CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2022-43276

    Last Modified: 7 May 2025

    Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the productId parameter at /php_action/fetchSelectedfood.php.

    Published: 28 Oct 2022
    7.8
    High

    CVE-2022-3377

    Last Modified: 16 Apr 2025

    Horner Automation's Cscape version 9.90 SP 6 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer, leading to an out-of-bounds memory read.

    Published: 27 Oct 2022
    7.8
    High

    CVE-2022-3378

    Last Modified: 16 Apr 2025

    Horner Automation's Cscape version 9.90 SP 7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer, leading to an out-of-bounds memory write.

    Published: 27 Oct 2022
    7.8
    High

    CVE-2022-3379

    Last Modified: 16 Apr 2025

    Horner Automation's Cscape version 9.90 SP7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by writing outside the memory buffer.

    Published: 27 Oct 2022
    6.5
    Medium

    CVE-2022-3387

    Last Modified: 16 Apr 2025

    Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks. An unauthorized attacker could remotely exploit vulnerable PHP code to delete .PDF files.

    Published: 27 Oct 2022
    9.8
    Critical

    CVE-2022-3386

    Last Modified: 16 Apr 2025

    Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename to overflow the stack buffer and enable remote code execution.

    Published: 27 Oct 2022
    9.8
    Critical

    CVE-2022-3385

    Last Modified: 16 Apr 2025

    Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stack buffer and enable remote code execution.

    Published: 27 Oct 2022
    8.7
    High

    CVE-2022-41702

    Last Modified: 16 Apr 2025

    The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the InsertReg API.

    Published: 27 Oct 2022
    8.7
    High

    CVE-2022-41651

    Last Modified: 16 Apr 2025

    The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the SetPF API.

    Published: 27 Oct 2022
    8.8
    High

    CVE-2022-41133

    Last Modified: 16 Apr 2025

    The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in GetDIAE_line_message_settingsListParameters. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.

    Published: 27 Oct 2022
    8.8
    High

    CVE-2022-41773

    Last Modified: 16 Apr 2025

    The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckDIACloud. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.

    Published: 27 Oct 2022
    8.7
    High

    CVE-2022-41701

    Last Modified: 16 Apr 2025

    The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutShift API.

    Published: 27 Oct 2022
    8.8
    High

    CVE-2022-40967

    Last Modified: 16 Apr 2025

    The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckIoTHubNameExisted. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.

    Published: 27 Oct 2022
    8.7
    High

    CVE-2022-41555

    Last Modified: 16 Apr 2025

    The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutLineMessageSetting API.

    Published: 27 Oct 2022
    8.7
    High

    CVE-2022-40965

    Last Modified: 16 Apr 2025

    The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PostEnergyType API.

    Published: 27 Oct 2022
    4.8
    Medium

    CVE-2022-41627

    Last Modified: 16 Apr 2025

    The physical IoT device of the AliveCor's KardiaMobile, a smartphone-based personal electrocardiogram (EKG) has no encryption for its data-over-sound protocols. Exploiting this vulnerability could allow an attacker to read patient EKG results or create a denial-of-service condition by emitting sounds at similar frequencies as the device, disrupting the smartphone microphone’s ability to accurately read the data. To carry out this attack, the attacker must be close (less than 5 feet) to pick up and emit sound waves.

    Published: 27 Oct 2022
    8.8
    High

    CVE-2022-0074

    Last Modified: 9 May 2025

    Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server Container allows Privilege Escalation. This affects versions from 1.6.15 before 1.7.16.1.

    Published: 27 Oct 2022
    8.8
    High

    CVE-2022-0073

    Last Modified: 5 May 2025

    Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Command Injection. This affects 1.7.0 versions before 1.7.16.1.

