CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2022-40002

    Last Modified: 21 Apr 2025

    Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbirtary code via the callback parameter to /cms/notify.

    Published: 15 Dec 2022
    9.6
    Critical

    CVE-2022-40004

    Last Modified: 21 Apr 2025

    Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Log.

    Published: 15 Dec 2022
    5.5
    Medium

    CVE-2021-4245

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in chbrown rfc6902. This affects an unknown part of the file pointer.ts. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The exploit has been disclosed to the public and may be used. The name of the patch is c006ce9faa43d31edb34924f1df7b79c137096cf. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-215883.

    Published: 15 Dec 2022
    5.3
    Medium

    CVE-2022-46392

    Last Modified: 5 Jun 2026

    An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA private key after observing the victim performing a single private-key operation, if the window size (MBEDTLS_MPI_WINDOW_SIZE) used for the exponentiation is 3 or smaller.

    Published: 15 Dec 2022
    5.3
    Medium

    CVE-2022-23526

    Last Modified: 18 Apr 2025

    Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the_chartutil_ package that can cause a segmentation violation. The _chartutil_ package contains a parser that loads a JSON Schema validation file. For example, the Helm client when rendering a chart will validate its values with the schema file. The _chartutil_ package parses the schema file and loads it into structures Go can work with. Some schema files can cause array data structures to be created causing a memory violation. Applications that use the _chartutil_ package in the Helm SDK to parse a schema file can suffer a Denial of Service when that input causes a panic that cannot be recovered from. Helm is not a long running service so the panic will not affect future uses of the Helm client. This issue has been patched in 3.10.3. SDK users can validate schema files that are correctly formatted before passing them to the _chartutil_ functions.

    Published: 15 Dec 2022
    —
    Unknown

    CVE-2022-4516

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 15 Dec 2022
    8.8
    High

    CVE-2022-46691

    Last Modified: 21 Apr 2025

    A memory consumption issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 15 Dec 2022
    5.5
    Medium

    CVE-2022-46692

    Last Modified: 21 Apr 2025

    A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may bypass Same Origin Policy.

    Published: 15 Dec 2022
    7
    High

    CVE-2022-46689

    Last Modified: 21 Apr 2025

    A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.

    Published: 15 Dec 2022
    7.8
    High

    CVE-2022-46690

    Last Modified: 21 Apr 2025

    An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.

    Published: 15 Dec 2022
    6.5
    Medium

    CVE-2022-46695

    Last Modified: 21 Apr 2025

    A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Visiting a website that frames malicious content may lead to UI spoofing.

    Published: 15 Dec 2022
    7.8
    High

    CVE-2022-46697

    Last Modified: 21 Apr 2025

    An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.1. An app may be able to execute arbitrary code with kernel privileges.

    Published: 15 Dec 2022
    7.8
    High

    CVE-2022-46701

    Last Modified: 18 Apr 2025

    The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2. Connecting to a malicious NFS server may lead to arbitrary code execution with kernel privileges.

    Published: 15 Dec 2022
    5.5
    Medium

    CVE-2022-46702

    Last Modified: 21 Apr 2025

    The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to disclose kernel memory.

    Published: 15 Dec 2022
    5.4
    Medium

    CVE-2022-40373

    Last Modified: 21 Apr 2025

    Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file.

    Published: 15 Dec 2022
    7.8
    High

    CVE-2022-42805

    Last Modified: 21 Apr 2025

    An integer overflow was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.

    Published: 15 Dec 2022
    7.8
    High

    CVE-2022-42841

    Last Modified: 21 Apr 2025

    A type confusion issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2. Processing a maliciously crafted package may lead to arbitrary code execution.

    Published: 15 Dec 2022
    6.5
    Medium

    CVE-2022-42852

    Last Modified: 21 Apr 2025

    The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may result in the disclosure of process memory.

    Published: 15 Dec 2022
    7.1
    High

    CVE-2022-42855

    Last Modified: 21 Apr 2025

    A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to use arbitrary entitlements.

    Published: 15 Dec 2022
    8.8
    High

    CVE-2022-42863

    Last Modified: 21 Apr 2025

    A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 15 Dec 2022
    5.5
    Medium

    CVE-2022-42865

    Last Modified: 21 Apr 2025

    This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to bypass Privacy preferences.

