CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2022-45760

    Last Modified: 22 Apr 2025

    SENS v1.0 is vulnerable to Incorrect Access Control vulnerability.

    Published: 12 Dec 2022
    9.1
    Critical

    CVE-2022-3782

    Last Modified: 9 Apr 2025

    keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field.

    Published: 12 Dec 2022
    5.3
    Medium

    CVE-2022-41881

    Last Modified: 22 Apr 2025

    Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.

    Published: 12 Dec 2022
    3.5
    Low

    CVE-2022-4421

    Last Modified: 15 Apr 2025

    A vulnerability was found in rAthena FluxCP. It has been classified as problematic. Affected is an unknown function of the file themes/default/servicedesk/view.php of the component Service Desk Image URL Handler. The manipulation of the argument sslink leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is 8a39b2b2bf28353b3503ff1421862393db15aa7e. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-215304.

    Published: 12 Dec 2022
    7.5
    High

    CVE-2022-45227

    Last Modified: 23 Apr 2025

    The web portal of Dragino Lora LG01 18ed40 IoT v4.3.4 has the directory listing at the URL https://10.10.20.74/lib/. This address has a backup file which can be downloaded without any authentication.

    Published: 12 Dec 2022
    3.5
    Low

    CVE-2022-45228

    Last Modified: 23 Apr 2025

    Dragino Lora LG01 18ed40 IoT v4.3.4 was discovered to contain a Cross-Site Request Forgery in the logout page.

    Published: 12 Dec 2022
    7.5
    High

    CVE-2022-45269

    Last Modified: 23 Apr 2025

    A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attackers to read arbitrary files.

    Published: 12 Dec 2022
    7.2
    High

    CVE-2022-45275

    Last Modified: 23 Apr 2025

    An arbitrary file upload vulnerability in /queuing/admin/ajax.php?action=save_settings of Dynamic Transaction Queuing System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 12 Dec 2022
    6.3
    Medium

    CVE-2023-25584

    Last Modified: 13 Feb 2025

    An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.

    Published: 12 Dec 2022
    —
    Unknown

    CVE-2022-4412

    Last Modified: 30 Aug 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error and is not a valid vulnerability. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 11 Dec 2022
    —
    Unknown

    CVE-2022-4411

    Last Modified: 19 Aug 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 11 Dec 2022
    —
    Unknown

    CVE-2022-4405

    Last Modified: 16 Aug 2024

    **REJECT** This is not considered a valid security vulnerability.

    Published: 11 Dec 2022
    —
    Unknown

    CVE-2022-4404

    Last Modified: 19 Aug 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 11 Dec 2022
    7.8
    High

    CVE-2023-2176

    Last Modified: 5 May 2025

    A vulnerability was found in compare_netdev_and_ip in drivers/infiniband/core/cma.c in RDMA in the Linux Kernel. The improper cleanup results in out-of-boundary read, where a local user can utilize this problem to crash the system or escalation of privilege.

    Published: 11 Dec 2022
    6.1
    Medium

    CVE-2022-4407

    Last Modified: 16 Feb 2026

    Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.9.

    Published: 11 Dec 2022
    3.5
    Low

    CVE-2022-4401

    Last Modified: 21 Nov 2024

    A vulnerability was found in pallidlight online-course-selection-system. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-215268.

    Published: 11 Dec 2022
    6.1
    Medium

    CVE-2022-4413

    Last Modified: 14 Apr 2025

    Cross-site Scripting (XSS) - Reflected in GitHub repository nuxt/framework prior to v3.0.0-rc.13.

    Published: 11 Dec 2022
    6.1
    Medium

    CVE-2022-4414

    Last Modified: 14 Apr 2025

    Cross-site Scripting (XSS) - DOM in GitHub repository nuxt/framework prior to v3.0.0-rc.13.

    Published: 11 Dec 2022
    3.5
    Low

    CVE-2022-4400

    Last Modified: 15 Apr 2025

    A vulnerability was found in zbl1996 FS-Blog and classified as problematic. This issue affects some unknown processing of the component Title Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-215267.

    Published: 11 Dec 2022
    4.7
    Medium

    CVE-2022-4402

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical has been found in RainyGao DocSys 2.02.37. This affects an unknown part of the component ZIP File Decompression Handler. The manipulation leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-215271.

    Published: 11 Dec 2022
    6.3
    Medium

    CVE-2022-4403

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical was found in SourceCodester Canteen Management System. This vulnerability affects unknown code of the file ajax_represent.php. The manipulation of the argument customer_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-215272.

