CVE Feed

    Dashboard / CVE

    4.5
    Medium

    CVE-2022-39375

    Last Modified: 23 Apr 2025

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Users may be able to create a public RSS feed to inject malicious code in dashboards of other users. This issue has been patched, please upgrade to version 10.0.4. There are currently no known workarounds.

    Published: 3 Nov 2022
    6.5
    Medium

    CVE-2022-40230

    Last Modified: 2 May 2025

    "IBM MQ Appliance 9.2 CD, 9.2 LTS, 9.3 CD, and LTS 9.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 235532."

    Published: 3 Nov 2022
    6.5
    Medium

    CVE-2022-40235

    Last Modified: 2 May 2025

    "IBM InfoSphere Information Server 11.7 could allow a user to cause a denial of service by removing the ability to run jobs due to improper input validation. IBM X-Force ID: 235725."

    Published: 3 Nov 2022
    5.5
    Medium

    CVE-2022-40276

    Last Modified: 2 May 2025

    Zettlr version 2.3.0 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown file through Zettlr. This is possible because the application does not have a CSP policy (or at least not strict enough) and/or does not properly validate the contents of markdown files before rendering them.

    Published: 3 Nov 2022
    5.4
    Medium

    CVE-2022-41435

    Last Modified: 5 May 2025

    OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /system/sshkeys.js. This vulnerability allows attackers to execute arbitrary web scripts or HTML via crafted public key comments.

    Published: 3 Nov 2022
    5.5
    Medium

    CVE-2022-41710

    Last Modified: 5 May 2025

    Markdownify version 1.4.1 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown file through Markdownify. This is possible because the application does not have a CSP policy (or at least not strict enough) and/or does not properly validate the contents of markdown files before rendering them.

    Published: 3 Nov 2022
    4.4
    Medium

    CVE-2021-39077

    Last Modified: 23 Jul 2025

    IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 215587.

    Published: 3 Nov 2022
    9.8
    Critical

    CVE-2022-22425

    Last Modified: 5 May 2025

    "IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598."

    Published: 3 Nov 2022
    8.8
    High

    CVE-2022-30608

    Last Modified: 5 May 2025

    "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a "user that the website trusts. IBM X-Force ID: 227295.

    Published: 3 Nov 2022
    7.5
    High

    CVE-2022-32287

    Last Modified: 2 May 2025

    A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows an attacker to create files outside the designated target directory using carefully crafted ZIP entry names. This issue affects Apache UIMA Apache UIMA version 3.3.0 and prior versions. Note that PEAR files should never be installed into an UIMA installation from untrusted sources because PEAR archives are executable plugins that will be able to perform any actions with the same privileges as the host Java Virtual Machine.

    Published: 3 Nov 2022
    4.7
    Medium

    CVE-2022-39234

    Last Modified: 23 Apr 2025

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Deleted/deactivated user could continue to use their account as long as its cookie is valid. This issue has been patched, please upgrade to version 10.0.4. There are currently no known workarounds.

    Published: 3 Nov 2022
    4.5
    Medium

    CVE-2022-39277

    Last Modified: 22 Apr 2025

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. External links are not properly sanitized and can therefore be used for a Cross-Site Scripting (XSS) attack. This issue has been patched, please upgrade to GLPI 10.0.4. There are currently no known workarounds.

    Published: 3 Nov 2022
    7.5
    High

    CVE-2022-39371

    Last Modified: 23 Apr 2025

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Script related HTML tags in assets inventory information are not properly neutralized. This issue has been patched, please upgrade to version 10.0.4. There are currently no known workarounds.

    Published: 3 Nov 2022
    3.5
    Low

    CVE-2022-39372

    Last Modified: 23 Apr 2025

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Authenticated users may store malicious code in their account information. This issue has been patched, please upgrade to version 10.0.4. There are currently no known workarounds.

    Published: 3 Nov 2022
    4.9
    Medium

    CVE-2022-39373

    Last Modified: 23 Apr 2025

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Administrator may store malicious code in entity name. This issue has been patched, please upgrade to version 10.0.4.

    Published: 3 Nov 2022
    2.6
    Low

    CVE-2022-39376

    Last Modified: 23 Apr 2025

    GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Users may be able to inject custom fields values in `mailto` links. This issue has been patched, please upgrade to version 10.0.4. There are currently no known workarounds.

