CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2022-4585

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in Opencaching Deutschland oc-server3. This affects an unknown part of the file htdocs/templates2/ocstyle/start.tpl of the component Cookie Handler. The manipulation of the argument usercountryCode leads to cross site scripting. It is possible to initiate the attack remotely. The name of the patch is c720f2777a452186c67ef30db3679dd409556544. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216171.

    Published: 17 Dec 2022
    4.3
    Medium

    CVE-2022-4587

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in Opencaching Deutschland oc-server3. This issue affects some unknown processing of the file htdocs/templates2/ocstyle/login.tpl of the component Login Page. The manipulation of the argument username leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 3296ebd61e7fe49e93b5755d5d7766d6e94a7667. It is recommended to apply a patch to fix this issue. The identifier VDB-216173 was assigned to this vulnerability.

    Published: 17 Dec 2022
    2.4
    Low

    CVE-2022-4588

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, was found in Boston Sleep slice up to 84.1.x. Affected is an unknown function of the component Layout Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 84.2.0 is able to address this issue. The name of the patch is 6523bb17d889e2ab13d767f38afefdb37083f1d0. It is recommended to upgrade the affected component. VDB-216174 is the identifier assigned to this vulnerability.

    Published: 17 Dec 2022
    8.1
    High

    CVE-2022-4567

    Last Modified: 14 Apr 2025

    Improper Access Control in GitHub repository openemr/openemr prior to 7.0.0.2.

    Published: 17 Dec 2022
    —
    Unknown

    CVE-2022-4579

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 17 Dec 2022
    3.5
    Low

    CVE-2022-4586

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic was found in Opencaching Deutschland oc-server3. This vulnerability affects unknown code of the file htdocs/templates2/ocstyle/cachelists.tpl of the component Cachelist Handler. The manipulation of the argument name_filter/by_filter leads to cross site scripting. The attack can be initiated remotely. The name of the patch is a9f79c7da78cd24a7ef1d298e6bc86006972ea73. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216172.

    Published: 17 Dec 2022
    3.5
    Low

    CVE-2022-4591

    Last Modified: 15 Apr 2025

    A vulnerability was found in mschaef toto up to 1.4.20. It has been declared as problematic. This vulnerability affects unknown code of the component Email Parameter Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.4.21 is able to address this issue. The name of the patch is 1f27f37c1a06f54a76971f70eaa6139dc139bdf9. It is recommended to upgrade the affected component. VDB-216178 is the identifier assigned to this vulnerability.

    Published: 17 Dec 2022
    5.4
    Medium

    CVE-2022-4572

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in UBI Reader up to 0.8.0. Affected by this issue is the function ubireader_extract_files of the file ubireader/ubifs/output.py of the component UBIFS File Handler. The manipulation leads to path traversal. The attack may be launched remotely. Upgrading to version 0.8.5 is able to address this issue. The name of the patch is d5d68e6b1b9f7070c29df5f67fc060f579ae9139. It is recommended to upgrade the affected component. VDB-216146 is the identifier assigned to this vulnerability.

    Published: 17 Dec 2022
    3.5
    Low

    CVE-2022-4582

    Last Modified: 15 Apr 2025

    A vulnerability was found in starter-public-edition-4 up to 4.6.10. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 4.6.11 is able to address this issue. The name of the patch is 2606983c20f6ea3430ac4b36b3d2e88aafef45da. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216168.

    Published: 17 Dec 2022
    5.5
    Medium

    CVE-2022-4589

    Last Modified: 21 Nov 2024

    A vulnerability has been found in cyface Terms and Conditions Module up to 2.0.9 and classified as problematic. Affected by this vulnerability is the function returnTo of the file termsandconditions/views.py. The manipulation leads to open redirect. The attack can be launched remotely. Upgrading to version 2.0.10 is able to address this issue. The name of the patch is 03396a1c2e0af95e12a45c5faef7e47a4b513e1a. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216175.

    Published: 17 Dec 2022
    3.5
    Low

    CVE-2022-4590

    Last Modified: 15 Apr 2025

    A vulnerability was found in mschaef toto up to 1.4.20. It has been classified as problematic. This affects an unknown part of the component Todo List Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.4.21 is able to address this issue. The name of the patch is fdc825ac5249f40683377e8a526a06cdc6870125. It is recommended to upgrade the affected component. The identifier VDB-216177 was assigned to this vulnerability.

    Published: 17 Dec 2022
    5.8
    Medium

    CVE-2022-23531

    Last Modified: 17 Apr 2025

    GuardDog is a CLI tool to identify malicious PyPI packages. Versions prior to 0.1.5 are vulnerable to Relative Path Traversal when scanning a specially-crafted local PyPI package. Running GuardDog against a specially-crafted package can allow an attacker to write an arbitrary file on the machine where GuardDog is executed due to a path traversal vulnerability when extracting the .tar.gz file of the package being scanned, which exists by design in the tarfile.TarFile.extractall function. This issue is patched in version 0.1.5.

