CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2022-2696

    Last Modified: 8 Apr 2026

    The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypass via several AJAX actions in versions up to, and including 2.3.0 due to missing capability checks and missing nonce validation. This makes it possible for authenticated attackers with minimal permissions to perform a wide variety of actions such as modifying the plugin's settings and modifying the ordering system preferences.

    Published: 3 Nov 2022
    6.4
    Medium

    CVE-2021-46846

    Last Modified: 2 May 2025

    Cross Site Scripting vulnerability in Hewlett Packard Enterprise Integrated Lights-Out 5.

    Published: 3 Nov 2022
    8
    High

    CVE-2022-37928

    Last Modified: 2 May 2025

    Insufficient Verification of Data Authenticity vulnerability in Hewlett Packard Enterprise HPE Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays.

    Published: 3 Nov 2022
    6.7
    Medium

    CVE-2022-37930

    Last Modified: 2 May 2025

    A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays and HPE Nimble Storage Secondary Flash Arrays which could potentially allow local disclosure of sensitive information.

    Published: 3 Nov 2022
    6.7
    Medium

    CVE-2022-37929

    Last Modified: 2 May 2025

    Improper Privilege Management vulnerability in Hewlett Packard Enterprise Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays.

    Published: 3 Nov 2022
    6.1
    Medium

    CVE-2022-37927

    Last Modified: 1 May 2025

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Hewlett Packard Enterprise HPE OneView Global Dashboard (OVGD).

    Published: 3 Nov 2022
    4.3
    Medium

    CVE-2022-35279

    Last Modified: 2 May 2025

    "IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2, 21.0.3, and 22.0.1 could disclose sensitive version information to authenticated users which could be used in further attacks against the system. IBM X-Force ID: 230537."

    Published: 3 Nov 2022
    9.8
    Critical

    CVE-2022-43101

    Last Modified: 2 May 2025

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.

    Published: 3 Nov 2022
    9.8
    Critical

    CVE-2022-43102

    Last Modified: 5 May 2025

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the timeZone parameter in the fromSetSysTime function.

    Published: 3 Nov 2022
    9.8
    Critical

    CVE-2022-43105

    Last Modified: 5 May 2025

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function.

    Published: 3 Nov 2022
    9.8
    Critical

    CVE-2022-43108

    Last Modified: 5 May 2025

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.

    Published: 3 Nov 2022
    6.5
    Medium

    CVE-2022-3854

    Last Modified: 6 Mar 2025

    A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of service.

    Published: 3 Nov 2022
    5.3
    Medium

    CVE-2022-38710

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation 21.0.1 and 21.0.2 could disclose sensitive version to an unauthorized control sphere information that could aid in further attacks against the system. IBM X-Force ID: 234292.

    Published: 3 Nov 2022
    5.1
    Medium

    CVE-2022-42895

    Last Modified: 21 Apr 2025

    There is an infoleak vulnerability in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_parse_conf_req function which can be used to leak kernel pointers remotely. We recommend upgrading past commit  https://github.com/torvalds/linux/commit/b1a2cd50c0357f243b7435a732b4e62ba3157a2e https://www.google.com/url

    Published: 3 Nov 2022
    8
    High

    CVE-2022-42896

    Last Modified: 21 Apr 2025

    There are use-after-free vulnerabilities in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_connect and l2cap_le_connect_req functions which may allow code execution and leaking kernel memory (respectively) remotely via Bluetooth. A remote attacker could execute code leaking kernel memory via Bluetooth if within proximity of the victim. We recommend upgrading past commit  https://www.google.com/url https://github.com/torvalds/linux/commit/711f8c3fb3db61897080468586b970c87c61d9e4 https://www.google.com/url

    Published: 3 Nov 2022
    7.2
    High

    CVE-2022-43061

    Last Modified: 5 May 2025

    Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /operations/travellers.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 3 Nov 2022
    7.2
    High

    CVE-2022-43063

    Last Modified: 5 May 2025

    Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Users.php?f=delete_client.

    Published: 3 Nov 2022
    9.8
    Critical

    CVE-2022-43103

    Last Modified: 5 May 2025

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the list parameter in the formSetQosBand function.

    Published: 3 Nov 2022
    9.8
    Critical

    CVE-2022-43104

    Last Modified: 5 May 2025

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the wpapsk_crypto parameter in the fromSetWirelessRepeat function.

    Published: 3 Nov 2022
    9.8
    Critical

    CVE-2022-43106

    Last Modified: 2 May 2025

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the schedStartTime parameter in the setSchedWifi function.

    Published: 3 Nov 2022
    9.8
    Critical

    CVE-2022-43107

    Last Modified: 2 May 2025

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement function.

    Published: 3 Nov 2022
    9.8
    Critical

    CVE-2022-43109

    Last Modified: 5 May 2025

    D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via a crafted packet.

    Published: 3 Nov 2022
    4.8
    Medium

    CVE-2022-43372

    Last Modified: 5 May 2025

    Emlog Pro v1.7.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /admin/store.php.

    Published: 3 Nov 2022
    7.5
    High

    CVE-2022-43574

    Last Modified: 2 May 2025

    "IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrect permission assignment which could allow access to application configurations. IBM X-Force ID: 238679."

