CVE Feed

    Dashboard / CVE

    8
    High

    CVE-2022-23771

    Last Modified: 9 May 2025

    This vulnerability occurs in user accounts creation and deleteion related pages of IPTIME NAS products. The vulnerability could be exploited by a lack of validation when a POST request is made to this page. An attacker can use this vulnerability to or delete user accounts, or to escalate arbitrary user privileges.

    Published: 17 Oct 2022
    6.5
    Medium

    CVE-2022-2533

    Last Modified: 13 May 2025

    An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.

    Published: 17 Oct 2022
    9.8
    Critical

    CVE-2022-47629

    Last Modified: 16 Apr 2025

    Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.

    Published: 17 Oct 2022
    4.8
    Medium

    CVE-2022-2563

    Last Modified: 13 May 2025

    The Tutor LMS WordPress plugin before 2.0.10 does not escape some course parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 17 Oct 2022
    8.4
    High

    CVE-2022-25750

    Last Modified: 13 May 2025

    Memory corruption in BTHOST due to double free while music playback and calls over bluetooth headset in Snapdragon Mobile

    Published: 17 Oct 2022
    4.3
    Medium

    CVE-2022-2630

    Last Modified: 13 May 2025

    An improper access control issue in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of confidential information via the Incident timeline events.

    Published: 17 Oct 2022
    9.9
    Critical

    CVE-2022-2884

    Last Modified: 14 May 2025

    A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

    Published: 17 Oct 2022
    4.2
    Medium

    CVE-2022-3244

    Last Modified: 13 May 2025

    The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not have authorisation in some places, which could allow any authenticated users to access some of the plugin features if they manage to get the related nonce

    Published: 17 Oct 2022
    7.5
    High

    CVE-2022-3283

    Last Modified: 13 May 2025

    A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 While cloning an issue with special crafted content added to the description could have been used to trigger high CPU usage.

    Published: 17 Oct 2022
    8.4
    High

    CVE-2022-33214

    Last Modified: 14 May 2025

    Memory corruption in display due to time-of-check time-of-use of metadata reserved size in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 17 Oct 2022
    5.6
    Medium

    CVE-2022-3421

    Last Modified: 21 Apr 2025

    An attacker can pre-create the `/Applications/Google\ Drive.app/Contents/MacOS` directory which is expected to be owned by root to be owned by a non-root user. When the Drive for Desktop installer is run for the first time, it will place a binary in that directory with execute permissions and set its setuid bit. Since the attacker owns the directory, the attacker can replace the binary with a symlink, causing the installer to set the setuid bit on the symlink. When the symlink is executed, it will run with root permissions. We recommend upgrading past version 64.0

    Published: 17 Oct 2022
    9.8
    Critical

    CVE-2022-3515

    Last Modified: 8 Apr 2025

    A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.

    Published: 17 Oct 2022
    3.5
    Low

    CVE-2022-3533

    Last Modified: 15 Apr 2025

    A vulnerability was found in Linux Kernel. It has been rated as problematic. This issue affects the function parse_usdt_arg of the file tools/lib/bpf/usdt.c of the component BPF. The manipulation of the argument reg_name leads to memory leak. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211031.

    Published: 17 Oct 2022
    6.5
    Medium

    CVE-2022-3540

    Last Modified: 13 May 2025

    An issue has been discovered in hunter2 affecting all versions before 2.1.0. Improper handling of auto-completion input allows an authenticated attacker to extract other users email addresses

    Published: 17 Oct 2022
    2.4
    Low

    CVE-2022-3546

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /csms/admin/?page=user/list of the component Create User Handler. The manipulation of the argument First Name/Last Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-211046 is the identifier assigned to this vulnerability.

    Published: 17 Oct 2022
    2.4
    Low

    CVE-2022-3547

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /csms/admin/?page=system_info of the component Setting Handler. The manipulation of the argument System Name/System Short Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-211047.

    Published: 17 Oct 2022
    3.5
    Low

    CVE-2022-3551

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in X.org Server. Affected by this issue is the function ProcXkbGetKbdByName of the file xkb/xkb.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211052.

    Published: 17 Oct 2022
    4.6
    Medium

    CVE-2022-3559

    Last Modified: 3 Nov 2025

    A vulnerability was found in Exim and classified as problematic. This issue affects some unknown processing of the component Regex Handler. The manipulation leads to use after free. The name of the patch is 4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2. It is recommended to apply a patch to fix this issue. The identifier VDB-211073 was assigned to this vulnerability.

