CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-44177

    Last Modified: 29 Apr 2025

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formWifiWpsStart.

    Published: 21 Nov 2022
    9.8
    Critical

    CVE-2022-44180

    Last Modified: 29 Apr 2025

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function addWifiMacFilter.

    Published: 21 Nov 2022
    8.8
    High

    CVE-2022-44784

    Last Modified: 29 Apr 2025

    An issue was discovered in Appalti & Contratti 9.12.2. The target web applications LFS and DL229 expose a set of services provided by the Axis 1.4 instance, embedded directly into the applications, as hinted by the WEB-INF/web.xml file leaked through Local File Inclusion. Among the exposed services, there is the Axis AdminService, which, through the default configuration, should normally be accessible only by the localhost. Nevertheless, by trying to access the mentioned service, both in LFS and DL229, the service can actually be reached even by remote users, allowing creation of arbitrary services on the server side. When an attacker can reach the AdminService, they can use it to instantiate arbitrary services on the server. The exploit procedure is well known and described in Generic AXIS-SSRF exploitation. Basically, the attack consists of writing a JSP page inside the root directory of the web application, through the org.apache.axis.handlers.LogHandler class.

    Published: 21 Nov 2022
    4.8
    Medium

    CVE-2022-42096

    Last Modified: 29 Apr 2025

    Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.

    Published: 21 Nov 2022
    8.8
    High

    CVE-2022-1578

    Last Modified: 30 Apr 2025

    The My wpdb WordPress plugin before 2.5 is missing CSRF check when running SQL queries, which could allow attacker to make a logged in admin run arbitrary SQL query via a CSRF attack

    Published: 21 Nov 2022
    7.5
    High

    CVE-2022-1579

    Last Modified: 30 Apr 2025

    The function check_is_login_page() uses headers for the IP check, which can be easily spoofed.

    Published: 21 Nov 2022
    7.5
    High

    CVE-2022-45470

    Last Modified: 29 Apr 2025

    missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Hama is EOL, we do not expect these issues to be fixed.

    Published: 21 Nov 2022
    6.1
    Medium

    CVE-2022-43707

    Last Modified: 29 Apr 2025

    MyBB 1.8.31 has a Cross-site scripting (XSS) vulnerability in the visual MyCode editor (SCEditor) allows remote attackers to inject HTML via user input or stored data

    Published: 21 Nov 2022
    6.1
    Medium

    CVE-2022-43708

    Last Modified: 29 Apr 2025

    MyBB 1.8.31 has a (issue 2 of 2) cross-site scripting (XSS) vulnerabilities in the post Attachments interface allow attackers to inject HTML by persuading the user to upload a file with specially crafted name

    Published: 21 Nov 2022
    4.9
    Medium

    CVE-2022-43709

    Last Modified: 29 Apr 2025

    MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify the query string via direct user input or stored search filter settings.

    Published: 21 Nov 2022
    9.8
    Critical

    CVE-2022-30257

    Last Modified: 30 Apr 2025

    An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effects of an exploit would be widespread and highly impactful, because the exploitation conforms to de facto DNS specifications and operational practices, and overcomes current mitigation patches for "Ghost" domain names.

    Published: 21 Nov 2022
    4.8
    Medium

    CVE-2022-45013

    Last Modified: 29 Apr 2025

    A cross-site scripting (XSS) vulnerability in the Show Advanced Option module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Section Header field.

    Published: 21 Nov 2022
    4.8
    Medium

    CVE-2022-45014

    Last Modified: 29 Apr 2025

    A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Header field.

    Published: 21 Nov 2022
    4.8
    Medium

    CVE-2022-45015

    Last Modified: 29 Apr 2025

    A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Footer field.

    Published: 21 Nov 2022
    4.8
    Medium

    CVE-2022-45016

    Last Modified: 29 Apr 2025

    A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Footer field.

    Published: 21 Nov 2022
    4.8
    Medium

    CVE-2022-45017

    Last Modified: 29 Apr 2025

    A cross-site scripting (XSS) vulnerability in the Overview Page settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Loop field.

