CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2022-40695

    Last Modified: 20 Feb 2025

    Multiple Cross-Site Scripting (CSRF) vulnerabilities in SEO Redirection Plugin plugin <= 8.9 on WordPress.

    Published: 18 Nov 2022
    9.8
    Critical

    CVE-2022-42698

    Last Modified: 20 Feb 2025

    Unauth. Arbitrary File Upload vulnerability in WordPress Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress.

    Published: 18 Nov 2022
    10
    Critical

    CVE-2022-42497

    Last Modified: 20 Feb 2025

    Arbitrary Code Execution vulnerability in Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress.

    Published: 18 Nov 2022
    5.4
    Medium

    CVE-2022-41788

    Last Modified: 21 Nov 2024

    Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Soledad premium theme <= 8.2.5 on WordPress.

    Published: 18 Nov 2022
    4.3
    Medium

    CVE-2022-43492

    Last Modified: 20 Feb 2025

    Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress.

    Published: 18 Nov 2022
    5.4
    Medium

    CVE-2022-44740

    Last Modified: 20 Feb 2025

    Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Creative Mail plugin <= 1.5.4 on WordPress.

    Published: 18 Nov 2022
    7.5
    High

    CVE-2022-44583

    Last Modified: 20 Feb 2025

    Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.

    Published: 18 Nov 2022
    9.1
    Critical

    CVE-2022-44584

    Last Modified: 20 Feb 2025

    Unauth. Arbitrary File Deletion vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.

    Published: 18 Nov 2022
    3.4
    Low

    CVE-2022-45082

    Last Modified: 21 Nov 2024

    Multiple Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabilities in Accordions plugin <= 2.0.3 on WordPress via &addons-style-name and &accordions_or_faqs_license_key.

    Published: 18 Nov 2022
    4.9
    Medium

    CVE-2022-44634

    Last Modified: 20 Feb 2025

    Auth. (admin+) Arbitrary File Read vulnerability in S2W – Import Shopify to WooCommerce plugin <= 1.1.12 on WordPress.

    Published: 18 Nov 2022
    4.3
    Medium

    CVE-2022-45369

    Last Modified: 20 Feb 2025

    Auth. (subscriber+) Broken Access Control vulnerability in Plugin for Google Reviews plugin <= 2.2.2 on WordPress.

    Published: 18 Nov 2022
    5.3
    Medium

    CVE-2022-41839

    Last Modified: 20 Feb 2025

    Broken Access Control vulnerability in WordPress LoginPress plugin <= 1.6.2 on WordPress leading to unauth. changing of Opt-In or Opt-Out tracking settings.

    Published: 18 Nov 2022
    5.3
    Medium

    CVE-2022-42883

    Last Modified: 20 Feb 2025

    Sensitive Information Disclosure vulnerability discovered by Quiz And Survey Master plugin <= 7.3.10 on WordPress.

    Published: 18 Nov 2022
    5.4
    Medium

    CVE-2022-40698

    Last Modified: 21 Nov 2024

    Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.

    Published: 18 Nov 2022
    5.4
    Medium

    CVE-2022-45073

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in REST API Authentication plugin <= 2.4.0 on WordPress.

    Published: 18 Nov 2022
    7.8
    High

    CVE-2022-38395

    Last Modified: 29 Apr 2025

    HP Support Assistant uses HP Performance Tune-up as a diagnostic tool. HP Support Assistant uses Fusion to launch HP Performance Tune-up. It is possible for an attacker to exploit the DLL hijacking vulnerability and elevate privileges when Fusion launches the HP Performance Tune-up.

    Published: 18 Nov 2022
    7.5
    High

    CVE-2022-2794

    Last Modified: 29 Apr 2025

    Certain HP PageWide Pro Printers may be vulnerable to a potential denial of service attack.

    Published: 18 Nov 2022
    5.4
    Medium

    CVE-2022-42461

    Last Modified: 20 Feb 2025

    Broken Access Control vulnerability in miniOrange's Google Authenticator plugin <= 5.6.1 on WordPress.

    Published: 18 Nov 2022
    4.3
    Medium

    CVE-2022-43482

    Last Modified: 20 Feb 2025

    Missing Authorization vulnerability in Appointment Booking Calendar plugin <= 1.3.69 on WordPress.

    Published: 18 Nov 2022
    6.5
    Medium

    CVE-2022-41781

    Last Modified: 20 Feb 2025

    Broken Access Control vulnerability in Permalink Manager Lite plugin <= 2.2.20 on WordPress.