    Published: 27 Oct 2022
    5.8
    Medium

    CVE-2022-0072

    Last Modified: 9 May 2025

    Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Path Traversal. This affects versions from 1.5.11 through 1.5.12, from 1.6.5 through 1.6.20.1, from 1.7.0 before 1.7.16.1

    Published: 27 Oct 2022
    6.5
    Medium

    CVE-2022-24669

    Last Modified: 6 May 2025

    It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be used to probe internal network services.

    Published: 27 Oct 2022
    7.1
    High

    CVE-2022-24670

    Last Modified: 9 May 2025

    An attacker can use the unrestricted LDAP queries to determine configuration entries

    Published: 27 Oct 2022
    8.8
    High

    CVE-2022-41996

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leading to arbitrary plugin installation/activation.

    Published: 27 Oct 2022
    7.5
    High

    CVE-2022-38744

    Last Modified: 5 May 2025

    An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, causing the service to fault and become unavailable. The affected port could be used as a server ping port and uses messages structured with XML.

    Published: 27 Oct 2022
    8.2
    High

    CVE-2022-3409

    Last Modified: 5 May 2025

    A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. This vulnerability was identified during mitigation for CVE-2022-2809. When fuzzing the multipart_parser code using AFL++ with address sanitizer enabled to find smallest memory corruptions possible. It detected problem in how multipart_parser handles unclosed http headers. If long enough http header is passed in the multipart form without colon there is one byte overwrite on heap. It can be conducted multiple times in a loop to cause DoS.

    Published: 27 Oct 2022
    8.2
    High

    CVE-2022-2809

    Last Modified: 5 May 2025

    A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. When fuzzing the multipart_parser code using AFL++ with address sanitizer enabled to find smallest memory corruptions possible. It detected problem in how multipart_parser handles unclosed http headers. If long enough http header is passed in the multipart form without colon there is one byte overwrite on heap. It can be conducted multiple times in a loop to cause DoS.

    Published: 27 Oct 2022
    4.7
    Medium

    CVE-2021-45476

    Last Modified: 18 May 2026

    Yordam Library Information Document Automation product before version 19.02 has an unauthenticated reflected XSS vulnerability.

    Published: 27 Oct 2022
    5.3
    Medium

    CVE-2021-45475

    Last Modified: 18 May 2026

    Yordam Library Information Document Automation product before version 19.02 has an unauthenticated Information disclosure vulnerability.

    Published: 27 Oct 2022
    5.3
    Medium

    CVE-2022-25918

    Last Modified: 5 May 2025

    The package shescape from 1.5.10 and before 1.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the escape function in index.js, due to the usage of insecure regex in the escapeArgBash function.

    Published: 27 Oct 2022
    5.4
    Medium

    CVE-2022-42993

    Last Modified: 12 May 2025

    Password Storage Application v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Setup page.

    Published: 27 Oct 2022
    7.5
    High

    CVE-2022-3719

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 27 Oct 2022
    4.8
    Medium

    CVE-2022-39330

    Last Modified: 23 Apr 2025

    Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior to versions 23.0.10 and 24.0.6 and Nextcloud Enterprise Server prior to versions 22.2.10, 23.0.10, and 24.0.6 are vulnerable to a logged-in attacker slowing down the system by generating a lot of database/cpu load. Nextcloud Server versions 23.0.10 and 24.0.6 and Nextcloud Enterprise Server versions 22.2.10, 23.0.10, and 24.0.6 contain patches for this issue. As a workaround, disable the Circles app.

    Published: 27 Oct 2022
    7.5
    High

    CVE-2022-40875

    Last Modified: 7 May 2025

    Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow in the function GetParentControlInfo.

    Published: 27 Oct 2022
    5.4
    Medium

    CVE-2022-42991

    Last Modified: 7 May 2025

    A stored cross-site scripting (XSS) vulnerability in Simple Online Public Access Catalog v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit Account Full Name field.

