CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-45703

    Last Modified: 21 Nov 2024

    Heap buffer overflow vulnerability in binutils readelf before 2.40 via function display_debug_section in file readelf.c.

    Published: 17 Nov 2022
    8.2
    High

    CVE-2022-39389

    Last Modified: 22 Apr 2025

    Lightning Network Daemon (lnd) is an implementation of a lightning bitcoin overlay network node. All lnd nodes before version `v0.15.4` are vulnerable to a block parsing bug that can cause a node to enter a degraded state once encountered. In this degraded state, nodes can continue to make payments and forward HTLCs, and close out channels. Opening channels is prohibited, and also on chain transaction events will be undetected. This can cause loss of funds if a CSV expiry is researched during a breach attempt or a CLTV delta expires forgetting the funds in the HTLC. A patch is available in `lnd` version 0.15.4. Users are advised to upgrade. Users unable to upgrade may use the `lncli updatechanpolicy` RPC call to increase their CLTV value to a very high amount or increase their fee policies. This will prevent nodes from routing through your node, meaning that no pending HTLCs can be present.

    Published: 17 Nov 2022
    6.3
    Medium

    CVE-2022-4051

    Last Modified: 15 Apr 2025

    A vulnerability has been found in Hostel Searching Project and classified as critical. This vulnerability affects unknown code of the file view-property.php. The manipulation of the argument property_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-213844.

    Published: 17 Nov 2022
    2.4
    Low

    CVE-2022-4053

    Last Modified: 15 Apr 2025

    A vulnerability was found in Student Attendance Management System. It has been classified as problematic. Affected is an unknown function of the file createClass.php. The manipulation of the argument className leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-213846 is the identifier assigned to this vulnerability.

    Published: 17 Nov 2022
    6.3
    Medium

    CVE-2022-41920

    Last Modified: 22 Apr 2025

    Lancet is a general utility library for the go programming language. Affected versions are subject to a ZipSlip issue when using the fileutil package to unzip files. This issue has been addressed and a fix will be included in versions 2.1.10 and 1.3.4. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 17 Nov 2022
    9.8
    Critical

    CVE-2022-42245

    Last Modified: 29 Apr 2025

    Dreamer CMS 4.0.01 is vulnerable to SQL Injection.

    Published: 17 Nov 2022
    8.8
    High

    CVE-2022-42246

    Last Modified: 29 Apr 2025

    Doufox 0.0.4 contains a CSRF vulnerability that can add system administrator account.

    Published: 17 Nov 2022
    5.4
    Medium

    CVE-2022-42954

    Last Modified: 30 Apr 2025

    Keyfactor EJBCA before 7.10.0 allows XSS.

    Published: 17 Nov 2022
    6.1
    Medium

    CVE-2022-43332

    Last Modified: 29 Apr 2025

    A cross-site scripting (XSS) vulnerability in Wondercms v3.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Site title field of the Configuration Panel.

    Published: 17 Nov 2022
    7.2
    High

    CVE-2022-44402

    Last Modified: 29 Apr 2025

    Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_transaction.

    Published: 17 Nov 2022
    —
    Unknown

    CVE-2022-4038

    Last Modified: 29 Jul 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 16 Nov 2022
    4
    Medium

    CVE-2022-34354

    Last Modified: 25 Apr 2025

    IBM Sterling Partner Engagement Manager 2.0 allows encrypted storage of client data to be stored locally which can be read by another user on the system. IBM X-Force ID: 230424.

    Published: 16 Nov 2022
    6.4
    Medium

    CVE-2022-4022

    Last Modified: 7 Feb 2025

    The SVG Support plugin for WordPress defaults to insecure settings in version 2.5 and 2.5.1. SVG files containing malicious javascript are not sanitized. While version 2.5 adds the ability to sanitize image as they are uploaded, the plugin defaults to disable sanitization and does not restrict SVG upload to only administrators. This allows authenticated attackers, with author-level privileges and higher, to upload malicious SVG files that can be embedded in posts and pages by higher privileged users. Additionally, the embedded JavaScript is also triggered on visiting the image URL, which allows an attacker to execute malicious code in browsers visiting that URL.