    Published: 18 Nov 2022
    6.1
    Medium

    CVE-2022-38075

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Mantenimiento web plugin <= 0.13 on WordPress.

    Published: 18 Nov 2022
    4.3
    Medium

    CVE-2022-41692

    Last Modified: 20 Feb 2025

    Missing Authorization vulnerability in Appointment Hour Booking plugin <= 1.3.71 on WordPress.

    Published: 18 Nov 2022
    4.8
    Medium

    CVE-2022-43463

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Custom Product Tabs for WooCommerce plugin <= 1.7.9 on WordPress.

    Published: 18 Nov 2022
    5.4
    Medium

    CVE-2022-40687

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress.

    Published: 18 Nov 2022
    5.4
    Medium

    CVE-2022-41805

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Booster for WooCommerce plugin <= 5.6.6 on WordPress.

    Published: 18 Nov 2022
    5.4
    Medium

    CVE-2022-40686

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress.

    Published: 18 Nov 2022
    6.5
    Medium

    CVE-2022-41652

    Last Modified: 20 Feb 2025

    Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.

    Published: 18 Nov 2022
    7.5
    High

    CVE-2022-41840

    Last Modified: 20 Feb 2025

    Unauth. Directory Traversal vulnerability in Welcart eCommerce plugin <= 2.7.7 on WordPress.

    Published: 18 Nov 2022
    4.3
    Medium

    CVE-2022-38974

    Last Modified: 20 Feb 2025

    Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with subscriber or higher user roles to change the status of the translation jobs.

    Published: 18 Nov 2022
    4.9
    Medium

    CVE-2022-22488

    Last Modified: 28 Apr 2025

    IBM OpenBMC OP910 and OP940 could allow a privileged user to cause a denial of service by uploading or deleting too many CA certificates in a short period of time. IBM X-Force ID: 2226337.

    Published: 18 Nov 2022
    3.5
    Low

    CVE-2022-45471

    Last Modified: 28 Apr 2025

    In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address

    Published: 18 Nov 2022
    6.5
    Medium

    CVE-2022-24038

    Last Modified: 20 May 2026

    Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to damage the page where the agents are listed.

    Published: 18 Nov 2022
    8.2
    High

    CVE-2022-24037

    Last Modified: 20 May 2026

    Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to obtain critical information.

    Published: 18 Nov 2022
    4.7
    Medium

    CVE-2023-1382

    Last Modified: 19 Mar 2025

    A data race flaw was found in the Linux kernel, between where con is allocated and con->sock is set. This issue leads to a NULL pointer dereference when accessing con->sock->sk in net/tipc/topsrv.c in the tipc protocol in the Linux kernel.

    Published: 18 Nov 2022
    5.5
    Medium

    CVE-2023-28328

    Last Modified: 19 Mar 2025

    A NULL pointer dereference flaw was found in the az6027 driver in drivers/media/usb/dev-usb/az6027.c in the Linux Kernel. The message from user space is not checked properly before transferring into the device. This flaw allows a local user to crash the system or potentially cause a denial of service.

    Published: 18 Nov 2022
    7.3
    High

    CVE-2022-31694

    Last Modified: 29 Apr 2025

    InstallBuilder Qt installers built with versions previous to 22.10 try to load DLLs from the installer binary parent directory when displaying popups. This may allow an attacker to plant a malicious DLL in the installer parent directory to allow executing code with the privileges of the installer (when the popup triggers the loading of the library). Exploiting these type of vulnerabilities generally require that an attacker has access to a vulnerable machine to plant the malicious DLL.

    Published: 18 Nov 2022
    6.5
    Medium

    CVE-2022-34665

    Last Modified: 29 Apr 2025

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a local user with basic capabilities can cause a null-pointer dereference, which may lead to denial of service.

    Published: 18 Nov 2022
    4.8
    Medium

    CVE-2022-41898

    Last Modified: 22 Apr 2025

    TensorFlow is an open source platform for machine learning. If `SparseFillEmptyRowsGrad` is given empty inputs, TensorFlow will crash. We have patched the issue in GitHub commit af4a6a3c8b95022c351edae94560acc61253a1b8. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.

    Published: 18 Nov 2022
    4.8
    Medium

    CVE-2022-41887

    Last Modified: 22 Apr 2025

    TensorFlow is an open source platform for machine learning. `tf.keras.losses.poisson` receives a `y_pred` and `y_true` that are passed through `functor::mul` in `BinaryOp`. If the resulting dimensions overflow an `int32`, TensorFlow will crash due to a size mismatch during broadcast assignment. We have patched the issue in GitHub commit c5b30379ba87cbe774b08ac50c1f6d36df4ebb7c. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1 and 2.9.3, as these are also affected and still in supported range. However, we will not cherrypick this commit into TensorFlow 2.8.x, as it depends on Eigen behavior that changed between 2.8 and 2.9.