    Published: 15 Dec 2022
    6.1
    Medium

    CVE-2022-44235

    Last Modified: 21 Apr 2025

    Beijing Zed-3 Technologies Co.,Ltd VoIP simpliclty ASG 8.5.0.17807 (20181130-16:12) is vulnerable to Cross Site Scripting (XSS).

    Published: 15 Dec 2022
    8.8
    High

    CVE-2022-4505

    Last Modified: 14 Apr 2025

    Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.2.

    Published: 15 Dec 2022
    8.8
    High

    CVE-2022-4506

    Last Modified: 14 Apr 2025

    Unrestricted Upload of File with Dangerous Type in GitHub repository openemr/openemr prior to 7.0.0.2.

    Published: 15 Dec 2022
    3.5
    Low

    CVE-2022-4514

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, was found in Opencaching Deutschland oc-server3. Affected is an unknown function of the file htdocs/lang/de/ocstyle/varset.inc.php. The manipulation of the argument varvalue leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 4bdd6a0e7b7760cea03b91812cbb80d7b16e3b5f. It is recommended to apply a patch to fix this issue. VDB-215886 is the identifier assigned to this vulnerability.

    Published: 15 Dec 2022
    3.5
    Low

    CVE-2022-4520

    Last Modified: 15 Apr 2025

    A vulnerability was found in WSO2 carbon-registry up to 4.8.11. It has been rated as problematic. Affected by this issue is some unknown functionality of the file components/registry/org.wso2.carbon.registry.search.ui/src/main/resources/web/search/advancedSearchForm-ajaxprocessor.jsp of the component Advanced Search. The manipulation of the argument mediaType/rightOp/leftOp/rightPropertyValue/leftPropertyValue leads to cross site scripting. The attack may be launched remotely. Upgrading to version 4.8.12 is able to address this issue. The name of the patch is 0c827cc1b14b82d8eb86117ab2e43c34bb91ddb4. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-215900.

    Published: 15 Dec 2022
    3.5
    Low

    CVE-2022-4521

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in WSO2 carbon-registry up to 4.8.6. This affects an unknown part of the component Request Parameter Handler. The manipulation of the argument parentPath/path/username/path/profile_menu leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 4.8.7 is able to address this issue. The name of the patch is 9f967abfde9317bee2cda469dbc09b57d539f2cc. It is recommended to upgrade the affected component. The identifier VDB-215901 was assigned to this vulnerability.

    Published: 15 Dec 2022
    3.5
    Low

    CVE-2022-4522

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic was found in CalendarXP up to 10.0.1. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 10.0.2 is able to address this issue. The name of the patch is e3715b2228ddefe00113296069969f9e184836da. It is recommended to upgrade the affected component. VDB-215902 is the identifier assigned to this vulnerability.

    Published: 15 Dec 2022
    3.5
    Low

    CVE-2022-4523

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, has been found in vexim2. This issue affects some unknown processing. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 21c0a60d12e9d587f905cd084b2c70f9b1592065. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-215903.

    Published: 15 Dec 2022
    3.5
    Low

    CVE-2022-4524

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, was found in Roots soil Plugin up to 4.0.x. Affected is the function language_attributes of the file src/Modules/CleanUpModule.php. The manipulation of the argument language leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 4.1.0 is able to address this issue. The name of the patch is 0c9151e00ab047da253e5cdbfccb204dd423269d. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-215904.

    Published: 15 Dec 2022
    3.5
    Low

    CVE-2022-4525

    Last Modified: 21 Nov 2024

    A vulnerability has been found in National Sleep Research Resource sleepdata.org up to 58.x and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 59.0.0.rc is able to address this issue. The name of the patch is da44a3893b407087829b006d09339780919714cd. It is recommended to upgrade the affected component. The identifier VDB-215905 was assigned to this vulnerability.

    Published: 15 Dec 2022
    3.5
    Low

    CVE-2022-4526

    Last Modified: 15 Apr 2025

    A vulnerability was found in django-photologue up to 3.15.1 and classified as problematic. Affected by this issue is some unknown functionality of the file photologue/templates/photologue/photo_detail.html of the component Default Template Handler. The manipulation of the argument object.caption leads to cross site scripting. The attack may be launched remotely. Upgrading to version 3.16 is able to address this issue. The name of the patch is 960cb060ce5e2964e6d716ff787c72fc18a371e7. It is recommended to apply a patch to fix this issue. VDB-215906 is the identifier assigned to this vulnerability.