    Published: 3 Nov 2022
    9.8
    Critical

    CVE-2022-39382

    Last Modified: 22 Apr 2025

    Keystone is a headless CMS for Node.js — built with GraphQL and React.`@keystone-6/[email protected] || 3.0.1` users that use `NODE_ENV` to trigger security-sensitive functionality in their production builds are vulnerable to `NODE_ENV` being inlined to `"development"` for user code, irrespective of what your environment variables. If you do not use `NODE_ENV` in your user code to trigger security-sensitive functionality, you are not impacted by this vulnerability. Any dependencies that use `NODE_ENV` to trigger particular behaviors (optimizations, security or otherwise) should still respect your environment's configured `NODE_ENV` variable. The application's dependencies, as found in `node_modules` (including `@keystone-6/core`), are typically not compiled as part of this process, and thus should be unaffected. We have tested this assumption by verifying that `NODE_ENV=production yarn keystone start` still uses secure cookies when using `statelessSessions`. This vulnerability has been fixed in @keystone-6/[email protected], regression tests have been added for this vulnerability in #8063.

    Published: 3 Nov 2022
    9.1
    Critical

    CVE-2022-40747

    Last Modified: 5 May 2025

    "IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 236584."

    Published: 3 Nov 2022
    3.3
    Low

    CVE-2022-42442

    Last Modified: 5 May 2025

    IBM Robotic Process Automation for Cloud Pak 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to exposure of the first tenant owner e-mail address to users with access to the container platform. IBM X-Force ID: 238214.

    Published: 3 Nov 2022
    7.2
    High

    CVE-2022-43062

    Last Modified: 5 May 2025

    Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_appointment.

    Published: 3 Nov 2022
    2.7
    Low

    CVE-2022-44622

    Last Modified: 2 May 2025

    In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive

    Published: 3 Nov 2022
    6.5
    Medium

    CVE-2022-44623

    Last Modified: 30 Apr 2025

    In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settings

    Published: 3 Nov 2022
    8.8
    High

    CVE-2022-44638

    Last Modified: 2 May 2025

    In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflow in pixman_sample_floor_y.

    Published: 3 Nov 2022
    2.2
    Low

    CVE-2022-44646

    Last Modified: 2 May 2025

    In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings

    Published: 3 Nov 2022
    5.3
    Medium

    CVE-2022-41713

    Last Modified: 3 Dec 2025

    deep-object-diff version 1.1.0 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the '__proto__' property to be edited.

    Published: 3 Nov 2022
    5.3
    Medium

    CVE-2022-41714

    Last Modified: 3 Dec 2025

    fastest-json-copy version 1.0.1 allows an external attacker to edit or add new properties to an object. This is possible because the application does not correctly validate the incoming JSON keys, thus allowing the '__proto__' property to be edited.

    Published: 3 Nov 2022
    5.3
    Medium

    CVE-2022-42743

    Last Modified: 3 Dec 2025

    deep-parse-json version 1.0.2 allows an external attacker to edit or add new properties to an object. This is possible because the application does not correctly validate the incoming JSON keys, thus allowing the '__proto__' property to be edited.

    Published: 3 Nov 2022
    4.8
    Medium

    CVE-2022-44586

    Last Modified: 20 Feb 2025

    Auth. (admin+) Stored Cross-Site Scripting (XSS) in Ayoub Media AM-HiLi plugin <= 1.0 on WordPress.

    Published: 2 Nov 2022
    4.8
    Medium

    CVE-2022-44576

    Last Modified: 20 Feb 2025

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in AgentEasy Properties plugin <= 1.0.4 on WordPress.

    Published: 2 Nov 2022
    9.1
    Critical

    CVE-2022-24942

    Last Modified: 5 May 2025

    Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTTP request.

    Published: 2 Nov 2022
    7.5
    High

    CVE-2022-3181

    Last Modified: 16 Apr 2025

    An Improper Input Validation vulnerability exists in Trihedral VTScada version 12.0.38 and prior. A specifically malformed HTTP request could cause the affected VTScada to crash. Both local area network (LAN)-only and internet facing systems are affected.

    Published: 2 Nov 2022
    8.3
    High

    CVE-2022-24936

    Last Modified: 2 May 2025

    Out-of-Bounds error in GBL parser in Silicon Labs Gecko Bootloader version 4.0.1 and earlier allows attacker to overwrite flash Sign key and OTA decryption key via malicious bootloader upgrade.

