CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-4719

    Last Modified: 9 Apr 2025

    Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5.

    Published: 23 Dec 2022
    6.1
    Medium

    CVE-2022-4720

    Last Modified: 9 Apr 2025

    Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.5.

    Published: 23 Dec 2022
    5.4
    Medium

    CVE-2022-4721

    Last Modified: 9 Apr 2025

    Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository ikus060/rdiffweb prior to 2.5.5.

    Published: 23 Dec 2022
    5.4
    Medium

    CVE-2022-47524

    Last Modified: 15 Apr 2025

    F-Secure SAFE Browser 19.1 before 19.2 for Android allows an IDN homograph attack.

    Published: 23 Dec 2022
    8.1
    High

    CVE-2022-47633

    Last Modified: 15 Apr 2025

    An image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a man-in-the-middle attacker) to inject unsigned arbitrary container images into a protected Kubernetes cluster. This is fixed in 1.8.5. This has been fixed in 1.8.5 and mitigations are available for impacted releases.

    Published: 23 Dec 2022
    9.8
    Critical

    CVE-2022-45706

    Last Modified: 15 Apr 2025

    IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the hostname parameter in the formSetNetCheckTools function.

    Published: 23 Dec 2022
    9.8
    Critical

    CVE-2022-45711

    Last Modified: 15 Apr 2025

    IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the hostname parameter in the formSetNetCheckTools function.

    Published: 23 Dec 2022
    9.8
    Critical

    CVE-2022-45712

    Last Modified: 15 Apr 2025

    IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsForward function.

    Published: 23 Dec 2022
    9.8
    Critical

    CVE-2022-45714

    Last Modified: 15 Apr 2025

    IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formQOSRuleDel function.

    Published: 23 Dec 2022
    9.8
    Critical

    CVE-2022-45715

    Last Modified: 15 Apr 2025

    IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pLanPortRange and pWanPortRange parameters in the formSetPortMapping function.

    Published: 23 Dec 2022
    9.8
    Critical

    CVE-2022-45716

    Last Modified: 15 Apr 2025

    IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formIPMacBindDel function.

    Published: 23 Dec 2022
    9.8
    Critical

    CVE-2022-45718

    Last Modified: 15 Apr 2025

    IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formIPMacBindAdd function.

    Published: 23 Dec 2022
    9.8
    Critical

    CVE-2022-45719

    Last Modified: 15 Apr 2025

    IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the gotoUrl parameter in the formPortalAuth function.

    Published: 23 Dec 2022
    9.8
    Critical

    CVE-2022-45721

    Last Modified: 15 Apr 2025

    IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the picName parameter in the formDelWewifiPic function.

    Published: 23 Dec 2022
    7.2
    High

    CVE-2022-38757

    Last Modified: 15 Apr 2025

    A vulnerability has been identified in Micro Focus ZENworks 2020 Update 3a and prior versions. This vulnerability allows administrators with rights to perform actions (e.g., install a bundle) on a set of managed devices, to be able to exercise these rights on managed devices in the ZENworks zone but which are outside the scope of the administrator. This vulnerability does not result in the administrators gaining additional rights on the managed devices, either in the scope or outside the scope of the administrator.

    Published: 23 Dec 2022
    5.3
    Medium

    CVE-2022-44565

    Last Modified: 15 Apr 2025

    An improper access validation vulnerability exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0.0 and airFiber GBE <1.4.1 that allows a malicious actor to retrieve status and usage data from the UISP device.

    Published: 23 Dec 2022
    9.6
    Critical

    CVE-2021-32692

    Last Modified: 15 Apr 2025

    Activity Watch is a free and open-source automated time tracker. Versions prior to 0.11.0 allow an attacker to execute arbitrary commands on any macOS machine with ActivityWatch running. The attacker can exploit this vulnerability by having the user visiting a website with the page title set to a malicious string. An attacker could use another application to accomplish the same, but the web browser is the most likely attack vector. This issue is patched in version 0.11.0. As a workaround, users can run the latest version of aw-watcher-window from source, or manually patch the `printAppTitle.scpt` file.

    Published: 23 Dec 2022
    5.9
    Medium

    CVE-2022-23539

    Last Modified: 15 Apr 2025

    Versions `<=8.5.1` of `jsonwebtoken` library could be misconfigured so that legacy, insecure key types are used for signature verification. For example, DSA keys could be used with the RS256 algorithm. You are affected if you are using an algorithm and a key type other than a combination listed in the GitHub Security Advisory as unaffected. This issue has been fixed, please update to version 9.0.0. This version validates for asymmetric key type and algorithm combinations. Please refer to the above mentioned algorithm / key type combinations for the valid secure configuration. After updating to version 9.0.0, if you still intend to continue with signing or verifying tokens using invalid key type/algorithm value combinations, you’ll need to set the `allowInvalidAsymmetricKeyTypes` option to `true` in the `sign()` and/or `verify()` functions.

