CVE Feed

    Dashboard / CVE

    8.2
    High

    CVE-2022-2741

    Last Modified: 5 May 2025

    The denial-of-service can be triggered by transmitting a carefully crafted CAN frame on the same CAN network as the vulnerable node. The frame must have a CAN ID matching an installed filter in the vulnerable node (this can easily be guessed based on CAN traffic analyses). The frame must contain the opposite RTR bit as what the filter installed in the vulnerable node contains (if the filter matches RTR frames, the frame must be a data frame or vice versa).

    Published: 31 Oct 2022
    6.5
    Medium

    CVE-2022-40742

    Last Modified: 5 May 2025

    Mail SQR Expert system has a Local File Inclusion vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary PHP file with .asp file extension under specific system paths, to access and modify partial system information but does not affect service availability.

    Published: 31 Oct 2022
    9.8
    Critical

    CVE-2022-40741

    Last Modified: 6 May 2025

    Mail SQR Expert’s specific function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerability to perform arbitrary system command and disrupt service.

    Published: 31 Oct 2022
    5.4
    Medium

    CVE-2022-40739

    Last Modified: 6 May 2025

    Ragic report generation page has insufficient filtering for special characters. A remote attacker with general user privilege can inject JavaScript to perform XSS (Reflected Cross-Site Scripting) attack.

    Published: 31 Oct 2022
    5.4
    Medium

    CVE-2022-39027

    Last Modified: 6 May 2025

    U-Office Force Forum function has insufficient filtering for special characters. A remote attacker with general user privilege can inject JavaScript and perform XSS (Stored Cross-Site Scripting) attack.

    Published: 31 Oct 2022
    5.4
    Medium

    CVE-2022-39026

    Last Modified: 6 May 2025

    U-Office Force UserDefault page has insufficient filtering for special characters in the HTTP header fields. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform XSS (Stored Cross-Site Scripting) attack.

    Published: 31 Oct 2022
    6.1
    Medium

    CVE-2022-39025

    Last Modified: 6 May 2025

    U-Office Force PrintMessage function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerability to inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.

    Published: 31 Oct 2022
    6.1
    Medium

    CVE-2022-39024

    Last Modified: 6 May 2025

    U-Office Force Bulletin function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerability to inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.

    Published: 31 Oct 2022
    6.5
    Medium

    CVE-2022-39023

    Last Modified: 6 May 2025

    U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to download arbitrary system file.

    Published: 31 Oct 2022
    6.5
    Medium

    CVE-2022-39022

    Last Modified: 6 May 2025

    U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to download arbitrary system file.

    Published: 31 Oct 2022
    6.1
    Medium

    CVE-2022-39021

    Last Modified: 6 May 2025

    U-Office Force login function has an Open Redirect vulnerability. An unauthenticated remote attacker can exploit this vulnerability to redirect user to arbitrary website.

    Published: 31 Oct 2022
    6.1
    Medium

    CVE-2022-3766

    Last Modified: 16 Feb 2026

    Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

    Published: 31 Oct 2022
    9.8
    Critical

    CVE-2022-31692

    Last Modified: 6 May 2025

    Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the following are true: The application expects that Spring Security applies security to forward and include dispatcher types. The application uses the AuthorizationFilter either manually or via the authorizeHttpRequests() method. The application configures the FilterChainProxy to apply to forward and/or include requests (e.g. spring.security.filter.dispatcher-types = request, error, async, forward, include). The application may forward or include the request to a higher privilege-secured endpoint.The application configures Spring Security to apply to every dispatcher type via authorizeHttpRequests().shouldFilterAllDispatcherTypes(true)

    Published: 31 Oct 2022
    7.2
    High

    CVE-2022-3366

    Last Modified: 6 May 2025

    The PublishPress Capabilities WordPress plugin before 2.5.2, PublishPress Capabilities Pro WordPress plugin before 2.5.2 unserializes the content of imported files, which could lead to PHP object injection attacks by administrators, on multisite WordPress configurations. Successful exploitation in this case requires other plugins with a suitable gadget chain to be present on the site.

