CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2022-43800

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43801

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43790

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43791

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43792

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43793

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43794

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43787

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43788

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43789

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43785

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43786

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43783

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43784

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Oct 2022
    5.5
    Medium

    CVE-2022-20776

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 26 Oct 2022
    6.1
    Medium

    CVE-2022-20959

    Last Modified: 21 Nov 2024

    A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by persuading an authenticated administrator of the web-based management interface to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

    Published: 26 Oct 2022
    5.5
    Medium

    CVE-2022-20955

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 26 Oct 2022
    5.5
    Medium

    CVE-2022-20954

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 26 Oct 2022
    5.5
    Medium

    CVE-2022-20953

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 26 Oct 2022
    8.6
    High

    CVE-2022-20933

    Last Modified: 21 Nov 2024

    A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z3 Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of client-supplied parameters while establishing an SSL VPN session. An attacker could exploit this vulnerability by crafting a malicious request and sending it to the affected device. A successful exploit could allow the attacker to cause the Cisco AnyConnect VPN server to crash and restart, resulting in the failure of the established SSL VPN connections and forcing remote users to initiate a new VPN connection and re-authenticate. A sustained attack could prevent new SSL VPN connections from being established. Note: When the attack traffic stops, the Cisco AnyConnect VPN server recovers gracefully without requiring manual intervention. Cisco Meraki has released software updates that address this vulnerability.

    Published: 26 Oct 2022
    7.1
    High

    CVE-2022-20822

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read and delete files on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains certain character sequences to an affected system. A successful exploit could allow the attacker to read or delete specific files on the device that their configured administrative level should not have access to. Cisco plans to release software updates that address this vulnerability.

    Published: 26 Oct 2022
    5.5
    Medium

    CVE-2022-20811

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 26 Oct 2022
    5.8
    Medium

    CVE-2022-43748

    Last Modified: 25 Apr 2025

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file operation management in Synology Presto File Server before 2.1.2-1601 allows remote attackers to write arbitrary files via unspecified vectors.

    Published: 26 Oct 2022
    4.3
    Medium

    CVE-2022-43749

    Last Modified: 9 May 2025

    Improper privilege management vulnerability in summary report management in Synology Presto File Server before 2.1.2-1601 allows remote authenticated users to bypass security constraint via unspecified vectors.

    Published: 26 Oct 2022
    7.7
    High

    CVE-2022-31256

    Last Modified: 9 May 2025

    A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: SUSE openSUSE Factory sendmail versions prior to 8.17.1-1.1.

    Published: 26 Oct 2022
    5.4
    Medium

    CVE-2022-25849

    Last Modified: 9 May 2025

    The package joyqi/hyper-down from 0.0.0 are vulnerable to Cross-site Scripting (XSS) because the module of parse markdown does not filter the href attribute very well.

    Published: 26 Oct 2022
    7.5
    High

    CVE-2022-42916

    Last Modified: 13 Feb 2026

    In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even when HTTP is provided in the URL. This mechanism could be bypassed if the host name in the given URL uses IDN characters that get replaced with ASCII counterparts as part of the IDN conversion, e.g., using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop of U+002E (.). The earliest affected version is 7.77.0 2021-05-26.

    Published: 26 Oct 2022
    9.8
    Critical

    CVE-2022-32221

    Last Modified: 13 Feb 2026

    When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.

    Published: 26 Oct 2022
    5.5
    Medium

    CVE-2022-44020

    Last Modified: 7 May 2025

    An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an "unsupported, production-like configuration."

    Published: 26 Oct 2022
    9.8
    Critical

    CVE-2022-42998

    Last Modified: 7 May 2025

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the srcip parameter at /goform/form2IPQoSTcAdd.

    Published: 26 Oct 2022
    7.3
    High

    CVE-2022-3664

    Last Modified: 14 Apr 2025

    A vulnerability classified as critical has been found in Axiomatic Bento4. Affected is the function AP4_BitStream::WriteBytes of the file Ap4BitStream.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212004.

    Published: 26 Oct 2022
    7.3
    High

    CVE-2022-3670

    Last Modified: 14 Apr 2025

    A vulnerability was found in Axiomatic Bento4. It has been classified as critical. Affected is the function WriteSample of the component mp42hevc. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-212010 is the identifier assigned to this vulnerability.