    Published: 16 Nov 2022
    8.8
    High

    CVE-2022-4021

    Last Modified: 8 Apr 2026

    The Permalink Manager Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.20.1. This is due to missing or incorrect nonce validation on the extra_actions function. This makes it possible for unauthenticated attackers to change plugin settings including permalinks and site maps, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 16 Nov 2022
    8.6
    High

    CVE-2022-24036

    Last Modified: 20 May 2026

    Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to modificate logs.

    Published: 16 Nov 2022
    9.8
    Critical

    CVE-2022-44006

    Last Modified: 30 Apr 2025

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files outside the intended target location. Achieving remote code execution is possible, e.g., by uploading an executable file.

    Published: 16 Nov 2022
    6.1
    Medium

    CVE-2022-44002

    Last Modified: 30 Apr 2025

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient output encoding of user-supplied data, the web application is vulnerable to cross-site scripting (XSS) at various locations.

    Published: 16 Nov 2022
    6.1
    Medium

    CVE-2022-43263

    Last Modified: 30 Apr 2025

    A cross-site scripting (XSS) vulnerability in Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the name of an uploaded file.

    Published: 16 Nov 2022
    9.8
    Critical

    CVE-2022-43262

    Last Modified: 21 Nov 2024

    Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /hrm/controller/login.php.

    Published: 16 Nov 2022
    9.8
    Critical

    CVE-2022-43234

    Last Modified: 30 Apr 2025

    An arbitrary file upload vulnerability in the /attachments component of Hoosk v1.8 allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 16 Nov 2022
    9.8
    Critical

    CVE-2022-43135

    Last Modified: 30 Apr 2025

    Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /diagnostic/login.php.

    Published: 16 Nov 2022
    9.8
    Critical

    CVE-2022-40752

    Last Modified: 23 Jul 2025

    IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID:  236687.

    Published: 16 Nov 2022
    4.3
    Medium

    CVE-2022-4014

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, has been found in FeehiCMS. Affected by this issue is some unknown functionality of the component Post My Comment Tab. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The identifier of this vulnerability is VDB-213788.

    Published: 16 Nov 2022
    4.3
    Medium

    CVE-2022-4013

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic was found in Hospital Management Center. Affected by this vulnerability is an unknown functionality of the file appointment.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-213787.

    Published: 16 Nov 2022
    6.3
    Medium

    CVE-2022-4012

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical has been found in Hospital Management Center. Affected is an unknown function of the file patient-info.php. The manipulation of the argument pt_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-213786 is the identifier assigned to this vulnerability.

    Published: 16 Nov 2022
    4.9
    Medium

    CVE-2022-39383

    Last Modified: 23 Apr 2025

    KubeVela is an open source application delivery platform. Users using the VelaUX APIServer could be affected by this vulnerability. When using Helm Chart as the component delivery method, the request address of the warehouse is not restricted, and there is a blind SSRF vulnerability. Users who're using v1.6, please update the v1.6.1. Users who're using v1.5, please update the v1.5.8. There are no known workarounds for this issue.

    Published: 16 Nov 2022
    9.8
    Critical

    CVE-2022-45047

    Last Modified: 1 May 2026

    Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apache MINA SSHD can choose for loading the host keys of an SSH server.

    Published: 16 Nov 2022
    4.6
    Medium

    CVE-2022-39317

    Last Modified: 23 Apr 2025

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing a range check for input offset index in ZGFX decoder. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it. This issue has been addressed in version 2.9.0. There are no known workarounds for this issue.

    Published: 16 Nov 2022
    9.8
    Critical

    CVE-2022-3980

    Last Modified: 29 Apr 2025

    An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.

    Published: 16 Nov 2022
    4.7
    Medium

    CVE-2022-4015

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in Sports Club Management System 119. This affects an unknown part of the file admin/make_payments.php. The manipulation of the argument m_id/plan leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-213789 was assigned to this vulnerability.

    Published: 16 Nov 2022
    3.7
    Low

    CVE-2022-41914

    Last Modified: 23 Apr 2025

    Zulip is an open-source team collaboration tool. For organizations with System for Cross-domain Identity Management(SCIM) account management enabled, Zulip Server 5.0 through 5.6 checked the SCIM bearer token using a comparator that did not run in constant time. Therefore, it might theoretically be possible for an attacker to infer the value of the token by performing a sophisticated timing analysis on a large number of failing requests. If successful, this would allow the attacker to impersonate the SCIM client for its abilities to read and update user accounts in the Zulip organization. Organizations where SCIM account management has not been enabled are not affected.

