CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2022-36924

    Last Modified: 28 Apr 2025

    The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to the SYSTEM user.

    Published: 17 Nov 2022
    3.3
    Low

    CVE-2022-28766

    Last Modified: 29 Apr 2025

    Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version 5.12.6 are susceptible to a DLL injection vulnerability. A local low-privileged user could exploit this vulnerability to run arbitrary code in the context of the Zoom client.

    Published: 17 Nov 2022
    8.8
    High

    CVE-2022-28768

    Last Modified: 29 Apr 2025

    The Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) before version 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to root.

    Published: 17 Nov 2022
    7.5
    High

    CVE-2022-36785

    Last Modified: 29 Apr 2025

    D-Link – G integrated Access Device4 Information Disclosure & Authorization Bypass. *Information Disclosure – file contains a URL with private IP at line 15 "login.asp" A. The window.location.href = http://192.168.1.1/setupWizard.asp" http://192.168.1.1/setupWizard.asp" ; "admin" – contains default username value "login.asp" B. While accessing the web interface, the login form at *Authorization Bypass – URL by "setupWizard.asp' while it blocks direct access to – the web interface does not properly validate user identity variables values located at the client side, it is available to access it without a "login_glag" and "login_status" checking browser and to read the admin user credentials for the web interface.

    Published: 17 Nov 2022
    7.2
    High

    CVE-2022-39179

    Last Modified: 28 Apr 2025

    College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload .php file that contains malicious code via student.php file.

    Published: 17 Nov 2022
    5.3
    Medium

    CVE-2022-39178

    Last Modified: 28 Apr 2025

    Webvendome - webvendome Internal Server IP Disclosure. Send GET Request to the request which is shown in the picture. Internal Server IP and Full path disclosure.

    Published: 17 Nov 2022
    9.8
    Critical

    CVE-2022-39180

    Last Modified: 29 Apr 2025

    College Management System v1.0 - SQL Injection (SQLi). By inserting SQL commands to the username and password fields in the login.php page

    Published: 17 Nov 2022
    6.1
    Medium

    CVE-2022-39181

    Last Modified: 29 Apr 2025

    GLPI - Reports plugin for GLPI Reflected Cross-Site-Scripting (RXSS). Type 1: Reflected XSS (or Non-Persistent) - The server reads data directly from the HTTP request and reflects it back in the HTTP response. Reflected XSS exploits occur when an attacker causes a victim to supply dangerous content to a vulnerable web application, which is then reflected back to the victim and executed by the web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or emailed directly to the victim. URLs constructed in this manner constitute the core of many phishing schemes, whereby an attacker convinces a victim to visit a URL that refers to a vulnerable site. After the site reflects the attacker's content back to the victim, the content is executed by the victim's browser.

    Published: 17 Nov 2022
    9.8
    Critical

    CVE-2022-36784

    Last Modified: 25 Apr 2025

    Elsight – Elsight Halo  Remote Code Execution (RCE) Elsight Halo web panel allows us to perform connection validation. through the POST request : /api/v1/nics/wifi/wlan0/ping we can abuse DESTINATION parameter and leverage it to remote code execution.

    Published: 17 Nov 2022
    9.8
    Critical

    CVE-2022-36787

    Last Modified: 25 Apr 2025

    webvendome - webvendome SQL Injection. SQL Injection in the Parameter " DocNumber" Request : Get Request : /webvendome/showfiles.aspx?jobnumber=nullDoc Number=HERE.

    Published: 17 Nov 2022
    6.3
    Medium

    CVE-2022-45069

    Last Modified: 20 Feb 2025

    Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress.

    Published: 17 Nov 2022
    4.8
    Medium

    CVE-2022-40694

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in News Announcement Scroll plugin <= 8.8.8 on WordPress.

    Published: 17 Nov 2022
    4.8
    Medium

    CVE-2022-44736

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Chameleon plugin <= 1.4.3 on WordPress.

    Published: 17 Nov 2022
    7.1
    High

    CVE-2022-40192

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.

    Published: 17 Nov 2022
    4.8
    Medium

    CVE-2022-41315

    Last Modified: 21 Nov 2024

    Auth. Stored Cross-Site Scripting (XSS) vulnerability in Ezoic plugin <= 2.8.8 on WordPress.