    Published: 16 Dec 2022
    5.8
    Medium

    CVE-2022-23530

    Last Modified: 17 Apr 2025

    GuardDog is a CLI tool to identify malicious PyPI packages. Versions prior to v0.1.8 are vulnerable to arbitrary file write when scanning a specially-crafted remote PyPI package. Extracting files using shutil.unpack_archive() from a potentially malicious tarball without validating that the destination file path is within the intended destination directory can cause files outside the destination directory to be overwritten. This issue is patched in version 0.1.8. Potential workarounds include using a safer module, like zipfile, and validating the location of the extracted files and discarding those with malicious paths.

    Published: 16 Dec 2022
    —
    Unknown

    CVE-2019-25082

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 16 Dec 2022
    —
    Unknown

    CVE-2019-25083

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 16 Dec 2022
    —
    Unknown

    CVE-2019-25080

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 16 Dec 2022
    —
    Unknown

    CVE-2019-25081

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 16 Dec 2022
    —
    Unknown

    CVE-2019-25079

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 16 Dec 2022
    4.3
    Medium

    CVE-2022-23490

    Last Modified: 17 Apr 2025

    BigBlueButton is an open source web conferencing system. Versions prior to 2.4.0 expose sensitive information to Unauthorized Actors. This issue affects meetings with polls, where the attacker is a meeting participant. Subscribing to the current-poll collection does not update the client UI, but does give the attacker access to the contents of the collection, which include the individual poll responses. This issue is patched in version 2.4.0. There are no workarounds.

    Published: 16 Dec 2022
    8.6
    High

    CVE-2022-3157

    Last Modified: 16 Apr 2025

    A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS).

    Published: 16 Dec 2022
    7.1
    High

    CVE-2022-46670

    Last Modified: 17 Apr 2025

    Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution.  The vulnerability is an unauthenticated stored cross-site scripting vulnerability in the embedded webserver. The payload is transferred to the controller over SNMP and is rendered on the homepage of the embedded website.

    Published: 16 Dec 2022
    7.5
    High

    CVE-2022-3166

    Last Modified: 17 Apr 2025

    Rockwell Automation was made aware that the webservers of the Micrologix 1100 and 1400 controllers contain a vulnerability that may lead to a denial-of-service condition. The security vulnerability could be exploited by an attacker with network access to the affected systems by sending TCP packets to webserver and closing it abruptly which would cause a denial-of-service condition for the web server application on the device

    Published: 16 Dec 2022
    3.3
    Low

    CVE-2022-2966

    Last Modified: 16 Apr 2025

    Out-of-bounds Read vulnerability in Delta Electronics DOPSoft.This issue affects DOPSoft: All Versions.

    Published: 16 Dec 2022
    2.9
    Low

    CVE-2022-41972

    Last Modified: 17 Apr 2025

    Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to 4.9 contain a NULL Pointer Dereference in BLE L2CAP module. The Contiki-NG operating system for IoT devices contains a Bluetooth Low Energy stack. An attacker can inject a packet in this stack, which causes the implementation to dereference a NULL pointer and triggers undefined behavior. More specifically, while processing the L2CAP protocol, the implementation maps an incoming channel ID to its metadata structure. In this structure, state information regarding credits is managed through calls to the function input_l2cap_credit in the module os/net/mac/ble/ble-l2cap.c. Unfortunately, the input_l2cap_credit function does not check that the metadata corresponding to the user-supplied channel ID actually exists, which can lead to the channel variable being set to NULL before a pointer dereferencing operation is performed. The vulnerability has been patched in the "develop" branch of Contiki-NG, and will be included in release 4.9. Users can apply the patch in Contiki-NG pull request #2253 as a workaround until the new package is released.

    Published: 16 Dec 2022
    5.7
    Medium

    CVE-2022-41964

    Last Modified: 17 Apr 2025

    BigBlueButton is an open source web conferencing system. This vulnerability only affects release candidates of BigBlueButton 2.4. The attacker can start a subscription for poll results before starting an anonymous poll, and use this subscription to see individual responses in the anonymous poll. The attacker had to be a meeting presenter. This issue is patched in version 2.4.0. There are no workarounds.

    Published: 16 Dec 2022
    7.8
    High

    CVE-2022-41992

    Last Modified: 15 Apr 2025

    A memory corruption vulnerability exists in the VHD File Format parsing CXSPARSE record functionality of PowerISO PowerISO 8.3. A specially-crafted file can lead to an out-of-bounds write. A victim needs to open a malicious file to trigger this vulnerability.

