CVE Feed

    Dashboard / CVE

    8.2
    High

    CVE-2022-1070

    Last Modified: 17 Apr 2025

    Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

    Published: 21 Oct 2022
    8.2
    High

    CVE-2022-1059

    Last Modified: 17 Apr 2025

    Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

    Published: 21 Oct 2022
    8.2
    High

    CVE-2022-26423

    Last Modified: 17 Apr 2025

    Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

    Published: 21 Oct 2022
    8.2
    High

    CVE-2022-1066

    Last Modified: 17 Apr 2025

    Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

    Published: 21 Oct 2022
    7.2
    High

    CVE-2022-38104

    Last Modified: 20 Feb 2025

    Auth. WordPress Options Change (siteurl, users_can_register, default_role, admin_email and new_admin_email) vulnerability in Biplob Adhikari's Accordions – Multiple Accordions or FAQs Builder plugin (versions <= 2.0.3 on WordPress.

    Published: 21 Oct 2022
    4.8
    Medium

    CVE-2022-40311

    Last Modified: 20 Feb 2025

    Auth. (admin+) Stored Cross-Site Scripting (XSS) in Fatcat Apps Analytics Cat plugin <= 1.0.9 on WordPress.

    Published: 21 Oct 2022
    5.4
    Medium

    CVE-2022-41638

    Last Modified: 20 Feb 2025

    Auth. Stored Cross-Site Scripting (XSS) in Pop-Up Chop Chop plugin <= 2.1.7 on WordPress.

    Published: 21 Oct 2022
    —
    Unknown

    CVE-2022-43586

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 21 Oct 2022
    —
    Unknown

    CVE-2022-43587

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 21 Oct 2022
    —
    Unknown

    CVE-2022-43583

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 21 Oct 2022
    —
    Unknown

    CVE-2022-43584

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 21 Oct 2022
    —
    Unknown

    CVE-2022-43585

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 21 Oct 2022
    9.8
    Critical

    CVE-2022-3203

    Last Modified: 7 May 2025

    On ORing net IAP-420(+) with FW version 2.0m a telnet server is enabled by default and cannot permanently be disabled. You can connect to the device via LAN or WiFi with hardcoded credentials and get an administrative shell. These credentials are reset to defaults with every reboot.

    Published: 21 Oct 2022
    6.8
    Medium

    CVE-2021-42553

    Last Modified: 8 Oct 2026

    A buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics in versions before 3.5.1 allows an attacker to execute arbitrary code when the descriptor contains more endpoints than USBH_MAX_NUM_ENDPOINTS. The library is typically integrated when using a RTOS such as FreeRTOS on STM32 MCUs.

    Published: 21 Oct 2022
    6.2
    Medium

    CVE-2022-23462

    Last Modified: 22 Apr 2025

    IOWOW is a C utility library and persistent key/value storage engine. Versions 1.4.15 and prior contain a stack buffer overflow vulnerability that allows for Denial of Service (DOS) when it parses scientific notation numbers present in JSON. A patch for this issue is available at commit a79d31e4cff1d5a08f665574b29fd885897a28fd in the `master` branch of the repository. There are no workarounds other than applying the patch.

    Published: 21 Oct 2022
    7.8
    High

    CVE-2022-36122

    Last Modified: 8 May 2025

    The Automox Agent before 40 on Windows incorrectly sets permissions on key files.

    Published: 21 Oct 2022
    2.6
    Low

    CVE-2022-3637

    Last Modified: 15 Apr 2025

    A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function jlink_init of the file monitor/jlink.c of the component BlueZ. The manipulation leads to denial of service. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211936.

    Published: 21 Oct 2022
    7.8
    High

    CVE-2022-41309

    Last Modified: 7 May 2025

    A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 21 Oct 2022
    7.8
    High

    CVE-2022-42933

    Last Modified: 7 May 2025

    A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 21 Oct 2022
    7.8
    High

    CVE-2022-42934

    Last Modified: 7 May 2025

    A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 21 Oct 2022
    7.8
    High

    CVE-2022-42936

    Last Modified: 7 May 2025

    A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 21 Oct 2022
    7.8
    High

    CVE-2022-42937

    Last Modified: 7 May 2025

    A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 21 Oct 2022
    7.8
    High

    CVE-2022-42938

    Last Modified: 7 May 2025

    A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 21 Oct 2022
    7.8
    High

    CVE-2022-42939

    Last Modified: 7 May 2025

    A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 21 Oct 2022
    7.8
    High

    CVE-2022-42940

    Last Modified: 7 May 2025

    A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 21 Oct 2022
    7.8
    High

    CVE-2022-42941

    Last Modified: 7 May 2025

    A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 21 Oct 2022
    7.8
    High

    CVE-2022-42943

    Last Modified: 7 May 2025

    A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 21 Oct 2022
    7.8
    High

    CVE-2022-42944

    Last Modified: 7 May 2025

    A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 21 Oct 2022
    9.8
    Critical

    CVE-2022-43400

    Last Modified: 7 May 2025

    A vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions < V22.2a (80)). The mobile server component of affected applications improperly handles the log in for Active Directory accounts that are part of Administrators group. This could allow an unauthenticated remote attacker to access the application without a valid account.

