CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2022-45791

    Last Modified: 22 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 22 Nov 2022
    6.5
    Medium

    CVE-2022-44737

    Last Modified: 28 Apr 2026

    Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plugin) <= 5.1.0 on WordPress.

    Published: 22 Nov 2022
    7.1
    High

    CVE-2022-2513

    Last Modified: 27 Aug 2025

    A vulnerability exists in the Intelligent Electronic Device (IED) Connectivity Package (ConnPack) credential storage function in Hitachi Energy’s PCM600 product included in the versions listed below, where IEDs credentials are stored in a cleartext format in the PCM600 database and logs files. An attacker having get access to the exported backup file can exploit the vulnerability and obtain user credentials of the IEDs. Additionally, an attacker with administrator access to the PCM600 host machine can obtain other user credentials by analyzing database log files. The credentials may be used to perform unauthorized modifications such as loading incorrect configurations, reboot the IEDs or cause a denial-of-service on the IEDs.

    Published: 22 Nov 2022
    5.5
    Medium

    CVE-2023-3358

    Last Modified: 10 Mar 2025

    A null pointer dereference was found in the Linux kernel's Integrated Sensor Hub (ISH) driver. This issue could allow a local user to crash the system.

    Published: 22 Nov 2022
    6.5
    Medium

    CVE-2022-3643

    Last Modified: 21 Nov 2024

    Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface reset/abort/crash in a Linux based network backend by sending certain kinds of packets. It appears to be an (unwritten?) assumption in the rest of the Linux network stack that packet protocol headers are all contained within the linear section of the SKB and some NICs behave badly if this is not the case. This has been reported to occur with Cisco (enic) and Broadcom NetXtrem II BCM5780 (bnx2x) though it may be an issue with other NICs/drivers as well. In case the frontend is sending requests with split headers, netback will forward those violating above mentioned assumption to the networking core, resulting in said misbehavior.

    Published: 22 Nov 2022
    5.4
    Medium

    CVE-2022-45363

    Last Modified: 21 Nov 2024

    Auth. (subscriber+) Stored Cross-Site Scripting (XSS) in Muffingroup Betheme theme <= 26.6.1 on WordPress.

    Published: 22 Nov 2022
    4.7
    Medium

    CVE-2023-0468

    Last Modified: 1 Apr 2025

    A use-after-free flaw was found in io_uring/poll.c in io_poll_check_events in the io_uring subcomponent in the Linux Kernel due to a race condition of poll_refs. This flaw may cause a NULL pointer dereference.

    Published: 22 Nov 2022
    5.5
    Medium

    CVE-2023-28327

    Last Modified: 19 Mar 2025

    A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag.c In unix_diag_get_exact in the Linux Kernel. The newly allocated skb does not have sk, leading to a NULL pointer. This flaw allows a local user to crash or potentially cause a denial of service.

    Published: 22 Nov 2022
    7.3
    High

    CVE-2022-37931

    Last Modified: 25 Apr 2025

    A vulnerability in NetBatch-Plus software allows unauthorized access to the application.  HPE has provided a workaround and fix. Please refer to HPE Security Bulletin HPESBNS04388 for details.

    Published: 22 Nov 2022
    8.8
    High

    CVE-2022-33012

    Last Modified: 29 Apr 2025

    Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.

    Published: 22 Nov 2022
    4.9
    Medium

    CVE-2022-45535

    Last Modified: 25 Apr 2025

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-36179

    Last Modified: 29 Apr 2025

    Fusiondirectory 1.3 suffers from Improper Session Handling.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-44196

    Last Modified: 29 Apr 2025

    Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_push1.

    Published: 22 Nov 2022
    5.4
    Medium

    CVE-2022-38724

    Last Modified: 29 Apr 2025

    Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin through 1.11.0 allow XSS.

    Published: 22 Nov 2022
    4.3
    Medium

    CVE-2022-3962

    Last Modified: 21 Nov 2024

    A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed.

    Published: 22 Nov 2022
    9.1
    Critical

    CVE-2022-40842

    Last Modified: 29 Apr 2025

    ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php.

    Published: 22 Nov 2022
    9.6
    Critical

    CVE-2022-41937

    Last Modified: 23 Apr 2025

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application allows anyone with view access to modify any page of the wiki by importing a crafted XAR package. The problem has been patched in XWiki 14.6RC1, 14.6 and 13.10.8. As a workaround, setting the right of the page Filter.WebHome and making sure only the main wiki administrators can view the application installed on main wiki or edit the page and apply the changed described in commit fb49b4f.

    Published: 22 Nov 2022
    7.5
    High

    CVE-2022-45331

    Last Modified: 25 Apr 2025

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnerability allows attackers to access database information.

    Published: 22 Nov 2022
    7.1
    High

    CVE-2022-41940

    Last Modified: 22 Apr 2025

    Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. This impacts all the users of the engine.io package, including those who uses depending packages like socket.io. There is no known workaround except upgrading to a safe version. There are patches for this issue released in versions 3.6.1 and 6.2.1.

    Published: 22 Nov 2022
    7.9
    High

    CVE-2022-41942

    Last Modified: 23 Apr 2025

    Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the gitserver service, present in all Sourcegraph deployments. This vulnerability was caused by a lack of input validation on the host parameter of the `/list-gitolite` endpoint. It was possible to send a crafted request to gitserver that would execute commands inside the container. Successful exploitation requires the ability to send local requests to gitserver. The issue is patched in version 4.1.0.

    Published: 22 Nov 2022
    9
    Critical

    CVE-2022-41943

    Last Modified: 23 Apr 2025

    sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the experimental `customGitFetch` feature was enabled. This experimental feature has now been disabled by default. This issue has been patched in version 4.1.0.

