CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-27773

    Last Modified: 24 Apr 2025

    A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elevated privileges.

    Published: 5 Dec 2022
    4.9
    Medium

    CVE-2022-42706

    Last Modified: 24 Apr 2025

    An issue was discovered in Sangoma Asterisk through 16.28, 17 and 18 through 18.14, 19 through 19.6, and certified through 18.9-cert1. GetConfig, via Asterisk Manager Interface, allows a connected application to access files outside of the asterisk configuration directory, aka Directory Traversal.

    Published: 5 Dec 2022
    7.5
    High

    CVE-2022-45019

    Last Modified: 24 Apr 2025

    SLiMS 9 Bulian v9.5.0 was discovered to contain a SQL injection vulnerability via the keywords parameter.

    Published: 5 Dec 2022
    6.7
    Medium

    CVE-2022-32596

    Last Modified: 24 Apr 2025

    In widevine, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07446213; Issue ID: ALPS07446213.

    Published: 5 Dec 2022
    6.7
    Medium

    CVE-2022-32619

    Last Modified: 24 Apr 2025

    In keyinstall, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07439659; Issue ID: ALPS07439659.

    Published: 5 Dec 2022
    6.7
    Medium

    CVE-2022-32620

    Last Modified: 24 Apr 2025

    In mpu, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07541753; Issue ID: ALPS07541753.

    Published: 5 Dec 2022
    6.7
    Medium

    CVE-2022-32629

    Last Modified: 24 Apr 2025

    In isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310774; Issue ID: ALPS07310774.

    Published: 5 Dec 2022
    6.7
    Medium

    CVE-2022-32630

    Last Modified: 24 Apr 2025

    In throttling, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07405966; Issue ID: ALPS07405966.

    Published: 5 Dec 2022
    6.7
    Medium

    CVE-2022-32633

    Last Modified: 24 Apr 2025

    In Wi-Fi, there is a possible memory access violation due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441637; Issue ID: ALPS07441637.

    Published: 5 Dec 2022
    9.8
    Critical

    CVE-2022-42496

    Last Modified: 24 Apr 2025

    OS command injection vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to obtain appkey of the product and execute an arbitrary OS command on the product.

    Published: 5 Dec 2022
    7.8
    High

    CVE-2022-35259

    Last Modified: 24 Apr 2025

    XML Injection with Endpoint Manager 2022. 3 and below causing a download of a malicious file to run and possibly execute to gain unauthorized privileges.

    Published: 5 Dec 2022
    7.5
    High

    CVE-2022-3596

    Last Modified: 21 Nov 2024

    An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discovering the IP address of the undercloud, possibly leading to compromising private information, including administrator access credentials.

    Published: 5 Dec 2022
    7.5
    High

    CVE-2022-37325

    Last Modified: 24 Apr 2025

    In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash.

    Published: 5 Dec 2022
    7.5
    High

    CVE-2022-37783

    Last Modified: 21 Nov 2024

    All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSRF-Tokens. Craft CMS uses a cookie called CRAFT_CSRF_TOKEN and a HTML hidden field called CRAFT_CSRF_TOKEN to avoid Cross Site Request Forgery attacks. The CRAFT_CSRF_TOKEN cookie discloses the password hash in without encoding it whereas the corresponding HTML hidden field discloses the users' password hash in a masked manner, which can be decoded by using public functions of the YII framework.

    Published: 5 Dec 2022
    8.1
    High

    CVE-2022-38336

    Last Modified: 24 Apr 2025

    An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without authentication.

    Published: 5 Dec 2022
    7.5
    High

    CVE-2022-41777

    Last Modified: 24 Apr 2025

    Improper check or handling of exceptional conditions vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to inject an invalid value to decodeURIComponent of nako3edit, which may lead the server to crash.

    Published: 5 Dec 2022
    7.5
    High

    CVE-2021-39434

    Last Modified: 24 Apr 2025

    A default username and password for an administrator account was discovered in ZKTeco ZKTime 10.0 through 11.1.0, builds 20180901, 20190510.1, 20200309.3, 20200930, 20201231, and 20210220.

    Published: 5 Dec 2022
    9.8
    Critical

    CVE-2022-43549

    Last Modified: 24 Apr 2025

    Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.

    Published: 5 Dec 2022
    8.8
    High

    CVE-2022-43553

    Last Modified: 24 Apr 2025

    A remote code execution vulnerability in EdgeRouters (Version 2.0.9-hotfix.4 and earlier) allows a malicious actor with an operator account to run arbitrary administrator commands.This vulnerability is fixed in Version 2.0.9-hotfix.5 and later.

