CVE Feed

    Dashboard / CVE

    4.2
    Medium

    CVE-2022-41919

    Last Modified: 23 Apr 2025

    Fastify is a web framework with minimal overhead and plugin architecture. The attacker can use the incorrect `Content-Type` to bypass the `Pre-Flight` checking of `fetch`. `fetch()` requests with Content-Type’s essence as "application/x-www-form-urlencoded", "multipart/form-data", or "text/plain", could potentially be used to invoke routes that only accepts `application/json` content type, thus bypassing any CORS protection, and therefore they could lead to a Cross-Site Request Forgery attack. This issue has been patched in version 4.10.2 and 3.29.4. As a workaround, implement Cross-Site Request Forgery protection using `@fastify/csrf'.

    Published: 22 Nov 2022
    5.3
    Medium

    CVE-2022-41936

    Last Modified: 23 Apr 2025

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The `modifications` rest endpoint does not filter out entries according to the user's rights. Therefore, information hidden from unauthorized users are exposed though the `modifications` rest endpoint (comments and page names etc). Users should upgrade to XWiki 14.6+, 14.4.3+, or 13.10.8+. Older versions have not been patched. There are no known workarounds.

    Published: 22 Nov 2022
    6.5
    Medium

    CVE-2022-41952

    Last Modified: 23 Apr 2025

    Synapse before 1.52.0 with URL preview functionality enabled will attempt to generate URL previews for media stream URLs without properly limiting connection time. Connections will only be terminated after `max_spider_size` (default: 10M) bytes have been downloaded, which can in some cases lead to long-lived connections towards the streaming media server (for instance, Icecast). This can cause excessive traffic and connections toward such servers if their stream URL is, for example, posted to a large room with many Synapse instances with URL preview enabled. Version 1.52.0 implements a timeout mechanism which will terminate URL preview connections after 30 seconds. Since generating URL previews for media streams is not supported and always fails, 1.53.0 additionally implements an allow list for content types for which Synapse will even attempt to generate a URL preview. Upgrade to 1.53.0 to fully resolve the issue. As a workaround, turn off URL preview functionality by setting `url_preview_enabled: false` in the Synapse configuration file.

    Published: 22 Nov 2022
    7.8
    High

    CVE-2022-43751

    Last Modified: 29 Apr 2025

    McAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the use of a variable pointing to a subdirectory that may be controllable by an unprivileged user. This may have allowed the unprivileged user to execute arbitrary code with system privileges.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-44187

    Last Modified: 29 Apr 2025

    Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via wan_dns1_pri.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-44190

    Last Modified: 29 Apr 2025

    Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter enable_band_steering.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-44191

    Last Modified: 29 Apr 2025

    Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameters KEY1 and KEY2.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-44194

    Last Modified: 29 Apr 2025

    Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_dns1_pri and apmode_dns1_sec.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-44201

    Last Modified: 29 Apr 2025

    D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-44202

    Last Modified: 29 Apr 2025

    D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-44801

    Last Modified: 29 Apr 2025

    D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-44804

    Last Modified: 29 Apr 2025

    D-Link DIR-882 1.10B02 and1.20B06 is vulnerable to Buffer Overflow via the websRedirect function.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-44806

    Last Modified: 29 Apr 2025

    D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-44807

    Last Modified: 29 Apr 2025

    D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow via webGetVarString.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2022-44808

    Last Modified: 25 Apr 2025

    A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can process the request, the system function executes an untrusted command that triggers the vulnerability.

    Published: 22 Nov 2022
    7.5
    High

    CVE-2022-45330

    Last Modified: 25 Apr 2025

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database information.

    Published: 22 Nov 2022
    6.8
    Medium

    CVE-2022-40765

    Last Modified: 3 Nov 2025

    A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters.

    Published: 22 Nov 2022
    9.8
    Critical

    CVE-2021-3919

    Last Modified: 29 Apr 2025

    A potential security vulnerability has been identified in OMEN Gaming Hub and in HP Command Center which may allow escalation of privilege and/or denial of service. HP has released software updates to mitigate the potential vulnerability.

