CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2022-3908

    Last Modified: 22 Apr 2025

    The Helloprint WordPress plugin before 1.4.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

    Published: 12 Dec 2022
    8.8
    High

    CVE-2022-3359

    Last Modified: 22 Apr 2025

    The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

    Published: 12 Dec 2022
    5.5
    Medium

    CVE-2022-4312

    Last Modified: 14 Apr 2025

    A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized user with access the email and short messaging service (SMS) accounts configuration files to discover the associated simple mail transfer protocol (SMTP) account credentials and the SIM card PIN code. Successful exploitation of this vulnerability could allow an unauthorized user access to the underlying email account and SIM card.

    Published: 12 Dec 2022
    4.7
    Medium

    CVE-2022-4311

    Last Modified: 14 Apr 2025

    An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConnect, which could include credentials. Successful exploitation of this vulnerability could allow other users unauthorized access to the underlying data sources.

    Published: 12 Dec 2022
    —
    Unknown

    CVE-2022-4425

    Last Modified: 19 Aug 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 12 Dec 2022
    —
    Unknown

    CVE-2022-4424

    Last Modified: 30 Aug 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error and is not a valid vulnerability. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 12 Dec 2022
    —
    Unknown

    CVE-2021-4243

    Last Modified: 13 Feb 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-32850. Reason: This candidate is a duplicate of CVE-2021-32850. Notes: All CVE users should reference CVE-2021-32850 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 12 Dec 2022
    9.8
    Critical

    CVE-2022-3485

    Last Modified: 22 Apr 2025

    In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number and thus gain full control of the device.

    Published: 12 Dec 2022
    6
    Medium

    CVE-2022-31596

    Last Modified: 22 Apr 2025

    Under certain conditions, an attacker authenticated as a CMS administrator and with high privileges access to the Network in SAP BusinessObjects Business Intelligence Platform (Monitoring DB) - version 430, can access BOE Monitoring database to retrieve and modify (non-personal) system data which would otherwise be restricted. Also, a potential attack could be used to leave the CMS's scope and impact the database. A successful attack could have a low impact on confidentiality, a high impact on integrity, and a low impact on availability.

    Published: 12 Dec 2022
    5.4
    Medium

    CVE-2022-45970

    Last Modified: 13 Feb 2026

    Alist v3.5.1 is vulnerable to Cross Site Scripting (XSS) via the bulletin board.

    Published: 12 Dec 2022
    8.8
    High

    CVE-2022-45968

    Last Modified: 13 Feb 2026

    Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (even a password protected one).

    Published: 12 Dec 2022
    4.7
    Medium

    CVE-2023-25586

    Last Modified: 13 Feb 2025

    A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a crash and local denial of service.

    Published: 12 Dec 2022
    0
    Low

    CVE-2023-2222

    Last Modified: 7 Nov 2023

    This was deemed not a security vulnerability by upstream.

    Published: 12 Dec 2022
    7.8
    High

    CVE-2022-4318

    Last Modified: 21 Nov 2024

    A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.

    Published: 12 Dec 2022
    6.3
    Medium

    CVE-2022-4416

    Last Modified: 15 Apr 2025

    A vulnerability was found in RainyGao DocSys. It has been declared as critical. This vulnerability affects the function getReposAllUsers of the file /DocSystem/Repos/getReposAllUsers.do. The manipulation of the argument searchWord/reposId leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-215278 is the identifier assigned to this vulnerability.

    Published: 12 Dec 2022
    7.3
    High

    CVE-2022-46908

    Last Modified: 5 May 2025

    SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.

    Published: 12 Dec 2022
    —
    Unknown

    CVE-2023-22603

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 12 Dec 2022
    —
    Unknown

    CVE-2023-22604

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 12 Dec 2022
    —
    Unknown

    CVE-2023-22605

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 12 Dec 2022
    —
    Unknown

    CVE-2023-22606

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 12 Dec 2022
    —
    Unknown

    CVE-2023-22607

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 12 Dec 2022
    —
    Unknown

    CVE-2023-22608

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 12 Dec 2022
    —
    Unknown

    CVE-2023-22609

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 12 Dec 2022
    7.8
    High

    CVE-2022-47673

    Last Modified: 21 Nov 2024

    An issue was discovered in Binutils addr2line before 2.39.3, function parse_module contains multiple out of bound reads which may cause a denial of service or other unspecified impacts.

    Published: 12 Dec 2022
    6.1
    Medium

    CVE-2021-41943

    Last Modified: 22 Apr 2025

    Logrhythm Web Console 7.4.9 allows for HTML tag injection through Contextualize Action -> Create a new Contextualize Action -> Inject your HTML tag in the name field.

    Published: 12 Dec 2022
    7.2
    High

    CVE-2022-45996

    Last Modified: 22 Apr 2025

    Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output.

    Published: 12 Dec 2022
    7.2
    High

    CVE-2022-45997

    Last Modified: 22 Apr 2025

    Tenda W20E V16.01.0.6(3392) is vulnerable to Buffer Overflow.

    Published: 12 Dec 2022
    6.1
    Medium

    CVE-2022-46905

    Last Modified: 22 Apr 2025

    Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an unauthenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Reflected XSS.

    Published: 12 Dec 2022
    5.4
    Medium

    CVE-2022-46906

    Last Modified: 22 Apr 2025

    Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Reflected XSS.

    Published: 12 Dec 2022
    8.8
    High

    CVE-2022-42716

    Last Modified: 21 Nov 2024

    An issue was discovered in the Arm Mali GPU Kernel Driver. There is a use-after-free. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Valhall r29p0 through r40P0.