    Published: 17 Nov 2022
    6.1
    Medium

    CVE-2022-41132

    Last Modified: 21 Nov 2024

    Unauthenticated Plugin Settings Change Leading To Stored XSS Vulnerability in Ezoic plugin <= 2.8.8 on WordPress.

    Published: 17 Nov 2022
    4.8
    Medium

    CVE-2022-44591

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Anthologize plugin <= 0.8.0 on WordPress.

    Published: 17 Nov 2022
    6.8
    Medium

    CVE-2022-41791

    Last Modified: 28 Apr 2026

    Auth. (subscriber+) CSV Injection vulnerability in ProfileGrid plugin <= 5.1.6 on WordPress.

    Published: 17 Nov 2022
    6.3
    Medium

    CVE-2022-45077

    Last Modified: 20 Feb 2025

    Auth. (subscriber+) PHP Object Injection vulnerability in Betheme theme <= 26.5.1.4 on WordPress.

    Published: 17 Nov 2022
    6.1
    Medium

    CVE-2022-36357

    Last Modified: 20 Feb 2025

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Webpsilon ULTIMATE TABLES plugin <= 1.6.5 versions.

    Published: 17 Nov 2022
    5.4
    Medium

    CVE-2022-45066

    Last Modified: 20 Feb 2025

    Auth. (subscriber+) Broken Access Control vulnerability in WooSwipe WooCommerce Gallery plugin <= 2.0.1 on WordPress.

    Published: 17 Nov 2022
    5.4
    Medium

    CVE-2022-45375

    Last Modified: 21 Nov 2024

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in iFeature Slider plugin <= 1.2 on WordPress.

    Published: 17 Nov 2022
    5.4
    Medium

    CVE-2021-36905

    Last Modified: 21 Nov 2024

    Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3.4 on WordPress.

    Published: 17 Nov 2022
    9.9
    Critical

    CVE-2022-40200

    Last Modified: 20 Feb 2025

    Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.

    Published: 17 Nov 2022
    5.4
    Medium

    CVE-2022-38461

    Last Modified: 20 Feb 2025

    Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with a subscriber or higher user role to change plugin settings (selected language for legacy widgets, the default behavior for media content).

    Published: 17 Nov 2022
    5.4
    Medium

    CVE-2022-45071

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress.

    Published: 17 Nov 2022
    4.3
    Medium

    CVE-2022-45072

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress.

    Published: 17 Nov 2022
    7.5
    High

    CVE-2022-3090

    Last Modified: 16 Apr 2025

    Red Lion Controls Crimson 3.0 versions 707.000 and prior, Crimson 3.1 versions 3126.001 and prior, and Crimson 3.2 versions 3.2.0044.0 and prior are vulnerable to path traversal. When attempting to open a file using a specific path, the user's password hash is sent to an arbitrary host. This could allow an attacker to obtain user credential hashes.

    Published: 17 Nov 2022
    4.8
    Medium

    CVE-2022-32537

    Last Modified: 7 May 2026

    A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pair system components while the pump is being paired with other system components. Exploitation requires nearby wireless signal proximity with the patient and the device; advanced technical knowledge is required for exploitation. Please refer to the Medtronic Product Security Bulletin for guidance

    Published: 17 Nov 2022
    5.4
    Medium

    CVE-2022-38390

    Last Modified: 29 Apr 2025

    Multiple IBM Business Automation Workflow versions are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 233978.

    Published: 17 Nov 2022
    4.9
    Medium

    CVE-2022-40751

    Last Modified: 29 Apr 2025

    IBM UrbanCode Deploy (UCD) 6.2.7.0 through 6.2.7.17, 7.0.0.0 through 7.0.5.12, 7.1.0.0 through 7.1.2.8, and 7.2.0.0 through 7.2.3.1 could allow a user with administrative privileges including "Manage Security" permissions may be able to recover a credential previously saved for performing authenticated LDAP searches.  IBM X-Force ID:   236601.

