CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2022-43860

    Last Modified: 15 Apr 2025

    IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information they are authorized to but not while using this interface. By performing an SQL injection an attacker could see user profile attributes through this interface. IBM X-Force ID: 239305.

    Published: 22 Dec 2022
    6.3
    Medium

    CVE-2022-43859

    Last Modified: 15 Apr 2025

    IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information for an object they are authorized to but not while using this interface. By performing a UNION based SQL injection an attacker could see file permissions through this interface. IBM X-Force ID: 239304.

    Published: 22 Dec 2022
    4.3
    Medium

    CVE-2022-43858

    Last Modified: 15 Apr 2025

    IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to access the file system and download files they are authorized to but not while using this interface. The remote authenticated user can bypass the interface checks by modifying a parameter thereby gaining access to their files through this interface. IBM X-Force ID: 239303.

    Published: 22 Dec 2022
    5.4
    Medium

    CVE-2022-3794

    Last Modified: 8 Apr 2026

    The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various AJAX actions in versions up to, and including, 2.5.6. Authenticated users can use an easily available nonce value to create header templates and make additional changes to the site, as the plugin does not use capability checks for this purpose.

    Published: 22 Dec 2022
    8.6
    High

    CVE-2022-3805

    Last Modified: 8 Apr 2026

    The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the plugin settings in versions up to, and including, 2.5.6. Unauthenticated users can use an easily available nonce, obtained from pages edited by the plugin, to update the MailChimp API key, global styles, 404 page settings, and enabled elements.

    Published: 22 Dec 2022
    4.3
    Medium

    CVE-2022-43857

    Last Modified: 15 Apr 2025

    IBM Navigator for i 7.3, 7.4 and 7.5 could allow an authenticated user to access IBM Navigator for i log files they are authorized to but not while using this interface. The remote authenticated user can bypass the interface checks and download log files by modifying servlet filter. IBM X-Force ID: 239301.

    Published: 22 Dec 2022
    5.9
    Medium

    CVE-2022-22461

    Last Modified: 15 Apr 2025

    IBM Security Verify Governance, Identity Manager 10.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225007.

    Published: 22 Dec 2022
    5.9
    Medium

    CVE-2022-35646

    Last Modified: 15 Apr 2025

    IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify or cancel any other user's access request using man-in-the-middle techniques. IBM X-Force ID: 231096.  

    Published: 22 Dec 2022
    8.6
    High

    CVE-2022-46170

    Last Modified: 15 Apr 2025

    CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin pages) and (2) a session handler is set to `DatabaseHandler`, `MemcachedHandler`, or `RedisHandler`, then if an attacker gets one session cookie (e.g., one for user pages), they may be able to access pages that require another session cookie (e.g., for admin pages). This issue has been patched, please upgrade to version 4.2.11 or later. As a workaround, use only one session cookie.

    Published: 22 Dec 2022
    7.7
    High

    CVE-2022-38658

    Last Modified: 15 Apr 2025

    BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix operator's sensitive data in clear text. Operators who use Notification Service related content from BES Support are at risk of leaving their SMTP sensitive data exposed.

    Published: 22 Dec 2022
    7
    High

    CVE-2022-23556

    Last Modified: 15 Apr 2025

    CodeIgniter is a PHP full-stack web framework. This vulnerability may allow attackers to spoof their IP address when the server is behind a reverse proxy. This issue has been patched, please upgrade to version 4.2.11 or later, and configure `Config\App::$proxyIPs`. As a workaround, do not use `$request->getIPAddress()`.

    Published: 22 Dec 2022
    5.4
    Medium

    CVE-2022-44510

    Last Modified: 23 Apr 2025

    Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

    Published: 22 Dec 2022
    9.8
    Critical

    CVE-2022-45347

    Last Modified: 15 Apr 2025

    Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session completely after client authentication failed, which allowed an attacker to execute normal commands by constructing a special MySQL client. This vulnerability has been fixed in Apache ShardingSphere 5.3.0.

    Published: 22 Dec 2022
    5
    Medium

    CVE-2022-47896

    Last Modified: 15 Apr 2025

    In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.

    Published: 22 Dec 2022
    4.7
    Medium

    CVE-2022-47895

    Last Modified: 15 Apr 2025

    In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.

    Published: 22 Dec 2022
    5.3
    Medium

    CVE-2022-41697

    Last Modified: 14 Apr 2025

    A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send a series of HTTP requests to trigger this vulnerability.