    Published: 18 Nov 2022
    4.8
    Medium

    CVE-2022-41895

    Last Modified: 22 Apr 2025

    TensorFlow is an open source platform for machine learning. If `MirrorPadGrad` is given outsize input `paddings`, TensorFlow will give a heap OOB error. We have patched the issue in GitHub commit 717ca98d8c3bba348ff62281fdf38dcb5ea1ec92. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.

    Published: 18 Nov 2022
    4.8
    Medium

    CVE-2022-41896

    Last Modified: 22 Apr 2025

    TensorFlow is an open source platform for machine learning. If `ThreadUnsafeUnigramCandidateSampler` is given input `filterbank_channel_count` greater than the allowed max size, TensorFlow will crash. We have patched the issue in GitHub commit 39ec7eaf1428e90c37787e5b3fbd68ebd3c48860. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.

    Published: 18 Nov 2022
    4.8
    Medium

    CVE-2022-41899

    Last Modified: 22 Apr 2025

    TensorFlow is an open source platform for machine learning. Inputs `dense_features` or `example_state_data` not of rank 2 will trigger a `CHECK` fail in `SdcaOptimizer`. We have patched the issue in GitHub commit 80ff197d03db2a70c6a111f97dcdacad1b0babfa. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.

    Published: 18 Nov 2022
    7.1
    High

    CVE-2022-41900

    Last Modified: 22 Apr 2025

    TensorFlow is an open source platform for machine learning. The security vulnerability results in FractionalMax(AVG)Pool with illegal pooling_ratio. Attackers using Tensorflow can exploit the vulnerability. They can access heap memory which is not in the control of user, leading to a crash or remote code execution. We have patched the issue in GitHub commit 216525144ee7c910296f5b05d214ca1327c9ce48. The fix will be included in TensorFlow 2.11.0. We will also cherry pick this commit on TensorFlow 2.10.1.

    Published: 18 Nov 2022
    4.8
    Medium

    CVE-2022-41901

    Last Modified: 22 Apr 2025

    TensorFlow is an open source platform for machine learning. An input `sparse_matrix` that is not a matrix with a shape with rank 0 will trigger a `CHECK` fail in `tf.raw_ops.SparseMatrixNNZ`. We have patched the issue in GitHub commit f856d02e5322821aad155dad9b3acab1e9f5d693. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.

    Published: 18 Nov 2022
    4.8
    Medium

    CVE-2022-41908

    Last Modified: 22 Apr 2025

    TensorFlow is an open source platform for machine learning. An input `token` that is not a UTF-8 bytestring will trigger a `CHECK` fail in `tf.raw_ops.PyFunc`. We have patched the issue in GitHub commit 9f03a9d3bafe902c1e6beb105b2f24172f238645. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.

    Published: 18 Nov 2022
    4.8
    Medium

    CVE-2022-41909

    Last Modified: 22 Apr 2025

    TensorFlow is an open source platform for machine learning. An input `encoded` that is not a valid `CompositeTensorVariant` tensor will trigger a segfault in `tf.raw_ops.CompositeTensorVariantToComponents`. We have patched the issue in GitHub commits bf594d08d377dc6a3354d9fdb494b32d45f91971 and 660ce5a89eb6766834bdc303d2ab3902aef99d3d. The fix will be included in TensorFlow 2.11. We will also cherrypick this commit on TensorFlow 2.10.1, 2.9.3, and TensorFlow 2.8.4, as these are also affected and still in supported range.

    Published: 18 Nov 2022
    7.2
    High

    CVE-2022-44415

    Last Modified: 29 Apr 2025

    Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/mechanics/view_mechanic.php?id=.

    Published: 18 Nov 2022
    7.2
    High

    CVE-2022-42904

    Last Modified: 30 Apr 2025

    Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.

    Published: 18 Nov 2022
    7.2
    High

    CVE-2022-44414

    Last Modified: 29 Apr 2025

    Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/services/manage_service.php?id=.

    Published: 18 Nov 2022
    7.8
    High

    CVE-2022-43308

    Last Modified: 30 Apr 2025

    INTELBRAS SG 2404 MR 20180928-rel64938 allows authenticated attackers to arbitrarily create Administrator accounts via crafted user cookies.

    Published: 18 Nov 2022