CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-44929

    Last Modified: 24 Apr 2025

    An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles.

    Published: 2 Dec 2022
    9.8
    Critical

    CVE-2022-44930

    Last Modified: 24 Apr 2025

    D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function.

    Published: 2 Dec 2022
    5.4
    Medium

    CVE-2022-44944

    Last Modified: 24 Apr 2025

    Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Announcement function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.

    Published: 2 Dec 2022
    9.8
    Critical

    CVE-2022-44945

    Last Modified: 24 Apr 2025

    Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter.

    Published: 2 Dec 2022
    5.4
    Medium

    CVE-2022-44946

    Last Modified: 24 Apr 2025

    Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Page function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.

    Published: 2 Dec 2022
    5.4
    Medium

    CVE-2022-44947

    Last Modified: 24 Apr 2025

    Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Highlight Row feature at /index.php?module=entities/listing_types&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Note field after clicking "Add".

    Published: 2 Dec 2022
    5.4
    Medium

    CVE-2022-44949

    Last Modified: 24 Apr 2025

    Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Short Name field.

    Published: 2 Dec 2022
    5.4
    Medium

    CVE-2022-44950

    Last Modified: 24 Apr 2025

    Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

    Published: 2 Dec 2022
    5.4
    Medium

    CVE-2022-44951

    Last Modified: 24 Apr 2025

    Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab function at /index.php?module=entities/forms&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

    Published: 2 Dec 2022
    5.4
    Medium

    CVE-2022-44952

    Last Modified: 24 Apr 2025

    Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in /index.php?module=configuration/application. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Copyright Text field after clicking "Add".

    Published: 2 Dec 2022
    5.4
    Medium

    CVE-2022-44953

    Last Modified: 24 Apr 2025

    webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /linkedcontent/listfiles.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field after clicking "Add".

    Published: 2 Dec 2022
    5.4
    Medium

    CVE-2022-44954

    Last Modified: 24 Apr 2025

    webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /contacts/listcontacts.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name field after clicking "Add".

    Published: 2 Dec 2022
    5.4
    Medium

    CVE-2022-44960

    Last Modified: 24 Apr 2025

    webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /general/search.php?searchtype=simple. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search field.

    Published: 2 Dec 2022
    5.4
    Medium

    CVE-2022-44961

    Last Modified: 24 Apr 2025

    webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /forums/editforum.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.

    Published: 2 Dec 2022
    5.4
    Medium

    CVE-2022-44962

    Last Modified: 24 Apr 2025

    webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /calendar/viewcalendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Subject field.

    Published: 2 Dec 2022
    5.4
    Medium

    CVE-2022-45215

    Last Modified: 24 Apr 2025

    A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the Add New System User module.

    Published: 2 Dec 2022
    8.8
    High

    CVE-2022-45562

    Last Modified: 24 Apr 2025

    Insecure permissions in Telos Alliance Omnia MPX Node v1.0.0 to v1.4.9 allow attackers to manipulate and access system settings with backdoor account low privilege, this can lead to change hardware settings and execute arbitrary commands in vulnerable system functions that is requires high privilege to access.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45648

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the devName parameter in the formSetDeviceName function.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45650

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the firewallEn parameter in the formSetFirewallCfg function.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45651

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the list parameter in the formSetVirtualSer function.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45652

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the startIp parameter in the formSetPPTPServer function.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45653

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the page parameter in the fromNatStaticSetting function.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45654

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the ssid parameter in the form_fast_setting_wifi_set function.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45655

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the timeZone parameter in the form_fast_setting_wifi_set function.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45657

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45660

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the schedStartTime parameter in the setSchedWifi function.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45661

    Last Modified: 24 Apr 2025

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the time parameter in the setSmartPowerManagement function.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45663

    Last Modified: 24 Apr 2025

    Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet function.

    Published: 2 Dec 2022
    7.5
    High

    CVE-2022-45664

    Last Modified: 24 Apr 2025

    Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDget function.

    Published: 2 Dec 2022
    6.5
    Medium

    CVE-2022-45667

    Last Modified: 23 Apr 2025

    Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.

    Published: 2 Dec 2022
    4.8
    Medium

    CVE-2022-41971

    Last Modified: 23 Apr 2025

    Nextcould Talk android is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.8, 13.0.10, 14.0.6, and 15.0.0, guests can continue to receive video streams from a call after being removed from a conversation. An attacker would be able to see videos on a call in a public conversation after being removed from that conversation, provided that they were removed while being in the call. Versions 12.2.8, 13.0.10, 14.0.6, and 15.0.0 contain patches for the issue. No known workarounds are available.

