CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2022-31684

    Last Modified: 4 Sept 2026

    Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTTP requests where logging at WARN level is enabled.

    Published: 19 Oct 2022
    7.5
    High

    CVE-2022-33077

    Last Modified: 4 Jul 2026

    An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint.

    Published: 19 Oct 2022
    9.8
    Critical

    CVE-2016-20017

    Last Modified: 5 Nov 2025

    D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.

    Published: 19 Oct 2022
    7.5
    High

    CVE-2013-4253

    Last Modified: 9 May 2025

    The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file.

    Published: 19 Oct 2022
    5.5
    Medium

    CVE-2013-4281

    Last Modified: 9 May 2025

    In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with local access to the broker to read this file.

    Published: 19 Oct 2022
    9.8
    Critical

    CVE-2016-20016

    Last Modified: 9 May 2025

    MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /shell URI. A remote unauthenticated attacker can execute arbitrary operating system commands as root. This vulnerability has also been referred to as the "JAWS webserver RCE" because of the easily identifying HTTP response server field. Other firmware versions, at least from 2014 through 2019, can be affected. This was exploited in the wild in 2017 through 2022.

    Published: 19 Oct 2022
    6.5
    Medium

    CVE-2022-43032

    Last Modified: 8 May 2025

    An issue was discovered in Bento4 v1.6.0-639. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp, as demonstrated by mp42aac.

    Published: 19 Oct 2022
    7.5
    High

    CVE-2022-40798

    Last Modified: 8 May 2025

    OcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending the same request with correct email its possible to account takeover.

    Published: 19 Oct 2022
    7.8
    High

    CVE-2022-41709

    Last Modified: 8 May 2025

    Markdownify version 1.4.1 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Markdownify. This is possible because the application has the "nodeIntegration" option enabled.

    Published: 19 Oct 2022
    6.5
    Medium

    CVE-2022-4172

    Last Modified: 14 Apr 2025

    An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record() and write_erst_record() functions. Both issues may allow the guest to overrun the host buffer allocated for the ERST memory device. A malicious guest could use these flaws to crash the QEMU process on the host.

    Published: 19 Oct 2022
    6.1
    Medium

    CVE-2022-43018

    Last Modified: 24 Sept 2025

    OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email function.

    Published: 19 Oct 2022
    9.8
    Critical

    CVE-2022-43024

    Last Modified: 9 May 2025

    Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.

    Published: 19 Oct 2022
    9.8
    Critical

    CVE-2022-43025

    Last Modified: 9 May 2025

    Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the startIp parameter at /goform/SetPptpServerCfg.

    Published: 19 Oct 2022
    9.8
    Critical

    CVE-2022-43026

    Last Modified: 9 May 2025

    Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the endIp parameter at /goform/SetPptpServerCfg.

    Published: 19 Oct 2022
    9.8
    Critical

    CVE-2022-43027

    Last Modified: 8 May 2025

    Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the firewallEn parameter at /goform/SetFirewallCfg.

    Published: 19 Oct 2022
    9.8
    Critical

    CVE-2022-43028

    Last Modified: 8 May 2025

    Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the timeZone parameter at /goform/SetSysTimeCfg.

    Published: 19 Oct 2022
    9.8
    Critical

    CVE-2022-43029

    Last Modified: 8 May 2025

    Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the time parameter at /goform/SetSysTimeCfg.

    Published: 19 Oct 2022
    6.5
    Medium

    CVE-2022-43033

    Last Modified: 8 May 2025

    An issue was discovered in Bento4 1.6.0-639. There is a bad free in the component AP4_HdlrAtom::~AP4_HdlrAtom() which allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 19 Oct 2022
    6.5
    Medium

    CVE-2022-43034

    Last Modified: 8 May 2025

    An issue was discovered in Bento4 v1.6.0-639. There is a heap buffer overflow vulnerability in the AP4_BitReader::SkipBits(unsigned int) function in mp42ts.

    Published: 19 Oct 2022
    6.5
    Medium

    CVE-2022-43035

    Last Modified: 8 May 2025

    An issue was discovered in Bento4 v1.6.0-639. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac.

    Published: 19 Oct 2022
    6.5
    Medium

    CVE-2022-43037

    Last Modified: 8 May 2025

    An issue was discovered in Bento4 1.6.0-639. There is a memory leak in the function AP4_File::ParseStream in /Core/Ap4File.cpp.

    Published: 19 Oct 2022
    6.5
    Medium

    CVE-2022-43038

    Last Modified: 8 May 2025

    Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadCache() function in mp42ts.

    Published: 19 Oct 2022
    5.5
    Medium

    CVE-2022-43039

    Last Modified: 8 May 2025

    GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_isom_meta_restore_items_ref at /isomedia/meta.c.

    Published: 19 Oct 2022
    9.8
    Critical

    CVE-2022-43184

    Last Modified: 8 May 2025

    D-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc.cgi.

    Published: 19 Oct 2022
    5.4
    Medium

    CVE-2022-43185

    Last Modified: 8 May 2025

    A stored cross-site scripting (XSS) vulnerability in the Configuration/Holidays module of Rukovoditel v3.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.