    Published: 21 Nov 2022
    9.8
    Critical

    CVE-2021-3821

    Last Modified: 29 Apr 2025

    A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Denial of Service when running HP Workpath solutions on potentially affected products.

    Published: 21 Nov 2022
    8.4
    High

    CVE-2021-3661

    Last Modified: 29 Apr 2025

    A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution. HP is releasing firmware mitigations for the potential vulnerability.

    Published: 21 Nov 2022
    9.8
    Critical

    CVE-2021-3437

    Last Modified: 29 Apr 2025

    Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of privilege and/or denial of service. HP is releasing software updates to mitigate the potential vulnerabilities.

    Published: 21 Nov 2022
    8.4
    High

    CVE-2022-37018

    Last Modified: 29 Apr 2025

    A potential vulnerability has been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerability.

    Published: 21 Nov 2022
    7.8
    High

    CVE-2022-1038

    Last Modified: 29 Apr 2025

    A potential security vulnerability has been identified in the HP Jumpstart software, which might allow escalation of privilege. HP is recommending that customers uninstall HP Jumpstart and use myHP software.

    Published: 21 Nov 2022
    7.5
    High

    CVE-2022-44654

    Last Modified: 29 Apr 2025

    Affected builds of Trend Micro Apex One and Apex One as a Service contain a monitor engine component that is complied without the /SAFESEH memory protection mechanism which helps to monitor for malicious payloads. The affected component's memory protection mechanism has been updated to enhance product security.

    Published: 21 Nov 2022
    7.8
    High

    CVE-2022-44653

    Last Modified: 28 Apr 2025

    A security agent directory traversal vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 21 Nov 2022
    7.8
    High

    CVE-2022-44652

    Last Modified: 28 Apr 2025

    An improper handling of exceptional conditions vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 21 Nov 2022
    7
    High

    CVE-2022-44651

    Last Modified: 28 Apr 2025

    A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 21 Nov 2022
    7.8
    High

    CVE-2022-44650

    Last Modified: 29 Apr 2025

    A memory corruption vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 21 Nov 2022
    7.8
    High

    CVE-2022-44649

    Last Modified: 29 Apr 2025

    An out-of-bounds access vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 21 Nov 2022
    5.5
    Medium

    CVE-2022-44648

    Last Modified: 29 Apr 2025

    An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This is similar to, but not the same as CVE-2022-44647.

    Published: 21 Nov 2022
    5.5
    Medium

    CVE-2022-44647

    Last Modified: 29 Apr 2025

    An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This is similar to, but not the same as CVE-2022-44648.

    Published: 21 Nov 2022
    7.2
    High

    CVE-2022-40746

    Last Modified: 24 Apr 2025

    IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 236581.

    Published: 21 Nov 2022
    7.8
    High

    CVE-2022-40129

    Last Modified: 15 Apr 2025

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A specially-crafted PDF document can trigger the reuse of previously freed memory via misusing Optional Content Group API, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially-crafted, malicious site if the browser plugin extension is enabled.

    Published: 21 Nov 2022
    7.8
    High

    CVE-2022-38097

    Last Modified: 15 Apr 2025

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely destroying annotation objects, a specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially-crafted, malicious site if the browser plugin extension is enabled.

    Published: 21 Nov 2022
    7.8
    High

    CVE-2022-37332

    Last Modified: 15 Apr 2025

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A specially-crafted PDF document can trigger the reuse of previously freed memory via misusing media player API, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially-crafted, malicious site if the browser plugin extension is enabled.

    Published: 21 Nov 2022
    7.8
    High

    CVE-2022-32774

    Last Modified: 15 Apr 2025

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely deleting objects associated with pages, a specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially-crafted, malicious site if the browser plugin extension is enabled.