    Published: 1 Dec 2022
    2.6
    Low

    CVE-2022-41970

    Last Modified: 23 Apr 2025

    Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares still allow download through preview images. Images could be downloaded and previews of documents (first page) can be downloaded without being watermarked. Versions 24.0.7 and 25.0.1 contain a fix for this issue. No known workarounds are available.

    Published: 1 Dec 2022
    2.4
    Low

    CVE-2022-41969

    Last Modified: 23 Apr 2025

    Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.11, 24.0.7, and 25.0.0, there is no password length limit when creating a user as an administrator. An administrator can cause a limited DoS attack against their own server. Versions 23.0.11, 24.0.7, and 25.0.0 contain a fix for the issue. As a workaround, don't create user accounts with long passwords.

    Published: 1 Dec 2022
    3.5
    Low

    CVE-2022-41968

    Last Modified: 23 Apr 2025

    Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths are not validated before writing to a database. As a result, an attacker can send unnecessary amounts of data against the database. Version 23.0.10 and 24.0.5 contain patches for the issue. No known workarounds are available.

    Published: 1 Dec 2022
    5.7
    Medium

    CVE-2022-43901

    Last Modified: 23 Apr 2025

    IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.3 could disclose sensitive information. An authenticated local attacker could exploit this vulnerability to possibly gain information to other IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps components. IBM X-Force ID: 240829.

    Published: 1 Dec 2022
    5.3
    Medium

    CVE-2022-43900

    Last Modified: 23 Apr 2025

    IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A local attacker can create an outbound network connection to another system. IBM X-Force ID: 240827.

    Published: 1 Dec 2022
    4.3
    Medium

    CVE-2022-41297

    Last Modified: 24 Apr 2025

    IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237212.

    Published: 1 Dec 2022
    6.5
    Medium

    CVE-2022-41296

    Last Modified: 25 Feb 2026

    IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237210.

    Published: 1 Dec 2022
    8.1
    High

    CVE-2022-2969

    Last Modified: 16 Apr 2025

    Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or directory located underneath a restricted parent directory. However, the software does not properly neutralize special elements within the pathname, which can cause the pathname to resolve to a location outside of the restricted directory.

    Published: 1 Dec 2022
    5.4
    Medium

    CVE-2021-38997

    Last Modified: 23 Apr 2025

    IBM API Connect V10.0.0.0 through V10.0.5.0, V10.0.1.0 through V10.0.1.7, and V2018.4.1.0 through 2018.4.1.19 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 213212.

    Published: 1 Dec 2022
    7.1
    High

    CVE-2022-45797

    Last Modified: 24 Apr 2025

    An arbitrary file deletion vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could allow a local attacker to escalate privileges and delete files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 1 Dec 2022
    9.8
    Critical

    CVE-2022-3270

    Last Modified: 24 Apr 2025

    In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.

    Published: 1 Dec 2022
    9.8
    Critical

    CVE-2022-4221

    Last Modified: 14 Apr 2025

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated attacker to inject arbitrary OS commands via unsanitized cookie values.This issue affects NAS-M25: through 1.0.1.7.

    Published: 1 Dec 2022
    6.1
    Medium

    CVE-2022-45050

    Last Modified: 25 Apr 2025

    A reflected XSS vulnerability has been found in Axiell Iguana CMS, allowing an attacker to execute code in a victim's browser. The title parameter on the twitter.php endpoint does not properly neutralise user input, resulting in the vulnerability.

    Published: 1 Dec 2022
    4.3
    Medium

    CVE-2022-4245

    Last Modified: 21 Nov 2024

    A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.

    Published: 1 Dec 2022
    3.5
    Low

    CVE-2022-4250

    Last Modified: 15 Apr 2025

    A vulnerability has been found in Movie Ticket Booking System and classified as problematic. Affected by this vulnerability is an unknown functionality of the file booking.php. The manipulation of the argument id leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-214627.

    Published: 1 Dec 2022
    5.5
    Medium

    CVE-2023-23005

    Last Modified: 19 Mar 2025

    In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case, whereas it is actually an error pointer). NOTE: this is disputed by third parties because there are no realistic cases in which a user can cause the alloc_memory_type error case to be reached.

    Published: 1 Dec 2022
    3.5
    Low

    CVE-2022-4252

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Canteen Management System. It has been classified as problematic. This affects the function builtin_echo of the file categories.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-214629 was assigned to this vulnerability.

    Published: 1 Dec 2022
    3.5
    Low

    CVE-2022-4253

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Canteen Management System. It has been declared as problematic. This vulnerability affects the function builtin_echo of the file customer.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-214630 is the identifier assigned to this vulnerability.

    Published: 1 Dec 2022
    7.5
    High

    CVE-2022-28607

    Last Modified: 24 Apr 2025

    An issue was discovered in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to gain sensitive information via the action parameter to /system/user/modules/mod_users/controller.php.

    Published: 1 Dec 2022