    Published: 11 Dec 2022
    5.4
    Medium

    CVE-2022-4408

    Last Modified: 14 Apr 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.9.

    Published: 11 Dec 2022
    7.5
    High

    CVE-2022-4409

    Last Modified: 14 Apr 2025

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.1.9.

    Published: 11 Dec 2022
    6.4
    Medium

    CVE-2022-23485

    Last Modified: 23 Apr 2025

    Sentry is an error tracking and performance monitoring platform. In versions of the sentry python library prior to 22.11.0 an attacker with a known valid invite link could manipulate a cookie to allow the same invite link to be reused on multiple accounts when joining an organization. As a result an attacker with a valid invite link can create multiple users and join an organization they may not have been originally invited to. This issue was patched in version 22.11.0. Sentry SaaS customers do not need to take action. Self-hosted Sentry installs on systems which can not upgrade can disable the invite functionality until they are ready to deploy the patched version by editing their `sentry.conf.py` file (usually located at `~/.sentry/`).

    Published: 10 Dec 2022
    3.5
    Low

    CVE-2022-4396

    Last Modified: 15 Apr 2025

    A vulnerability was found in RDFlib pyrdfa3 and classified as problematic. This issue affects the function _get_option of the file pyRdfa/__init__.py. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is ffd1d62dd50d5f4190013b39cedcdfbd81f3ce3e. It is recommended to apply a patch to fix this issue. The identifier VDB-215249 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 10 Dec 2022
    7.8
    High

    CVE-2022-4398

    Last Modified: 14 Apr 2025

    Integer Overflow or Wraparound in GitHub repository radareorg/radare2 prior to 5.8.0.

    Published: 10 Dec 2022
    4.3
    Medium

    CVE-2022-4397

    Last Modified: 15 Apr 2025

    A vulnerability was found in morontt zend-blog-number-2. It has been classified as problematic. Affected is an unknown function of the file application/forms/Comment.php of the component Comment Handler. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The name of the patch is 36b2d4abe20a6245e4f8df7a4b14e130b24d429d. It is recommended to apply a patch to fix this issue. VDB-215250 is the identifier assigned to this vulnerability.

    Published: 10 Dec 2022
    5.5
    Medium

    CVE-2022-4399

    Last Modified: 15 Apr 2025

    A vulnerability was found in TicklishHoneyBee nodau. It has been rated as critical. Affected by this issue is some unknown functionality of the file src/db.c. The manipulation of the argument value/name leads to sql injection. The name of the patch is 7a7d737a3929f335b9717ddbd31db91151b69ad2. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-215252.

    Published: 10 Dec 2022
    9.8
    Critical

    CVE-2022-45145

    Last Modified: 23 Apr 2025

    egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape characters in a .egg file.

    Published: 10 Dec 2022
    6.5
    Medium

    CVE-2022-23497

    Last Modified: 23 Apr 2025

    FreshRSS is a free, self-hostable RSS aggregator. User configuration files can be accessed by a remote user. In addition to user preferences, such configurations contain hashed passwords (brypt with cost 9, salted) of FreshRSS Web interface. If the API is used, the configuration might contain a hashed password (brypt with cost 9, salted) of the GReader API, and a hashed password (MD5 salted) of the Fever API. Users should update to version 1.20.2 or edge. Users unable to upgrade can apply the patch manually or delete the file `./FreshRSS/p/ext.php`.

    Published: 9 Dec 2022
    9.6
    Critical

    CVE-2022-23510

    Last Modified: 23 Apr 2025

    cube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL row-level security and run arbitrary SQL via the newly introduced /v1/sql-runner endpoint. This issue has been resolved in version 0.31.24. Users are advised to either upgrade to 0.31.24 or to downgrade to 0.31.22. There are no known workarounds for this vulnerability.

    Published: 9 Dec 2022
    8.6
    High

    CVE-2022-2993

    Last Modified: 22 Apr 2025

    There is an error in the condition of the last if-statement in the function smp_check_keys. It was rejecting current keys if all requirements were unmet.