    Published: 22 Dec 2022
    5.3
    Medium

    CVE-2022-23513

    Last Modified: 15 Apr 2025

    Pi-Hole is a network-wide ad blocking via your own Linux hardware, AdminLTE is a Pi-hole Dashboard for stats and more. In case of an attack, the threat actor will obtain the ability to perform an unauthorized query for blocked domains on `queryads` endpoint. In the case of application, this vulnerability exists because of a lack of validation in code on a root server path: `/admin/scripts/pi-hole/phpqueryads.php.` Potential threat actor(s) are able to perform an unauthorized query search in blocked domain lists. This could lead to the disclosure for any victims' personal blacklists.

    Published: 22 Dec 2022
    5.9
    Medium

    CVE-2022-43603

    Last Modified: 14 Apr 2025

    A denial of service vulnerability exists in the ZfileOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 22 Dec 2022
    8.1
    High

    CVE-2022-43602

    Last Modified: 14 Apr 2025

    Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to a heap buffer overflow. An attacker can provide malicious input to trigger these vulnerabilities.This vulnerability arises when the `ymax` variable is set to 0xFFFF and `m_spec.format` is `TypeDesc::UINT8`

    Published: 22 Dec 2022
    8.1
    High

    CVE-2022-43601

    Last Modified: 14 Apr 2025

    Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to a heap buffer overflow. An attacker can provide malicious input to trigger these vulnerabilities.This vulnerability arises when the `ymax` variable is set to 0xFFFF and `m_spec.format` is `TypeDesc::UINT16`

    Published: 22 Dec 2022
    8.1
    High

    CVE-2022-43600

    Last Modified: 14 Apr 2025

    Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to a heap buffer overflow. An attacker can provide malicious input to trigger these vulnerabilities.This vulnerability arises when the `xmax` variable is set to 0xFFFF and `m_spec.format` is `TypeDesc::UINT16`

    Published: 22 Dec 2022
    8.1
    High

    CVE-2022-43599

    Last Modified: 14 Apr 2025

    Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to a heap buffer overflow. An attacker can provide malicious input to trigger these vulnerabilities.This vulnerability arises when the `xmax` variable is set to 0xFFFF and `m_spec.format` is `TypeDesc::UINT8`

    Published: 22 Dec 2022
    8.1
    High

    CVE-2022-43598

    Last Modified: 14 Apr 2025

    Multiple memory corruption vulnerabilities exist in the IFFOutput alignment padding functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to arbitrary code execution. An attacker can provide malicious input to trigger these vulnerabilities.This vulnerability arises when the `m_spec.format` is `TypeDesc::UINT16`.

    Published: 22 Dec 2022
    8.1
    High

    CVE-2022-43597

    Last Modified: 15 Apr 2025

    Multiple memory corruption vulnerabilities exist in the IFFOutput alignment padding functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to arbitrary code execution. An attacker can provide malicious input to trigger these vulnerabilities.This vulnerability arises when the `m_spec.format` is `TypeDesc::UINT8`.

    Published: 22 Dec 2022
    5.9
    Medium

    CVE-2022-43596

    Last Modified: 15 Apr 2025

    An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. An attacker can provide malicious input to trigger this vulnerability.

    Published: 22 Dec 2022
    5.9
    Medium

    CVE-2022-43595

    Last Modified: 14 Apr 2025

    Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .fits files.

    Published: 22 Dec 2022
    5.9
    Medium

    CVE-2022-43594

    Last Modified: 13 Feb 2025

    Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .bmp files.

    Published: 22 Dec 2022
    5.9
    Medium

    CVE-2022-43593

    Last Modified: 14 Apr 2025

    A denial of service vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to null pointer dereference. An attacker can provide malicious input to trigger this vulnerability.

    Published: 22 Dec 2022
    5.9
    Medium

    CVE-2022-43592

    Last Modified: 14 Apr 2025

    An information disclosure vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. An attacker can provide malicious input to trigger this vulnerability.

    Published: 22 Dec 2022
    7.5
    High

    CVE-2022-41999

    Last Modified: 14 Apr 2025

    A denial of service vulnerability exists in the DDS native tile reading functionality of OpenImageIO Project OpenImageIO v2.3.19.0 and v2.4.4.2. A specially-crafted .dds can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 22 Dec 2022
    7.5
    High

    CVE-2022-41988

    Last Modified: 14 Apr 2025

    An information disclosure vulnerability exists in the OpenImageIO::decode_iptc_iim() functionality of OpenImageIO Project OpenImageIO v2.3.19.0. A specially-crafted TIFF file can lead to a disclosure of sensitive information. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 22 Dec 2022
    8.1
    High

    CVE-2022-41981

    Last Modified: 14 Apr 2025

    A stack-based buffer overflow vulnerability exists in the TGA file format parser of OpenImageIO v2.3.19.0. A specially-crafted targa file can lead to out of bounds read and write on the process stack, which can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 22 Dec 2022
    3.3
    Low

