CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2022-3653

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Vulkan in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Nov 2022
    8.8
    High

    CVE-2022-3654

    Last Modified: 21 Nov 2024

    Use after free in Layout in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Nov 2022
    8.8
    High

    CVE-2022-3657

    Last Modified: 21 Nov 2024

    Use after free in Extensions in Google Chrome prior to 107.0.5304.62 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)

    Published: 1 Nov 2022
    4.3
    Medium

    CVE-2022-3661

    Last Modified: 21 Nov 2024

    Insufficient data validation in Extensions in Google Chrome prior to 107.0.5304.62 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted Chrome extension. (Chromium security severity: Low)

    Published: 1 Nov 2022
    —
    Unknown

    CVE-2022-3788

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 1 Nov 2022
    —
    Unknown

    CVE-2022-3790

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 1 Nov 2022
    —
    Unknown

    CVE-2022-3791

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 1 Nov 2022
    —
    Unknown

    CVE-2022-3796

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 1 Nov 2022
    6.3
    Medium

    CVE-2022-3797

    Last Modified: 15 Apr 2025

    A vulnerability was found in eolinker apinto-dashboard. It has been rated as problematic. This issue affects some unknown processing of the file /login. The manipulation of the argument callback leads to open redirect. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-212633 was assigned to this vulnerability.

    Published: 1 Nov 2022
    6.3
    Medium

    CVE-2022-3798

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical has been found in IBAX go-ibax. Affected is an unknown function of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-212634 is the identifier assigned to this vulnerability.

    Published: 1 Nov 2022
    5.9
    Medium

    CVE-2021-27784

    Last Modified: 2 May 2025

    The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages.

    Published: 31 Oct 2022
    —
    Unknown

    CVE-2022-44540

    Last Modified: 7 Nov 2023

    CVE was unused by HPE.

    Published: 31 Oct 2022
    —
    Unknown

    CVE-2022-44541

    Last Modified: 7 Nov 2023

    CVE was unused by HPE.

    Published: 31 Oct 2022
    —
    Unknown

    CVE-2022-44536

    Last Modified: 7 Nov 2023

    CVE was unused by HPE.

    Published: 31 Oct 2022
    —
    Unknown

    CVE-2022-44537

    Last Modified: 7 Nov 2023

    CVE was unused by HPE.

    Published: 31 Oct 2022
    —
    Unknown

    CVE-2022-44538

    Last Modified: 7 Nov 2023

    CVE was unused by HPE.

    Published: 31 Oct 2022
    —
    Unknown

    CVE-2022-44539

    Last Modified: 7 Nov 2023

    CVE was unused by HPE.

    Published: 31 Oct 2022
    8.8
    High

    CVE-2022-40190

    Last Modified: 16 Apr 2025

    SAUTER Controls moduWeb firmware version 2.7.1 is vulnerable to reflective cross-site scripting (XSS). The web application does not adequately sanitize request strings of malicious JavaScript. An attacker utilizing XSS could then execute malicious code in users’ browsers and steal sensitive information, including user credentials.

    Published: 31 Oct 2022
    8.2
    High

    CVE-2022-39018

    Last Modified: 2 May 2025

    Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a known URL.

    Published: 31 Oct 2022
    6.3
    Medium

    CVE-2022-39019

    Last Modified: 2 May 2025

    Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to upload malicious files to the application server.

    Published: 31 Oct 2022
    8.8
    High

    CVE-2022-40294

    Last Modified: 6 May 2025

    The application was identified to have an CSV injection in data export functionality, allowing for malicious code to be embedded within export data and then triggered in exported data viewers.

    Published: 31 Oct 2022
    6.1
    Medium

    CVE-2022-40290

    Last Modified: 6 May 2025

    The application was vulnerable to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in the barcode generation functionality, allowing attackers to generate an unsafe link that could compromise users.

    Published: 31 Oct 2022
    4.9
    Medium

    CVE-2022-40295

    Last Modified: 25 Feb 2026

    The application was vulnerable to an authenticated information disclosure, allowing administrators to view unsalted user passwords, which could lead to the compromise of plaintext passwords via offline attacks.

    Published: 31 Oct 2022
    9
    Critical

    CVE-2022-40287

    Last Modified: 6 May 2025

    The application was found to be vulnerable to an authenticated Stored Cross-Site Scripting (XSS) vulnerability in messaging functionality, leading to privilege escalation or a compromise of a targeted account.

    Published: 31 Oct 2022
    9.8
    Critical

    CVE-2022-40296

    Last Modified: 6 May 2025

    The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with unexpected endpoints, potentially including internal and local services, leading to attacks in other downstream systems.

    Published: 31 Oct 2022
    9
    Critical

    CVE-2022-40289

    Last Modified: 6 May 2025

    The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the upload and download functionality, which could be leveraged to escalate privileges or compromise any accounts they can coerce into observing the targeted files.

    Published: 31 Oct 2022
    8.2
    High

    CVE-2022-39017

    Last Modified: 2 May 2025

    Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to introduce cross-site scripting attacks via specially crafted comments.

    Published: 31 Oct 2022
    5.3
    Medium

    CVE-2022-40292

    Last Modified: 6 May 2025

    The application allowed for Unauthenticated User Enumeration by interacting with an unsecured endpoint to retrieve information on each account within the system.

    Published: 31 Oct 2022
    8.6
    High

    CVE-2022-3059

    Last Modified: 5 May 2025

    The application was vulnerable to multiple instances of SQL injection (authenticated and unauthenticated) through a vulnerable parameter. Due to the stacked query support, complex SQL commands could be crafted and injected into the vulnerable parameter and using a sleep based inferential SQL injection it was possible to extract data from the database.