    Published: 22 Nov 2022
    9
    Critical

    CVE-2022-42989

    Last Modified: 29 Apr 2025

    ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa de Entrada.

    Published: 22 Nov 2022
    6.4
    Medium

    CVE-2022-41950

    Last Modified: 22 Apr 2025

    super-xray is the GUI alternative for vulnerability scanning tool xray. In 0.2-beta, a privilege escalation vulnerability was discovered. This caused inaccurate default xray permissions. Note: this vulnerability only affects Linux and Mac OS systems. Users should upgrade to super-xray 0.3-beta.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-43212

    Last Modified: 29 Apr 2025

    Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-43214

    Last Modified: 29 Apr 2025

    Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-43215

    Last Modified: 29 Apr 2025

    Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-44184

    Last Modified: 29 Apr 2025

    Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_sec.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-44186

    Last Modified: 29 Apr 2025

    Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_pri.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-44188

    Last Modified: 29 Apr 2025

    Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter enable_band_steering.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-44193

    Last Modified: 29 Apr 2025

    Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameters: starthour, startminute , endhour, and endminute.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-44197

    Last Modified: 29 Apr 2025

    Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-44198

    Last Modified: 29 Apr 2025

    Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_push1.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-44199

    Last Modified: 29 Apr 2025

    Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-44200

    Last Modified: 29 Apr 2025

    Netgear R7000P V1.3.0.8, V1.3.1.64 is vulnerable to Buffer Overflow via parameters: stamode_dns1_pri and stamode_dns1_sec.

    Published: 22 Nov 2022
    4.9
    Medium

    CVE-2022-45529

    Last Modified: 25 Apr 2025

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information.

    Published: 22 Nov 2022
    4.9
    Medium

    CVE-2022-45536

    Last Modified: 29 Apr 2025

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php. This vulnerability allows attackers to access database information.

    Published: 22 Nov 2022
    4.8
    Medium

    CVE-2022-42094

    Last Modified: 29 Apr 2025

    Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content.

    Published: 22 Nov 2022
    4.8
    Medium

    CVE-2022-42097

    Last Modified: 29 Apr 2025

    Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via 'Comment.' .

    Published: 22 Nov 2022
    8.8
    High

    CVE-2022-42098

    Last Modified: 29 Apr 2025

    KLiK SocialMediaWebsite version v1.0.1 is vulnerable to SQL Injection via the profile.php.

    Published: 22 Nov 2022
    7.2
    High

    CVE-2022-30529

    Last Modified: 28 Apr 2025

    File upload vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to upload arbitrary files via /system/application/libs/js/tinymce/plugins/filemanager/dialog.php and /system/application/libs/js/tinymce/plugins/filemanager/upload.php.

    Published: 22 Nov 2022
    7.8
    High

    CVE-2022-35407

    Last Modified: 29 Apr 2025

    An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow leads to arbitrary code execution in the SetupUtility driver on Intel platforms. An attacker can change the values of certain UEFI variables. If the size of the second variable exceeds the size of the first, then the buffer will be overwritten. This issue affects the SetupUtility driver of InsydeH2O.

    Published: 22 Nov 2022
    9.6
    Critical

    CVE-2022-36180

    Last Modified: 29 Apr 2025

    Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout=1&message=[injection]&plug=106.

    Published: 22 Nov 2022
    6.5
    Medium

    CVE-2022-37773

    Last Modified: 29 Apr 2025

    An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the filter parameter, allows the complete disclosure of all databases.

    Published: 22 Nov 2022
    6.1
    Medium

    CVE-2022-38462

    Last Modified: 29 Apr 2025

    Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-39070

    Last Modified: 29 Apr 2025

    There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote attackers could use the vulnerability to log in to the device and execute any operation.

    Published: 22 Nov 2022
    5.8
    Medium

    CVE-2022-39199

    Last Modified: 23 Apr 2025

    immudb is a database with built-in cryptographic proof and verification. immudb client SDKs use server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state for multiple servers. SDK does not validate this uuid and can accept any value reported by the server. A malicious server can change the reported UUID tricking the client to treat it as a different server thus accepting a state completely irrelevant to the one previously retrieved from the server. This issue has been patched in version 1.4.1. As a workaround, when initializing an immudb client object a custom state handler can be used to store the state. Providing custom implementation that ignores the server UUID can be used to ensure that even if the server changes the UUID, client will still consider it to be the same server.

    Published: 22 Nov 2022
    5.6
    Medium

    CVE-2022-39397

    Last Modified: 23 Apr 2025

    aliyun-oss-client is a rust client for Alibaba Cloud OSS. Users of this library will be affected, the incoming secret will be disclosed unintentionally. This issue has been patched in version 0.8.1.

    Published: 22 Nov 2022
    8.1
    High

    CVE-2022-40870

    Last Modified: 29 Apr 2025

    The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header Injection attacks. This vulnerability allows attackers to execute arbitrary commands via a crafted payload injected into the Host header.

    Published: 22 Nov 2022
    7.8
    High

    CVE-2022-41131

    Last Modified: 29 Apr 2025

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airflow allows an attacker to execute arbtrary commands in the task execution context, without write access to DAG files. This issue affects Hive Provider versions prior to 4.1.0. It also impacts any Apache Airflow versions prior to 2.3.0 in case HIve Provider is installed (Hive Provider 4.1.0 can only be installed for Airflow 2.3.0+). Note that you need to manually install the HIve Provider version 4.1.0 in order to get rid of the vulnerability on top of Airflow 2.3.0+ version that has lower version of the Hive Provider installed).

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-4116

    Last Modified: 29 Apr 2025

    A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution.

    Published: 22 Nov 2022