CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-42718

    Last Modified: 24 Apr 2025

    Incorrect default permissions in the installation folder for NI LabVIEW Command Line Interface (CLI) may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 1 Dec 2022
    5
    Medium

    CVE-2022-4248

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, has been found in Movie Ticket Booking System. This issue affects some unknown processing of the file editBooking.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-214625 was assigned to this vulnerability.

    Published: 1 Dec 2022
    7.2
    High

    CVE-2022-3226

    Last Modified: 24 Apr 2025

    An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version 19.5 GA.

    Published: 1 Dec 2022
    3.5
    Low

    CVE-2022-4249

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, was found in Movie Ticket Booking System. Affected is an unknown function of the component POST Request Handler. The manipulation of the argument ORDER_ID leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-214626 is the identifier assigned to this vulnerability.

    Published: 1 Dec 2022
    8.8
    High

    CVE-2022-35120

    Last Modified: 24 Apr 2025

    IXPdata EasyInstall 6.6.14725 contains an access control issue.

    Published: 1 Dec 2022
    7.2
    High

    CVE-2022-3696

    Last Modified: 24 Apr 2025

    A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA.

    Published: 1 Dec 2022
    6.8
    Medium

    CVE-2022-3709

    Last Modified: 24 Apr 2025

    A stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sophos Firewall releases older than version 19.5 GA.

    Published: 1 Dec 2022
    4.3
    Medium

    CVE-2022-3711

    Last Modified: 23 Apr 2025

    A post-auth read-only SQL injection vulnerability allows users to read non-sensitive configuration database contents in the User Portal of Sophos Firewall releases older than version 19.5 GA.

    Published: 1 Dec 2022
    8.8
    High

    CVE-2022-3713

    Last Modified: 24 Apr 2025

    A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 GA.

    Published: 1 Dec 2022
    8.8
    High

    CVE-2022-40489

    Last Modified: 24 Apr 2025

    ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrator user to be injected into administrative users.

    Published: 1 Dec 2022
    5.4
    Medium

    CVE-2022-40849

    Last Modified: 24 Apr 2025

    ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS). An attacker who successfully exploited this vulnerability could inject a Persistent XSS payload in the Slideshow Management section that execute arbitrary JavaScript code on the client side, e.g., to steal the administrator's PHP session token (PHPSESSID).

    Published: 1 Dec 2022
    2.4
    Low

    CVE-2022-4251

    Last Modified: 15 Apr 2025

    A vulnerability was found in Movie Ticket Booking System and classified as problematic. Affected by this issue is some unknown functionality of the file editBooking.php. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214628.

    Published: 1 Dec 2022
    6.5
    Medium

    CVE-2022-23737

    Last Modified: 24 Apr 2025

    An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improper privileges to create or delete pages via the API. To exploit this vulnerability, an attacker would need to be added to an organization's repo with write permissions. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.7 and was fixed in versions 3.2.20, 3.3.15, 3.4.10, 3.5.7, and 3.6.3. This vulnerability was reported via the GitHub Bug Bounty program.

    Published: 1 Dec 2022
    9.8
    Critical

    CVE-2022-43333

    Last Modified: 24 Apr 2025

    Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the component action_export_control.php.

    Published: 1 Dec 2022
    5.9
    Medium

    CVE-2022-44212

    Last Modified: 24 Apr 2025

    In GL.iNet Goodcloud 1.0, insecure design allows remote attacker to access devices' admin panel.

    Published: 1 Dec 2022
    4.7
    Medium

    CVE-2022-29837

    Last Modified: 24 Apr 2025

    A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to initiate installation of custom ZIP packages and overwrite system files. This could potentially lead to a code execution.

    Published: 1 Dec 2022
    9.8
    Critical

    CVE-2022-36431

    Last Modified: 24 Apr 2025

    An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file. Issue fixed in version 7.9.6.1.

    Published: 1 Dec 2022
    9.8
    Critical

    CVE-2022-37016

    Last Modified: 24 Apr 2025

    Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

    Published: 1 Dec 2022
    7.5
    High

    CVE-2022-37017

    Last Modified: 24 Apr 2025

    Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing security controls. This CVE applies narrowly to the Client User Interface Password protection and Policy Import/Export Password protection, if it has been enabled.

    Published: 1 Dec 2022
    2.7
    Low

    CVE-2022-3710

    Last Modified: 23 Apr 2025

    A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database contents in the API controller of Sophos Firewall releases older than version 19.5 GA.

    Published: 1 Dec 2022
    7.5
    High

    CVE-2022-4244

    Last Modified: 5 May 2025

    A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outside the intended folder. By manipulating files with "dot-dot-slash (../)" sequences and their variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on the file system, including application source code, configuration, and other critical system files.

    Published: 1 Dec 2022
    4.3
    Medium

    CVE-2022-4246

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in Kakao PotPlayer. This affects an unknown part of the component MID File Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-214623.

    Published: 1 Dec 2022
    6.3
    Medium

    CVE-2022-4247

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical was found in Movie Ticket Booking System. This vulnerability affects unknown code of the file booking.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214624.

    Published: 1 Dec 2022
    6.3
    Medium

    CVE-2022-4257

    Last Modified: 15 Apr 2025

    A vulnerability was found in C-DATA Web Management System. It has been rated as critical. This issue affects some unknown processing of the file cgi-bin/jumpto.php of the component GET Parameter Handler. The manipulation of the argument hostname leads to argument injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-214631.

    Published: 1 Dec 2022
    7.4
    High

    CVE-2022-44211

    Last Modified: 24 Apr 2025

    In GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings.