    Published: 2 Nov 2022
    9.8
    Critical

    CVE-2022-3575

    Last Modified: 5 May 2025

    Frauscher Sensortechnik GmbH FDS102 for FAdC R2 and FAdCi R2 v2.8.0 to v2.9.1 are vulnerable to malicious code upload without authentication by using the configuration upload function. This could lead to a complete compromise of the FDS102 device.

    Published: 2 Nov 2022
    7.5
    High

    CVE-2022-41716

    Last Modified: 21 Nov 2024

    Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL values are not properly checked for. A malicious environment variable value can exploit this behavior to set a value for a different environment variable. For example, the environment variable string "A=B\x00C=D" sets the variables "A=B" and "C=D".

    Published: 2 Nov 2022
    7.1
    High

    CVE-2021-45448

    Last Modified: 2 May 2025

    Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 using the Pentaho Analyzer plugin exposes a service endpoint for templates which allows a user-supplied path to access resources that are out of bounds.  The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.  By using special elements such as ".." and "/" separators, attackers can escape outside of the restricted location to access files or directories that are elsewhere on the system.

    Published: 2 Nov 2022
    7.7
    High

    CVE-2021-45447

    Last Modified: 2 May 2025

    Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.2 and 8.3.0.25 with the Data Lineage feature enabled transmits database passwords in clear text.   The transmission of sensitive data in clear text allows unauthorized actors with access to the network to sniff and obtain sensitive information that can be later used to gain unauthorized access.

    Published: 2 Nov 2022
    5
    Medium

    CVE-2021-45446

    Last Modified: 2 May 2025

    A vulnerability in Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 does not cascade the hidden property to the children of the Home folder.  This directory listing provides an attacker with the complete index of all the resources located inside the directory.

    Published: 2 Nov 2022
    —
    Unknown

    CVE-2022-43511

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 2 Nov 2022
    —
    Unknown

    CVE-2022-44613

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 2 Nov 2022
    —
    Unknown

    CVE-2022-44609

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 2 Nov 2022
    —
    Unknown

    CVE-2022-43510

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 2 Nov 2022
    —
    Unknown

    CVE-2022-43661

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 2 Nov 2022
    —
    Unknown

    CVE-2022-43446

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 2 Nov 2022
    —
    Unknown

    CVE-2022-44618

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 2 Nov 2022
    —
    Unknown

    CVE-2022-44614

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 2 Nov 2022
    —
    Unknown

    CVE-2022-44452

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 2 Nov 2022
    7.6
    High

    CVE-2022-39241

    Last Modified: 23 Apr 2025

    Discourse is a platform for community discussion. A malicious admin could use this vulnerability to perform port enumeration on the local host or other hosts on the internal network, as well as against hosts on the Internet. Latest `stable`, `beta`, and `test-passed` versions are now patched. As a workaround, self-hosters can use `DISCOURSE_BLOCKED_IP_BLOCKS` env var (which overrides `blocked_ip_blocks` setting) to stop webhooks from accessing private IPs.

    Published: 2 Nov 2022
    6.3
    Medium

    CVE-2022-3827

    Last Modified: 15 Apr 2025

    A vulnerability was found in centreon. It has been declared as critical. This vulnerability affects unknown code of the file formContactGroup.php of the component Contact Groups Form. The manipulation of the argument cg_id leads to sql injection. The attack can be initiated remotely. The name of the patch is 293b10628f7d9f83c6c82c78cf637cbe9b907369. It is recommended to apply a patch to fix this issue. VDB-212794 is the identifier assigned to this vulnerability.

    Published: 2 Nov 2022
    7.5
    High

    CVE-2022-39381

    Last Modified: 22 Apr 2025

    Muhammara is a node module with c/cpp bindings to modify PDF with js for node or electron (based/replacement on/of galkhana/hummusjs). The package muhammara before 2.6.0; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be appended to another. This issue has been patched in 2.6.0 for muhammara and not at all for hummus. As a workaround, do not process files from untrusted sources.

    Published: 2 Nov 2022
    4.4
    Medium

    CVE-2022-39949

    Last Modified: 21 Nov 2024

    An improper control of a resource through its lifetime vulnerability [CWE-664] in FortiEDR CollectorWindows 4.0.0 through 4.1, 5.0.0 through 5.0.3.751, 5.1.0 may allow a privileged user to terminate the FortiEDR processes with special tools and bypass the EDR protection.

    Published: 2 Nov 2022