    Published: 19 Oct 2022
    8.8
    High

    CVE-2022-43407

    Last Modified: 8 May 2025

    Jenkins Pipeline: Input Step Plugin 451.vf1a_a_4f405289 and earlier does not restrict or sanitize the optionally specified ID of the 'input' step, which is used for the URLs that process user interactions for the given 'input' step (proceed or abort) and is not correctly encoded, allowing attackers able to configure Pipelines to have Jenkins build URLs from 'input' step IDs that would bypass the CSRF protection of any target URL in Jenkins when the 'input' step is interacted with.

    Published: 19 Oct 2022
    5.3
    Medium

    CVE-2022-43412

    Last Modified: 8 May 2025

    Jenkins Generic Webhook Trigger Plugin 1.84.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.

    Published: 19 Oct 2022
    4.3
    Medium

    CVE-2022-43413

    Last Modified: 8 May 2025

    Jenkins Job Import Plugin 3.5 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

    Published: 19 Oct 2022
    5.3
    Medium

    CVE-2022-43414

    Last Modified: 8 May 2025

    Jenkins NUnit Plugin 0.27 and earlier implements an agent-to-controller message that parses files inside a user-specified directory as test results, allowing attackers able to control agent processes to obtain test results from files in an attacker-specified directory on the Jenkins controller.

    Published: 19 Oct 2022
    4.3
    Medium

    CVE-2022-43417

    Last Modified: 8 May 2025

    Jenkins Katalon Plugin 1.0.32 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 19 Oct 2022
    4.3
    Medium

    CVE-2022-43418

    Last Modified: 8 May 2025

    A cross-site request forgery (CSRF) vulnerability in Jenkins Katalon Plugin 1.0.33 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 19 Oct 2022
    5.4
    Medium

    CVE-2022-43420

    Last Modified: 8 May 2025

    Jenkins Contrast Continuous Application Security Plugin 3.9 and earlier does not escape data returned from the Contrast service when generating a report, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control or modify Contrast service API responses.

    Published: 19 Oct 2022
    5.3
    Medium

    CVE-2022-43422

    Last Modified: 8 May 2025

    Jenkins Compuware Topaz Utilities Plugin 1.0.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.

    Published: 19 Oct 2022
    5.3
    Medium

    CVE-2022-43423

    Last Modified: 8 May 2025

    Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.

    Published: 19 Oct 2022
    5.3
    Medium

    CVE-2022-43424

    Last Modified: 8 May 2025

    Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.

    Published: 19 Oct 2022
    5.4
    Medium

    CVE-2022-43425

    Last Modified: 8 May 2025

    Jenkins Custom Checkbox Parameter Plugin 1.4 and earlier does not escape the name and description of Custom Checkbox Parameter parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 19 Oct 2022
    4.3
    Medium

    CVE-2022-43427

    Last Modified: 8 May 2025

    Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

    Published: 19 Oct 2022
    5.3
    Medium

    CVE-2022-43428

    Last Modified: 8 May 2025

    Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.

    Published: 19 Oct 2022
    7.5
    High

    CVE-2022-43429

    Last Modified: 8 May 2025

    Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to read arbitrary files on the Jenkins controller file system.

    Published: 19 Oct 2022
    7.5
    High

    CVE-2022-43430

    Last Modified: 8 May 2025

    Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 19 Oct 2022
    4.3
    Medium

    CVE-2022-43432

    Last Modified: 8 May 2025

    Jenkins XFramium Builder Plugin 1.0.22 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.

    Published: 19 Oct 2022
    4.3
    Medium

    CVE-2022-43433

    Last Modified: 8 May 2025

    Jenkins ScreenRecorder Plugin 0.7 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.

    Published: 19 Oct 2022
    5.3
    Medium

    CVE-2022-43434

    Last Modified: 8 May 2025

    Jenkins NeuVector Vulnerability Scanner Plugin 1.20 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.

    Published: 19 Oct 2022
    5.3
    Medium

    CVE-2022-43435

    Last Modified: 8 May 2025

    Jenkins 360 FireLine Plugin 1.7.2 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.

    Published: 19 Oct 2022
    7.5
    High

    CVE-2022-43415

    Last Modified: 9 May 2025

    Jenkins REPO Plugin 1.15.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 19 Oct 2022
    9.9
    Critical

    CVE-2022-43401

    Last Modified: 21 Nov 2024

    A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

    Published: 19 Oct 2022
    9.9
    Critical

    CVE-2022-43402

    Last Modified: 21 Nov 2024

    A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Pipeline: Groovy Plugin 2802.v5ea_628154b_c2 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

    Published: 19 Oct 2022
    9.9
    Critical

    CVE-2022-43406

    Last Modified: 21 Nov 2024

    A sandbox bypass vulnerability in Jenkins Pipeline: Deprecated Groovy Libraries Plugin 583.vf3b_454e43966 and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

    Published: 19 Oct 2022
    7.5
    High

    CVE-2022-42227

    Last Modified: 8 May 2025

    jsonlint 1.0 is vulnerable to heap-buffer-overflow via /home/hjsz/jsonlint/src/lexer.

    Published: 19 Oct 2022
    7.5
    High

    CVE-2020-23648

    Last Modified: 9 May 2025

    Asus RT-N12E 2.0.0.39 is affected by an incorrect access control vulnerability. Through system.asp / start_apply.htm, an attacker can change the administrator password without any authentication.

    Published: 19 Oct 2022