE-2022-46492

    Last Modified: 15 Apr 2025

    nbnbk commit 879858451d53261d10f77d4709aee2d01c72c301 was discovered to contain an arbitrary file read vulnerability via the component /api/Index/getFileBinary.

    Published: 23 Dec 2022
    9.8
    Critical

    CVE-2022-45707

    Last Modified: 15 Apr 2025

    IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsHijack function.

    Published: 23 Dec 2022
    9.8
    Critical

    CVE-2022-45708

    Last Modified: 15 Apr 2025

    IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the sPortMapIndex parameter in the formDelPortMapping function.

    Published: 23 Dec 2022
    9.8
    Critical

    CVE-2022-45709

    Last Modified: 15 Apr 2025

    IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple command injection vulnerabilities via the pEnable, pLevel, and pModule parameters in the formSetDebugCfg function.

    Published: 23 Dec 2022
    9.8
    Critical

    CVE-2022-45717

    Last Modified: 15 Apr 2025

    IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function. This vulnerability is exploited via a crafted GET request.

    Published: 23 Dec 2022
    5.4
    Medium

    CVE-2022-4695

    Last Modified: 9 Apr 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.

    Published: 23 Dec 2022
    9.1
    Critical

    CVE-2022-28228

    Last Modified: 15 Apr 2025

    Out-of-bounds read was discovered in YDB server. An attacker could construct a query with insert statement that would allow him to read sensitive information from other memory locations or cause a crash.

    Published: 23 Dec 2022
    7.5
    High

    CVE-2022-28229

    Last Modified: 15 Apr 2025

    The hash functionality in userver before 42059b6319661583b3080cab9b595d4f8ac48128 allows attackers to cause a denial of service via crafted HTTP request, involving collisions.

    Published: 23 Dec 2022
    9.8
    Critical

    CVE-2022-47945

    Last Modified: 15 Apr 2025

    ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by including pearcmd.php.

    Published: 23 Dec 2022
    6.5
    Medium

    CVE-2022-4683

    Last Modified: 9 Apr 2025

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository usememos/memos prior to 0.9.0.

    Published: 23 Dec 2022
    9.8
    Critical

    CVE-2022-44567

    Last Modified: 15 Apr 2025

    A command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternalVideoChatWindow to shell.openExternal(), which may lead to remote code execution (internalVideoChatWindow.ts#L17). To exploit the vulnerability, the internal video chat window must be disabled or a Mac App Store build must be used (internalVideoChatWindow.ts#L14). The vulnerability may be exploited by an XSS attack because the function openInternalVideoChatWindow is exposed in the Rocket.Chat-Desktop-API.

    Published: 23 Dec 2022
    9.8
    Critical

    CVE-2022-45710

    Last Modified: 15 Apr 2025

    IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pEnable, pLevel, and pModule parameters in the formSetDebugCfg function.

    Published: 23 Dec 2022
    9.8
    Critical

    CVE-2022-45720

    Last Modified: 15 Apr 2025

    IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the ip, mac, and remark parameters in the formIPMacBindModify function.

    Published: 23 Dec 2022
    7.2
    High

    CVE-2022-46562

    Last Modified: 15 Apr 2025

    D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the PSK parameter in the SetQuickVPNSettings module.

    Published: 23 Dec 2022
    7.2
    High

    CVE-2022-46563

    Last Modified: 15 Apr 2025

    D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetDynamicDNSSettings module.

    Published: 23 Dec 2022
    7.2
    High

    CVE-2022-46568

    Last Modified: 15 Apr 2025

    D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the AccountPassword parameter in the SetSysEmailSettings module.

    Published: 23 Dec 2022
    8.8
    High

    CVE-2022-4665

    Last Modified: 9 Apr 2025

    Unrestricted Upload of File with Dangerous Type in GitHub repository ampache/ampache prior to 5.5.6.

    Published: 23 Dec 2022
    —
    Unknown

    CVE-2022-4685

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 23 Dec 2022
    8.1
    High

    CVE-2022-4687

    Last Modified: 9 Apr 2025

    Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0.

    Published: 23 Dec 2022
    8.8
    High

    CVE-2022-4689

    Last Modified: 10 Apr 2025

    Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.

    Published: 23 Dec 2022
    5.4
    Medium

    CVE-2022-4690

    Last Modified: 10 Apr 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.

    Published: 23 Dec 2022
    5.4
    Medium

    CVE-2022-4691

    Last Modified: 10 Apr 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.

    Published: 23 Dec 2022
    5.4
    Medium

    CVE-2022-4692

    Last Modified: 9 Apr 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.

    Published: 23 Dec 2022
    5.4
    Medium

    CVE-2022-4694

    Last Modified: 9 Apr 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.

    Published: 23 Dec 2022