CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2022-43164

    Last Modified: 8 May 2025

    A stored cross-site scripting (XSS) vulnerability in the Global Lists feature (/index.php?module=global_lists/lists) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add".

    Published: 28 Oct 2022
    5.4
    Medium

    CVE-2022-43165

    Last Modified: 8 May 2025

    A stored cross-site scripting (XSS) vulnerability in the Global Variables feature (/index.php?module=global_vars/vars) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Value parameter after clicking "Create".

    Published: 28 Oct 2022
    5.4
    Medium

    CVE-2022-43166

    Last Modified: 8 May 2025

    A stored cross-site scripting (XSS) vulnerability in the Global Entities feature (/index.php?module=entities/entities) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add New Entity".

    Published: 28 Oct 2022
    5.4
    Medium

    CVE-2022-43167

    Last Modified: 8 May 2025

    A stored cross-site scripting (XSS) vulnerability in the Users Alerts feature (/index.php?module=users_alerts/users_alerts) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter after clicking "Add".

    Published: 28 Oct 2022
    9.8
    Critical

    CVE-2022-43168

    Last Modified: 8 May 2025

    Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the reports_id parameter.

    Published: 28 Oct 2022
    5.4
    Medium

    CVE-2022-43169

    Last Modified: 8 May 2025

    A stored cross-site scripting (XSS) vulnerability in the Users Access Groups feature (/index.php?module=users_groups/users_groups) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add New Group".

    Published: 28 Oct 2022
    5.4
    Medium

    CVE-2022-43170

    Last Modified: 7 May 2025

    A stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_configure/index) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter after clicking "Add info block".

    Published: 28 Oct 2022
    7.2
    High

    CVE-2022-43228

    Last Modified: 7 May 2025

    Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /clearance/clearance.php.

    Published: 28 Oct 2022
    7.2
    High

    CVE-2022-43229

    Last Modified: 7 May 2025

    Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /bookings/update_status.php.

    Published: 28 Oct 2022
    7.2
    High

    CVE-2022-43230

    Last Modified: 7 May 2025

    Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=bookings/view_details.

    Published: 28 Oct 2022
    7.2
    High

    CVE-2022-43232

    Last Modified: 7 May 2025

    Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_action/fetchOrderData.php.

    Published: 28 Oct 2022
    7.2
    High

    CVE-2022-43233

    Last Modified: 7 May 2025

    Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_action/fetchSelectedUser.php.

    Published: 28 Oct 2022
    7.2
    High

    CVE-2022-43275

    Last Modified: 7 May 2025

    Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 28 Oct 2022
    7.1
    High

    CVE-2022-43280

    Last Modified: 7 May 2025

    wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDropKeepCount.

    Published: 28 Oct 2022
    7.8
    High

    CVE-2022-43281

    Last Modified: 8 May 2025

    wasm-interp v1.0.29 was discovered to contain a heap overflow via the component std::vector<wabt::Type, std::allocator<wabt::Type>>::size() at /bits/stl_vector.h.

    Published: 28 Oct 2022
    7.1
    High

    CVE-2022-43282

    Last Modified: 8 May 2025

    wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetReturnCallDropKeepCount.

    Published: 28 Oct 2022
    5.5
    Medium

    CVE-2022-43283

    Last Modified: 8 May 2025

    wasm2c v1.0.29 was discovered to contain an abort in CWriter::Write.

    Published: 28 Oct 2022
    7.5
    High

    CVE-2022-43284

    Last Modified: 21 Nov 2024

    Nginx NJS v0.7.2 to v0.7.4 was discovered to contain a segmentation violation via njs_scope_valid_value at njs_scope.h. NOTE: the vendor disputes the significance of this report because NJS does not operate on untrusted input.

    Published: 28 Oct 2022
    9.8
    Critical

    CVE-2022-43286

    Last Modified: 7 May 2025

    Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_json_parse_iterator_call at njs_json.c.

    Published: 28 Oct 2022
    9.8
    Critical

    CVE-2021-38729

    Last Modified: 7 May 2025

    SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.

    Published: 28 Oct 2022
    8.8
    High

    CVE-2021-35387

    Last Modified: 7 May 2025

    Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php.

    Published: 28 Oct 2022
    5.4
    Medium

    CVE-2021-35388

    Last Modified: 7 May 2025

    Hospital Management System v 4.0 is vulnerable to Cross Site Scripting (XSS) via /hospital/hms/admin/patient-search.php.

    Published: 28 Oct 2022
    5.4
    Medium

    CVE-2021-37781

    Last Modified: 7 May 2025

    Employee Record Management System v 1.2 is vulnerable to Cross Site Scripting (XSS) via editempprofile.php.

    Published: 28 Oct 2022
    9.8
    Critical

    CVE-2021-37782

    Last Modified: 12 May 2025

    Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php.

    Published: 28 Oct 2022
    9.8
    Critical

    CVE-2021-38217

    Last Modified: 8 May 2025

    SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.

    Published: 28 Oct 2022
    6.1
    Medium

    CVE-2021-38728

    Last Modified: 7 May 2025

    SEMCMS SHOP v 1.1 is vulnerable to Cross Site Scripting (XSS) via Ant_M_Coup.php.

    Published: 28 Oct 2022
    9.8
    Critical

    CVE-2021-38730

    Last Modified: 7 May 2025

    SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.

    Published: 28 Oct 2022
    9.8
    Critical

    CVE-2021-38731

    Last Modified: 7 May 2025

    SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.

