CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2022-21602

    Last Modified: 21 Nov 2024

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

    Published: 18 Oct 2022
    9.8
    Critical

    CVE-2022-21587

    Last Modified: 27 Oct 2025

    Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

    Published: 18 Oct 2022
    5.4
    Medium

    CVE-2022-21591

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: UI Infrastructure). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Transportation Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Transportation Management. CVSS 3.1 Base Score 5.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).

    Published: 18 Oct 2022
    4.4
    Medium

    CVE-2022-21595

    Last Modified: 21 Nov 2024

    Vulnerability in the MySQL Server product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.36 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

    Published: 18 Oct 2022
    7.8
    High

    CVE-2022-3569

    Last Modified: 13 May 2025

    Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the 'zimbra' user can effectively coerce postfix into running arbitrary commands as 'root'.

    Published: 17 Oct 2022
    9.6
    Critical

    CVE-2020-8976

    Last Modified: 23 Apr 2025

    The integrated server of the ZGR TPS200 NG on its 2.00 firmware version and 1.01 hardware version, allows a remote attacker to perform actions with the permissions of a victim user. For this to happen, the victim user has to have an active session and triggers the malicious request.

    Published: 17 Oct 2022
    9.3
    Critical

    CVE-2020-8973

    Last Modified: 13 May 2025

    ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, does not properly accept specially constructed requests. This allows an attacker with access to the network where the affected asset is located, to operate and change several parameters without having to be registered as a user on the web that owns the device.

    Published: 17 Oct 2022
    10
    Critical

    CVE-2020-8974

    Last Modified: 13 May 2025

    In ZGR TPS200 NG 2.00 firmware version and 1.01 hardware version, the firmware upload process does not perform any type of restriction. This allows an attacker to modify it and re-upload it via web with malicious modifications, rendering the device unusable.

    Published: 17 Oct 2022
    7.5
    High

    CVE-2020-8975

    Last Modified: 12 May 2025

    ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, allows a remote attacker with access to the web application and knowledge of the routes (URIs) used by the application, to access sensitive information about the system.

    Published: 17 Oct 2022
    7.3
    High

    CVE-2022-3368

    Last Modified: 10 May 2025

    A vulnerability within the Software Updater functionality of Avira Security for Windows allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avira Security version 1.1.72.30556.

    Published: 17 Oct 2022
    7.5
    High

    CVE-2022-3382

    Last Modified: 16 Apr 2025

    HIWIN Robot System Software version 3.3.21.9869 does not properly address the terminated command source. As a result, an attacker could craft code to disconnect HRSS and the controller and cause a denial-of-service condition.

    Published: 17 Oct 2022
    9
    Critical

    CVE-2022-32176

    Last Modified: 27 May 2025

    In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the "Compress Upload" functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin's cookie leading to account takeover.

    Published: 17 Oct 2022
    4.8
    Medium

    CVE-2022-26375

    Last Modified: 20 Feb 2025

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mammothology AB Press Optimizer plugin <= 1.1.1 on WordPress.

    Published: 17 Oct 2022
    5.5
    Medium

    CVE-2022-3640

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in Linux Kernel. Affected is the function l2cap_conn_del of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211944.

    Published: 17 Oct 2022
    —
    Unknown

    CVE-2022-43375

    Last Modified: 4 Jan 2024

    This CVE ID was unused by the CNA.

    Published: 17 Oct 2022
    3.5
    Low

    CVE-2022-3501

    Last Modified: 10 May 2025

    Article template contents with sensitive data could be accessed from agents without permissions.

    Published: 17 Oct 2022
    7.5
    High

    CVE-2022-39052

    Last Modified: 10 May 2025

    An external attacker is able to send a specially crafted email (with many recipients) and trigger a potential DoS of the system

    Published: 17 Oct 2022
    7.5
    High

    CVE-2022-3281

    Last Modified: 10 May 2025

    WAGO Series PFC100/PFC200, Series Touch Panel 600, Compact Controller CC100 and Edge Controller in multiple versions are prone to a loss of MAC-Address-Filtering after reboot. This may allow an remote attacker to circumvent the reach the network that should be protected by the MAC address filter.

    Published: 17 Oct 2022
    9.8
    Critical

    CVE-2022-2052

    Last Modified: 10 May 2025

    Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use these accounts to remotely gain full access to the system.

    Published: 17 Oct 2022
    5.4
    Medium

    CVE-2022-41542

    Last Modified: 4 Jul 2026

    devhub 0.102.0 was discovered to contain a broken session control.

    Published: 17 Oct 2022
    5.9
    Medium

    CVE-2022-3206

    Last Modified: 14 May 2025

    The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to decode. This puts the password at risk in case the cookies get leaked.

    Published: 17 Oct 2022
    6.1
    Medium

    CVE-2022-3149

    Last Modified: 14 May 2025

    The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when creating and editing cursors, which could allow attackers to made a logged in admin perform such actions via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping in some of the cursor options, it could also lead to Stored Cross-Site Scripting

    Published: 17 Oct 2022
    2.4
    Low

    CVE-2022-3548

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the component Add New Storage Handler. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-211048.

    Published: 17 Oct 2022
    4.7
    Medium

    CVE-2022-3549

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /csms/admin/?page=user/manage_user of the component Avatar Handler. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-211049 was assigned to this vulnerability.