    Published: 26 Oct 2022
    8.8
    High

    CVE-2022-39286

    Last Modified: 23 Apr 2025

    Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in CWD. This vulnerability allows one user to run code as another. Version 4.11.2 contains a patch for this issue. There are no known workarounds.

    Published: 26 Oct 2022
    8.8
    High

    CVE-2022-39362

    Last Modified: 23 Apr 2025

    Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, unsaved SQL queries are auto-executed, which could pose a possible attack vector. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9. Metabase no longer automatically executes ad-hoc native queries. Now the native editor shows the query and gives the user the option to manually run the query if they want.

    Published: 26 Oct 2022
    8.8
    High

    CVE-2022-39944

    Last Modified: 7 May 2025

    In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures a JDBC EC with a MySQL data source and malicious parameters. Therefore, the parameters in the jdbc url should be blacklisted. Versions of Apache Linkis <= 1.2.0 will be affected, We recommend users to update to 1.3.0.

    Published: 26 Oct 2022
    7.5
    High

    CVE-2022-42999

    Last Modified: 7 May 2025

    D-Link DIR-816 A2 1.10 B05 was discovered to contain multiple command injection vulnerabilities via the admuser and admpass parameters at /goform/setSysAdm.

    Published: 26 Oct 2022
    9.8
    Critical

    CVE-2022-43000

    Last Modified: 7 May 2025

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep4_pskpwd parameter at /goform/form2WizardStep4.

    Published: 26 Oct 2022
    9.8
    Critical

    CVE-2022-43001

    Last Modified: 7 May 2025

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setSecurity function.

    Published: 26 Oct 2022
    9.8
    Critical

    CVE-2022-43002

    Last Modified: 7 May 2025

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep54_pskpwd parameter at /goform/form2WizardStep54.

    Published: 26 Oct 2022
    9.8
    Critical

    CVE-2022-43003

    Last Modified: 7 May 2025

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setRepeaterSecurity function.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43942

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43943

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 26 Oct 2022
    —
    Unknown

    CVE-2022-43944

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 26 Oct 2022
    7.5
    High

    CVE-2022-43747

    Last Modified: 21 Nov 2024

    baramundi Management Agent (bMA) in baramundi Management Suite (bMS) 2021 R1 and R2 and 2022 R1 allows remote code execution. This is fixed in security update S-2022-01, which contains fixed bMA setup files for these versions. This also is fixed in baramundi Management Suite 2022 R2.

    Published: 26 Oct 2022
    9.8
    Critical

    CVE-2022-43774

    Last Modified: 7 May 2025

    The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.

    Published: 26 Oct 2022
    9.8
    Critical

    CVE-2022-43775

    Last Modified: 7 May 2025

    The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.

    Published: 26 Oct 2022
    6.5
    Medium

    CVE-2022-43776

    Last Modified: 7 May 2025

    The url parameter of the /api/geojson endpoint in Metabase versions <44.5 can be used to perform Server Side Request Forgery attacks. Previously implemented blacklists could be circumvented by leveraging 301 and 302 redirects.

    Published: 26 Oct 2022
    5.1
    Medium

    CVE-2022-3474

    Last Modified: 21 Nov 2024

    A bad credential handling in the remote assets API for Bazel versions prior to 5.3.2 and 4.2.3 sends all user-provided credentials instead of only the required ones for the requests. We recommend upgrading to versions later than or equal to 5.3.2 or 4.2.3.

    Published: 26 Oct 2022
    6.5
    Medium

    CVE-2022-35260

    Last Modified: 21 Nov 2024

    curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the readworks, write a zero byte beyond its boundary.This will in most cases cause a segfault or similar, but circumstances might also cause different outcomes.If a malicious user can provide a custom netrc file to an application or otherwise affect its contents, this flaw could be used as denial-of-service.

    Published: 26 Oct 2022
    7.3
    High

    CVE-2022-3665

    Last Modified: 14 Apr 2025

    A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is an unknown functionality of the file AvcInfo.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-212005 was assigned to this vulnerability.

    Published: 26 Oct 2022