CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2022-42029

    Last Modified: 14 May 2025

    Chamilo 1.11.16 is affected by an authenticated local file inclusion vulnerability which allows authenticated users with access to 'big file uploads' to copy/move files from anywhere in the file system into the web directory.

    Published: 17 Oct 2022
    8.8
    High

    CVE-2022-42221

    Last Modified: 15 May 2025

    Netgear R6220 v1.1.0.114_1.0.1 suffers from Incorrect Access Control, resulting in a command injection vulnerability.

    Published: 17 Oct 2022
    9.8
    Critical

    CVE-2022-42237

    Last Modified: 10 May 2025

    A SQL Injection issue in Merchandise Online Store v.1.0 allows an attacker to log in to the admin account.

    Published: 17 Oct 2022
    7.5
    High

    CVE-2022-23769

    Last Modified: 13 May 2025

    Remote code execution vulnerability due to insufficient user privilege verification in reverseWall-MDS. Remote attackers can exploit the vulnerability such as stealing account, through remote code execution.

    Published: 17 Oct 2022
    8.8
    High

    CVE-2022-23770

    Last Modified: 13 May 2025

    This vulnerability could allow a remote attacker to execute remote commands with improper validation of parameters of certain API constructors. Remote attackers could use this vulnerability to execute malicious commands such as directory traversal.

    Published: 17 Oct 2022
    6.4
    Medium

    CVE-2022-2428

    Last Modified: 13 May 2025

    A crafted tag in the Jupyter Notebook viewer in GitLab EE/CE affecting all versions before 15.1.6, 15.2 to 15.2.4, and 15.3 to 15.3.2 allows an attacker to issue arbitrary HTTP requests

    Published: 17 Oct 2022
    6.5
    Medium

    CVE-2022-2455

    Last Modified: 13 May 2025

    A business logic issue in the handling of large repositories in all versions of GitLab CE/EE from 10.0 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2 allowed an authenticated and authorized user to exhaust server resources by importing a malicious project.

    Published: 17 Oct 2022
    8.4
    High

    CVE-2022-25723

    Last Modified: 13 May 2025

    Memory corruption in multimedia due to use after free during callback registration failure in Snapdragon Mobile

    Published: 17 Oct 2022
    4.8
    Medium

    CVE-2022-2574

    Last Modified: 13 May 2025

    The Meks Easy Social Share WordPress plugin before 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 17 Oct 2022
    6.5
    Medium

    CVE-2022-2592

    Last Modified: 13 May 2025

    A lack of length validation in Snippet descriptions in GitLab CE/EE affecting all versions prior to 15.1.6, 15.2 prior to 15.2.4 and 15.3 prior to 15.3.2 allows an authenticated attacker to create a maliciously large Snippet which when requested with or without authentication places excessive load on the server, potential leading to Denial of Service.

    Published: 17 Oct 2022
    6.5
    Medium

    CVE-2022-28291

    Last Modified: 13 May 2025

    Insufficiently Protected Credentials: An authenticated user with debug privileges can retrieve stored Nessus policy credentials from the “nessusd” process in cleartext via process dumping. The affected products are all versions of Nessus Essentials and Professional. The vulnerability allows an attacker to access credentials stored in Nessus scanners, potentially compromising its customers’ network of assets.

    Published: 17 Oct 2022
    7.3
    High

    CVE-2022-2865

    Last Modified: 14 May 2025

    A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

    Published: 17 Oct 2022
    4.3
    Medium

    CVE-2022-2908

    Last Modified: 13 May 2025

    A potential DoS vulnerability was discovered in Gitlab CE/EE versions starting from 10.7 before 15.1.5, all versions starting from 15.2 before 15.2.3, all versions starting from 15.3 before 15.3.1 allowed an attacker to trigger high CPU usage via a special crafted input added in the Commit message field.

    Published: 17 Oct 2022
    9.9
    Critical

    CVE-2022-2992

    Last Modified: 14 May 2025

    A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.

    Published: 17 Oct 2022
    4.3
    Medium

    CVE-2022-3030

    Last Modified: 13 May 2025

    An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users.

    Published: 17 Oct 2022
    3.7
    Low

    CVE-2022-3031

    Last Modified: 13 May 2025

    An issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It may be possible for an attacker to guess a user's password by brute force by sending crafted requests to a specific endpoint, even if the victim user has 2FA enabled on their account.

    Published: 17 Oct 2022
    5.4
    Medium

    CVE-2022-3066

    Last Modified: 13 May 2025

    An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an unauthorised user to create issues in a project.

    Published: 17 Oct 2022
    6.5
    Medium

    CVE-2022-3067

    Last Modified: 13 May 2025

    An issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an authenticated user to read arbitrary projects' content given the project's ID.