    CVE-2022-41977

    Last Modified: 14 Apr 2025

    An out of bounds read vulnerability exists in the way OpenImageIO version v2.3.19.0 processes string fields in TIFF image files. A specially-crafted TIFF file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 22 Dec 2022
    9.8
    Critical

    CVE-2022-41838

    Last Modified: 15 Apr 2025

    A code execution vulnerability exists in the DDS scanline parsing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially-crafted .dds can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 22 Dec 2022
    9.8
    Critical

    CVE-2022-41837

    Last Modified: 15 Apr 2025

    An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can lead to stack-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 22 Dec 2022
    9.8
    Critical

    CVE-2022-41794

    Last Modified: 15 Apr 2025

    A heap based buffer overflow vulnerability exists in the PSD thumbnail resource parsing code of OpenImageIO 2.3.19.0. A specially-crafted PSD file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 22 Dec 2022
    5.5
    Medium

    CVE-2022-41684

    Last Modified: 15 Apr 2025

    A heap out of bounds read vulnerability exists in the OpenImageIO master-branch-9aeece7a when parsing the image file directory part of a PSD image file. A specially-crafted .psd file can cause a read of arbitrary memory address which can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 22 Dec 2022
    9.1
    Critical

    CVE-2022-41649

    Last Modified: 15 Apr 2025

    A heap out of bounds read vulnerability exists in the handling of IPTC data while parsing TIFF images in OpenImageIO v2.3.19.0. A specially-crafted TIFF file can cause a read of adjacent heap memory, which can leak sensitive process information. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 22 Dec 2022
    9.8
    Critical

    CVE-2022-41639

    Last Modified: 15 Apr 2025

    A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branch-9aeece7a and v2.3.19.0. A specially-crafted TIFF file can lead to an out of bounds memory corruption, which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 22 Dec 2022
    9.8
    Critical

    CVE-2022-38143

    Last Modified: 13 Feb 2025

    A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images. A specially-crafted bmp file can write to arbitrary out of bounds memory, which can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 22 Dec 2022
    5.3
    Medium

    CVE-2022-36354

    Last Modified: 14 Apr 2025

    A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch-9aeece7a and v2.3.19.0. More specifically, in the way run-length encoded byte spans are handled. A malformed RLA file can lead to an out-of-bounds read of heap metadata which can result in sensitive information leak. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 22 Dec 2022
    7.5
    High

    CVE-2022-22184

    Last Modified: 14 Apr 2025

    An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). If a BGP update message is received over an established BGP session, and that message contains a specific, optional transitive attribute, this session will be torn down with an update message error. This issue cannot propagate beyond an affected system as the processing error occurs as soon as the update is received. This issue is exploitable remotely as the respective attribute will propagate through unaffected systems and intermediate AS (if any). Continuous receipt of a BGP update containing this attribute will create a sustained Denial of Service (DoS) condition. Since this issue only affects 22.3R1, Juniper strongly encourages customers to move to 22.3R1-S1. Juniper SIRT felt that the need to promptly warn customers about this issue affecting the 22.3R1 versions of Junos OS and Junos OS Evolved warranted an Out of Cycle JSA. This issue affects: Juniper Networks Junos OS version 22.3R1. Juniper Networks Junos OS Evolved version 22.3R1-EVO. This issue does not affect: Juniper Networks Junos OS versions prior to 22.3R1. Juniper Networks Junos OS Evolved versions prior to 22.3R1-EVO.

    Published: 22 Dec 2022
    5.3
    Medium

    CVE-2022-22449

    Last Modified: 15 Apr 2025

    IBM Security Verify Governance, Identity Manager 10.01 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 224915.

    Published: 22 Dec 2022
    7.8
    High

    CVE-2022-45798

    Last Modified: 15 Apr 2025

    A link following vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could allow a local attacker to escalate privileges by creating a symbolic link and abusing the service to delete a file. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 22 Dec 2022
    5.3
    Medium

    CVE-2022-22457

    Last Modified: 15 Apr 2025

    IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 225007.

    Published: 22 Dec 2022
    7.5
    High

    CVE-2020-26302

    Last Modified: 14 Apr 2025

    is.js is a general-purpose check library. Versions 0.9.0 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). is.js uses a regex copy-pasted from a gist to validate URLs. Trying to validate a malicious string can cause the regex to loop “forever." This vulnerability was found using a CodeQL query which identifies inefficient regular expressions. is.js has no patch for this issue.

    Published: 22 Dec 2022
    6.3
    Medium

    CVE-2022-22458

    Last Modified: 15 Apr 2025

    IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear text which can be read by a remote authenticated user. IBM X-Force ID: 225009.

    Published: 22 Dec 2022
    4.2
    Medium

    CVE-2022-22456

    Last Modified: 15 Apr 2025

    IBM Security Verify Governance, Identity Manager 10.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 225004.

    Published: 22 Dec 2022