CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2022-45863

    Last Modified: 17 Mar 2025

    Not used

    Published: 23 Nov 2022
    —
    Unknown

    CVE-2022-45864

    Last Modified: 17 Mar 2025

    Not used

    Published: 23 Nov 2022
    7.8
    High

    CVE-2023-2236

    Last Modified: 5 Mar 2025

    A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Both io_install_fixed_file and its callers call fput in a file in case of an error, causing a reference underflow which leads to a use-after-free vulnerability. We recommend upgrading past commit 9d94c04c0db024922e886c9fd429659f22f48ea4.

    Published: 23 Nov 2022
    5.5
    Medium

    CVE-2023-0469

    Last Modified: 1 Apr 2025

    A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Linux Kernel during call cleanup. This flaw may lead to a denial of service.

    Published: 23 Nov 2022
    3.1
    Low

    CVE-2022-4045

    Last Modified: 6 Dec 2024

    A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple requests to one of the API endpoints which could fetch a large amount of data. 

    Published: 23 Nov 2022
    4.3
    Medium

    CVE-2022-4044

    Last Modified: 6 Dec 2024

    A denial-of-service vulnerability in Mattermost allows an authenticated user to crash the server via multiple large autoresponder messages.

    Published: 23 Nov 2022
    4.3
    Medium

    CVE-2022-4019

    Last Modified: 6 Dec 2024

    A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to one of the Playbooks API endpoints.

    Published: 23 Nov 2022
    5.4
    Medium

    CVE-2022-35500

    Last Modified: 28 Apr 2025

    Amasty Blog 2.10.3 is vulnerable to Cross Site Scripting (XSS) via leave comment functionality.

    Published: 23 Nov 2022
    7.2
    High

    CVE-2022-39833

    Last Modified: 25 Apr 2025

    FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported API endpoints via a crafted HTTP request.

    Published: 23 Nov 2022
    4.9
    Medium

    CVE-2022-40771

    Last Modified: 28 Apr 2025

    Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External Entity attack that leads to Information Disclosure.

    Published: 23 Nov 2022
    0
    Low

    CVE-2022-4133

    Last Modified: 7 Nov 2023

    We were unable to verify this vulnerbility.

    Published: 23 Nov 2022
    8.1
    High

    CVE-2022-41922

    Last Modified: 23 Apr 2025

    `yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. This has been patched in 1.1.27.

    Published: 23 Nov 2022
    4.9
    Medium

    CVE-2022-41929

    Last Modified: 22 Apr 2025

    org.xwiki.platform:xwiki-platform-oldcore is missing authorization in User#setDisabledStatus, which may allow an incorrectly authorized user with only Script rights to enable or disable a user. This operation is meant to only be available for users with admin rights. This problem has been patched in XWiki 13.10.7, 14.4.2 and 14.5RC1.

    Published: 23 Nov 2022
    9.1
    Critical

    CVE-2022-43196

    Last Modified: 28 Apr 2025

    dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php.

    Published: 23 Nov 2022
    7.5
    High

    CVE-2022-41932

    Last Modified: 23 Apr 2025

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to make XWiki create many new schemas and fill them with tables just by using a crafted user identifier in the login form. This may lead to degraded database performance. The problem has been patched in XWiki 13.10.8, 14.6RC1 and 14.4.2. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 23 Nov 2022
    9.8
    Critical

    CVE-2022-44118

    Last Modified: 28 Apr 2025

    dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php.

    Published: 23 Nov 2022
    9.8
    Critical

    CVE-2022-44139

    Last Modified: 25 Apr 2025

    Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php.

    Published: 23 Nov 2022
    9.8
    Critical

    CVE-2022-44250

    Last Modified: 25 Apr 2025

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.

    Published: 23 Nov 2022
    8.8
    High

    CVE-2022-44253

    Last Modified: 25 Apr 2025

    TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosisCfg function.

    Published: 23 Nov 2022
    8.8
    High

    CVE-2022-44254

    Last Modified: 25 Apr 2025

    TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg function.

    Published: 23 Nov 2022
    9.8
    Critical

    CVE-2020-23583

    Last Modified: 25 Apr 2025

    OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that leads to COMMAND EXECUTION. An attacker can successfully trigger the COMMAND and can compromise full system.

    Published: 23 Nov 2022
    6.5
    Medium

    CVE-2020-23589

    Last Modified: 29 Apr 2025

    A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to cause a Denial of Service by Rebooting the router through " /mgm_dev_reboot.asp."

    Published: 23 Nov 2022
    8.8
    High

    CVE-2022-44256

    Last Modified: 25 Apr 2025

    TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter lang in the setLanguageCfg function.

    Published: 23 Nov 2022
    8.8
    High

    CVE-2022-44257

    Last Modified: 25 Apr 2025

    TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setOpModeCfg function.

    Published: 23 Nov 2022
    8.8
    High

    CVE-2022-44258

    Last Modified: 25 Apr 2025

    TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTracerouteCfg function.

    Published: 23 Nov 2022
    8.8
    High

    CVE-2022-44259

    Last Modified: 25 Apr 2025

    TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter week, sTime, and eTime in the setParentalRules function.

    Published: 23 Nov 2022
    7.2
    High

    CVE-2022-44278

    Last Modified: 25 Apr 2025

    Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=user/manage_user&id=.