    Published: 31 Oct 2022
    8.8
    High

    CVE-2022-40291

    Last Modified: 6 May 2025

    The application was vulnerable to Cross-Site Request Forgery (CSRF) attacks, allowing an attacker to coerce users into sending malicious requests to the site to delete their account, or in rare circumstances, hijack their account and create other admin accounts.

    Published: 31 Oct 2022
    8.2
    High

    CVE-2022-39016

    Last Modified: 6 May 2025

    Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF upload.

    Published: 31 Oct 2022
    7.6
    High

    CVE-2022-39020

    Last Modified: 6 May 2025

    Multiple instances of XSS (stored and reflected) was found in the application. For example, features such as student assessment submission, file upload, news, ePortfolio and calendar event creation were found to be vulnerable to cross-site scripting.

    Published: 31 Oct 2022
    9.8
    Critical

    CVE-2022-40293

    Last Modified: 6 May 2025

    The application was vulnerable to a session fixation that could be used hijack accounts.

    Published: 31 Oct 2022
    9
    Critical

    CVE-2022-40288

    Last Modified: 6 May 2025

    The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the user profile data fields, which could be leveraged to escalate privileges within and compromise any account that views their user profile.

    Published: 31 Oct 2022
    4.7
    Medium

    CVE-2022-41679

    Last Modified: 2 May 2025

    Forma LMS version 3.1.0 and earlier are affected by an Cross-Site scripting vulnerability, that could allow a remote attacker to inject javascript code on the “back_url” parameter in appLms/index.php?modname=faq&op=play function. The exploitation of this vulnerability could allow an attacker to steal the user´s cookies in order to log in to the application.

    Published: 31 Oct 2022
    7.6
    High

    CVE-2022-42924

    Last Modified: 5 May 2025

    Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerability could allow an authenticated attacker (with the role of student) to perform a SQL injection on the 'dyn_filter' parameter in the 'appLms/ajax.adm_server.php?r=widget/userselector/getusertabledata' function in order to dump the entire database.

    Published: 31 Oct 2022
    9.9
    Critical

    CVE-2022-41681

    Last Modified: 6 May 2025

    There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of student) to privilege escalate in order to upload a Zip file through the SCORM importer feature. The exploitation of this vulnerability could lead to a remote code injection.

    Published: 31 Oct 2022
    7.6
    High

    CVE-2022-41680

    Last Modified: 6 May 2025

    Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerability could allow an authenticated attacker (with the role of student) to perform a SQL injection on the 'search[value] parameter in the appLms/ajax.server.php?r=mycertificate/getMyCertificates' function in order to dump the entire database.

    Published: 31 Oct 2022
    9.9
    Critical

    CVE-2022-42925

    Last Modified: 6 May 2025

    There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of student) to privilege escalate in order to upload a Zip file through the plugin upload component. The exploitation of this vulnerability could lead to a remote code injection.

    Published: 31 Oct 2022
    8.3
    High

    CVE-2022-42923

    Last Modified: 6 May 2025

    Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerability could allow an authenticated attacker (with the role of student) to perform a SQL injection on the 'id' parameter in the 'appCore/index.php?r=adm/mediagallery/delete' function in order to dump the entire database or delete all contents from the 'core_user_file' table.

    Published: 31 Oct 2022
    7.5
    High

    CVE-2022-41629

    Last Modified: 16 Apr 2025

    Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, which could allow an attacker to retrieve any file from the “RunningConfigs” directory. The attacker could then view and modify configuration files such as UserListInfo.xml, which would allow them to see existing administrative passwords.

    Published: 31 Oct 2022
    8.8
    High

    CVE-2022-28763

    Last Modified: 2 May 2025

    The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including session takeovers.

    Published: 31 Oct 2022
    7.5
    High

    CVE-2022-41776

    Last Modified: 16 Apr 2025

    Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration method, which could allow an attacker to provide new values for user configuration files such as UserListInfo.xml. This could lead to the changing of administrative passwords.

    Published: 31 Oct 2022
    8.8
    High

    CVE-2022-41644

    Last Modified: 16 Apr 2025

    Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that changes group privileges. An attacker could use this to create a denial-of-service state or escalate their own privileges.

    Published: 31 Oct 2022
    9.8
    Critical

    CVE-2022-41688

    Last Modified: 16 Apr 2025

    Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that create and modify user groups. An attacker could provide malicious serialized objects that could run these functions without authentication to create a new user and add them to the administrator group.

    Published: 31 Oct 2022
    9.8
    Critical

    CVE-2022-40202

    Last Modified: 16 Apr 2025

    The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authentication. An attacker could provide malicious serialized objects which, when deserialized, could activate an opcode for a backup scheduling function without authentication. This function allows the user to designate all function arguments and the file to be executed. This could allow the attacker to start any new process and achieve remote code execution.

    Published: 31 Oct 2022
    9.8
    Critical

    CVE-2022-41772

    Last Modified: 16 Apr 2025

    Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This path traversal could result in remote code execution.

    Published: 31 Oct 2022
    9.8
    Critical

    CVE-2022-41657

    Last Modified: 16 Apr 2025

    Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in file operation application programmable interfaces (APIs). This could create arbitrary files, which could be used in API operations and could ultimately result in remote code execution.

    Published: 31 Oct 2022
    8.8
    High

    CVE-2022-41779

    Last Modified: 16 Apr 2025

    Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper verification. If the device connects to an attacker-controlled server, the attacker could send maliciously crafted packets that would be deserialized and executed, leading to remote code execution.

    Published: 31 Oct 2022
    9.8
    Critical

    CVE-2022-38142

    Last Modified: 16 Apr 2025

    Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization.

    Published: 31 Oct 2022