    Published: 16 Dec 2022
    5.5
    Medium

    CVE-2022-44502

    Last Modified: 23 Apr 2025

    Adobe Illustrator versions 26.5.1 (and earlier), and 27.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Dec 2022
    5.5
    Medium

    CVE-2022-44500

    Last Modified: 23 Apr 2025

    Adobe Illustrator versions 26.5.1 (and earlier), and 27.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Dec 2022
    5.5
    Medium

    CVE-2022-44499

    Last Modified: 23 Apr 2025

    Adobe Illustrator versions 26.5.1 (and earlier), and 27.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Dec 2022
    5.5
    Medium

    CVE-2022-44498

    Last Modified: 23 Apr 2025

    Adobe Illustrator versions 26.5.1 (and earlier), and 27.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Dec 2022
    5.4
    Medium

    CVE-2022-44473

    Last Modified: 23 Apr 2025

    Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

    Published: 16 Dec 2022
    5.4
    Medium

    CVE-2022-44469

    Last Modified: 23 Apr 2025

    Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

    Published: 16 Dec 2022
    5.4
    Medium

    CVE-2022-44468

    Last Modified: 23 Apr 2025

    Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

    Published: 16 Dec 2022
    5.4
    Medium

    CVE-2022-44462

    Last Modified: 23 Apr 2025

    Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

    Published: 16 Dec 2022
    5.4
    Medium

    CVE-2022-42367

    Last Modified: 23 Apr 2025

    Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

    Published: 16 Dec 2022
    5.4
    Medium

    CVE-2022-42366

    Last Modified: 23 Apr 2025

    Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

    Published: 16 Dec 2022
    5.4
    Medium

    CVE-2022-42360

    Last Modified: 23 Apr 2025

    Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

    Published: 16 Dec 2022
    4.3
    Medium

    CVE-2022-42351

    Last Modified: 23 Apr 2025

    Adobe Experience Manager version 6.5.14 (and earlier) is affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to disclose low level confidentiality information. Exploitation of this issue does not require user interaction.

    Published: 16 Dec 2022
    6.5
    Medium

    CVE-2022-42343

    Last Modified: 23 Apr 2025

    Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.

    Published: 16 Dec 2022
    5.4
    Medium

    CVE-2022-35696

    Last Modified: 23 Apr 2025

    Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

    Published: 16 Dec 2022
    5.4
    Medium

    CVE-2022-35694

    Last Modified: 23 Apr 2025

    Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

    Published: 16 Dec 2022
    5.5
    Medium

    CVE-2022-20531

    Last Modified: 3 Dec 2024

    In Telecom, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 16 Dec 2022
    5.5
    Medium

    CVE-2022-4326

    Last Modified: 14 Apr 2025

    Improper preservation of permissions vulnerability in Trellix Endpoint Agent (xAgent) prior to V35.31.22 on Windows allows a local user with administrator privileges to bypass the product protection to uninstall the agent via incorrectly applied permissions in the removal protection functionality.

    Published: 16 Dec 2022
    6.5
    Medium

    CVE-2022-4555

    Last Modified: 8 Apr 2026

    The WP Shamsi plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the deactivate() function hooked via init() in versions up to, and including, 4.1.0. This makes it possible for unauthenticated attackers to deactivate arbitrary plugins on the site. This can be used to deactivate security plugins that aids in exploiting other vulnerabilities.

    Published: 16 Dec 2022
    2.7
    Low

    CVE-2022-41963

    Last Modified: 17 Apr 2025

    BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3 contain a whiteboard grace period that exists to handle delayed messages, but this grace period could be used by attackers to take actions in the few seconds after their access is revoked. The attacker must be a meeting participant. This issue is patched in version 2.4.3 an version 2.5-alpha-1

    Published: 16 Dec 2022
    5.4
    Medium

    CVE-2022-46870

    Last Modified: 17 Apr 2025

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin allows logged-in users to execute arbitrary javascript in other users' browsers. This issue affects Apache Zeppelin before 0.8.2. Users are recommended to upgrade to a supported version of Zeppelin.

    Published: 16 Dec 2022
    6.5
    Medium

    CVE-2021-28655

    Last Modified: 17 Apr 2025

    The improper Input Validation vulnerability in "”Move folder to Trash” feature of Apache Zeppelin allows an attacker to delete the arbitrary files. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.

    Published: 16 Dec 2022
    2.7
    Low

    CVE-2022-41962

    Last Modified: 17 Apr 2025

    BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6, and 2.5-alpha-1 contain Incorrect Authorization for setting emoji status. A user with moderator rights can use the clear status feature to set any emoji status for other users. Moderators should only be able to set none as the status of other users. This issue is patched in 2.4-rc-6 and 2.5-alpha-1There are no workarounds.

    Published: 16 Dec 2022
    4.3
    Medium

    CVE-2022-41961

    Last Modified: 17 Apr 2025

    BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are subject to Ineffective user bans. The attacker could register multiple users, and join the meeting with one of them. When that user is banned, they could still join the meeting with the remaining registered users from the same extId. This issue has been fixed by improving permissions such that banning a user removes all users related to their extId, including registered users that have not joined the meeting. This issue is patched in versions 2.4-rc-6 and 2.5-alpha-1. There are no workarounds.

    Published: 16 Dec 2022
    —
    Unknown

    CVE-2022-4540

    Last Modified: 30 Aug 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error and is not a valid vulnerability. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 16 Dec 2022