    Published: 12 Dec 2022
    8.8
    High

    CVE-2022-45043

    Last Modified: 22 Apr 2025

    Tenda AX12 V22.03.01.16_cn is vulnerable to command injection via goform/fast_setting_internet_set.

    Published: 12 Dec 2022
    5.4
    Medium

    CVE-2022-46903

    Last Modified: 22 Apr 2025

    Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Stored XSS.

    Published: 12 Dec 2022
    5.4
    Medium

    CVE-2022-46904

    Last Modified: 22 Apr 2025

    Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Self-XSS.

    Published: 12 Dec 2022
    2.6
    Low

    CVE-2021-4244

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in yikes-inc-easy-mailchimp-extender Plugin up to 6.8.5. This affects an unknown part of the file admin/partials/ajax/add_field_to_form.php. The manipulation of the argument field_name/merge_tag/field_type/list_id leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 6.8.6 is able to address this issue. The name of the patch is 3662c6593aa1bb4286781214891d26de2e947695. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-215307.

    Published: 12 Dec 2022
    7.1
    High

    CVE-2022-23511

    Last Modified: 23 Apr 2025

    A privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and logs from Amazon EC2 instances and on-premises servers, in versions up to and including v1.247354. When users trigger a repair of the Agent, a pop-up window opens with SYSTEM permissions. Users with administrative access to affected hosts may use this to create a new command prompt as NT AUTHORITY\SYSTEM. To trigger this issue, the third party must be able to access the affected host and elevate their privileges such that they're able to trigger the agent repair process. They must also be able to install the tools required to trigger the issue. This issue does not affect the CloudWatch Agent for macOS or Linux. Agent users should upgrade to version 1.247355 of the CloudWatch Agent to address this issue. There is no recommended work around. Affected users must update the installed version of the CloudWatch Agent to address this issue.

    Published: 12 Dec 2022
    6.1
    Medium

    CVE-2022-44031

    Last Modified: 22 Apr 2025

    Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization of the blockquote syntax in Textile-formatted fields.

    Published: 12 Dec 2022
    6.1
    Medium

    CVE-2022-44637

    Last Modified: 23 Apr 2025

    Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization in Redcloth3 Textile-formatted fields. Depending on the configuration, this may require login as a registered user.

    Published: 12 Dec 2022
    8.8
    High

    CVE-2022-45759

    Last Modified: 22 Apr 2025

    SENS v1.0 has a file upload vulnerability.

    Published: 12 Dec 2022
    6.1
    Medium

    CVE-2022-45756

    Last Modified: 22 Apr 2025

    SENS v1.0 is vulnerable to Cross Site Scripting (XSS).

    Published: 12 Dec 2022
    5.4
    Medium

    CVE-2022-45758

    Last Modified: 23 Apr 2025

    SENS v1.0 is vulnerable to Cross Site Scripting (XSS) via com.liuyanzhao.sens.web.controller.admin, getRegister.

    Published: 12 Dec 2022
    8.8
    High

    CVE-2022-45977

    Last Modified: 22 Apr 2025

    Tenda AX12 V22.03.01.21_CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function.

    Published: 12 Dec 2022
    5.3
    Medium

    CVE-2022-45956

    Last Modified: 22 Apr 2025

    Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass the Basic Authorization mechanism.

    Published: 12 Dec 2022
    7.5
    High

    CVE-2022-45957

    Last Modified: 22 Apr 2025

    ZTE ZXHN-H108NS router with firmware version H108NSV1.0.7u_ZRD_GR2_A68 is vulnerable to remote stack buffer overflow.

    Published: 12 Dec 2022
    7.5
    High

    CVE-2022-45979

    Last Modified: 22 Apr 2025

    Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the ssid parameter at /goform/fast_setting_wifi_set .

    Published: 12 Dec 2022
    8.8
    High

    CVE-2022-45980

    Last Modified: 22 Apr 2025

    Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via /goform/SysToolRestoreSet .

    Published: 12 Dec 2022
    4.7
    Medium

    CVE-2022-47016

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 12 Dec 2022
    7.5
    High

    CVE-2022-25836

    Last Modified: 22 Apr 2025

    Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when the MITM negotiates Legacy Passkey Pairing with the pairing Initiator and Secure Connections Passkey Pairing with the pairing Responder and brute forces the Passkey entered by the user into the Initiator. The MITM attacker can use the identified Passkey value to complete authentication with the Responder via Bluetooth pairing method confusion.

    Published: 12 Dec 2022
    7.5
    High

    CVE-2022-25837

    Last Modified: 22 Apr 2025

    Bluetooth® Pairing in Bluetooth Core Specification v1.0B through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when at least one device supports BR/EDR Secure Connections pairing and the other BR/EDR Legacy PIN code pairing if the MITM negotiates BR/EDR Secure Simple Pairing in Secure Connections mode using the Passkey association model with the pairing Initiator and BR/EDR Legacy PIN code pairing with the pairing Responder and brute forces the Passkey entered by the user into the Responder as a 6-digit PIN code. The MITM attacker can use the identified PIN code value as the Passkey value to complete authentication with the Initiator via Bluetooth pairing method confusion.

    Published: 12 Dec 2022
    4.7
    Medium

    CVE-2023-25585

    Last Modified: 13 Feb 2025

    A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.

    Published: 12 Dec 2022
    4.7
    Medium

    CVE-2023-25588

    Last Modified: 13 Feb 2025

    A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_symtab` function, which may lead to an application crash and local denial of service.

    Published: 12 Dec 2022