CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-44785

    Last Modified: 29 Apr 2025

    An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection vulnerabilities, some of which executable even by unauthenticated users, as demonstrated by the GetListaEnti.do cfamm parameter.

    Published: 21 Nov 2022
    7.5
    High

    CVE-2022-44786

    Last Modified: 29 Apr 2025

    An issue was discovered in Appalti & Contratti 9.12.2. The target web applications allow Local File Inclusion in any page relying on the href parameter to specify the JSP page to be rendered. This affects ApriPagina.do POST and GET requests to each application.

    Published: 21 Nov 2022
    6.1
    Medium

    CVE-2022-44787

    Last Modified: 29 Apr 2025

    An issue was discovered in Appalti & Contratti 9.12.2. The web applications are vulnerable to a Reflected Cross-Site Scripting issue. The idPagina parameter is reflected inside the server response without any HTML encoding, resulting in XSS when the victim moves the mouse pointer inside the page. As an example, the onmouseenter attribute is not sanitized.

    Published: 21 Nov 2022
    6.5
    Medium

    CVE-2022-44788

    Last Modified: 29 Apr 2025

    An issue was discovered in Appalti & Contratti 9.12.2. It allows Session Fixation. When a user logs in providing a JSESSIONID cookie that is issued by the server at the first visit, the cookie value is not updated after a successful login.

    Published: 21 Nov 2022
    7.8
    High

    CVE-2022-44830

    Last Modified: 29 Apr 2025

    Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.

    Published: 21 Nov 2022
    4.8
    Medium

    CVE-2022-45012

    Last Modified: 29 Apr 2025

    A cross-site scripting (XSS) vulnerability in the Modify Page module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Source field.

    Published: 21 Nov 2022
    7.8
    High

    CVE-2022-45422

    Last Modified: 28 Apr 2025

    When LG SmartShare is installed, local privilege escalation is possible through DLL Hijacking attack. The LG ID is LVE-HOT-220005.

    Published: 21 Nov 2022
    —
    Unknown

    CVE-2022-45614

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-4228. Reason: This candidate is a reservation duplicate of CVE-2022-4228. Notes: All CVE users should reference CVE-2022-4228 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 21 Nov 2022
    —
    Unknown

    CVE-2022-4074

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 20 Nov 2022
    6.1
    Medium

    CVE-2022-3516

    Last Modified: 25 Apr 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.

    Published: 20 Nov 2022
    8.8
    High

    CVE-2022-3525

    Last Modified: 24 Apr 2025

    Deserialization of Untrusted Data in GitHub repository librenms/librenms prior to 22.10.0.

    Published: 20 Nov 2022
    6.1
    Medium

    CVE-2022-3561

    Last Modified: 29 Apr 2025

    Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.

    Published: 20 Nov 2022
    5.4
    Medium

    CVE-2022-4068

    Last Modified: 25 Apr 2025

    A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Moreover, the username is not properly sanitized in the admin user overview. This enables an XSS attack that enables an attacker with a low privilege user to execute arbitrary JavaScript in the context of an admin's account.

    Published: 20 Nov 2022
    —
    Unknown

    CVE-2022-4071

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 20 Nov 2022
    —
    Unknown

    CVE-2022-4072

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 20 Nov 2022
    —
    Unknown

    CVE-2022-4073

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 20 Nov 2022
    —
    Unknown

    CVE-2022-4075

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 20 Nov 2022
    —
    Unknown

    CVE-2022-4076

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 20 Nov 2022
    —
    Unknown

    CVE-2022-4077

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 20 Nov 2022
    —
    Unknown

    CVE-2022-4078

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 20 Nov 2022
    —
    Unknown

    CVE-2022-4079

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 20 Nov 2022
    —
    Unknown

    CVE-2022-4080

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 20 Nov 2022
    —
    Unknown

    CVE-2022-4082

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 20 Nov 2022
    —
    Unknown

    CVE-2022-4083

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 20 Nov 2022
    —
    Unknown

    CVE-2022-4084

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 20 Nov 2022
    —
    Unknown

    CVE-2022-4086

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 20 Nov 2022
    5.4
    Medium

    CVE-2022-3562

    Last Modified: 28 Apr 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.

    Published: 20 Nov 2022
    5.4
    Medium

    CVE-2022-4067

    Last Modified: 28 Apr 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.

    Published: 20 Nov 2022
    4.8
    Medium

    CVE-2022-4069

    Last Modified: 24 Apr 2025

    Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.

    Published: 20 Nov 2022
    9.8
    Critical

    CVE-2022-4070

    Last Modified: 14 Apr 2025

    Insufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0.

    Published: 20 Nov 2022
    —
    Unknown

    CVE-2022-4081

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 20 Nov 2022
    —
    Unknown

    CVE-2022-4085

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 20 Nov 2022
    6.1
    Medium

    CVE-2022-41939

    Last Modified: 22 Apr 2025

    knative.dev/func is is a client library and CLI enabling the development and deployment of Kubernetes functions. Developers using a malicious or compromised third-party buildpack could expose their registry credentials or local docker socket to a malicious `lifecycle` container. This issues has been patched in PR #1442, and is part of release 1.8.1. This issue only affects users who are using function buildpacks from third-parties; pinning the builder image to a specific content-hash with a valid `lifecycle` image will also mitigate the attack.