    Published: 5 Dec 2022
    6.1
    Medium

    CVE-2022-43556

    Last Modified: 24 Apr 2025

    Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XSS in the text input field since the result dashboard page output is not sanitized. The Concrete CMS security team has ranked this 4.2 with CVSS v3.1 vector AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N Thanks @_akbar_jafarli_ for reporting. Remediate by updating to Concrete CMS 8.5.10 and Concrete CMS 9.1.3.

    Published: 5 Dec 2022
    8.1
    High

    CVE-2022-24439

    Last Modified: 3 Nov 2025

    All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments.

    Published: 5 Dec 2022
    8.8
    High

    CVE-2022-45771

    Last Modified: 24 Apr 2025

    An issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary code via uploading a crafted audit file.

    Published: 5 Dec 2022
    6.1
    Medium

    CVE-2022-45769

    Last Modified: 24 Apr 2025

    A cross-site scripting (XSS) vulnerability in ClicShopping_V3 v3.402 allows attackers to execute arbitrary web scripts or HTML via a crafted URL parameter.

    Published: 5 Dec 2022
    6.1
    Medium

    CVE-2022-45990

    Last Modified: 24 Apr 2025

    A cross-site scripting (XSS) vulnerability in the component /signup_script.php of Ecommerce-Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the eMail parameter.

    Published: 5 Dec 2022
    —
    Unknown

    CVE-2022-46464

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 5 Dec 2022
    —
    Unknown

    CVE-2022-46620

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 5 Dec 2022
    —
    Unknown

    CVE-2022-46621

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 5 Dec 2022
    6.7
    Medium

    CVE-2022-32597

    Last Modified: 24 Apr 2025

    In widevine, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07446228; Issue ID: ALPS07446228.

    Published: 5 Dec 2022
    6.7
    Medium

    CVE-2022-32598

    Last Modified: 24 Apr 2025

    In widevine, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07446228; Issue ID: ALPS07446228.

    Published: 5 Dec 2022
    6.7
    Medium

    CVE-2022-32622

    Last Modified: 24 Apr 2025

    In gz, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363786; Issue ID: ALPS07363786.

    Published: 5 Dec 2022
    6.7
    Medium

    CVE-2022-32624

    Last Modified: 24 Apr 2025

    In throttling, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07405923; Issue ID: ALPS07405923.

    Published: 5 Dec 2022
    6.7
    Medium

    CVE-2022-32625

    Last Modified: 24 Apr 2025

    In display, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326216; Issue ID: ALPS07326216.

    Published: 5 Dec 2022
    6.7
    Medium

    CVE-2022-32626

    Last Modified: 24 Apr 2025

    In display, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326239; Issue ID: ALPS07326239.

    Published: 5 Dec 2022
    6.7
    Medium

    CVE-2022-32628

    Last Modified: 24 Apr 2025

    In isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310780; Issue ID: ALPS07310780.

    Published: 5 Dec 2022
    6.7
    Medium

    CVE-2022-32631

    Last Modified: 24 Apr 2025

    In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453613; Issue ID: ALPS07453613.

    Published: 5 Dec 2022
    6.7
    Medium

    CVE-2022-32632

    Last Modified: 24 Apr 2025

    In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441630; Issue ID: ALPS07441630.

    Published: 5 Dec 2022
    6.7
    Medium

    CVE-2022-32634

    Last Modified: 24 Apr 2025

    In ccci, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138646; Issue ID: ALPS07138646.

    Published: 5 Dec 2022
    7.5
    High

    CVE-2022-35254

    Last Modified: 24 Apr 2025

    An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust Access in versions prior to 22.3R1.

    Published: 5 Dec 2022
    7.5
    High

    CVE-2022-35258

    Last Modified: 21 Nov 2024

    An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust Access in versions prior to 22.3R1.

    Published: 5 Dec 2022
    9.1
    Critical

    CVE-2022-38337

    Last Modified: 24 Apr 2025

    When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server. The server treats this as an invalid login attempt which can result in a Denial of Service (DoS) for the user if services like fail2ban are used.

    Published: 5 Dec 2022
    9.8
    Critical

    CVE-2022-41642

    Last Modified: 24 Apr 2025

    OS command injection vulnerability in Nadesiko3 (PC Version) v3.3.61 and earlier allows a remote attacker to execute an arbitrary OS command when processing compression and decompression on the product.