    Published: 17 Nov 2022
    9.8
    Critical

    CVE-2022-43782

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path. This vulnerability can only be exploited by IPs specified under the crowd application allowlist in the Remote Addresses configuration, which is {{none}} by default. The affected versions are all versions 3.x.x, versions 4.x.x before version 4.4.4, and versions 5.x.x before 5.0.3

    Published: 17 Nov 2022
    9.8
    Critical

    CVE-2022-43781

    Last Modified: 21 Nov 2024

    There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.

    Published: 17 Nov 2022
    7.5
    High

    CVE-2022-45461

    Last Modified: 29 Apr 2025

    The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that have been explicitly added to the auth.conf file) to execute arbitrary commands as root.

    Published: 17 Nov 2022
    6.7
    Medium

    CVE-2022-20428

    Last Modified: 30 Apr 2025

    In (TBD) of (TBD), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239555411References: N/A

    Published: 17 Nov 2022
    6.8
    Medium

    CVE-2022-43096

    Last Modified: 30 Apr 2025

    Mediatrix 4102 before v48.5.2718 allows local attackers to gain root access via the UART port.

    Published: 17 Nov 2022
    9.8
    Critical

    CVE-2022-38165

    Last Modified: 30 Apr 2025

    Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with the contents in arbitrary locations on the F-Secure Policy Manager Server.

    Published: 17 Nov 2022
    4.7
    Medium

    CVE-2022-4052

    Last Modified: 15 Apr 2025

    A vulnerability was found in Student Attendance Management System and classified as critical. This issue affects some unknown processing of the file /Admin/createClass.php. The manipulation of the argument Id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-213845 was assigned to this vulnerability.

    Published: 17 Nov 2022
    8.8
    High

    CVE-2022-44384

    Last Modified: 29 Apr 2025

    An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 17 Nov 2022
    7.5
    High

    CVE-2022-42894

    Last Modified: 30 Apr 2025

    A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). An unauthenticated Server-Side Request Forgery (SSRF) vulnerability was identified in one of the web services exposed on the syngo Dynamics application that could allow for the leaking of NTLM credentials as well as local service enumeration.

    Published: 17 Nov 2022
    7.5
    High

    CVE-2022-42982

    Last Modified: 30 Apr 2025

    BKG Professional NtripCaster 2.0.39 allows querying information over the UDP protocol without authentication. The NTRIP sourcetable is typically quite long (tens of kBs) and can be requested with a packet of only 30 bytes. This presents a vector that can be used for UDP amplification attacks. Normally, only authenticated streaming data will be provided over UDP and not the sourcetable.

    Published: 17 Nov 2022
    4.8
    Medium

    CVE-2022-42985

    Last Modified: 25 Apr 2025

    The ScratchLogin extension through 1.1 for MediaWiki does not escape verification failure messages, which allows users with administrator privileges to perform cross-site scripting (XSS).

    Published: 17 Nov 2022
    9.8
    Critical

    CVE-2022-43138

    Last Modified: 30 Apr 2025

    Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.

    Published: 17 Nov 2022
    7.5
    High

    CVE-2022-43140

    Last Modified: 30 Apr 2025

    kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#getCorsFile. This vulnerability allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the url parameter.

    Published: 17 Nov 2022
    6.1
    Medium

    CVE-2022-43142

    Last Modified: 29 Apr 2025

    A cross-site scripting (XSS) vulnerability in the add-fee.php component of Password Storage Application v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cmddept parameter.

    Published: 17 Nov 2022
    7.2
    High

    CVE-2022-43162

    Last Modified: 29 Apr 2025

    Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tests/view_test.php.

    Published: 17 Nov 2022
    7.2
    High

    CVE-2022-43163

    Last Modified: 29 Apr 2025

    Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clients/view_client.php.

    Published: 17 Nov 2022
    6.5
    Medium

    CVE-2022-43171

    Last Modified: 29 Apr 2025

    A heap buffer overflow in the LIEF::MachO::BinaryParser::parse_dyldinfo_generic_bind function of LIEF v0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted MachO file.

    Published: 17 Nov 2022
    7.2
    High

    CVE-2022-43179

    Last Modified: 29 Apr 2025

    Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/?page=user/manage_user&id=.

    Published: 17 Nov 2022
    8.8
    High

    CVE-2022-43183

    Last Modified: 29 Apr 2025

    XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.

    Published: 17 Nov 2022