    Published: 31 Oct 2022
    4.8
    Medium

    CVE-2022-3408

    Last Modified: 6 May 2025

    The WP Word Count WordPress plugin through 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

    Published: 31 Oct 2022
    4.8
    Medium

    CVE-2022-3441

    Last Modified: 6 May 2025

    The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 31 Oct 2022
    7.5
    High

    CVE-2022-37620

    Last Modified: 1 Jun 2025

    A Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0 because of the reCustomIgnore regular expression.

    Published: 31 Oct 2022
    6.3
    Medium

    CVE-2022-3784

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical was found in Axiomatic Bento4 5e7bb34. Affected by this vulnerability is the function AP4_Mp4AudioDsiParser::ReadBits of the file Ap4Mp4AudioInfo.cpp of the component mp4hls. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212563.

    Published: 31 Oct 2022
    6.1
    Medium

    CVE-2022-40487

    Last Modified: 6 May 2025

    ProcessWire v3.0.200 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Search Users and Search Pages function. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via injection of a crafted payload.

    Published: 31 Oct 2022
    7.5
    High

    CVE-2022-40617

    Last Modified: 6 May 2025

    strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or sends an excessive amount of application data.

    Published: 31 Oct 2022
    6.1
    Medium

    CVE-2022-42799

    Last Modified: 5 May 2025

    The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Visiting a malicious website may lead to user interface spoofing.

    Published: 31 Oct 2022
    8.8
    High

    CVE-2022-42823

    Last Modified: 21 Apr 2025

    A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 31 Oct 2022
    5.5
    Medium

    CVE-2022-43148

    Last Modified: 6 May 2025

    rtf2html v0.2.0 was discovered to contain a heap overflow in the component /rtf2html/./rtf_tools.h.

    Published: 31 Oct 2022
    5.5
    Medium

    CVE-2022-43151

    Last Modified: 6 May 2025

    timg v1.4.4 was discovered to contain a memory leak via the function timg::QueryBackgroundColor() at /timg/src/term-query.cc.

    Published: 31 Oct 2022
    5.5
    Medium

    CVE-2022-43152

    Last Modified: 6 May 2025

    tsMuxer v2.6.16 was discovered to contain a heap overflow via the function BitStreamWriter::flushBits() at /tsMuxer/bitStream.h.

    Published: 31 Oct 2022
    5.5
    Medium

    CVE-2022-44079

    Last Modified: 6 May 2025

    pycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component __sanitizer::StackDepotBase<__sanitizer::StackDepotNode.

    Published: 31 Oct 2022
    5.5
    Medium

    CVE-2022-44081

    Last Modified: 6 May 2025

    Lodepng v20220717 was discovered to contain a segmentation fault via the function pngdetail.

    Published: 31 Oct 2022
    9.8
    Critical

    CVE-2020-21016

    Last Modified: 7 May 2025

    D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via HNAP1/control/SetGuestWLanSettings.php.

    Published: 31 Oct 2022
    9.8
    Critical

    CVE-2021-40241

    Last Modified: 7 May 2025

    xfig 3.2.7 is vulnerable to Buffer Overflow.

    Published: 31 Oct 2022
    7.2
    High

    CVE-2022-3380

    Last Modified: 27 Mar 2026

    The Customizer Export/Import WordPress plugin before 0.9.5 unserializes the content of an imported file, which could lead to PHP object injection issues when an admin imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

    Published: 31 Oct 2022
    6.1
    Medium

    CVE-2022-2190

    Last Modified: 7 May 2025

    The Gallery Plugin for WordPress plugin before 1.8.4.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

    Published: 31 Oct 2022
    7.8
    High

    CVE-2022-43752

    Last Modified: 6 May 2025

    Oracle Solaris version 10 1/13, when using the Common Desktop Environment (CDE), is vulnerable to a privilege escalation vulnerability. A low privileged user can escalate to root by crafting a malicious printer and double clicking on the the crafted printer's icon.

    Published: 31 Oct 2022
    9.1
    Critical

    CVE-2022-27583

    Last Modified: 7 May 2025

    A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2 running an affected firmware version to potentially impact the availability of the FlexiCompact.