    Published: 21 Nov 2022
    8.8
    High

    CVE-2022-3861

    Last Modified: 8 Apr 2026

    The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via deserialization of untrusted input supplied via the import, mfn-items-import-page, and mfn-items-import parameters passed through the mfn_builder_import, mfn_builder_import_page, importdata, importsinglepage, and importfromclipboard functions. This makes it possible for authenticated attackers, with subscriber level permissions and above to inject a PHP Object. The additional presence of a POP chain would make it possible for attackers to execute code, retrieve sensitive data, delete files, etc..

    Published: 21 Nov 2022
    8.1
    High

    CVE-2022-3589

    Last Modified: 25 Apr 2025

    An API Endpoint used by Miele's "AppWash" MobileApp in all versions was vulnerable to an authorization bypass. A low privileged, remote attacker would have been able to gain read and partial write access to other users data by modifying a small part of a HTTP request sent to the API. Reading or changing the password of another user was not possible, thus no impact to Availability.

    Published: 21 Nov 2022
    4.3
    Medium

    CVE-2022-3336

    Last Modified: 30 Apr 2025

    The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attackers to make logged in admin delete arbitrary visitors via a CSRF attack

    Published: 21 Nov 2022
    9.8
    Critical

    CVE-2022-44178

    Last Modified: 29 Apr 2025

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow. via function formWifiWpsOOB.

    Published: 21 Nov 2022
    9.8
    Critical

    CVE-2022-44183

    Last Modified: 29 Apr 2025

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetWifiGuestBasic.

    Published: 21 Nov 2022
    2.6
    Low

    CVE-2022-4087

    Last Modified: 15 Apr 2025

    A vulnerability was found in iPXE. It has been declared as problematic. This vulnerability affects the function tls_new_ciphertext of the file src/net/tls.c of the component TLS. The manipulation of the argument pad_len leads to information exposure through discrepancy. The name of the patch is 186306d6199096b7a7c4b4574d4be8cdb8426729. It is recommended to apply a patch to fix this issue. VDB-214054 is the identifier assigned to this vulnerability.

    Published: 21 Nov 2022
    5.5
    Medium

    CVE-2022-45146

    Last Modified: 21 Nov 2024

    An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collector in Java 13 and later trigger an issue in the BC-FJA FIPS modules where it is possible for temporary keys used by the module to be zeroed out while still in use by the module, resulting in errors or potential information loss. NOTE: FIPS compliant users are unaffected because the FIPS certification is only for Java 7, 8, and 11.

    Published: 21 Nov 2022
    6.5
    Medium

    CVE-2022-41945

    Last Modified: 22 Apr 2025

    super-xray is a vulnerability scanner (xray) GUI launcher. In version 0.1-beta, the URL is not filtered and directly spliced ​​into the command, resulting in a possible RCE vulnerability. Users should upgrade to super-xray 0.2-beta.

    Published: 21 Nov 2022
    5.4
    Medium

    CVE-2022-43117

    Last Modified: 29 Apr 2025

    Sourcecodester Password Storage Application in PHP/OOP and MySQL 1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Name, Username, Description and Site Feature parameters.

    Published: 21 Nov 2022
    9.6
    Critical

    CVE-2022-43143

    Last Modified: 29 Apr 2025

    A cross-site scripting (XSS) vulnerability in Beekeeper Studio v3.6.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error modal container.

    Published: 21 Nov 2022
    7.5
    High

    CVE-2022-44158

    Last Modified: 29 Apr 2025

    Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via function via set_device_name.

    Published: 21 Nov 2022
    9.8
    Critical

    CVE-2022-44174

    Last Modified: 29 Apr 2025

    Tenda AC18 V15.03.05.05 is vulnerable to Buffer Overflow via function formSetDeviceName.

    Published: 21 Nov 2022
    9.8
    Critical

    CVE-2022-44175

    Last Modified: 29 Apr 2025

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetMacFilterCfg.

    Published: 21 Nov 2022
    9.8
    Critical

    CVE-2022-44176

    Last Modified: 29 Apr 2025

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic.

    Published: 21 Nov 2022