CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2022-43548

    Last Modified: 30 Apr 2025

    A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.The fix for this issue in https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32212 was incomplete and this new CVE is to complete the fix.

    Published: 4 Nov 2022
    8.9
    High

    CVE-2022-44724

    Last Modified: 2 May 2025

    The Handy Tip macro in Stiltsoft Handy Macros for Confluence Server/Data Center 3.x before 3.5.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability.

    Published: 4 Nov 2022
    7.8
    High

    CVE-2021-34055

    Last Modified: 2 May 2025

    jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.

    Published: 4 Nov 2022
    9.8
    Critical

    CVE-2022-3023

    Last Modified: 2 May 2025

    Use of Externally-Controlled Format String in GitHub repository pingcap/tidb prior to 6.4.0, 6.1.3.

    Published: 4 Nov 2022
    8.8
    High

    CVE-2022-43571

    Last Modified: 2 May 2025

    In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation component.

    Published: 3 Nov 2022
    6.4
    Medium

    CVE-2022-43561

    Last Modified: 25 Apr 2025

    In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user that holds the “power” Splunk role can store arbitrary scripts that can lead to persistent cross-site scripting (XSS). The vulnerability affects instances with Splunk Web enabled.

    Published: 3 Nov 2022
    3.8
    Low

    CVE-2022-20962

    Last Modified: 21 Nov 2024

    A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make unauthorized changes to the file system of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted HTTP request with absolute path sequences. A successful exploit could allow the attacker to upload malicious files to arbitrary locations within the file system. Using this method, it is possible to access the underlying operating system and execute commands with system privileges.

    Published: 3 Nov 2022
    3.8
    Low

    CVE-2022-37911

    Last Modified: 8 Oct 2026

    Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume system resources, resulting in a denial of service condition.

    Published: 3 Nov 2022
    4.3
    Medium

    CVE-2022-25952

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Keywordrush Content Egg plugin <= 5.4.0 on WordPress.

    Published: 3 Nov 2022
    4.4
    Medium

    CVE-2022-37910

    Last Modified: 8 Oct 2026

    A buffer overflow vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in a denial of service on the affected system.

    Published: 3 Nov 2022
    2.7
    Low

    CVE-2021-36906

    Last Modified: 20 Feb 2025

    Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress.

    Published: 3 Nov 2022
    5.9
    Medium

    CVE-2022-44628

    Last Modified: 28 Apr 2026

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in JumpDEMAND Inc. 4ECPS Web Forms plugin <= 0.2.17 on WordPress.

    Published: 3 Nov 2022
    4.7
    Medium

    CVE-2022-20772

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to the failure of the application or its environment to properly sanitize input values. An attacker could exploit this vulnerability by injecting malicious HTTP headers, controlling the response body, or splitting the response into multiple responses.

    Published: 3 Nov 2022
    5.4
    Medium

    CVE-2022-20963

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker would need valid credentials to access the web-based management interface of an affected device.

    Published: 3 Nov 2022
    5.3
    Medium

    CVE-2022-37909

    Last Modified: 8 Oct 2026

    Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the control of attackers.

    Published: 3 Nov 2022
    5.3
    Medium

    CVE-2022-20937

    Last Modified: 21 Nov 2024

    A vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker to negatively affect the performance of an affected device. This vulnerability is due to insufficient management of system resources. An attacker could exploit this vulnerability by taking actions that cause Cisco ISE Software to receive specific RADIUS traffic. A successful and sustained exploit of this vulnerability could allow the attacker to cause reduced performance of the affected device, resulting in significant delays to RADIUS authentications. There are workarounds that address this vulnerability.

    Published: 3 Nov 2022
    4.8
    Medium

    CVE-2022-20969

    Last Modified: 21 Nov 2024

    A vulnerability in multiple management dashboard pages of Cisco Umbrella could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the Cisco Umbrella dashboard. This vulnerability is due to unsanitized user input. An attacker could exploit this vulnerability by submitting custom JavaScript to the web application and persuading a user of the interface to click a maliciously crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive browser-based information.

