CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2022-37208

    Last Modified: 15 May 2025

    JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

    Published: 13 Oct 2022
    5.4
    Medium

    CVE-2022-38902

    Last Modified: 15 May 2025

    A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic.

    Published: 13 Oct 2022
    6.8
    Medium

    CVE-2022-39201

    Last Modified: 23 Apr 2025

    Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Grafana could leak the authentication cookie of users to plugins. The vulnerability impacts data source and plugin proxy endpoints under certain conditions. The destination plugin could receive a user's Grafana authentication cookie. Versions 9.1.8 and 8.5.14 contain a patch for this issue. There are no known workarounds.

    Published: 13 Oct 2022
    7.7
    High

    CVE-2022-39300

    Last Modified: 23 Apr 2025

    node SAML is a SAML 2.0 library based on the SAML implementation of passport-saml. A remote attacker may be able to bypass SAML authentication on a website using passport-saml. A successful attack requires that the attacker is in possession of an arbitrary IDP signed XML element. Depending on the IDP used, fully unauthenticated attacks (e.g without access to a valid user) might also be feasible if generation of a signed message can be triggered. Users should upgrade to node-saml version 4.0.0-beta5 or newer. Disabling SAML authentication may be done as a workaround.

    Published: 13 Oct 2022
    5.5
    Medium

    CVE-2022-39302

    Last Modified: 23 Apr 2025

    Ree6 is a moderation bot. This vulnerability would allow other server owners to create configurations such as "Better-Audit-Logging" which contain a channel from another server as a target. This would mean you could send log messages to another Guild channel and bypass raid and webhook protections. A specifically crafted log message could allow spamming and mass advertisements. This issue has been patched in version 1.9.9. There are currently no known workarounds.

    Published: 13 Oct 2022
    8
    High

    CVE-2022-40187

    Last Modified: 15 May 2025

    Foresight GC3 Launch Monitor 1.3.15.68 ships with a Target Communication Framework (TCF) service enabled. This service listens on a TCP port on all interfaces and allows for process debugging, file system modification, and terminal access as the root user. In conjunction with a hosted wireless access point and the known passphrase of FSSPORTS, an attacker could use this service to modify a device and steal intellectual property.

    Published: 13 Oct 2022
    9.8
    Critical

    CVE-2022-41390

    Last Modified: 15 May 2025

    OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at download.php.

    Published: 13 Oct 2022
    6.1
    Medium

    CVE-2022-41473

    Last Modified: 15 May 2025

    RPCMS v3.0.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Search function.

    Published: 13 Oct 2022
    6.5
    Medium

    CVE-2022-41474

    Last Modified: 15 May 2025

    RPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily change the password of any account.

    Published: 13 Oct 2022
    8.8
    High

    CVE-2022-41475

    Last Modified: 15 May 2025

    RPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add an administrator account.

    Published: 13 Oct 2022
    7.5
    High

    CVE-2022-41481

    Last Modified: 15 May 2025

    Tenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x47de1c function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 13 Oct 2022
    7.5
    High

    CVE-2022-41482

    Last Modified: 15 May 2025

    Tenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x47c5dc function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 13 Oct 2022
    7.5
    High

    CVE-2022-41483

    Last Modified: 15 May 2025

    Tenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x4a12cc function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 13 Oct 2022
    7.5
    High

    CVE-2022-41484

    Last Modified: 15 May 2025

    Tenda AC1900 AP500(US)_V1_180320(Beta) was discovered to contain a buffer overflow in the 0x32384 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 13 Oct 2022
    7.5
    High

    CVE-2022-41485

    Last Modified: 15 May 2025

    Tenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x47ce00 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 13 Oct 2022
    9.8
    Critical

    CVE-2022-41496

    Last Modified: 15 May 2025

    iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php.

    Published: 13 Oct 2022
    9.8
    Critical

    CVE-2022-41497

    Last Modified: 15 May 2025

    ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/index.php.

    Published: 13 Oct 2022
    7.2
    High

    CVE-2022-41533

    Last Modified: 15 May 2025

    Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 13 Oct 2022
    7.2
    High

    CVE-2022-41534

    Last Modified: 15 May 2025

    Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/createOrder.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 13 Oct 2022
    8.3
    High

    CVE-2022-1471

    Last Modified: 18 Jun 2025

    SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.