    Published: 19 Nov 2022
    3.5
    Low

    CVE-2022-4066

    Last Modified: 15 Apr 2025

    A vulnerability was found in davidmoreno onion. It has been rated as problematic. Affected by this issue is the function onion_response_flush of the file src/onion/response.c of the component Log Handler. The manipulation leads to allocation of resources. The name of the patch is de8ea938342b36c28024fd8393ebc27b8442a161. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-214028.

    Published: 19 Nov 2022
    6.3
    Medium

    CVE-2022-4064

    Last Modified: 15 Apr 2025

    A vulnerability was found in Dalli up to 3.2.2. It has been classified as problematic. Affected is the function self.meta_set of the file lib/dalli/protocol/meta/request_formatter.rb of the component Meta Protocol Handler. The manipulation of the argument cas/ttl leads to injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 3.2.3 is able to address this issue. The patch is identified as 48d594dae55934476fec61789e7a7c3700e0f50d. It is recommended to upgrade the affected component.

    Published: 19 Nov 2022
    5.5
    Medium

    CVE-2022-4065

    Last Modified: 21 Nov 2024

    A vulnerability was found in cbeust testng 7.5.0/7.6.0/7.6.1/7.7.0. It has been declared as critical. Affected by this vulnerability is the function testngXmlExistsInJar of the file testng-core/src/main/java/org/testng/JarFileUtils.java of the component XML File Parser. The manipulation leads to path traversal. The attack can be launched remotely. Upgrading to version 7.5.1 and 7.7.1 is able to address this issue. The patch is named 9150736cd2c123a6a3b60e6193630859f9f0422b. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-214027.

    Published: 19 Nov 2022
    9
    Critical

    CVE-2022-41938

    Last Modified: 23 Apr 2025

    Flarum is an open source discussion platform. Flarum's page title system allowed for page titles to be converted into HTML DOM nodes when pages were rendered. The change was made after `v1.5` and was not noticed. This allowed an attacker to inject malicious HTML markup using a discussion title input, either by creating a new discussion or renaming one. The XSS attack occurs after a visitor opens the relevant discussion page. All communities running Flarum from `v1.5.0` to `v1.6.1` are impacted. The vulnerability has been fixed and published as flarum/core `v1.6.2`. All communities running Flarum from `v1.5.0` to `v1.6.1` have to upgrade as soon as possible to v1.6.2. There are no known workarounds for this issue.

    Published: 19 Nov 2022
    6.4
    Medium

    CVE-2022-41609

    Last Modified: 20 Feb 2025

    Auth. (subscriber+) Server-Side Request Forgery (SSRF) vulnerability in Better Messages plugin 1.9.10.68 on WordPress.

    Published: 18 Nov 2022
    5.3
    Medium

    CVE-2022-41155

    Last Modified: 20 Feb 2025

    Block BYPASS vulnerability in iQ Block Country plugin <= 1.2.18 on WordPress.

    Published: 18 Nov 2022
    4.3
    Medium

    CVE-2022-40216

    Last Modified: 28 Apr 2026

    Auth. (subscriber+) Messaging Block Bypass vulnerability in Better Messages plugin <= 1.9.10.69 on WordPress.

    Published: 18 Nov 2022
    4.3
    Medium

    CVE-2022-40130

    Last Modified: 20 Feb 2025

    Auth. (subscriber+) Race Condition vulnerability in WP-Polls plugin <= 2.76.0 on WordPress.

    Published: 18 Nov 2022
    3.7
    Low

    CVE-2022-41618

    Last Modified: 20 Feb 2025

    Unauthenticated Error Log Disclosure vulnerability in Media Library Assistant plugin <= 3.00 on WordPress.

    Published: 18 Nov 2022
    6.1
    Medium

    CVE-2022-41615

    Last Modified: 21 Nov 2024

    Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Store Locator plugin <= 1.4.5 on WordPress.

    Published: 18 Nov 2022
    5.4
    Medium

    CVE-2022-41634

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Media Library Folders plugin <= 7.1.1 on WordPress.

    Published: 18 Nov 2022
    6.5
    Medium

    CVE-2022-41135

    Last Modified: 20 Feb 2025

    Unauth. Plugin Settings Change vulnerability in Modula plugin <= 2.6.9 on WordPress.

    Published: 18 Nov 2022
    4.3
    Medium

    CVE-2022-41655

    Last Modified: 20 Feb 2025

    Auth. (subscriber+) Sensitive Data Exposure vulnerability in Phone Orders for WooCommerce plugin <= 3.7.1 on WordPress.

    Published: 18 Nov 2022
    4.8
    Medium

    CVE-2022-41643

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Accessibility plugin <= 1.0.3 on WordPress.

    Published: 18 Nov 2022
    4.8
    Medium

    CVE-2022-40963

    Last Modified: 21 Nov 2024

    Multiple Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerabilities in WP Page Builder plugin <= 1.2.6 on WordPress.

    Published: 18 Nov 2022
    5.4
    Medium

    CVE-2022-41685

    Last Modified: 28 Apr 2026

    Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Viszt Péter's Integration for Szamlazz.hu & WooCommerce plugin <= 5.6.3.2 and Csomagpontok és szállítási címkék WooCommerce-hez plugin <= 1.9.0.2 on WordPress.

    Published: 18 Nov 2022
    7.2
    High

    CVE-2022-42459

    Last Modified: 20 Feb 2025

    Auth. WordPress Options Change vulnerability in Image Hover Effects Ultimate plugin <= 9.7.1 on WordPress.

    Published: 18 Nov 2022