    Published: 3 Nov 2022
    5.4
    Medium

    CVE-2022-44627

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO plugin <= 1.8.12 on WordPress allows attackers to create or delete sitemaps.

    Published: 3 Nov 2022
    6.5
    Medium

    CVE-2022-20942

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to retrieve sensitive information from an affected device, including user credentials. This vulnerability is due to weak enforcement of back-end authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain confidential data that is stored on the affected device.

    Published: 3 Nov 2022
    7.5
    High

    CVE-2022-20960

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain TLS connections that are processed by an affected device. An attacker could exploit this vulnerability by establishing a large number of concurrent TLS connections to an affected device. A successful exploit could allow the attacker to cause the device to drop new TLS email messages that come from the associated email servers. Exploitation of this vulnerability does not cause the affected device to unexpectedly reload. The device will recover autonomously within a few hours of when the attack is halted or mitigated.

    Published: 3 Nov 2022
    5.8
    Medium

    CVE-2022-37908

    Last Modified: 8 Oct 2026

    An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful exploitation can compromise the hardware chain of trust on the impacted controller.

    Published: 3 Nov 2022
    4.7
    Medium

    CVE-2022-20868

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate privileges on an affected system. The attacker needs valid credentials to exploit this vulnerability. This vulnerability is due to the use of a hardcoded value to encrypt a token used for certain APIs calls . An attacker could exploit this vulnerability by authenticating to the device and sending a crafted HTTP request. A successful exploit could allow the attacker to impersonate another valid user and execute commands with the privileges of that user account.

    Published: 3 Nov 2022
    5.4
    Medium

    CVE-2022-20867

    Last Modified: 21 Nov 2024

    A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct SQL injection attacks as root on an affected system. The attacker must have the credentials of a high-privileged user account. This vulnerability is due to improper validation of user-submitted parameters. An attacker could exploit this vulnerability by authenticating to the application and sending malicious requests to an affected system. A successful exploit could allow the attacker to obtain data or modify data that is stored in the underlying database of the affected system.

    Published: 3 Nov 2022
    7.1
    High

    CVE-2022-20956

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files. This vulnerability is due to improper access control in the web-based management interface of an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to list, download, and delete certain files that they should not have access to. Cisco plans to release software updates that address this vulnerability. https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-access-contol-EeufSUCx ["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-access-contol-EeufSUCx"]

    Published: 3 Nov 2022
    5.4
    Medium

    CVE-2022-36404

    Last Modified: 20 Feb 2025

    Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO (WordPress plugin) plugin <= 1.8.12 versions.

    Published: 3 Nov 2022
    8.3
    High

    CVE-2022-20958

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an unauthenticated, remote attacker to perform a server-side request forgery (SSRF) attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web interface. A successful exploit could allow the attacker to obtain confidential information from the BroadWorks server and other device on the network. {{value}} ["%7b%7bvalue%7d%7d"])}]]

    Published: 3 Nov 2022
    7.7
    High

    CVE-2022-20951

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an authenticated, remote attacker to perform a server-side request forgery (SSRF) attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web interface. A successful exploit could allow the attacker to obtain confidential information from the BroadWorks server and other device on the network. {{value}} ["%7b%7bvalue%7d%7d"])}]]

    Published: 3 Nov 2022
    5.4
    Medium

    CVE-2022-40131

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in a3rev Software Page View Count plugin <= 2.5.5 on WordPress allows an attacker to reset the plugin settings.

    Published: 3 Nov 2022
    5.8
    Medium

    CVE-2022-37907

    Last Modified: 8 Oct 2026

    A vulnerability exists in the ArubaOS bootloader on 7xxx series controllers which can result in a denial of service (DoS) condition on an impacted system. A successful attacker can cause a system hang which can only be resolved via a power cycle of the impacted controller.

    Published: 3 Nov 2022
    4.8
    Medium

    CVE-2022-36428

    Last Modified: 20 Feb 2025

    Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Stage Rock Convert plugin <= 2.11.0 on WordPress.