    Published: 9 Dec 2022
    8.8
    High

    CVE-2022-46157

    Last Modified: 22 Apr 2025

    Akeneo PIM is an open source Product Information Management (PIM). Akeneo PIM Community Edition versions before v5.0.119 and v6.0.53 allows remote authenticated users to execute arbitrary PHP code on the server by uploading a crafted image. Akeneo PIM Community Edition after the versions aforementioned provides patched Apache HTTP server configuration file, for docker setup and in documentation sample, to fix this vulnerability. Community Edition users must change their Apache HTTP server configuration accordingly to be protected. The patch for Cloud Based Akeneo PIM Services customers has been applied since 30th October 2022. Users are advised to upgrade. Users unable to upgrade may Replace any reference to `<FilesMatch \.php$>` in their apache httpd configurations with: `<Location "/index.php">`.

    Published: 9 Dec 2022
    8
    High

    CVE-2022-46166

    Last Modified: 23 Apr 2025

    Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are affected. Users are advised to upgrade to the most recent releases of Spring Boot Admin 2.6.10 and 2.7.8 to resolve this issue. Users unable to upgrade may disable any notifier or disable write access (POST request) on `/env` actuator endpoint.

    Published: 9 Dec 2022
    4.4
    Medium

    CVE-2022-41299

    Last Modified: 29 Oct 2025

    IBM Cloud Transformation Advisor 2.0.1 through 3.3.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 237214.

    Published: 9 Dec 2022
    9.1
    Critical

    CVE-2022-23477

    Last Modified: 23 Apr 2025

    xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in audin_send_open() function. There are no known workarounds for this issue. Users are advised to upgrade.

    Published: 9 Dec 2022
    8.2
    High

    CVE-2022-23484

    Last Modified: 23 Apr 2025

    xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Integer Overflow in xrdp_mm_process_rail_update_window_text() function. There are no known workarounds for this issue. Users are advised to upgrade.

    Published: 9 Dec 2022
    7.5
    High

    CVE-2022-23483

    Last Modified: 23 Apr 2025

    xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in libxrdp_send_to_channel() function. There are no known workarounds for this issue. Users are advised to upgrade.

    Published: 9 Dec 2022
    0
    Low

    CVE-2022-23482

    Last Modified: 23 Apr 2025

    xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_sec_process_mcs_data_CS_CORE() function. There are no known workarounds for this issue. Users are advised to upgrade.

    Published: 9 Dec 2022
    0
    Low

    CVE-2022-23481

    Last Modified: 23 Apr 2025

    xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_caps_process_confirm_active() function. There are no known workarounds for this issue. Users are advised to upgrade.

    Published: 9 Dec 2022
    9.1
    Critical

    CVE-2022-23480

    Last Modified: 23 Apr 2025

    xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in devredir_proc_client_devlist_announce_req() function. There are no known workarounds for this issue. Users are advised to upgrade.

    Published: 9 Dec 2022
    9.1
    Critical

    CVE-2022-23479

    Last Modified: 23 Apr 2025

    xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_mm_chan_data_in() function. There are no known workarounds for this issue. Users are advised to upgrade.

    Published: 9 Dec 2022
    9.1
    Critical

    CVE-2022-23478

    Last Modified: 23 Apr 2025

    xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Write in xrdp_mm_trans_process_drdynvc_channel_open() function. There are no known workarounds for this issue. Users are advised to upgrade.

    Published: 9 Dec 2022
    6.5
    Medium

    CVE-2022-23468

    Last Modified: 23 Apr 2025

    xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_login_wnd_create() function. There are no known workarounds for this issue. Users are advised to upgrade.

    Published: 9 Dec 2022
    9.1
    Critical

    CVE-2022-23493

    Last Modified: 23 Apr 2025

    xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_mm_trans_process_drdynvc_channel_close() function. There are no known workarounds for this issue. Users are advised to upgrade.

    Published: 9 Dec 2022
    6.5
    Medium

    CVE-2022-4264

    Last Modified: 23 Feb 2026

    Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration.

    Published: 9 Dec 2022
    5.5
    Medium

    CVE-2022-2752

    Last Modified: 22 Apr 2025

    A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions. This issue affects: Secomea GateManager versions from 9.4 through 9.7.

    Published: 9 Dec 2022
    7.8
    High

    CVE-2022-4378

    Last Modified: 10 Apr 2025

    A stack overflow flaw was found in the Linux kernel's SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.

    Published: 9 Dec 2022
    5.5
    Medium

    CVE-2022-33187

    Last Modified: 22 Apr 2025

    Brocade SANnav before v2.2.1 logs usernames and encoded passwords in debug-enabled logs. The vulnerability could allow an attacker with admin privilege to read sensitive information.

    Published: 9 Dec 2022
    9.8
    Critical

    CVE-2022-4170

    Last Modified: 14 Apr 2025

    The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.

    Published: 9 Dec 2022