CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2022-42960

    Last Modified: 30 Apr 2025

    EqualWeb Accessibility Widget 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.10, 3.0.0, 3.0.1, 3.0.2, 4.0.0, and 4.0.1 allows DOM XSS due to improper validation of message events to accessibility.js.

    Published: 16 Nov 2022
    9.8
    Critical

    CVE-2022-43999

    Last Modified: 30 Apr 2025

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system commands can be executed on the server.

    Published: 16 Nov 2022
    7.5
    High

    CVE-2022-45930

    Last Modified: 29 Apr 2025

    A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/DomainStore.java deleteDomain function is affected for the /auth/v1/domains/ API interface.

    Published: 16 Nov 2022
    5.5
    Medium

    CVE-2022-39320

    Last Modified: 3 Nov 2025

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP may attempt integer addition on too narrow types leads to allocation of a buffer too small holding the data written. A malicious server can trick a FreeRDP based client to read out of bound data and send it back to the server. This issue has been addressed in version 2.9.0 and all users are advised to upgrade. Users unable to upgrade should not use the `/usb` redirection switch.

    Published: 16 Nov 2022
    4.8
    Medium

    CVE-2022-39316

    Last Modified: 3 Nov 2025

    FreeRDP is a free remote desktop protocol library and clients. In affected versions there is an out of bound read in ZGFX decoder component of FreeRDP. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it likely resulting in a crash. This issue has been addressed in the 2.9.0 release. Users are advised to upgrade.

    Published: 16 Nov 2022
    4.8
    Medium

    CVE-2022-39318

    Last Modified: 3 Nov 2025

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input validation in `urbdrc` channel. A malicious server can trick a FreeRDP based client to crash with division by zero. This issue has been addressed in version 2.9.0. All users are advised to upgrade. Users unable to upgrade should not use the `/usb` redirection switch.

    Published: 16 Nov 2022
    4.6
    Medium

    CVE-2022-39319

    Last Modified: 3 Nov 2025

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length validation in the `urbdrc` channel. A malicious server can trick a FreeRDP based client to read out of bound data and send it back to the server. This issue has been addressed in version 2.9.0 and all users are advised to upgrade. Users unable to upgrade should not use the `/usb` redirection switch.

    Published: 16 Nov 2022
    2.6
    Low

    CVE-2022-39347

    Last Modified: 3 Nov 2025

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for `drive` channel. A malicious server can trick a FreeRDP based client to read files outside the shared directory. This issue has been addressed in version 2.9.0 and all users are advised to upgrade. Users unable to upgrade should not use the `/drive`, `/drives` or `+home-drive` redirection switch.

    Published: 16 Nov 2022
    4.2
    Medium

    CVE-2022-27895

    Last Modified: 29 Apr 2025

    Information Exposure Through Log Files vulnerability discovered in Foundry when logs were captured using an underlying library known as Build2. This issue was present in versions earlier than 1.785.0. Upgrade to Build2 version 1.785.0 or greater.

    Published: 15 Nov 2022
    9
    Critical

    CVE-2022-41558

    Last Modified: 29 Apr 2025

    The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analyst, TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Desktop, TIBCO Spotfire Desktop, TIBCO Spotfire Desktop, TIBCO Spotfire Server, TIBCO Spotfire Server, and TIBCO Spotfire Server contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analyst: versions 11.4.4 and below, TIBCO Spotfire Analyst: versions 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, and 12.0.1, TIBCO Spotfire Analyst: version 12.1.0, TIBCO Spotfire Analytics Platform for AWS Marketplace: versions 12.1.0 and below, TIBCO Spotfire Desktop: versions 11.4.4 and below, TIBCO Spotfire Desktop: versions 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, and 12.0.1, TIBCO Spotfire Desktop: version 12.1.0, TIBCO Spotfire Server: versions 11.4.8 and below, TIBCO Spotfire Server: versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.7.0, 11.8.0, 11.8.1, 12.0.0, and 12.0.1, and TIBCO Spotfire Server: version 12.1.0.

    Published: 15 Nov 2022
    7.5
    High

    CVE-2022-43780

    Last Modified: 30 Apr 2025

    Certain HP ENVY, OfficeJet, and DeskJet printers may be vulnerable to a Denial of Service attack.

    Published: 15 Nov 2022
    3.3
    Low

    CVE-2022-42001

    Last Modified: 29 Apr 2025

    Cross-site Scripting (XSS) vulnerability in BlueSpiceBookshelf extension of BlueSpice allows user with regular account and edit permissions to inject arbitrary HTML into the book navigation.