    Published: 13 Oct 2022
    8.6
    High

    CVE-2022-39293

    Last Modified: 27 Oct 2025

    Azure RTOS USBX is a high-performance USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. The case is, in [_ux_host_class_pima_read](https://github.com/azure-rtos/usbx/blob/master/common/usbx_host_classes/src/ux_host_class_pima_read.c), there is data length from device response, returned in the very first packet, and read by [L165 code](https://github.com/azure-rtos/usbx/blob/082fd9db09a3669eca3358f10b8837a5c1635c0b/common/usbx_host_classes/src/ux_host_class_pima_read.c#L165), as header_length. Then in [L178 code](https://github.com/azure-rtos/usbx/blob/082fd9db09a3669eca3358f10b8837a5c1635c0b/common/usbx_host_classes/src/ux_host_class_pima_read.c#L178), there is a “if” branch, which check the expression of “(header_length - UX_HOST_CLASS_PIMA_DATA_HEADER_SIZE) > data_length” where if header_length is smaller than UX_HOST_CLASS_PIMA_DATA_HEADER_SIZE, calculation could overflow and then [L182 code](https://github.com/azure-rtos/usbx/blob/082fd9db09a3669eca3358f10b8837a5c1635c0b/common/usbx_host_classes/src/ux_host_class_pima_read.c#L182) the calculation of data_length is also overflow, this way the later [while loop start from L192](https://github.com/azure-rtos/usbx/blob/082fd9db09a3669eca3358f10b8837a5c1635c0b/common/usbx_host_classes/src/ux_host_class_pima_read.c#L192) can move data_pointer to unexpected address and cause write buffer overflow. The fix has been included in USBX release [6.1.12](https://github.com/azure-rtos/usbx/releases/tag/v6.1.12_rel). The following can be used as a workaround: Add check of `header_length`: 1. It must be greater than `UX_HOST_CLASS_PIMA_DATA_HEADER_SIZE`. 1. It should be greater or equal to the current returned data length (`transfer_request -> ux_transfer_request_actual_length`).

    Published: 13 Oct 2022
    7.8
    High

    CVE-2022-47695

    Last Modified: 21 Nov 2024

    An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function bfd_mach_o_get_synthetic_symtab in match-o.c.

    Published: 13 Oct 2022
    4.9
    Medium

    CVE-2022-31130

    Last Modified: 23 Apr 2025

    Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. The vulnerability impacts data source and plugin proxy endpoints with authentication tokens. The destination plugin could receive a user's Grafana authentication token. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not use API keys, JWT authentication, or any HTTP Header based authentication.

    Published: 13 Oct 2022
    6.3
    Medium

    CVE-2022-3492

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in SourceCodester Human Resource Management System 1.0. This vulnerability affects unknown code of the component Profile Photo Handler. The manipulation of the argument parameter leads to os command injection. The attack can be initiated remotely. The identifier of this vulnerability is VDB-210772.

    Published: 13 Oct 2022
    3.5
    Low

    CVE-2022-3493

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the component Add Employee Handler. The manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-210773 was assigned to this vulnerability.

    Published: 13 Oct 2022
    6.2
    Medium

    CVE-2022-35944

    Last Modified: 23 Apr 2025

    October is a self-hosted Content Management System (CMS) platform based on the Laravel PHP Framework. This vulnerability only affects installations that rely on the safe mode restriction, commonly used when providing public access to the admin panel. Assuming an attacker has access to the admin panel and permission to open the "Editor" section, they can bypass the Safe Mode (`cms.safe_mode`) restriction to introduce new PHP code in a CMS template using a specially crafted request. The issue has been patched in versions 2.2.34 and 3.0.66.

    Published: 13 Oct 2022
    4.3
    Medium

    CVE-2022-39229

    Last Modified: 23 Apr 2025

    Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user's login attempt by registering someone else'e email address as a username. A Grafana user’s username and email address are unique fields, that means no other user can have the same username or email address as another user. A user can have an email address as a username. However, the login system allows users to log in with either username or email address. Since Grafana allows a user to log in with either their username or email address, this creates an usual behavior where `user_1` can register with one email address and `user_2` can register their username as `user_1`’s email address. This prevents `user_1` logging into the application since `user_1`'s password won’t match with `user_2`'s email address. Versions 9.1.8 and 8.5.14 contain a patch. There are no workarounds for this issue.

    Published: 13 Oct 2022
    9.8
    Critical

    CVE-2022-41391

    Last Modified: 15 May 2025

    OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php.

    Published: 13 Oct 2022
    7.5
    High

    CVE-2022-41480

    Last Modified: 15 May 2025

    Tenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x475dc function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 13 Oct 2022
    9.8
    Critical

    CVE-2022-41495

    Last Modified: 15 May 2025

    ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manager/index.php.

    Published: 13 Oct 2022
    9.8
    Critical

    CVE-2022-42889

    Last Modified: 21 Nov 2024

    Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.

    Published: 13 Oct 2022
    8.8
    High

    CVE-2022-42902

    Last Modified: 15 May 2025

    In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitization, an anonymous user can force the lava-server-gunicorn service to execute user-provided code on the server.