    Published: 21 Nov 2022
    8.8
    High

    CVE-2022-3388

    Last Modified: 23 Jul 2025

    An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role.

    Published: 21 Nov 2022
    6.8
    Medium

    CVE-2022-35897

    Last Modified: 30 Apr 2025

    An stack buffer overflow vulnerability leads to arbitrary code execution issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. If the attacker modifies specific UEFI variables, it can cause a stack overflow, leading to arbitrary code execution. The specific variables are normally locked (read-only) at the OS level and therefore an attack would require direct SPI modification. If an attacker can change the values of at least two variables out of three (SecureBootEnforce, SecureBoot, RestoreBootSettings), it is possible to execute arbitrary code.

    Published: 21 Nov 2022
    9.8
    Critical

    CVE-2022-3600

    Last Modified: 30 Apr 2025

    The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which could lead to CSV injection.

    Published: 21 Nov 2022
    9.8
    Critical

    CVE-2022-3634

    Last Modified: 29 Apr 2025

    The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV file, which could lead to CSV injection

    Published: 21 Nov 2022
    4.8
    Medium

    CVE-2022-3690

    Last Modified: 29 Apr 2025

    The Popup Maker WordPress plugin before 1.16.11 does not sanitise and escape some of its Popup options, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks, which could be used against admins

    Published: 21 Nov 2022
    7.5
    High

    CVE-2022-3691

    Last Modified: 30 Apr 2025

    The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor.

    Published: 21 Nov 2022
    4.7
    Medium

    CVE-2022-3750

    Last Modified: 30 Apr 2025

    The has a CSRF vulnerability that allows the deletion of a post without using a nonce or prompting for confirmation.

    Published: 21 Nov 2022
    6.5
    Medium

    CVE-2022-3762

    Last Modified: 30 Apr 2025

    The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 do not validate files to download in some of its modules, which could allow ShopManager and Admin to download arbitrary files from the server even when they are not supposed to be able to (for example in multisite)

    Published: 21 Nov 2022
    8.1
    High

    CVE-2022-3763

    Last Modified: 30 Apr 2025

    The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 do not have CSRF check in place when deleting files uploaded at the checkout, allowing attackers to make a logged in shop manager or admin delete them via a CSRF attack

    Published: 21 Nov 2022
    5.4
    Medium

    CVE-2022-38146

    Last Modified: 30 Apr 2025

    Silverstripe silverstripe/framework through 4.11 allows XSS (issue 2 of 3).

    Published: 21 Nov 2022
    8.8
    High

    CVE-2022-38148

    Last Modified: 30 Apr 2025

    Silverstripe silverstripe/framework through 4.11 allows SQL Injection.

    Published: 21 Nov 2022
    5.3
    Medium

    CVE-2022-38755

    Last Modified: 29 Apr 2025

    A vulnerability has been identified in Micro Focus Filr in versions prior to 4.3.1.1. The vulnerability could be exploited to allow a remote unauthenticated attacker to enumerate valid users of the system. Remote unauthenticated user enumeration. This issue affects: Micro Focus Filr versions prior to 4.3.1.1.

    Published: 21 Nov 2022
    4.8
    Medium

    CVE-2022-40470

    Last Modified: 29 Apr 2025

    Phpgurukul Blood Donor Management System 1.0 allows Cross Site Scripting via Add Blood Group Name Feature.

    Published: 21 Nov 2022
    6.5
    Medium

    CVE-2022-4096

    Last Modified: 14 Apr 2025

    Server-Side Request Forgery (SSRF) in GitHub repository appsmithorg/appsmith prior to 1.8.2.

    Published: 21 Nov 2022
    5.4
    Medium

    CVE-2022-4105

    Last Modified: 14 Apr 2025

    A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a UI redressing attack (clickjacking) and an HTML injection which disables the use of the history page.

    Published: 21 Nov 2022
    6.1
    Medium

    CVE-2022-0421

    Last Modified: 30 Apr 2025

    The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could perform Cross-Site Scripting attacks against a logged in admin viewing the failed payments

    Published: 21 Nov 2022
    6.5
    Medium

    CVE-2020-23582

    Last Modified: 29 Apr 2025

    A vulnerability in the "/admin/wlmultipleap.asp" of optilink OP-XT71000N version: V2.2 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to create Multiple WLAN BSSID.