    Published: 15 Nov 2022
    3.3
    Low

    CVE-2022-42000

    Last Modified: 28 Apr 2025

    Cross-site Scripting (XSS) vulnerability in BlueSpiceSocialProfile extension of BlueSpice allows user with comment permissions to inject arbitrary HTML into the comment section of a wikipage.

    Published: 15 Nov 2022
    3.3
    Low

    CVE-2022-41814

    Last Modified: 29 Apr 2025

    Cross-site Scripting (XSS) vulnerability in BlueSpiceFoundation extension of BlueSpice allows user with regular account and edit permissions to inject arbitrary HTML into the history view of a wikipage.

    Published: 15 Nov 2022
    3.3
    Low

    CVE-2022-41789

    Last Modified: 29 Apr 2025

    Cross-site Scripting (XSS) vulnerability in BlueSpiceDiscovery skin of BlueSpice allows logged in user with edit permissions to inject arbitrary HTML into the default page header of a wikipage.

    Published: 15 Nov 2022
    2.3
    Low

    CVE-2022-41611

    Last Modified: 29 Apr 2025

    Cross-site Scripting (XSS) vulnerability in BlueSpiceDiscovery skin of BlueSpice allows user with admin privileges to inject arbitrary HTML into the main navigation of the application.

    Published: 15 Nov 2022
    3.3
    Low

    CVE-2022-3958

    Last Modified: 29 Apr 2025

    Cross-site Scripting (XSS) vulnerability in BlueSpiceUserSidebar extension of BlueSpice allows user with regular account and edit permissions to inject arbitrary HTML into the personal menu navigation of their own and other users. This allows for targeted attacks.

    Published: 15 Nov 2022
    4
    Medium

    CVE-2022-3895

    Last Modified: 29 Apr 2025

    Some UI elements of the Common User Interface Component are not properly sanitizing output and therefore prone to output arbitrary HTML (XSS).

    Published: 15 Nov 2022
    2.3
    Low

    CVE-2022-3893

    Last Modified: 29 Apr 2025

    Cross-site Scripting (XSS) vulnerability in BlueSpiceCustomMenu extension of BlueSpice allows user with admin permissions to inject arbitrary HTML into the custom menu navigation of the application.

    Published: 15 Nov 2022
    8.8
    High

    CVE-2022-3240

    Last Modified: 8 Apr 2026

    The "Follow Me Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.1. This is due to missing nonce validation on the FollowMeIgniteSocialMedia_options_page() function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 15 Nov 2022
    7.8
    High

    CVE-2022-3461

    Last Modified: 29 Apr 2025

    In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 manipulated PC Worx or Config+ files could lead to a heap buffer overflow and a read access violation. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.

    Published: 15 Nov 2022
    7.8
    High

    CVE-2022-3737

    Last Modified: 28 Apr 2025

    In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.

    Published: 15 Nov 2022
    7.5
    High

    CVE-2022-3480

    Last Modified: 29 Apr 2025

    A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending a larger number of unauthenticated HTTPS connections originating from different source IP’s. Configuring firewall limits for incoming connections cannot prevent the issue.

    Published: 15 Nov 2022
    8.6
    High

    CVE-2022-2601

    Last Modified: 20 May 2025

    A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow and a heap based out-of-bounds write. An attacker may use this vulnerability to circumvent the secure boot mechanism.

    Published: 15 Nov 2022
    7.5
    High

    CVE-2022-33239

    Last Modified: 22 Apr 2025

    Transient DOS due to loop with unreachable exit condition in WLAN firmware while parsing IPV6 extension header. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 15 Nov 2022
    7.5
    High

    CVE-2022-38666

    Last Modified: 30 Apr 2025

    Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.146 and earlier unconditionally disables SSL/TLS certificate and hostname validation for several features.

    Published: 15 Nov 2022
    7.8
    High

    CVE-2022-41396

    Last Modified: 30 Apr 2025

    Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command injection vulnerabilities in the function setIPsecTunnelList via the IPsecLocalNet and IPsecRemoteNet parameters.

    Published: 15 Nov 2022
    6.3
    Medium

    CVE-2022-41918

    Last Modified: 23 Apr 2025

    OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementation of fine-grained access control rules (document-level security, field-level security and field masking) where they are not correctly applied to the indices that back data streams potentially leading to incorrect access authorization. OpenSearch 1.3.7 and 2.4.0 contain a fix for this issue. Users are advised to update. There are no known workarounds for this issue.

    Published: 15 Nov 2022
    7.5
    High

    CVE-2022-42977

    Last Modified: 30 Apr 2025

    The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the functionality to generate a list of users in the application, and export it. During export, the HTTP request has a fileName parameter that accepts any file on the system (e.g., an SSH private key) to be downloaded.