    Published: 13 Oct 2022
    7.8
    High

    CVE-2022-42906

    Last Modified: 15 May 2025

    powerline-gitstatus (aka Powerline Gitstatus) before 1.3.2 allows arbitrary code execution. git repositories can contain per-repository configuration that changes the behavior of git, including running arbitrary commands. When using powerline-gitstatus, changing to a directory automatically runs git commands in order to display information about the current repository in the prompt. If an attacker can convince a user to change their current directory to one controlled by the attacker, such as in a shared filesystem or extracted archive, powerline-gitstatus will run arbitrary commands under the attacker's control. NOTE: this is similar to CVE-2022-20001.

    Published: 13 Oct 2022
    7.5
    High

    CVE-2022-34391

    Last Modified: 16 May 2025

    Dell Client BIOS Versions prior to the remediated version contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

    Published: 12 Oct 2022
    7.5
    High

    CVE-2022-34390

    Last Modified: 12 May 2025

    Dell BIOS contains a use of uninitialized variable vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

    Published: 12 Oct 2022
    7.1
    High

    CVE-2022-33937

    Last Modified: 16 May 2025

    Dell GeoDrive, Versions 1.0 - 2.2, contain a Path Traversal Vulnerability in the reporting function. A local, low privileged attacker could potentially exploit this vulnerability, to gain unauthorized delete access to the files stored on the server filesystem, with the privileges of the GeoDrive service: NT AUTHORITY\SYSTEM.

    Published: 12 Oct 2022
    7
    High

    CVE-2022-33922

    Last Modified: 15 May 2025

    Dell GeoDrive, versions prior to 2.2, contains Insecure File and Folder Permissions vulnerabilities. A low privilege attacker could potentially exploit this vulnerability, leading to the execution of arbitrary code in the SYSTEM security context. Dell recommends customers to upgrade at the earliest opportunity.

    Published: 12 Oct 2022
    7
    High

    CVE-2022-33921

    Last Modified: 15 May 2025

    Dell GeoDrive, versions prior to 2.2, contains Multiple DLL Hijacking Vulnerabilities. A low privilege attacker could potentially exploit this vulnerability, leading to the execution of arbitrary code in the SYSTEM security context.

    Published: 12 Oct 2022
    7.8
    High

    CVE-2022-33920

    Last Modified: 15 May 2025

    Dell GeoDrive, versions prior to 2.2, contains an Unquoted File Path vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to the execution of arbitrary code in the SYSTEM security context.

    Published: 12 Oct 2022
    7.8
    High

    CVE-2022-33919

    Last Modified: 15 May 2025

    Dell GeoDrive, versions 2.1 - 2.2, contains an information disclosure vulnerability in GUI. An authenticated non-admin user could potentially exploit this vulnerability and view sensitive information.

    Published: 12 Oct 2022
    5.5
    Medium

    CVE-2022-33918

    Last Modified: 15 May 2025

    Dell GeoDrive, Versions 2.1 - 2.2, contains an information disclosure vulnerability. An authenticated non-admin user could potentially exploit this vulnerability and gain access to sensitive information.

    Published: 12 Oct 2022
    6
    Medium

    CVE-2022-32493

    Last Modified: 15 May 2025

    Dell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

    Published: 12 Oct 2022
    4.1
    Medium

    CVE-2022-32491

    Last Modified: 15 May 2025

    Dell Client BIOS contains a Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by manipulating an SMI to cause an arbitrary write during SMM.

    Published: 12 Oct 2022
    8.2
    High

    CVE-2022-32489

    Last Modified: 15 May 2025

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

    Published: 12 Oct 2022
    8.2
    High

    CVE-2022-32488

    Last Modified: 15 May 2025

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

    Published: 12 Oct 2022
    7.5
    High

    CVE-2022-32487

    Last Modified: 15 May 2025

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

    Published: 12 Oct 2022
    7.5
    High

    CVE-2022-32485

    Last Modified: 16 May 2025

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

    Published: 12 Oct 2022
    5.6
    Medium

    CVE-2022-32484

    Last Modified: 16 May 2025

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

    Published: 12 Oct 2022
    5.6
    Medium

    CVE-2022-32483

    Last Modified: 16 May 2025

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

    Published: 12 Oct 2022
    8.1
    High

    CVE-2022-31228

    Last Modified: 15 May 2025

    Dell EMC XtremIO versions prior to X2 6.4.0-22 contain a bruteforce vulnerability. A remote unauthenticated attacker can potentially exploit this vulnerability and gain access to an admin account.

    Published: 12 Oct 2022