    Published: 27 Oct 2022
    5.4
    Medium

    CVE-2022-42992

    Last Modified: 7 May 2025

    Multiple stored cross-site scripting (XSS) vulnerabilities in Train Scheduler App v1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Train Code, Train Name, and Destination text fields.

    Published: 27 Oct 2022
    8.8
    High

    CVE-2022-43340

    Last Modified: 12 May 2025

    A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and grant Administrator rights to regular users.

    Published: 27 Oct 2022
    7.5
    High

    CVE-2022-43364

    Last Modified: 12 May 2025

    An access control issue in the password reset page of IP-COM EW9 V15.11.0.14(9732) allows unauthenticated attackers to arbitrarily change the admin password.

    Published: 27 Oct 2022
    7.5
    High

    CVE-2022-43365

    Last Modified: 12 May 2025

    IP-COM EW9 V15.11.0.14(9732) was discovered to contain a buffer overflow in the formSetDebugCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

    Published: 27 Oct 2022
    7.5
    High

    CVE-2022-43366

    Last Modified: 12 May 2025

    IP-COM EW9 V15.11.0.14(9732) allows unauthenticated attackers to access sensitive information via the checkLoginUser, ate, telnet, version, setDebugCfg, and boot interfaces.

    Published: 27 Oct 2022
    9.8
    Critical

    CVE-2022-43367

    Last Modified: 12 May 2025

    IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function.

    Published: 27 Oct 2022
    5.4
    Medium

    CVE-2022-42054

    Last Modified: 7 May 2025

    Multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Company Name and Description text fields.

    Published: 27 Oct 2022
    6.5
    Medium

    CVE-2022-42055

    Last Modified: 7 May 2025

    Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via the ping and traceroute tools allow attackers to read arbitrary files on the system.

    Published: 27 Oct 2022
    5.3
    Medium

    CVE-2022-2508

    Last Modified: 7 May 2025

    In affected versions of Octopus Server it is possible to reveal the existence of resources in a space that the user does not have access to due to verbose error messaging.

    Published: 27 Oct 2022
    9.8
    Critical

    CVE-2022-3095

    Last Modified: 21 Apr 2025

    The implementation of backslash parsing in the Dart URI class for versions prior to 2.18 and Flutter versions prior to 3.30 differs from the WhatWG URL standards. Dart uses the RFC 3986 syntax, which creates incompatibilities with the '\' characters in URIs, which can lead to auth bypass in webapps interpreting URIs. We recommend updating Dart or Flutter to mitigate the issue.

    Published: 27 Oct 2022
    6.5
    Medium

    CVE-2022-31630

    Last Modified: 21 Nov 2024

    In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information. 

    Published: 27 Oct 2022
    6.1
    Medium

    CVE-2022-32407

    Last Modified: 7 May 2025

    Softr v2.0 was discovered to contain a Cross-Site Scripting (XSS) vulnerability via the First Name parameter under the Create A New Account module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 27 Oct 2022
    6.1
    Medium

    CVE-2022-36182

    Last Modified: 7 May 2025

    Hashicorp Boundary v0.8.0 is vulnerable to Clickjacking which allow for the interception of login credentials, re-direction of users to malicious sites, or causing users to perform malicious actions on the site.

    Published: 27 Oct 2022
    7.5
    High

    CVE-2022-3717

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 27 Oct 2022
    6.5
    Medium

    CVE-2022-3718

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 27 Oct 2022
    3.5
    Low

    CVE-2022-39329

    Last Modified: 23 Apr 2025

    Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without direct database access. Versions 23.0.9 and 24.0.5 contains patches for this issue. No known workarounds are available.

    Published: 27 Oct 2022
    9.8
    Critical

    CVE-2022-39365

    Last Modified: 23 Apr 2025

    Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/Mail` & `ClassDefinition\Layout\Text` is vulnerable to server-side template injection, which could lead to remote code execution. Version 10.5.9 contains a patch for this issue. As a workaround, one may apply the patch manually.

    Published: 27 Oct 2022