    Published: 28 Oct 2022
    9.8
    Critical

    CVE-2021-38732

    Last Modified: 7 May 2025

    SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.

    Published: 28 Oct 2022
    9.8
    Critical

    CVE-2021-38733

    Last Modified: 7 May 2025

    SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.

    Published: 28 Oct 2022
    9.8
    Critical

    CVE-2021-38734

    Last Modified: 7 May 2025

    SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.

    Published: 28 Oct 2022
    9.8
    Critical

    CVE-2021-38736

    Last Modified: 7 May 2025

    SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.

    Published: 28 Oct 2022
    9.8
    Critical

    CVE-2021-38737

    Last Modified: 7 May 2025

    SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.

    Published: 28 Oct 2022
    6.5
    Medium

    CVE-2022-26884

    Last Modified: 7 May 2025

    Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.

    Published: 28 Oct 2022
    5.5
    Medium

    CVE-2022-2882

    Last Modified: 7 May 2025

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A malicious maintainer could exfiltrate a GitHub integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

    Published: 28 Oct 2022
    9.1
    Critical

    CVE-2022-31678

    Last Modified: 8 May 2025

    VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.

    Published: 28 Oct 2022
    6.3
    Medium

    CVE-2022-3730

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, was found in seccome Ehoney. Affected is an unknown function of the file /api/v1/attack/falco. The manipulation of the argument Payload leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-212412.

    Published: 28 Oct 2022
    6.3
    Medium

    CVE-2022-3732

    Last Modified: 15 Apr 2025

    A vulnerability was found in seccome Ehoney and classified as critical. Affected by this issue is some unknown functionality of the file /api/v1/bait/set. The manipulation of the argument Payload leads to sql injection. The attack may be launched remotely. VDB-212414 is the identifier assigned to this vulnerability.

    Published: 28 Oct 2022
    6.3
    Medium

    CVE-2022-3735

    Last Modified: 15 Apr 2025

    A vulnerability was found in seccome Ehoney. It has been rated as critical. This issue affects some unknown processing of the file /api/public/signup. The manipulation leads to improper access controls. The identifier VDB-212417 was assigned to this vulnerability.

    Published: 28 Oct 2022
    9.8
    Critical

    CVE-2022-37621

    Last Modified: 7 May 2025

    Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the fullPath variable in resolve-shims.js.

    Published: 28 Oct 2022
    9.8
    Critical

    CVE-2022-37913

    Last Modified: 7 May 2025

    Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to bypass authentication. Successful exploitation of these vulnerabilities could allow an attacker to gain administrative privileges leading to a complete compromise of the Aruba EdgeConnect Enterprise Orchestrator with versions 9.1.2.40051 and below, 9.0.7.40108 and below, 8.10.23.40009 and below, and any older branches of Orchestrator not specifically mentioned.

    Published: 28 Oct 2022
    8.1
    High

    CVE-2022-1415

    Last Modified: 21 Nov 2024

    A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.

    Published: 28 Oct 2022
    3.8
    Low

    CVE-2023-0091

    Last Modified: 9 Apr 2025

    A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitive information.

    Published: 28 Oct 2022
    2.7
    Low

    CVE-2022-2826

    Last Modified: 7 May 2025

    An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. TODO

    Published: 28 Oct 2022
    6.8
    Medium

    CVE-2022-3018

    Last Modified: 7 May 2025

    An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 allows a project maintainer to access the DataDog integration API key from webhook logs.

    Published: 28 Oct 2022
    5
    Medium

    CVE-2022-3733

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been classified as critical. This affects an unknown part of the file Admin/edit-admin.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212415.

    Published: 28 Oct 2022
    9.8
    Critical

    CVE-2022-3741

    Last Modified: 9 May 2025

    Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depending on the amount of system resources available, to create a DoS event in the server. These accounts still need to be activated; however, it is possible to identify the output Status Code to separate accounts that are generated and waiting for email verification. \n\nFor the sign in directories, it is possible to brute force login attempts to either login portal, which could lead to account compromise.

    Published: 28 Oct 2022
    9.8
    Critical

    CVE-2022-37914

    Last Modified: 7 May 2025

    Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to bypass authentication. Successful exploitation of these vulnerabilities could allow an attacker to gain administrative privileges leading to a complete compromise of the Aruba EdgeConnect Enterprise Orchestrator with versions 9.1.2.40051 and below, 9.0.7.40108 and below, 8.10.23.40009 and below, and any older branches of Orchestrator not specifically mentioned.

    Published: 28 Oct 2022
    8.6
    High

    CVE-2022-39367

    Last Modified: 22 Apr 2025

    QTIWorks is a software suite for standards-based assessment delivery. Prior to version 1.0-beta15, the QTIWorks Engine allows users to upload QTI content packages as ZIP files. The ZIP handling code does not sufficiently check the paths of files contained within ZIP files, so can insert files into other locations in the filesystem if they are writable by the process running the QTIWorks Engine. In extreme cases, this could allow anonymous users to change files in arbitrary locations in the filesystem. In normal QTIWorks Engine deployments, the impact is somewhat reduced because the default QTIWorks configuration does not enable the public demo functionality, so ZIP files can only be uploaded by users with "instructor" privileges. This vulnerability is fixed in version 1.0-beta15. There are no database configuration changes required when upgrading to this version. No known workarounds for this issue exist.

    Published: 28 Oct 2022
    7.2
    High

    CVE-2022-43231

    Last Modified: 7 May 2025

    Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/manage_website.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 28 Oct 2022