    Published: 3 Nov 2022
    8.4
    High

    CVE-2021-44862

    Last Modified: 2 May 2025

    Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which should be restricted. The vulnerability exists because the sensitive information is not masked/scrubbed before writing in the logs. A malicious user can use the sensitive information to download data and impersonate another user.

    Published: 3 Nov 2022
    6.5
    Medium

    CVE-2022-37906

    Last Modified: 8 Oct 2026

    An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of the vulnerability results in the ability to delete arbitrary files on the underlying operating system.

    Published: 3 Nov 2022
    6.6
    Medium

    CVE-2022-37905

    Last Modified: 2 May 2025

    Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.

    Published: 3 Nov 2022
    6.5
    Medium

    CVE-2022-43495

    Last Modified: 30 Apr 2025

    OpenHarmony-v3.1.2 and prior versions had a DOS vulnerability in distributedhardware_device_manager when joining a network. Network attakcers can send an abonormal packet when joining a network, cause a nullptr reference and device reboot.

    Published: 3 Nov 2022
    6.2
    Medium

    CVE-2022-43449

    Last Modified: 2 May 2025

    OpenHarmony-v3.1.2 and prior versions had an Arbitrary file read vulnerability via download_server. Local attackers can install an malicious application on the device and reveal any file from the filesystem that is accessible to download_server service which run with UID 1000.

    Published: 3 Nov 2022
    8.4
    High

    CVE-2022-43451

    Last Modified: 21 Nov 2024

    OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arbitrary directories or escape application sandbox.If chained with other vulnerabilities it would allow an unprivileged process to gain full root privileges.

    Published: 3 Nov 2022
    6.6
    Medium

    CVE-2022-37904

    Last Modified: 2 May 2025

    Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.

    Published: 3 Nov 2022
    7.2
    High

    CVE-2022-37903

    Last Modified: 2 May 2025

    A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface. Successful exploitation of this vulnerability could lead to full compromise the underlying host operating system.

    Published: 3 Nov 2022
    7.2
    High

    CVE-2022-37912

    Last Modified: 8 Oct 2026

    Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

    Published: 3 Nov 2022
    7.2
    High

    CVE-2022-37902

    Last Modified: 2 May 2025

    Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

    Published: 3 Nov 2022
    7.2
    High

    CVE-2022-37901

    Last Modified: 2 May 2025

    Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

    Published: 3 Nov 2022
    7.2
    High

    CVE-2022-37900

    Last Modified: 1 May 2025

    Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

    Published: 3 Nov 2022
    8.8
    High

    CVE-2022-20961

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on the affected device with the privileges of the target user.

    Published: 3 Nov 2022
    7.2
    High

    CVE-2022-37899

    Last Modified: 2 May 2025

    Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

    Published: 3 Nov 2022
    7.2
    High

    CVE-2022-37898

    Last Modified: 2 May 2025

    Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

    Published: 3 Nov 2022
    9.8
    Critical

    CVE-2022-37897

    Last Modified: 8 Oct 2026

    There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

    Published: 3 Nov 2022
    3.7
    Low

    CVE-2022-3258

    Last Modified: 1 May 2025

    Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentication Abuse.

    Published: 3 Nov 2022
    2.6
    Low

    CVE-2022-3675

    Last Modified: 2 May 2025

    Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requires a password to access the GRUB command-line, modify kernel command-line arguments, or boot non-default OSTree deployments. Recent Fedora CoreOS releases have a misconfiguration which allows booting non-default OSTree deployments without entering a password. This allows someone with access to the GRUB menu to boot into an older version of Fedora CoreOS, reverting any security fixes that have recently been applied to the machine. A password is still required to modify kernel command-line arguments and to access the GRUB command line.

    Published: 3 Nov 2022
    8.8
    High

    CVE-2022-3852

    Last Modified: 8 Apr 2026

    The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to delete, and modify calendars as well as the plugin settings, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 3 Nov 2022
    8.8
    High

    CVE-2022-3776

    Last Modified: 8 Apr 2026

    The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. This is due to missing or incorrect nonce validation on several functions called via AJAX actions such as forms_action, set_option, & chosen_options to name a few . This makes it possible for unauthenticated attackers to perform a variety of administrative actions like modifying forms, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 3 Nov 2022