    Published: 21 Oct 2022
    7.2
    High

    CVE-2022-42189

    Last Modified: 7 May 2025

    Emlog Pro 1.6.0 plugins upload suffers from a remote code execution (RCE) vulnerability.

    Published: 21 Oct 2022
    5.4
    Medium

    CVE-2022-42205

    Last Modified: 8 May 2025

    PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via add-patient.php.

    Published: 21 Oct 2022
    5.4
    Medium

    CVE-2022-42206

    Last Modified: 8 May 2025

    PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via doctor/view-patient.php, admin/view-patient.php, and view-medhistory.php.

    Published: 21 Oct 2022
    0
    Low

    CVE-2022-3638

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 21 Oct 2022
    —
    Unknown

    CVE-2022-3642

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 21 Oct 2022
    5
    Medium

    CVE-2022-39272

    Last Modified: 23 Apr 2025

    Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a Denial of Service. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields `.spec.interval` or `.spec.timeout` (and structured variations of these fields), causing the entire object type to stop being processed. This issue is patched in version 0.35.0. As a workaround, Admission controllers can be employed to restrict the values that can be used for fields `.spec.interval` and `.spec.timeout`, however upgrading to the latest versions is still the recommended mitigation.

    Published: 21 Oct 2022
    7.8
    High

    CVE-2022-41310

    Last Modified: 7 May 2025

    A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 21 Oct 2022
    7.5
    High

    CVE-2022-41575

    Last Modified: 7 May 2025

    A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a subset of application data (e.g., cleartext credentials). This is fixed in 2022.3.3.

    Published: 21 Oct 2022
    5.3
    Medium

    CVE-2024-5458

    Last Modified: 3 Nov 2025

    In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.

    Published: 21 Oct 2022
    4.3
    Medium

    CVE-2022-3639

    Last Modified: 7 May 2025

    A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Improper data handling on branch creation could have been used to trigger high CPU usage.

    Published: 21 Oct 2022
    3.1
    Low

    CVE-2022-3647

    Last Modified: 15 Apr 2025

    ** DISPUTED ** A vulnerability, which was classified as problematic, was found in Redis up to 6.2.7/7.0.5. Affected is the function sigsegvHandler of the file debug.c of the component Crash Report. The manipulation leads to denial of service. The complexity of an attack is rather high. The exploitability is told to be difficult. The real existence of this vulnerability is still doubted at the moment. Upgrading to version 6.2.8 and 7.0.6 is able to address this issue. The patch is identified as 0bf90d944313919eb8e63d3588bf63a367f020a3. It is recommended to apply a patch to fix this issue. VDB-211962 is the identifier assigned to this vulnerability. NOTE: The vendor claims that this is not a DoS because it applies to the crash logging mechanism which is triggered after a crash has occurred.

    Published: 21 Oct 2022
    3.3
    Low

    CVE-2022-39259

    Last Modified: 22 Apr 2025

    jadx is a set of command line and GUI tools for producing Java source code from Android Dex and Apk files. versions prior to 1.4.5 are subject to a Denial of Service when opening zip files with HTML sequences. This issue has been patched in version 1.4.5. There are no known workarounds.

    Published: 21 Oct 2022
    7.8
    High

    CVE-2022-42935

    Last Modified: 7 May 2025

    A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 21 Oct 2022
    7.8
    High

    CVE-2022-42942

    Last Modified: 8 May 2025

    A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 21 Oct 2022
    7.2
    High

    CVE-2022-38108

    Last Modified: 8 May 2025

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

    Published: 20 Oct 2022
    8.8
    High

    CVE-2022-36958

    Last Modified: 8 May 2025

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands.

    Published: 20 Oct 2022
    7.2
    High

    CVE-2022-36957

    Last Modified: 5 May 2025

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

    Published: 20 Oct 2022
    5.4
    Medium

    CVE-2022-36966

    Last Modified: 7 May 2025

    Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability in SolarWinds Platform 2022.3 and previous.

    Published: 20 Oct 2022
    —
    Unknown

    CVE-2022-43560

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 20 Oct 2022
    —
    Unknown

    CVE-2022-43559

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 20 Oct 2022
    —
    Unknown

    CVE-2022-43558

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 20 Oct 2022