    Published: 31 Oct 2022
    4.8
    Medium

    CVE-2022-3237

    Last Modified: 6 May 2025

    The WP Contact Slider WordPress plugin before 2.4.8 does not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 31 Oct 2022
    8.8
    High

    CVE-2022-32888

    Last Modified: 5 May 2025

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, watchOS 9, macOS Monterey 12.6, tvOS 16. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 31 Oct 2022
    7.2
    High

    CVE-2022-3334

    Last Modified: 6 May 2025

    The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

    Published: 31 Oct 2022
    8.1
    High

    CVE-2022-3360

    Last Modified: 6 May 2025

    The LearnPress WordPress plugin before 4.1.7.2 unserialises user input in a REST API endpoint available to unauthenticated users, which could lead to PHP Object Injection when a suitable gadget is present, leadint to remote code execution (RCE). To successfully exploit this vulnerability attackers must have knowledge of the site secrets, allowing them to generate a valid hash via the wp_hash() function.

    Published: 31 Oct 2022
    6.5
    Medium

    CVE-2022-3419

    Last Modified: 6 May 2025

    The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator

    Published: 31 Oct 2022
    4.8
    Medium

    CVE-2022-3420

    Last Modified: 6 May 2025

    The Official Integration for Billingo WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users with a role as low as Shop Manager to perform Stored Cross-Site Scripting attacks.

    Published: 31 Oct 2022
    6.1
    Medium

    CVE-2022-3440

    Last Modified: 6 May 2025

    The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape an URL before outputting it back in an attribute when a specific widget is present on a page, leading to a Reflected Cross-Site Scripting

    Published: 31 Oct 2022
    6.5
    Medium

    CVE-2022-3499

    Last Modified: 5 May 2025

    An authenticated attacker could utilize the identical agent and cluster node linking keys to potentially allow for a scenario where unauthorized disclosure of agent logs and data is present.

    Published: 31 Oct 2022
    5.4
    Medium

    CVE-2022-3765

    Last Modified: 2 May 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

    Published: 31 Oct 2022
    9.8
    Critical

    CVE-2022-37623

    Last Modified: 6 May 2025

    Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the shimPath variable in resolve-shims.js.

    Published: 31 Oct 2022
    —
    Unknown

    CVE-2022-3772

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-36534. Reason: This candidate is a reservation duplicate of CVE-2020-36534. Notes: All CVE users should reference CVE-2020-36534 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 31 Oct 2022
    —
    Unknown

    CVE-2022-3773

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 31 Oct 2022
    —
    Unknown

    CVE-2022-3778

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 31 Oct 2022
    6.3
    Medium

    CVE-2022-3785

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4_DataBuffer::SetDataSize of the component Avcinfo. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212564.

    Published: 31 Oct 2022
    9.8
    Critical

    CVE-2022-40471

    Last Modified: 6 May 2025

    Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functionality in users.php

    Published: 31 Oct 2022
    7.5
    High

    CVE-2021-40661

    Last Modified: 7 May 2025

    A remote, unauthenticated, directory traversal vulnerability was identified within the web interface used by IND780 Advanced Weighing Terminals Build 8.0.07 March 19, 2018 (SS Label 'IND780_8.0.07'), Version 7.2.10 June 18, 2012 (SS Label 'IND780_7.2.10'). It was possible to traverse the folders of the affected host by providing a traversal path to the 'webpage' parameter in AutoCE.ini This could allow a remote unauthenticated adversary to access additional files on the affected system. This could also allow the adversary to perform further enumeration against the affected host to identify the versions of the systems in use, in order to launch further attacks in future.

    Published: 31 Oct 2022
    8.1
    High

    CVE-2022-31690

    Last Modified: 8 May 2025

    Spring Security, versions 5.7 prior to 5.7.5, and 5.6 prior to 5.6.9, and older unsupported versions could be susceptible to a privilege escalation under certain conditions. A malicious user or attacker can modify a request initiated by the Client (via the browser) to the Authorization Server which can lead to a privilege escalation on the subsequent approval. This scenario can happen if the Authorization Server responds with an OAuth2 Access Token Response containing an empty scope list (per RFC 6749, Section 5.1) on the subsequent request to the token endpoint to obtain the access token.

    Published: 31 Oct 2022