    Published: 15 Dec 2022
    3.5
    Low

    CVE-2022-4527

    Last Modified: 21 Nov 2024

    A vulnerability was found in collective.task up to 3.0.8. It has been classified as problematic. This affects the function renderCell/AssignedGroupColumn of the file src/collective/task/browser/table.py. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 3.0.9 is able to address this issue. The name of the patch is 1aac7f83fa2c2b41d59ba02748912953461f3fac. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-215907.

    Published: 15 Dec 2022
    6.8
    Medium

    CVE-2020-4497

    Last Modified: 17 Apr 2025

    IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between Spectrum Protect Plus vSnap and its agents. An attacker could obtain information using main in the middle techniques. IBM X-Force ID: 182106.

    Published: 14 Dec 2022
    6.4
    Medium

    CVE-2022-4410

    Last Modified: 8 Apr 2026

    The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including 2.2.20.3 due to improper output escaping on post/page/media titles. This makes it possible for attackers to inject arbitrary web scripts on the permalink-manager page if another plugin or theme is installed on the site that allows lower privileged users with unfiltered_html the ability to modify post/page titles with malicious web scripts.

    Published: 14 Dec 2022
    4.6
    Medium

    CVE-2022-3917

    Last Modified: 17 Apr 2025

    Improper access control of bootloader function was discovered in Motorola Mobility Motorola e20 prior to version RONS31.267-38-8 allows attacker with local access to read partition or RAM data.

    Published: 14 Dec 2022
    7.1
    High

    CVE-2022-4501

    Last Modified: 8 Apr 2026

    The Mega Addons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the vc_saving_data function in versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update the plugin's settings.

    Published: 14 Dec 2022
    —
    Unknown

    CVE-2022-47405

    Last Modified: 17 Mar 2025

    Not used

    Published: 14 Dec 2022
    —
    Unknown

    CVE-2022-47402

    Last Modified: 17 Mar 2025

    Not used

    Published: 14 Dec 2022
    —
    Unknown

    CVE-2022-47403

    Last Modified: 17 Mar 2025

    Not used

    Published: 14 Dec 2022
    —
    Unknown

    CVE-2022-47404

    Last Modified: 17 Mar 2025

    Not used

    Published: 14 Dec 2022
    —
    Unknown

    CVE-2022-47399

    Last Modified: 17 Mar 2025

    Not used

    Published: 14 Dec 2022
    —
    Unknown

    CVE-2022-47400

    Last Modified: 17 Mar 2025

    Not used

    Published: 14 Dec 2022
    —
    Unknown

    CVE-2022-47401

    Last Modified: 17 Mar 2025

    Not used

    Published: 14 Dec 2022
    —
    Unknown

    CVE-2022-47396

    Last Modified: 17 Mar 2025

    Not used

    Published: 14 Dec 2022
    —
    Unknown

    CVE-2022-47397

    Last Modified: 17 Mar 2025

    Not used

    Published: 14 Dec 2022
    —
    Unknown

    CVE-2022-47398

    Last Modified: 17 Mar 2025

    Not used

    Published: 14 Dec 2022
    7.7
    High

    CVE-2022-23512

    Last Modified: 21 Apr 2025

    MeterSphere is a one-stop open source continuous testing platform. Versions prior to 2.4.1 are vulnerable to Path Injection in ApiTestCaseService::deleteBodyFiles which takes a user-controlled string id and passes it to ApiTestCaseService, which uses the user-provided value (testId) in new File(BODY_FILE_DIR + "/" + testId), being deleted later by file.delete(). By adding some camouflage parameters to the url, an attacker can target files on the server. The vulnerability has been fixed in v2.4.1.

    Published: 14 Dec 2022
    8.8
    High

    CVE-2022-34271

    Last Modified: 18 Apr 2025

    A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0.

    Published: 14 Dec 2022
    5.9
    Medium

    CVE-2022-3590

    Last Modified: 21 Apr 2025

    WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

    Published: 14 Dec 2022