    Published: 17 Oct 2022
    6.5
    Medium

    CVE-2022-3082

    Last Modified: 13 May 2025

    The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logged in users, such as subscriber to call them, and disable the app for example

    Published: 17 Oct 2022
    4.3
    Medium

    CVE-2022-3126

    Last Modified: 14 May 2025

    The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could allow attackers to make logged in users upload files on their behalf

    Published: 17 Oct 2022
    7.2
    High

    CVE-2022-3131

    Last Modified: 14 May 2025

    The Search Logger WordPress plugin through 0.9 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users

    Published: 17 Oct 2022
    5.3
    Medium

    CVE-2022-3286

    Last Modified: 13 May 2025

    Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token

    Published: 17 Oct 2022
    3.5
    Low

    CVE-2022-3288

    Last Modified: 13 May 2025

    A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.

    Published: 17 Oct 2022
    6.5
    Medium

    CVE-2022-3291

    Last Modified: 13 May 2025

    Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 can leak sensitive information via cache

    Published: 17 Oct 2022
    3.5
    Low

    CVE-2022-3293

    Last Modified: 13 May 2025

    Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1

    Published: 17 Oct 2022
    8.4
    High

    CVE-2022-33210

    Last Modified: 14 May 2025

    Memory corruption in automotive multimedia due to use of out-of-range pointer offset while parsing command request packet with a very large type value. in Snapdragon Auto

    Published: 17 Oct 2022
    7.8
    High

    CVE-2022-33217

    Last Modified: 14 May 2025

    Memory corruption in Qualcomm IPC due to buffer copy without checking the size of input while starting communication with a compromised kernel. in Snapdragon Mobile

    Published: 17 Oct 2022
    2.7
    Low

    CVE-2022-3325

    Last Modified: 13 May 2025

    Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing the approval rules via the API by an unauthorised user.

    Published: 17 Oct 2022
    4.3
    Medium

    CVE-2022-3330

    Last Modified: 14 May 2025

    It was possible for a guest user to read a todo targeting an inaccessible note in Gitlab CE/EE affecting all versions from 15.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1.

    Published: 17 Oct 2022
    3.5
    Low

    CVE-2022-3331

    Last Modified: 14 May 2025

    An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab's Zentao integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Zentao project issues.

    Published: 17 Oct 2022
    4.3
    Medium

    CVE-2022-3351

    Last Modified: 14 May 2025

    An issue has been discovered in GitLab EE affecting all versions starting from 13.7 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A user's primary email may be disclosed to an attacker through group member events webhooks.

    Published: 17 Oct 2022
    —
    Unknown

    CVE-2022-3531

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 17 Oct 2022
    —
    Unknown

    CVE-2022-3532

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 17 Oct 2022
    —
    Unknown

    CVE-2022-3535

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 17 Oct 2022
    5.5
    Medium

    CVE-2022-3550

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211051.

    Published: 17 Oct 2022
    5.3
    Medium

    CVE-2022-3554

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 17 Oct 2022
    3.1
    Low

    CVE-2022-3555

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 17 Oct 2022
    9.8
    Critical

    CVE-2022-40055

    Last Modified: 14 May 2025

    An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page.

    Published: 17 Oct 2022
    6.1
    Medium

    CVE-2022-40605

    Last Modified: 14 May 2025

    MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40606.

    Published: 17 Oct 2022
    5.4
    Medium

    CVE-2022-41139

    Last Modified: 14 May 2025

    MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary commands on agents.

    Published: 17 Oct 2022
    5.4
    Medium

    CVE-2022-41431

    Last Modified: 14 May 2025

    xzs v3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /admin/question/edit. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title text field.

    Published: 17 Oct 2022
    7.2
    High

    CVE-2022-41498

    Last Modified: 13 May 2025

    Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editbrand.php.

    Published: 17 Oct 2022
    —
    Unknown

    CVE-2020-35539

    Last Modified: 13 Feb 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 17 Oct 2022
    7.3
    High

    CVE-2022-3060

    Last Modified: 13 May 2025

    Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to generate content which could cause a victim to make unintended arbitrary requests

    Published: 17 Oct 2022
    4.8
    Medium

    CVE-2022-3139

    Last Modified: 14 May 2025

    The We’re Open! WordPress plugin before 1.42 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 17 Oct 2022
    7.2
    High

    CVE-2022-3150

    Last Modified: 14 May 2025

    The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privileged users such as admin

    Published: 17 Oct 2022
    4.3
    Medium

    CVE-2022-3151

    Last Modified: 14 May 2025

    The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when deleting cursors, which could allow attackers to made a logged in admin delete arbitrary cursors via a CSRF attack.

    Published: 17 Oct 2022
    9.8
    Critical

    CVE-2022-22128

    Last Modified: 13 May 2025

    Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow remote code execution.Tableau only supports product versions for 24 months after release. Older versions have reached their End of Life and are no longer supported. They are also not assessed for potential security issues and do not receive security updates.

    Published: 17 Oct 2022
    8.8
    High

    CVE-2022-3158

    Last Modified: 14 May 2025

    Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation vulnerability. The FactoryTalk VantagePoint SQL Server lacks input validation when users enter SQL statements to retrieve information from the back-end database. If successfully exploited, this could allow a user with basic user privileges to perform remote code execution on the server.

    Published: 17 Oct 2022
    9.8
    Critical

    CVE-2022-0699

    Last Modified: 24 Jan 2026

    A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attacker to cause a denial of service or have other unspecified impact via control over malloc.

    Published: 17 Oct 2022