    Published: 17 Oct 2022
    7.2
    High

    CVE-2022-3552

    Last Modified: 12 May 2025

    Unrestricted Upload of File with Dangerous Type in GitHub repository boxbilling/boxbilling prior to 0.0.1.

    Published: 17 Oct 2022
    3.5
    Low

    CVE-2022-3553

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, was found in X.org Server. This affects an unknown part of the file hw/xquartz/X11Controller.m of the component xquartz. The manipulation leads to denial of service. It is recommended to apply a patch to fix this issue. The identifier VDB-211053 was assigned to this vulnerability.

    Published: 17 Oct 2022
    8.8
    High

    CVE-2022-38743

    Last Modified: 13 May 2025

    Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access control vulnerability. The FactoryTalk VantagePoint SQL Server account could allow a malicious user with read-only privileges to execute SQL statements in the back-end database. If successfully exploited, this could allow the attacker to execute arbitrary code and gain access to restricted data.

    Published: 17 Oct 2022
    6.1
    Medium

    CVE-2022-40606

    Last Modified: 14 May 2025

    MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40605.

    Published: 17 Oct 2022
    7.8
    High

    CVE-2022-41751

    Last Modified: 13 May 2025

    Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.

    Published: 17 Oct 2022
    7.2
    High

    CVE-2022-3243

    Last Modified: 14 May 2025

    The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin

    Published: 17 Oct 2022
    7.5
    High

    CVE-2022-42975

    Last Modified: 10 May 2025

    socket/transport.ex in Phoenix before 1.6.14 mishandles check_origin wildcarding. NOTE: LiveView applications are unaffected by default because of the presence of a LiveView CSRF token.

    Published: 17 Oct 2022
    9.8
    Critical

    CVE-2022-42980

    Last Modified: 10 May 2025

    go-admin (aka GO Admin) 2.0.12 uses the string go-admin as a production JWT key.

    Published: 17 Oct 2022
    8.8
    High

    CVE-2022-42983

    Last Modified: 10 May 2025

    anji-plus AJ-Report 0.9.8.6 allows remote attackers to bypass login authentication by spoofing JWT Tokens.

    Published: 17 Oct 2022
    —
    Unknown

    CVE-2022-42986

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-39122. Reason: This candidate is a reservation duplicate of CVE-2023-39122. Notes: All CVE users should reference CVE-2023-39122 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 17 Oct 2022
    2.7
    Low

    CVE-2022-3279

    Last Modified: 13 May 2025

    An unhandled exception in job log parsing in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to prevent access to job logs

    Published: 17 Oct 2022
    4.3
    Medium

    CVE-2022-3282

    Last Modified: 13 May 2025

    The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.5 does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the file length limit and bypass the limit set by admins in the contact form.

    Published: 17 Oct 2022
    7.2
    High

    CVE-2022-42142

    Last Modified: 14 May 2025

    Online Tours & Travels Management System v1.0 is vulnerable to Arbitrary code execution via ip/tour/admin/operations/update_settings.php.

    Published: 17 Oct 2022
    7.2
    High

    CVE-2022-42143

    Last Modified: 14 May 2025

    Open Source SACCO Management System v1.0 is vulnerable to SQL Injection via /sacco_shield/manage_payment.php.

    Published: 17 Oct 2022
    6.1
    Medium

    CVE-2022-42147

    Last Modified: 14 May 2025

    kkFileView 4.0 is vulnerable to Cross Site Scripting (XSS) via controller\ Filecontroller.java.

    Published: 17 Oct 2022
    9.8
    Critical

    CVE-2022-42149

    Last Modified: 14 May 2025

    kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java.

    Published: 17 Oct 2022
    9.8
    Critical

    CVE-2022-42154

    Last Modified: 14 May 2025

    An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 17 Oct 2022
    9.8
    Critical

    CVE-2022-42163

    Last Modified: 15 May 2025

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/fromNatStaticSetting.

    Published: 17 Oct 2022
    9.8
    Critical

    CVE-2022-42164

    Last Modified: 15 May 2025

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetClientState.

    Published: 17 Oct 2022
    9.8
    Critical

    CVE-2022-42165

    Last Modified: 13 May 2025

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetDeviceName.

    Published: 17 Oct 2022
    9.8
    Critical

    CVE-2022-42166

    Last Modified: 13 May 2025

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetSpeedWan.

    Published: 17 Oct 2022
    9.8
    Critical

    CVE-2022-42167

    Last Modified: 15 May 2025

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetFirewallCfg.

    Published: 17 Oct 2022
    9.8
    Critical

    CVE-2022-42168

    Last Modified: 15 May 2025

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/fromSetIpMacBind.

    Published: 17 Oct 2022
    9.8
    Critical

    CVE-2022-42169

    Last Modified: 15 May 2025

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/addWifiMacFilter.

    Published: 17 Oct 2022
    9.8
    Critical

    CVE-2022-42170

    Last Modified: 15 May 2025

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formWifiWpsStart.

    Published: 17 Oct 2022
    9.8
    Critical

    CVE-2022-42171

    Last Modified: 15 May 2025

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/saveParentControlInfo.

    Published: 17 Oct 2022