    Published: 22 Dec 2022
    4.3
    Medium

    CVE-2022-41654

    Last Modified: 14 Apr 2025

    An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 22 Dec 2022
    5.3
    Medium

    CVE-2022-25948

    Last Modified: 14 Apr 2025

    The package liquidjs before 10.0.0 are vulnerable to Information Exposure when ownPropertyOnly parameter is set to False, which results in leaking properties of a prototype. Workaround For versions 9.34.0 and higher, an option to disable this functionality is provided.

    Published: 22 Dec 2022
    4.3
    Medium

    CVE-2022-38474

    Last Modified: 19 Aug 2026

    A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once permission has been granted.<br />*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 104.

    Published: 22 Dec 2022
    6.5
    Medium

    CVE-2022-31746

    Last Modified: 19 Aug 2026

    Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Firefox for iOS < 102.

    Published: 22 Dec 2022
    9.8
    Critical

    CVE-2022-31748

    Last Modified: 15 Apr 2025

    Mozilla developers Gabriele Svelto, Timothy Nikkel, Randell Jesup, Jon Coppeard, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 101.

    Published: 22 Dec 2022
    6.1
    Medium

    CVE-2022-34475

    Last Modified: 15 Apr 2025

    SVG <code>&lt;use&gt;</code> tags that referenced a same-origin document could have resulted in script execution if attacker input was sanitized via the HTML Sanitizer API. This would have required the attacker to reference a same-origin JavaScript file containing the script to be executed. This vulnerability affects Firefox < 102.

    Published: 22 Dec 2022
    6.1
    Medium

    CVE-2022-36316

    Last Modified: 15 Apr 2025

    When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL had been subject to a redirect. This vulnerability affects Firefox < 103.

    Published: 22 Dec 2022
    6.5
    Medium

    CVE-2022-40961

    Last Modified: 15 Apr 2025

    During startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially exploitable crash.<br>*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects Firefox < 105.

    Published: 22 Dec 2022
    7.1
    High

    CVE-2022-42930

    Last Modified: 15 Apr 2025

    If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the `ThirdPartyUtil` component. This vulnerability affects Firefox < 106.

    Published: 22 Dec 2022
    5.4
    Medium

    CVE-2022-43271

    Last Modified: 15 Apr 2025

    Inhabit Systems Pty Ltd Move CRM version 4, build 260 was discovered to contain a cross-site scripting (XSS) vulnerability via the User profile component.

    Published: 22 Dec 2022
    6.1
    Medium

    CVE-2022-4644

    Last Modified: 10 Apr 2025

    Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.4.

    Published: 22 Dec 2022
    8.8
    High

    CVE-2022-46871

    Last Modified: 15 Apr 2025

    An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.

    Published: 22 Dec 2022
    4.3
    Medium

    CVE-2022-46877

    Last Modified: 15 Apr 2025

    By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 108.

    Published: 22 Dec 2022
    8.8
    High

    CVE-2022-46883

    Last Modified: 15 Apr 2025

    Mozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 106. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.<br />*Note*: This advisory was added on December 13th, 2022 after discovering it was inadvertently left out of the original advisory. The fix was included in the original release of Firefox 107. This vulnerability affects Firefox < 107.

    Published: 22 Dec 2022
    9.8
    Critical

    CVE-2022-47939

    Last Modified: 14 Apr 2025

    An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c has a use-after-free and OOPS for SMB2_TREE_DISCONNECT.

    Published: 22 Dec 2022
    7.5
    High

    CVE-2022-47941

    Last Modified: 15 Apr 2025

    An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c omits a kfree call in certain smb2_handle_negotiate error conditions, aka a memory leak.

    Published: 22 Dec 2022
    —
    Unknown

    CVE-2022-4659

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 22 Dec 2022
    4.3
    Medium

    CVE-2022-45417

    Last Modified: 15 Apr 2025

    Service Workers did not detect Private Browsing Mode correctly in all cases, which could have led to Service Workers being written to disk for websites visited in Private Browsing Mode. This would not have persisted them in a state where they would run again, but it would have leaked Private Browsing Mode details to disk. This vulnerability affects Firefox < 107.

    Published: 22 Dec 2022
    6.7
    Medium

    CVE-2021-36631

    Last Modified: 16 Apr 2025

    Untrusted search path vulnerability in Baidunetdisk Version 7.4.3 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 22 Dec 2022
    5.4
    Medium

    CVE-2021-43657

    Last Modified: 16 Apr 2025

    A Stored Cross-site scripting (XSS) vulnerability via MAster.php in Sourcecodetester Simple Client Management System (SCMS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the vulnerable input fields.

