CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-39976

    Last Modified: 7 May 2025

    School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /modules/announcement/index.php?view=edit&id=.

    Published: 27 Oct 2022
    7.2
    High

    CVE-2022-39977

    Last Modified: 7 May 2025

    Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in the User module. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file uploaded through the picture upload point.

    Published: 27 Oct 2022
    7.2
    High

    CVE-2022-39978

    Last Modified: 7 May 2025

    Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in the Product List module. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file uploaded through the picture upload point.

    Published: 27 Oct 2022
    5.1
    Medium

    CVE-2022-40184

    Last Modified: 9 May 2025

    Incomplete filtering of JavaScript code in different configuration fields of the web based interface of the VIDEOJET multi 4000 allows an attacker with administrative credentials to store JavaScript code which will be executed for all administrators accessing the same configuration option.

    Published: 27 Oct 2022
    7.5
    High

    CVE-2022-40874

    Last Modified: 7 May 2025

    Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow vulnerability in the GetParentControlInfo function, which can cause a denial of service attack through a carefully constructed http request.

    Published: 27 Oct 2022
    9.8
    Critical

    CVE-2022-40876

    Last Modified: 7 May 2025

    In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can cause a stack overflow and enable remote code execution (RCE).

    Published: 27 Oct 2022
    7.8
    High

    CVE-2022-3715

    Last Modified: 3 Nov 2025

    A flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems.

    Published: 27 Oct 2022
    6.8
    Medium

    CVE-2022-31898

    Last Modified: 7 May 2025

    gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered to contain multiple command injection vulnerabilities via the ping_addr and trace_addr function parameters.

    Published: 27 Oct 2022
    5.1
    Medium

    CVE-2022-3500

    Last Modified: 29 Apr 2025

    A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that stopped attestation attempts for that host leaving it in an attested state but not verifying that anymore.

    Published: 27 Oct 2022
    5
    Medium

    CVE-2022-3714

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in SourceCodester Online Medicine Ordering System 1.0. Affected is an unknown function of the file admin/?page=orders/view_order. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. VDB-212346 is the identifier assigned to this vulnerability.

    Published: 27 Oct 2022
    3.5
    Low

    CVE-2022-3716

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic was found in SourceCodester Online Medicine Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /omos/admin/?page=user/list. The manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-212347.

    Published: 27 Oct 2022
    6.3
    Medium

    CVE-2022-3725

    Last Modified: 9 May 2025

    Crash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file

    Published: 27 Oct 2022
    4
    Medium

    CVE-2022-39364

    Last Modified: 22 Apr 2025

    Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server prior to versions 23.0.9 and 24.0.5 and Nextcloud Enterprise Server prior to versions 22.2.10.5, 23.0.9, and 24.0.5 an attacker reading `nextcloud.log` may gain knowledge of credentials to connect to a SharePoint service. Nextcloud Server versions 23.0.9 and 24.0.5 and Nextcloud Enterprise Server versions 22.2.10.5, 23.0.9, and 24.0.5 contain a patch for this issue. As a workaround, set `zend.exception_ignore_args = On` as an option in `php.ini`.

    Published: 27 Oct 2022
    5.8
    Medium

    CVE-2022-40183

    Last Modified: 5 May 2025

    An error in the URL handler of the VIDEOJET multi 4000 may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the encoder address can send a crafted link to a user, which will execute JavaScript code in the context of the user.

    Published: 27 Oct 2022
    5.2
    Medium

    CVE-2022-40703

    Last Modified: 16 Apr 2025

    CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App version 5.17.1-754993421 and prior on Android allows an unauthenticated attacker with physical access to the Android device containing the app to bypass application authentication and alter information in the app.

    Published: 26 Oct 2022
    8.8
    High

    CVE-2022-40238

    Last Modified: 7 May 2025

    A Remote Code Injection vulnerability exists in CERT software prior to version 1.50.5. An authenticated attacker can inject arbitrary pickle object as part of a user's profile. This can lead to code execution on the server when the user's profile is accessed.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43830

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43827

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43829

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43826

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43828

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43819

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43822

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43820

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43821

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43824

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43825

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43823

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43811

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43812

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43815

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43813

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43814

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43816

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43817

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43818

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43806

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43807

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43808

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43809

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43810

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43802

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43803

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43804

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43805

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43795

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43796

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43797

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43798

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43799

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022