    Published: 16 Nov 2022
    9.8
    Critical

    CVE-2022-43256

    Last Modified: 30 Apr 2025

    SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.

    Published: 16 Nov 2022
    7.5
    High

    CVE-2022-43264

    Last Modified: 30 Apr 2025

    Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to perform directory traversal and download arbitrary files via a crafted web request.

    Published: 16 Nov 2022
    9.8
    Critical

    CVE-2022-44000

    Last Modified: 30 Apr 2025

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is possible to execute arbitrary system commands on the server.

    Published: 16 Nov 2022
    9.8
    Critical

    CVE-2022-44004

    Last Modified: 30 Apr 2025

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can complete the password-reset process for any account and set a new password.

    Published: 16 Nov 2022
    5.3
    Medium

    CVE-2022-44005

    Last Modified: 30 Apr 2025

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to the use of consecutive IDs in verification links, the newsletter sign-up functionality is vulnerable to the enumeration of subscribers' e-mail addresses. Furthermore, it is possible to subscribe and verify other persons' e-mail addresses to newsletters without their consent.

    Published: 16 Nov 2022
    6.5
    Medium

    CVE-2022-44008

    Last Modified: 30 Apr 2025

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation, arbitrary local files can be retrieved by accessing the back-end Tomcat server directly.

    Published: 16 Nov 2022
    5.4
    Medium

    CVE-2022-44069

    Last Modified: 30 Apr 2025

    Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via the Nest library module.

    Published: 16 Nov 2022
    5.4
    Medium

    CVE-2022-44070

    Last Modified: 30 Apr 2025

    Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via News articles.

    Published: 16 Nov 2022
    5.4
    Medium

    CVE-2022-44071

    Last Modified: 30 Apr 2025

    Zenario CMS 9.3.57186 is is vulnerable to Cross Site Scripting (XSS) via profile.

    Published: 16 Nov 2022
    5.4
    Medium

    CVE-2022-44073

    Last Modified: 30 Apr 2025

    Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via svg,Users & Contacts.

    Published: 16 Nov 2022
    9.8
    Critical

    CVE-2022-44003

    Last Modified: 30 Apr 2025

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations.

    Published: 16 Nov 2022
    8.8
    High

    CVE-2022-44007

    Last Modified: 29 Apr 2025

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to an unsafe implementation of session tracking, it is possible for an attacker to trick users into opening an authenticated user session for a session identifier known to the attacker, aka Session Fixation.

    Published: 16 Nov 2022
    8.8
    High

    CVE-2021-38819

    Last Modified: 30 Apr 2025

    A SQL injection vulnerability exits on the Simple Image Gallery System 1.0 application through "id" parameter on the album page.

    Published: 16 Nov 2022
    7.5
    High

    CVE-2022-45931

    Last Modified: 29 Apr 2025

    A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/UserStore.java deleteUser function is affected when the API interface /auth/v1/users/ is used.

    Published: 16 Nov 2022
    7.5
    High

    CVE-2022-45932

    Last Modified: 29 Apr 2025

    A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/RoleStore.java deleteRole function is affected when the API interface /auth/v1/roles/ is used.

    Published: 16 Nov 2022
    6.5
    Medium

    CVE-2022-4011

    Last Modified: 14 Apr 2025

    A vulnerability was found in Simple History Plugin. It has been rated as critical. This issue affects some unknown processing of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to improper output neutralization for logs. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-213785 was assigned to this vulnerability.

    Published: 16 Nov 2022
    4.3
    Medium

    CVE-2022-4018

    Last Modified: 14 Apr 2025

    Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.

    Published: 16 Nov 2022
    9.8
    Critical

    CVE-2022-2166

    Last Modified: 29 Apr 2025

    Improper Restriction of Excessive Authentication Attempts in GitHub repository mastodon/mastodon prior to 4.0.0.

    Published: 16 Nov 2022
    4.6
    Medium

    CVE-2022-41877

    Last Modified: 3 Nov 2025

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length validation in `drive` channel. A malicious server can trick a FreeRDP based client to read out of bound data and send it back to the server. This issue has been addressed in version 2.9.0 and all users are advised to upgrade. Users unable to upgrade should not use the drive redirection channel - command line options `/drive`, `+drives` or `+home-drive`.

    Published: 16 Nov 2022