    Published: 1 Dec 2022
    9.8
    Critical

    CVE-2022-44262

    Last Modified: 29 Apr 2025

    ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).

    Published: 1 Dec 2022
    8.8
    High

    CVE-2022-45045

    Last Modified: 24 Apr 2025

    Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow authenticated users to execute arbitrary commands as root, as exploited in the wild starting in approximately 2019. A remote and authenticated attacker, possibly using the default admin:tlJwpbo6 credentials, can connect to port 34567 and execute arbitrary operating system commands via a crafted JSON file during an upgrade request. Since at least 2021, Xiongmai has applied patches to prevent attackers from using this mechanism to execute telnetd.

    Published: 1 Dec 2022
    7.5
    High

    CVE-2022-45640

    Last Modified: 24 Apr 2025

    Tenda Tenda AC6V1.0 V15.03.05.19 is affected by buffer overflow. Causes a denial of service (local).

    Published: 1 Dec 2022
    9.8
    Critical

    CVE-2022-30528

    Last Modified: 24 Apr 2025

    SQL Injection vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to execute arbitrary commands via the username parameter to /system/user/modules/mod_users/controller.php.

    Published: 1 Dec 2022
    4.1
    Medium

    CVE-2022-40204

    Last Modified: 16 Apr 2025

    A cross-site scripting (XSS) vulnerability exists in all current versions of Digital Alert Systems DASDEC software via the Host Header in undisclosed pages after login.

    Published: 30 Nov 2022
    4.7
    Medium

    CVE-2019-18265

    Last Modified: 16 Apr 2025

    Digital Alert Systems’ DASDEC software prior to version 4.1 contains a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via the SSH username, username field of the login page, or via the HTTP host header. The injected content is stored in logs and rendered when viewed in the web application.

    Published: 30 Nov 2022
    6.5
    Medium

    CVE-2022-42446

    Last Modified: 24 Apr 2025

    Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to browse the User Directory and potentially create chats with internal users.

    Published: 30 Nov 2022
    7.2
    High

    CVE-2022-44533

    Last Modified: 24 Apr 2025

    A vulnerability in the Aruba EdgeConnect Enterprise web management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.

    Published: 30 Nov 2022
    4.9
    Medium

    CVE-2022-44532

    Last Modified: 24 Apr 2025

    An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.

    Published: 30 Nov 2022
    7.2
    High

    CVE-2022-43542

    Last Modified: 24 Apr 2025

    Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.

    Published: 30 Nov 2022
    7.2
    High

    CVE-2022-43541

    Last Modified: 24 Apr 2025

    Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.

    Published: 30 Nov 2022
    4.9
    Medium

    CVE-2022-43518

    Last Modified: 24 Apr 2025

    An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise web interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.

    Published: 30 Nov 2022
    5.5
    Medium

    CVE-2022-37926

    Last Modified: 24 Apr 2025

    A vulnerability within the web-based management interface of EdgeConnect Enterprise could allow a remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface by uploading a specially crafted file. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.

    Published: 30 Nov 2022
    6.1
    Medium

    CVE-2022-37925

    Last Modified: 24 Apr 2025

    A vulnerability within the web-based management interface of Aruba EdgeConnect Enterprise could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.

    Published: 30 Nov 2022
    7.2
    High

    CVE-2022-37924

    Last Modified: 24 Apr 2025

    Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.

    Published: 30 Nov 2022
    7.2
    High

    CVE-2022-37923

    Last Modified: 24 Apr 2025

    Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.

    Published: 30 Nov 2022
    7.2
    High

    CVE-2022-37922

    Last Modified: 24 Apr 2025

    Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.

    Published: 30 Nov 2022
    7.2
    High

    CVE-2022-37921

    Last Modified: 24 Apr 2025

    Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.

    Published: 30 Nov 2022
    7.2
    High

    CVE-2022-37920

    Last Modified: 24 Apr 2025

    Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.

    Published: 30 Nov 2022
    7.5
    High

    CVE-2022-37919

    Last Modified: 24 Apr 2025

    A vulnerability exists in the API of Aruba EdgeConnect Enterprise. An unauthenticated attacker can exploit this condition via the web-based management interface to create a denial-of-service condition which prevents the appliance from properly responding to API requests in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below;

    Published: 30 Nov 2022
    8.8
    High

    CVE-2022-37932

    Last Modified: 24 Apr 2025

    A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches. The vulnerability could be remotely exploited to allow authentication bypass. HPE has made the following software updates to resolve the vulnerability in Hewlett Packard Enterprise OfficeConnect 1820, 1850 and 1920S Network switches versions: Prior to PT.02.14; Prior to PC.01.22; Prior to PO.01.21; Prior to PD.02.22;

    Published: 30 Nov 2022
    5.3
    Medium

    CVE-2022-1911

    Last Modified: 23 Feb 2026

    Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated access to some information of the underlying operating system.

    Published: 30 Nov 2022
    2.4
    Low

    CVE-2022-1606

    Last Modified: 23 Feb 2026

    Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to read unmanaged objects.

    Published: 30 Nov 2022
    5.3
    Medium

    CVE-2022-45842

    Last Modified: 14 Mar 2025

    Unauth. Race Condition vulnerability in WP ULike Plugin <= 4.6.4 on WordPress allows attackers to increase/decrease rating scores.

    Published: 30 Nov 2022
    5.4
    Medium

    CVE-2022-26366

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) in AdRotate Banner Manager Plugin <= 5.9 on WordPress.

    Published: 30 Nov 2022