    Published: 15 Nov 2022
    5.5
    Medium

    CVE-2022-43071

    Last Modified: 30 Apr 2025

    A stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

    Published: 15 Nov 2022
    7.5
    High

    CVE-2022-45379

    Last Modified: 21 Nov 2024

    Jenkins Script Security Plugin 1189.vb_a_b_7c8fd5fde and earlier stores whole-script approvals as the SHA-1 hash of the script, making it vulnerable to collision attacks.

    Published: 15 Nov 2022
    9.8
    Critical

    CVE-2022-43265

    Last Modified: 30 Apr 2025

    An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 15 Nov 2022
    5.4
    Medium

    CVE-2022-45387

    Last Modified: 30 Apr 2025

    Jenkins BART Plugin 1.0.3 and earlier does not escape the parsed content of build logs before rendering it on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability.

    Published: 15 Nov 2022
    8.8
    High

    CVE-2022-42898

    Last Modified: 14 Apr 2025

    PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."

    Published: 15 Nov 2022
    7.5
    High

    CVE-2022-45391

    Last Modified: 30 Apr 2025

    Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/TLS certificate and hostname validation for the entire Jenkins controller JVM.

    Published: 15 Nov 2022
    6.5
    Medium

    CVE-2022-45408

    Last Modified: 15 Apr 2025

    Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

    Published: 15 Nov 2022
    7.2
    High

    CVE-2022-43279

    Last Modified: 21 Nov 2024

    LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php.

    Published: 15 Nov 2022
    7
    High

    CVE-2022-45885

    Last Modified: 29 Apr 2025

    An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_frontend.c has a race condition that can cause a use-after-free when a device is disconnected.

    Published: 15 Nov 2022
    4.7
    Medium

    CVE-2022-45887

    Last Modified: 25 Apr 2025

    An issue was discovered in the Linux kernel through 6.0.9. drivers/media/usb/ttusb-dec/ttusb_dec.c has a memory leak because of the lack of a dvb_frontend_detach call.

    Published: 15 Nov 2022
    5.4
    Medium

    CVE-2022-45380

    Last Modified: 30 Apr 2025

    Jenkins JUnit Plugin 1159.v0b_396e1e07dd and earlier converts HTTP(S) URLs in test report output to clickable links in an unsafe manner, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 15 Nov 2022
    7.5
    High

    CVE-2022-45388

    Last Modified: 30 Apr 2025

    Jenkins Config Rotator Plugin 2.0.1 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing unauthenticated attackers to read arbitrary files with '.xml' extension on the Jenkins controller file system.

    Published: 15 Nov 2022
    5.3
    Medium

    CVE-2022-45389

    Last Modified: 30 Apr 2025

    A missing permission check in Jenkins XP-Dev Plugin 1.0 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to an attacker-specified repository.

    Published: 15 Nov 2022
    9.8
    Critical

    CVE-2022-45397

    Last Modified: 30 Apr 2025

    Jenkins OSF Builder Suite : : XML Linter Plugin 1.0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 15 Nov 2022
    4.3
    Medium

    CVE-2022-45398

    Last Modified: 30 Apr 2025

    A cross-site request forgery (CSRF) vulnerability in Jenkins Cluster Statistics Plugin 0.4.6 and earlier allows attackers to delete recorded Jenkins Cluster Statistics.

    Published: 15 Nov 2022
    4.3
    Medium

    CVE-2022-45399

    Last Modified: 30 Apr 2025

    A missing permission check in Jenkins Cluster Statistics Plugin 0.4.6 and earlier allows attackers to delete recorded Jenkins Cluster Statistics.

    Published: 15 Nov 2022
    9.8
    Critical

    CVE-2022-45400

    Last Modified: 30 Apr 2025

    Jenkins JAPEX Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 15 Nov 2022
    5.4
    Medium

    CVE-2022-45401

    Last Modified: 30 Apr 2025

    Jenkins Associated Files Plugin 0.2.1 and earlier does not escape names of associated files, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 15 Nov 2022
    7.8
    High

    CVE-2022-42053

    Last Modified: 7 Jul 2025

    Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the PortMappingServer parameter in the setPortMapping function.

    Published: 15 Nov 2022
    9.8
    Critical

    CVE-2022-42058

    Last Modified: 30 Apr 2025

    Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setRemoteWebManage function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

    Published: 15 Nov 2022
    7.5
    High

    CVE-2022-42060

    Last Modified: 13 May 2025

    Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setWanPpoe function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

    Published: 15 Nov 2022