    Published: 3 Nov 2022
    4.9
    Medium

    CVE-2021-37823

    Last Modified: 5 May 2025

    OpenCart 3.0.3.7 allows users to obtain database information or read server files through SQL injection in the background.

    Published: 3 Nov 2022
    5.9
    Medium

    CVE-2021-46853

    Last Modified: 5 May 2025

    Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent before STARTTLS.

    Published: 3 Nov 2022
    6.5
    Medium

    CVE-2022-22442

    Last Modified: 5 May 2025

    "IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information restricted to users with elevated privileges due to improper access controls. IBM X-Force ID: 224427."

    Published: 3 Nov 2022
    9.8
    Critical

    CVE-2020-22818

    Last Modified: 5 May 2025

    MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter.

    Published: 3 Nov 2022
    9.8
    Critical

    CVE-2020-22819

    Last Modified: 5 May 2025

    MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter.

    Published: 3 Nov 2022
    9.8
    Critical

    CVE-2020-22820

    Last Modified: 5 May 2025

    MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter.

    Published: 3 Nov 2022
    8.8
    High

    CVE-2022-42750

    Last Modified: 5 May 2025

    CandidATS version 3.0.0 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the files uploaded by the user.

    Published: 3 Nov 2022
    8.8
    High

    CVE-2022-42751

    Last Modified: 5 May 2025

    CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the application suffers from CSRF. This allows to persuade an administrator to create a new account with administrative permissions.

    Published: 3 Nov 2022
    6.1
    Medium

    CVE-2022-42753

    Last Modified: 5 May 2025

    SalonERP version 3.0.2 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the page parameter against XSS attacks.

    Published: 3 Nov 2022
    5.4
    Medium

    CVE-2022-30615

    Last Modified: 5 May 2025

    "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 227592.

    Published: 3 Nov 2022
    6.5
    Medium

    CVE-2022-44624

    Last Modified: 2 May 2025

    In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special characters

    Published: 3 Nov 2022
    6.5
    Medium

    CVE-2022-34339

    Last Modified: 2 May 2025

    "IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 229963."

    Published: 3 Nov 2022
    5.4
    Medium

    CVE-2022-35642

    Last Modified: 2 May 2025

    "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 227592."

    Published: 3 Nov 2022
    7.8
    High

    CVE-2022-35717

    Last Modified: 2 May 2025

    "IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-"Force ID: 231361.

    Published: 3 Nov 2022
    9.8
    Critical

    CVE-2022-42744

    Last Modified: 5 May 2025

    CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is possible because the application does not correctly validate the entriesPerPage parameter against SQLi attacks.

    Published: 3 Nov 2022
    7.5
    High

    CVE-2022-42745

    Last Modified: 21 Nov 2024

    CandidATS version 3.0.0 allows an external attacker to read arbitrary files from the server. This is possible because the application is vulnerable to XXE.

    Published: 3 Nov 2022
    6.1
    Medium

    CVE-2022-42746

    Last Modified: 5 May 2025

    CandidATS version 3.0.0 on 'indexFile' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

    Published: 3 Nov 2022
    6.1
    Medium

    CVE-2022-42747

    Last Modified: 5 May 2025

    CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

    Published: 3 Nov 2022
    6.1
    Medium

    CVE-2022-42748

    Last Modified: 5 May 2025

    CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

    Published: 3 Nov 2022
    6.1
    Medium

    CVE-2022-42749

    Last Modified: 5 May 2025

    CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

    Published: 3 Nov 2022
    9.1
    Critical

    CVE-2022-38168

    Last Modified: 2 May 2025

    Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.

    Published: 3 Nov 2022
    5.9
    Medium

    CVE-2022-38712

    Last Modified: 2 May 2025

    "IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middle attacker to conduct SOAPAction spoofing to execute unwanted or unauthorized operations. IBM X-Force ID: 234762."

    Published: 3 Nov 2022
    5.2
    Medium

    CVE-2022-39262

    Last Modified: 22 Apr 2025

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package, GLPI administrator can define rich-text content to be displayed on login page. The displayed content is can contains malicious code that can be used to steal credentials. This issue has been patched, please upgrade to version 10.0.4.

    Published: 3 Nov 2022
    3.5
    Low

    CVE-2022-39276

    Last Modified: 22 Apr 2025

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Usage of RSS feeds or an external calendar in planning is subject to SSRF exploit. In case a remote script returns a redirect response, the redirect target URL is not checked against the URL allow list defined by administrator. This issue has been patched, please upgrade to 10.0.4. There are currently no known workarounds.

    Published: 3 Nov 2022
    7.4
    High

    CVE-2022-39323

    Last Modified: 23 Apr 2025

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Time based attack using a SQL injection in api REST user_token. This issue has been patched, please upgrade to version 10.0.4. As a workaround, disable login with user_token on API Rest.

    Published: 3 Nov 2022
    4.3
    Medium

    CVE-2022-39370

    Last Modified: 23 Apr 2025

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Connected users may gain access to debug panel through the GLPI update script. This issue has been patched, please upgrade to 10.0.4. As a workaround, delete the `install/update.php` script.

    Published: 3 Nov 2022