    Published: 21 Nov 2022
    5.3
    Medium

    CVE-2022-1581

    Last Modified: 30 Apr 2025

    The WP-Polls WordPress plugin before 2.76.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.

    Published: 21 Nov 2022
    9.8
    Critical

    CVE-2022-30258

    Last Modified: 30 Apr 2025

    An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effects of an exploit would be widespread and highly impactful, because the exploitation conforms to de facto DNS specifications and operational practices, and overcomes current mitigation patches for "Ghost" domain names.

    Published: 21 Nov 2022
    7.5
    High

    CVE-2022-44167

    Last Modified: 29 Apr 2025

    Tenda AC15 V15.03.05.18 is avulnerable to Buffer Overflow via function formSetPPTPServer.

    Published: 21 Nov 2022
    7.5
    High

    CVE-2022-44168

    Last Modified: 29 Apr 2025

    Tenda AC15 V15.03.05.18 is vulnerable to Buffer Overflow via function fromSetRouteStatic..

    Published: 21 Nov 2022
    7.5
    High

    CVE-2022-44169

    Last Modified: 29 Apr 2025

    Tenda AC15 V15.03.05.18 is vulnerable to Buffer Overflow via function formSetVirtualSer.

    Published: 21 Nov 2022
    9.8
    Critical

    CVE-2022-44171

    Last Modified: 29 Apr 2025

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function form_fast_setting_wifi_set.

    Published: 21 Nov 2022
    9.8
    Critical

    CVE-2022-44172

    Last Modified: 29 Apr 2025

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function R7WebsSecurityHandler.

    Published: 21 Nov 2022
    9.8
    Critical

    CVE-2021-24649

    Last Modified: 30 Apr 2025

    The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having access to the AUTH_KEY and AUTH_SALT constant (via an arbitrary file access issue for example, or if the blog is using the default keys) to create an account with any role they want, such as admin

    Published: 21 Nov 2022
    4.8
    Medium

    CVE-2022-3618

    Last Modified: 29 Apr 2025

    The Spacer WordPress plugin before 3.0.7 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

    Published: 21 Nov 2022
    8.8
    High

    CVE-2022-3688

    Last Modified: 29 Apr 2025

    The WPQA Builder WordPress plugin before 5.9 does not have CSRF check when following and unfollowing users, which could allow attackers to make logged in users perform such actions via CSRF attacks

    Published: 21 Nov 2022
    7.2
    High

    CVE-2022-3720

    Last Modified: 30 Apr 2025

    The Event Monster WordPress plugin before 1.2.0 does not validate and escape some parameters before using them in SQL statements, which could lead to SQL Injection exploitable by high privilege users

    Published: 21 Nov 2022
    4.8
    Medium

    CVE-2022-3753

    Last Modified: 30 Apr 2025

    The Evaluate WordPress plugin through 1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

    Published: 21 Nov 2022
    7
    High

    CVE-2022-45919

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 6.0.10. In drivers/media/dvb-core/dvb_ca_en50221.c, a use-after-free can occur is there is a disconnect after an open, because of the lack of a wait_event.

    Published: 21 Nov 2022
    7.8
    High

    CVE-2022-45934

    Last Modified: 29 Apr 2025

    An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets.

    Published: 21 Nov 2022
    9.8
    Critical

    CVE-2022-4093

    Last Modified: 14 Apr 2025

    SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to reputational damage and regulatory fines. In some cases, an attacker can obtain a persistent backdoor into an organization's systems, leading to a long-term compromise that can go unnoticed for an extended period. This affect 16.0.1 and 16.0.2 only. 16.0.0 or lower, and 16.0.3 or higher are not affected

    Published: 21 Nov 2022
    7.5
    High

    CVE-2022-44156

    Last Modified: 29 Apr 2025

    Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetIpMacBind.

    Published: 21 Nov 2022
    7.5
    High

    CVE-2022-44163

    Last Modified: 29 Apr 2025

    Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via function formSetMacFilterCfg.

    Published: 21 Nov 2022