    Published: 17 Oct 2022
    6.5
    Medium

    CVE-2022-41471

    Last Modified: 14 May 2025

    74cmsSE v3.12.0 allows authenticated attackers with low-level privileges to arbitrarily change the rights and credentials of the Super Administrator account.

    Published: 17 Oct 2022
    5.4
    Medium

    CVE-2022-41472

    Last Modified: 14 May 2025

    74cmsSE v3.12.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /apiadmin/notice/add. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.

    Published: 17 Oct 2022
    7.3
    High

    CVE-2022-2527

    Last Modified: 13 May 2025

    An issue in Incident Timelines has been discovered in GitLab CE/EE affecting all versions starting from 14.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.which allowed an authenticated attacker to inject arbitrary content. A victim interacting with this content could lead to arbitrary requests.

    Published: 17 Oct 2022
    5.3
    Medium

    CVE-2022-2834

    Last Modified: 13 May 2025

    The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Email Address depending on the plugin's settings

    Published: 17 Oct 2022
    7.5
    High

    CVE-2022-2931

    Last Modified: 13 May 2025

    A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. Malformed content added to the issue description could have been used to trigger high CPU usage.

    Published: 17 Oct 2022
    —
    Unknown

    CVE-2022-3527

    Last Modified: 13 Feb 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 16 Oct 2022
    —
    Unknown

    CVE-2022-3530

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 16 Oct 2022
    9.8
    Critical

    CVE-2022-42968

    Last Modified: 14 May 2025

    Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.

    Published: 16 Oct 2022
    5.3
    Medium

    CVE-2022-42969

    Last Modified: 14 May 2025

    The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data, because the InfoSvnCommand argument is mishandled. Note: This has been disputed by multiple third parties as not being reproduceable and they argue this is not a valid vulnerability.

    Published: 16 Oct 2022
    —
    Unknown

    CVE-2022-3529

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 16 Oct 2022
    —
    Unknown

    CVE-2022-3528

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 16 Oct 2022
    5.3
    Medium

    CVE-2022-42961

    Last Modified: 14 May 2025

    An issue was discovered in wolfSSL before 5.5.0. A fault injection attack on RAM via Rowhammer leads to ECDSA key disclosure. Users performing signing operations with private ECC keys, such as in server-side TLS connections, might leak faulty ECC signatures. These signatures can be processed via an advanced technique for ECDSA key recovery. (In 5.5.0 and later, WOLFSSL_CHECK_SIG_FAULTS can be used to address the vulnerability.)

    Published: 15 Oct 2022
    2.4
    Low

    CVE-2022-3519

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic was found in SourceCodester Sanitization Management System 1.0. Affected by this vulnerability is an unknown functionality of the component Quote Requests Tab. The manipulation of the argument Manage Remarks leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-211015.

    Published: 15 Oct 2022
    2.4
    Low

    CVE-2022-3518

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in SourceCodester Sanitization Management System 1.0. Affected is an unknown function of the component User Creation Handler. The manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting. It is possible to launch the attack remotely. VDB-211014 is the identifier assigned to this vulnerability.

    Published: 15 Oct 2022
    9.8
    Critical

    CVE-2017-20149

    Last Modified: 14 May 2025

    The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthenticated user can trigger the vulnerability by sending a crafted HTTP request. An attacker can use this vulnerability to execute arbitrary code on the affected system, as exploited in the wild in mid-2017 and later.

    Published: 15 Oct 2022
    7.8
    High

    CVE-2022-38448

    Last Modified: 23 Apr 2025

    Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-38444

    Last Modified: 23 Apr 2025

    Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-38446

    Last Modified: 23 Apr 2025

    Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-38443

    Last Modified: 23 Apr 2025

    Adobe Dimension versions 3.4.5 is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-38442

    Last Modified: 23 Apr 2025

    Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-38445

    Last Modified: 23 Apr 2025

    Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-38447

    Last Modified: 23 Apr 2025

    Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-38441

    Last Modified: 23 Apr 2025

    Adobe Dimension versions 3.4.5 is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-38440

    Last Modified: 23 Apr 2025

    Adobe Dimension versions 3.4.5 is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2022
    5.3
    Medium

    CVE-2022-35689

    Last Modified: 23 Apr 2025

    Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.

    Published: 14 Oct 2022
    10
    Critical

    CVE-2022-35698

    Last Modified: 23 Apr 2025

    Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-38437

    Last Modified: 23 Apr 2025

    Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-38449

    Last Modified: 23 Apr 2025

    Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-35691

    Last Modified: 23 Apr 2025

    Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-42339

    Last Modified: 23 Apr 2025

    Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-42342

    Last Modified: 23 Apr 2025

    Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-38450

    Last Modified: 23 Apr 2025

    Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2022