    Published: 23 Nov 2022
    6.7
    Medium

    CVE-2009-1142

    Last Modified: 25 Apr 2025

    An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can gain privileges via a symlink attack on /tmp files if vmware-user-suid-wrapper is setuid root and the ChmodChownDirectory function is enabled.

    Published: 23 Nov 2022
    5.4
    Medium

    CVE-2022-45151

    Last Modified: 25 Apr 2025

    The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

    Published: 23 Nov 2022
    9.8
    Critical

    CVE-2021-35284

    Last Modified: 28 Apr 2025

    SQL Injection vulnerability in function get_user in login_manager.php in rizalafani cms-php v1.

    Published: 23 Nov 2022
    4.8
    Medium

    CVE-2022-42095

    Last Modified: 28 Apr 2025

    Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.

    Published: 23 Nov 2022
    7.5
    High

    CVE-2021-46854

    Last Modified: 28 Apr 2025

    mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.

    Published: 23 Nov 2022
    5.4
    Medium

    CVE-2022-45472

    Last Modified: 25 Apr 2025

    CAE LearningSpace Enterprise (with Intuity License) image 267r patch 639 allows DOM XSS, related to ontouchmove and onpointerup.

    Published: 23 Nov 2022
    7
    High

    CVE-2009-1143

    Last Modified: 25 Apr 2025

    An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink attack that leverages a realpath race condition in mount.vmhgfs (aka hgfsmounter).

    Published: 23 Nov 2022
    8.8
    High

    CVE-2020-23585

    Last Modified: 25 Apr 2025

    A remote attacker can conduct a cross-site request forgery (CSRF) attack on OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028. The vulnerability is due to insufficient CSRF protections for the "mgm_config_file.asp" because of which attacker can create a crafted "csrf form" which sends " malicious xml data" to "/boaform/admin/formMgmConfigUpload". the exploit allows attacker to "gain full privileges" and to "fully compromise of router & network".

    Published: 23 Nov 2022
    4.3
    Medium

    CVE-2020-23586

    Last Modified: 25 Apr 2025

    A vulnerability found in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to Add Network Traffic Control Type Rule.

    Published: 23 Nov 2022
    3.1
    Low

    CVE-2020-23587

    Last Modified: 25 Apr 2025

    A vulnerability found in the OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to men in the middle attack by adding New Routes in RoutingConfiguration on " /routing.asp ".

    Published: 23 Nov 2022
    9.8
    Critical

    CVE-2020-23591

    Last Modified: 29 Apr 2025

    A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker to upload arbitrary files through " /mgm_dev_upgrade.asp " which can "delete every file for Denial of Service (using 'rm -rf *.*' in the code), reverse connection (using '.asp' webshell), backdoor.

    Published: 23 Nov 2022
    6.5
    Medium

    CVE-2020-23593

    Last Modified: 29 Apr 2025

    A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2, Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross site request forgery (CSRF) attack to enable syslog mode through ' /mgm_log_cfg.asp.' The system starts to log events, 'Remote' mode or 'Both' mode on "Syslog -- Configuration page" logs events and sends to remote syslog server IP and Port.

    Published: 23 Nov 2022
    5.4
    Medium

    CVE-2022-37421

    Last Modified: 25 Apr 2025

    Silverstripe silverstripe/cms through 4.11.0 allows XSS.

    Published: 23 Nov 2022
    5.4
    Medium

    CVE-2022-37429

    Last Modified: 25 Apr 2025

    Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a javascript URL with white space characters.

    Published: 23 Nov 2022
    5.3
    Medium

    CVE-2022-38115

    Last Modified: 24 Apr 2025

    Insecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUT

    Published: 23 Nov 2022
    5.4
    Medium

    CVE-2022-38145

    Last Modified: 25 Apr 2025

    Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta description and get it executed in the versioned history compare view.

    Published: 23 Nov 2022
    5.4
    Medium

    CVE-2022-38147

    Last Modified: 25 Apr 2025

    Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3).

    Published: 23 Nov 2022
    6.5
    Medium

    CVE-2022-40772

    Last Modified: 28 Apr 2025

    Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the report module.

    Published: 23 Nov 2022
    5.9
    Medium

    CVE-2022-4132

    Last Modified: 21 Nov 2024

    A flaw was found in JSS. A memory leak in JSS requires non-standard configuration but is a low-effort DoS vector if configured that way (repeatedly hitting the login page).

    Published: 23 Nov 2022
    5.4
    Medium

    CVE-2022-41446

    Last Modified: 28 Apr 2025

    An access control issue in /Admin/dashboard.php of Record Management System using CodeIgniter v1.0 allows attackers to access and modify user data.

    Published: 23 Nov 2022
    9.8
    Critical

    CVE-2020-23584

    Last Modified: 25 Apr 2025

    Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute commands on " /diag_tracert_admin.asp " in the "PingTest" parameter that leads to command execution.

    Published: 23 Nov 2022
    4.3
    Medium

    CVE-2020-23588

    Last Modified: 25 Apr 2025

    A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to "Enable or Disable Ports" and to "Change port number" through " /rmtacc.asp ".

    Published: 23 Nov 2022
    6.5
    Medium

    CVE-2020-23590

    Last Modified: 29 Apr 2025

    A vulnerability in Optilink OP-XT71000N Hardware version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated remote attacker to conduct a cross-site request forgery (CSRF) attack to change the Password for "WLAN SSID" through "wlwpa.asp".

    Published: 23 Nov 2022