CVE Feed

    Dashboard / CVE

    2
    Low

    CVE-2022-4270

    Last Modified: 23 Feb 2026

    Incorrect privilege assignment issue in M-Files Web in M-Files Web versions before 22.5.11436.1 could have changed permissions accidentally.

    Published: 2 Dec 2022
    8.8
    High

    CVE-2022-2808

    Last Modified: 20 May 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Algan Software Prens Student Information System allows Object Relational Mapping Injection. This issue affects Prens Student Information System: before 2.1.11.

    Published: 2 Dec 2022
    9.8
    Critical

    CVE-2022-2807

    Last Modified: 20 May 2026

    SQL Injection vulnerability in Algan Software Prens Student Information System allows SQL Injection. This issue affects Prens Student Information System: before 2.1.11.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45670

    Last Modified: 24 Apr 2025

    Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the ping1 parameter in the formSetAutoPing function.

    Published: 2 Dec 2022
    9.8
    Critical

    CVE-2022-43325

    Last Modified: 24 Apr 2025

    An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows attackers to execute arbitrary commands via a crafted payload injected into the license input.

    Published: 2 Dec 2022
    7.2
    High

    CVE-2022-44347

    Last Modified: 24 Apr 2025

    Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=inquiries/view_inquiry&id=.

    Published: 2 Dec 2022
    9.8
    Critical

    CVE-2022-44362

    Last Modified: 24 Apr 2025

    Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/AddSysLogRule.

    Published: 2 Dec 2022
    9.8
    Critical

    CVE-2022-44363

    Last Modified: 24 Apr 2025

    Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setSnmpInfo.

    Published: 2 Dec 2022
    9.8
    Critical

    CVE-2022-44367

    Last Modified: 24 Apr 2025

    Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setUplinkInfo.

    Published: 2 Dec 2022
    9.8
    Critical

    CVE-2022-44366

    Last Modified: 24 Apr 2025

    Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setDiagnoseInfo.

    Published: 2 Dec 2022
    5.9
    Medium

    CVE-2022-45480

    Last Modified: 24 Apr 2025

    PC Keyboard WiFi & Bluetooth allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

    Published: 2 Dec 2022
    9.8
    Critical

    CVE-2022-45482

    Last Modified: 24 Apr 2025

    Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticated users to easily and quickly brute force the PIN and execute arbitrary commands. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

    Published: 2 Dec 2022
    5.9
    Medium

    CVE-2022-45483

    Last Modified: 24 Apr 2025

    Lazy Mouse allows an attacker (in a man in the middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45641

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 is vulnerable to Buffer Overflow via formSetMacFilterCfg.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45643

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the deviceId parameter in the addWifiMacFilter function.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45644

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the deviceId parameter in the formSetClientState function.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45645

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the deviceMac parameter in the addWifiMacFilter function.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45646

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the limitSpeedUp parameter in the formSetClientState function.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45647

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the limitSpeed parameter in the formSetClientState function.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45649

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the endIp parameter in the formSetPPTPServer function.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45656

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the time parameter in the fromSetSysTime function.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45658

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the schedEndTime parameter in the setSchedWifi function.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45659

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the wpapsk_crypto parameter in the fromSetWirelessRepeat function.

    Published: 2 Dec 2022
    6.5
    Medium

    CVE-2022-45668

    Last Modified: 24 Apr 2025

    Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45669

    Last Modified: 24 Apr 2025

    Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterGet function.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45671

    Last Modified: 24 Apr 2025

    Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the appData parameter in the formSetAppFilterRule function.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45672

    Last Modified: 24 Apr 2025

    Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the formWx3AuthorizeSet function.

    Published: 2 Dec 2022
    6.5
    Medium

    CVE-2022-45673

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.

    Published: 2 Dec 2022
    6.5
    Medium

    CVE-2022-45674

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

    Published: 2 Dec 2022
    8.8
    High

    CVE-2022-4262

    Last Modified: 24 Oct 2025

    Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Dec 2022
    5.4
    Medium

    CVE-2022-4271

    Last Modified: 14 Apr 2025

    Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to 1.16.4.