    Published: 22 Dec 2022
    8.8
    High

    CVE-2022-0511

    Last Modified: 16 Apr 2025

    Mozilla developers and community members Gabriele Svelto, Sebastian Hengst, Randell Jesup, Luan Herrera, Lars T Hansen, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 97.

    Published: 22 Dec 2022
    6.5
    Medium

    CVE-2022-46491

    Last Modified: 15 Apr 2025

    A Cross-Site Request Forgery (CSRF) vulnerability in the Add Administrator function of the default version of nbnbk allows attackers to arbitrarily add Administrator accounts.

    Published: 22 Dec 2022
    9.8
    Critical

    CVE-2022-46493

    Last Modified: 15 Apr 2025

    Default version of nbnbk was discovered to contain an arbitrary file upload vulnerability via the component /api/User/download_img.

    Published: 22 Dec 2022
    8.1
    High

    CVE-2022-47940

    Last Modified: 14 Apr 2025

    An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.18 before 5.18.18. fs/ksmbd/smb2pdu.c lacks length validation in the non-padding case in smb2_write.

    Published: 22 Dec 2022
    7.6
    High

    CVE-2020-15679

    Last Modified: 16 Apr 2025

    An OAuth session fixation vulnerability existed in the VPN login flow, where an attacker could craft a custom login URL, convince a VPN user to login via that URL, and obtain authenticated access as that user. This issue is limited to cases where attacker and victim are sharing the same source IP and could allow the ability to view session states and disconnect VPN sessions. This vulnerability affects Mozilla VPN iOS 1.0.7 < (929), Mozilla VPN Windows < 1.2.2, and Mozilla VPN Android 1.1.0 < (1360).

    Published: 22 Dec 2022
    4.3
    Medium

    CVE-2020-36625

    Last Modified: 21 Nov 2024

    A vulnerability was found in destiny.gg chat. It has been rated as problematic. This issue affects the function websocket.Upgrader of the file main.go. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The name of the patch is bebd256fc3063111fb4503ca25e005ebf6e73780. It is recommended to apply a patch to fix this issue. The identifier VDB-216521 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 22 Dec 2022
    6.5
    Medium

    CVE-2022-26385

    Last Modified: 15 Apr 2025

    In unusual circumstances, an individual thread may outlive the thread's manager during shutdown. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 98.

    Published: 22 Dec 2022
    6.5
    Medium

    CVE-2022-28283

    Last Modified: 16 Apr 2025

    The sourceMapURL feature in devtools was missing security checks that would have allowed a webpage to attempt to include local files or other files that should have been inaccessible. This vulnerability affects Firefox < 99.

    Published: 22 Dec 2022
    8.8
    High

    CVE-2022-28284

    Last Modified: 16 Apr 2025

    SVG's <code>&lt;use&gt;</code> element could have been used to load unexpected content that could have executed script in certain circumstances. While the specification seems to allow this, other browsers do not, and web developers relied on this property for script security so gecko's implementation was aligned with theirs. This vulnerability affects Firefox < 99.

    Published: 22 Dec 2022
    6.1
    Medium

    CVE-2022-29910

    Last Modified: 16 Apr 2025

    When closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.<br>*Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 100.

    Published: 22 Dec 2022
    4.3
    Medium

    CVE-2022-29915

    Last Modified: 15 Apr 2025

    The Performance API did not properly hide the fact whether a request cross-origin resource has observed redirects. This vulnerability affects Firefox < 100.

    Published: 22 Dec 2022
    4.3
    Medium

    CVE-2022-31745

    Last Modified: 15 Apr 2025

    If array shift operations are not used, the Garbage Collector may have become confused about valid objects. This vulnerability affects Firefox < 101.

    Published: 22 Dec 2022
    6.1
    Medium

    CVE-2022-34473

    Last Modified: 15 Apr 2025

    The HTML Sanitizer should have sanitized the <code>href</code> attribute of SVG <code>&lt;use&gt;</code> tags; however it incorrectly did not sanitize <code>xlink:href</code> attributes. This vulnerability affects Firefox < 102.

    Published: 22 Dec 2022
    6.1
    Medium

    CVE-2022-34474

    Last Modified: 15 Apr 2025

    Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an external protocol the browser would process the redirect and prompt the user as appropriate. This vulnerability affects Firefox < 102.

    Published: 22 Dec 2022