    Published: 5 Dec 2022
    6.5
    Medium

    CVE-2022-41798

    Last Modified: 24 Apr 2025

    Session information easily guessable vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacent attacker to log in to the product by spoofing a user with guessed session information. Affected products/versions are as follows: TASKalfa 7550ci/6550ci, TASKalfa 5550ci/4550ci/3550ci/3050ci, TASKalfa 255c/205c, TASKalfa 256ci/206ci, ECOSYS M6526cdn/M6526cidn, FS-C2126MFP/C2126MFP+/C2026MFP/C2026MFP+, TASKalfa 8000i/6500i, TASKalfa 5500i/4500i/3500i, TASKalfa 305/255, TASKalfa 306i/256i, LS-3140MFP/3140MFP+/3640MFP, ECOSYS M2535dn, LS-1135MFP/1035MFP, LS-C8650DN/C8600DN, ECOSYS P6026cdn, FS-C5250DN, LS-4300DN/4200DN/2100DN, ECOSYS P4040dn, ECOSYS P2135dn, and FS-1370DN.

    Published: 5 Dec 2022
    6.5
    Medium

    CVE-2022-41807

    Last Modified: 24 Apr 2025

    Missing authorization vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacent attacker to alter the product settings without authentication by sending a specially crafted request. Affected products/versions are as follows: TASKalfa 7550ci/6550ci, TASKalfa 5550ci/4550ci/3550ci/3050ci, TASKalfa 255c/205c, TASKalfa 256ci/206ci, ECOSYS M6526cdn/M6526cidn, FS-C2126MFP/C2126MFP+/C2026MFP/C2026MFP+, TASKalfa 8000i/6500i, TASKalfa 5500i/4500i/3500i, TASKalfa 305/255, TASKalfa 306i/256i, LS-3140MFP/3140MFP+/3640MFP, ECOSYS M2535dn, LS-1135MFP/1035MFP, LS-C8650DN/C8600DN, ECOSYS P6026cdn, FS-C5250DN, LS-4300DN/4200DN/2100DN, ECOSYS P4040dn, ECOSYS P2135dn, and FS-1370DN.

    Published: 5 Dec 2022
    4.8
    Medium

    CVE-2022-41830

    Last Modified: 24 Apr 2025

    Stored cross-site scripting vulnerability in Kyocera Document Solutions MFPs and printers allows a remote authenticated attacker with an administrative privilege to inject arbitrary script. Affected products/versions are as follows: TASKalfa 7550ci/6550ci, TASKalfa 5550ci/4550ci/3550ci/3050ci, TASKalfa 255c/205c, TASKalfa 256ci/206ci, ECOSYS M6526cdn/M6526cidn, FS-C2126MFP/C2126MFP+/C2026MFP/C2026MFP+, TASKalfa 8000i/6500i, TASKalfa 5500i/4500i/3500i, TASKalfa 305/255, TASKalfa 306i/256i, LS-3140MFP/3140MFP+/3640MFP, ECOSYS M2535dn, LS-1135MFP/1035MFP, LS-C8650DN/C8600DN, ECOSYS P6026cdn, FS-C5250DN, LS-4300DN/4200DN/2100DN, ECOSYS P4040dn, ECOSYS P2135dn, and FS-1370DN.

    Published: 5 Dec 2022
    6.5
    Medium

    CVE-2022-42705

    Last Modified: 24 Apr 2025

    A use-after-free in res_pjsip_pubsub.c in Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2 may allow a remote authenticated attacker to crash Asterisk (denial of service) by performing activity on a subscription via a reliable transport at the same time that Asterisk is also performing activity on that subscription.

    Published: 5 Dec 2022
    6.1
    Medium

    CVE-2022-43487

    Last Modified: 24 Apr 2025

    Cross-site scripting vulnerability in Salon booking system versions prior to 7.9 allows a remote unauthenticated attacker to inject an arbitrary script.

    Published: 5 Dec 2022
    5.3
    Medium

    CVE-2022-43504

    Last Modified: 24 Apr 2025

    Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all versions since 3.7.

    Published: 5 Dec 2022
    9.8
    Critical

    CVE-2022-44039

    Last Modified: 24 Apr 2025

    Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrite (remote). ¶¶ An attacker can overwrite system files like [system.conf] and [passwd], this occurs because the insecure usage of "fopen" system function with the mode "wb" which allows overwriting file if exists. Overwriting files such as passwd, allows an attacker to escalate his privileges by planting backdoor user with root privilege or change root password.

    Published: 5 Dec 2022
    8.8
    High

    CVE-2022-45020

    Last Modified: 24 Apr 2025

    Rukovoditel v3.2.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in the component /rukovoditel/index.php?module=users/login. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

    Published: 5 Dec 2022
    —
    Unknown

    CVE-2022-45046

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 5 Dec 2022