    Published: 2 Dec 2022
    5.4
    Medium

    CVE-2022-44948

    Last Modified: 24 Apr 2025

    Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group feature at/index.php?module=entities/entities_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field after clicking "Add".

    Published: 2 Dec 2022
    5.4
    Medium

    CVE-2022-44955

    Last Modified: 24 Apr 2025

    webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the Chat function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Messages field.

    Published: 2 Dec 2022
    5.4
    Medium

    CVE-2022-44956

    Last Modified: 24 Apr 2025

    webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /projects/listprojects.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

    Published: 2 Dec 2022
    5.4
    Medium

    CVE-2022-44957

    Last Modified: 24 Apr 2025

    webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /clients/listclients.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

    Published: 2 Dec 2022
    5.4
    Medium

    CVE-2022-44959

    Last Modified: 24 Apr 2025

    webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /meetings/listmeetings.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

    Published: 2 Dec 2022
    9.8
    Critical

    CVE-2022-3520

    Last Modified: 23 Apr 2025

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.

    Published: 2 Dec 2022
    7.8
    High

    CVE-2022-4292

    Last Modified: 14 Apr 2025

    Use After Free in GitHub repository vim/vim prior to 9.0.0882.

    Published: 2 Dec 2022
    9.8
    Critical

    CVE-2022-44290

    Last Modified: 24 Apr 2025

    webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.

    Published: 2 Dec 2022
    9.8
    Critical

    CVE-2022-44291

    Last Modified: 24 Apr 2025

    webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.

    Published: 2 Dec 2022
    9.8
    Critical

    CVE-2022-46366

    Last Modified: 21 Nov 2024

    Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability only affects Apache Tapestry version line 3.x, which is no longer supported by the maintainer. Users are recommended to upgrade to a supported version line of Apache Tapestry.

    Published: 2 Dec 2022
    7.8
    High

    CVE-2022-3591

    Last Modified: 24 Sept 2026

    Use After Free in GitHub repository vim/vim prior to 9.0.0789.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-43272

    Last Modified: 3 Nov 2025

    DCMTK v3.6.7 was discovered to contain a memory leak via the T_ASC_Association object.

    Published: 2 Dec 2022
    8.8
    High

    CVE-2022-4223

    Last Modified: 14 Apr 2025

    The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities such as pg_dump and pg_restore. The utility is executed by the server to determine what PostgreSQL version it is from. Versions of pgAdmin prior to 6.17 failed to properly secure this API, which could allow an unauthenticated user to call it with a path of their choosing, such as a UNC path to a server they control on a Windows machine. This would cause an appropriately named executable in the target path to be executed by the pgAdmin server.

    Published: 2 Dec 2022
    5.5
    Medium

    CVE-2022-4293

    Last Modified: 14 Apr 2025

    Floating Point Comparison with Incorrect Operator in GitHub repository vim/vim prior to 9.0.0804.

    Published: 2 Dec 2022
    7.2
    High

    CVE-2022-44277

    Last Modified: 24 Apr 2025

    Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/classes/Master.php?f=delete_product.

    Published: 2 Dec 2022
    7.2
    High

    CVE-2022-44345

    Last Modified: 24 Apr 2025

    Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=quotes/view_quote&id=.

    Published: 2 Dec 2022
    7.2
    High

    CVE-2022-44348

    Last Modified: 24 Apr 2025

    Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/update_status.php?id=.

    Published: 2 Dec 2022
    9.8
    Critical

    CVE-2022-44365

    Last Modified: 24 Apr 2025

    Tenda i21 V1.0.0.14(4656) has a stack overflow vulnerability via /goform/setSysPwd.

    Published: 2 Dec 2022
    9.8
    Critical

    CVE-2022-44928

    Last Modified: 24 Apr 2025

    D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.

    Published: 2 Dec 2022