CVE Feed

    Dashboard / CVE

    7.6
    High

    CVE-2022-39013

    Last Modified: 21 Nov 2024

    Under certain conditions an authenticated attacker can get access to OS credentials. Getting access to OS credentials enables the attacker to modify system data and make the system unavailable leading to high impact on confidentiality and low impact on integrity and availability of the application.

    Published: 11 Oct 2022
    8.6
    High

    CVE-2022-39296

    Last Modified: 23 Apr 2025

    MelisAssetManager provides deliveries of Melis Platform's assets located in every module's public folder. Attackers can read arbitrary files on affected versions of `melisplatform/melis-asset-manager`, leading to the disclosure of sensitive information. Conducting this attack does not require authentication. Users should immediately upgrade to `melisplatform/melis-asset-manager` >= 5.0.1. This issue was addressed by restricting access to files to intended directories only.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-39805

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated Computer Graphics Metafile (.cgm, CgmTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    7.5
    High

    CVE-2022-39802

    Last Modified: 21 Nov 2024

    SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The intended file path can be manipulated to allow arbitrary traversal of directories on the remote server. The file content within each directory can be read which may lead to information disclosure.

    Published: 11 Oct 2022
    5.4
    Medium

    CVE-2022-40047

    Last Modified: 21 Nov 2024

    Flatpress v1.2.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the page parameter at /flatpress/admin.php.

    Published: 11 Oct 2022
    7.4
    High

    CVE-2022-40147

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Industrial Edge Management (All versions < V1.5.1). The affected software does not properly validate the server certificate when initiating a TLS connection. This could allow an attacker to spoof a trusted entity by interfering in the communication path between the client and the intended server.

    Published: 11 Oct 2022
    7.5
    High

    CVE-2022-34425

    Last Modified: 21 Nov 2024

    Dell Enterprise SONiC OS, 4.0.0, 4.0.1, contain a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to communication.

    Published: 10 Oct 2022
    6.8
    Medium

    CVE-2022-34402

    Last Modified: 21 Nov 2024

    Dell Wyse ThinOS 2205 contains a Regular Expression Denial of Service Vulnerability in UI. An admin privilege attacker could potentially exploit this vulnerability, leading to denial-of-service.

    Published: 10 Oct 2022
    6.5
    Medium

    CVE-2022-34334

    Last Modified: 21 Nov 2024

    IBM Sterling Partner Engagement Manager 2.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 229704.

    Published: 10 Oct 2022
    4.6
    Medium

    CVE-2022-20864

    Last Modified: 21 Nov 2024

    A vulnerability in the password-recovery disable feature of Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco Catalyst Switches could allow an unauthenticated, local attacker to recover the configuration or reset the enable password. This vulnerability is due to a problem with the file and boot variable permissions in ROMMON. An attacker could exploit this vulnerability by rebooting the switch into ROMMON and entering specific commands through the console. A successful exploit could allow the attacker to read any file or reset the enable password.

    Published: 10 Oct 2022
    8.6
    High

    CVE-2022-20837

    Last Modified: 21 Nov 2024

    A vulnerability in the DNS application layer gateway (ALG) functionality that is used by Network Address Translation (NAT) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability is due to a logic error that occurs when an affected device inspects certain TCP DNS packets. An attacker could exploit this vulnerability by sending crafted DNS packets through the affected device that is performing NAT for DNS packets. A successful exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition on the affected device. Note: This vulnerability can be exploited only by sending IPv4 TCP packets through an affected device. This vulnerability cannot be exploited by sending IPv6 traffic.

    Published: 10 Oct 2022
    7.7
    High

    CVE-2022-20920

    Last Modified: 1 Aug 2025

    A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to improper handling of resources during an exceptional situation. An attacker could exploit this vulnerability by continuously connecting to an affected device and sending specific SSH requests. A successful exploit could allow the attacker to cause the affected device to reload.

    Published: 10 Oct 2022
    7.4
    High

    CVE-2022-20915

    Last Modified: 21 Nov 2024

    A vulnerability in the implementation of IPv6 VPN over MPLS (6VPE) with Zone-Based Firewall (ZBFW) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling of an IPv6 packet that is forwarded from an MPLS and ZBFW-enabled interface in a 6VPE deployment. An attacker could exploit this vulnerability by sending a crafted IPv6 packet sourced from a device on the IPv6-enabled virtual routing and forwarding (VRF) interface through the affected device. A successful exploit could allow the attacker to reload the device, resulting in a DoS condition.

    Published: 10 Oct 2022
    8.6
    High

    CVE-2022-20870

    Last Modified: 21 Nov 2024

    A vulnerability in the egress MPLS packet processing function of Cisco IOS XE Software for Cisco Catalyst 3650, Catalyst 3850, and Catalyst 9000 Family Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient input validation of IPv4 traffic. An attacker could exploit this vulnerability by sending a malformed packet out of an affected MPLS-enabled interface. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

    Published: 10 Oct 2022
    6.1
    Medium

    CVE-2022-20944

    Last Modified: 21 Nov 2024

    A vulnerability in the software image verification functionality of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches could allow an unauthenticated, physical attacker to execute unsigned code at system boot time. This vulnerability is due to an improper check in the code function that manages the verification of the digital signatures of system image files during the initial boot process. An attacker could exploit this vulnerability by loading unsigned software on an affected device. A successful exploit could allow the attacker to boot a malicious software image or execute unsigned code and bypass the image verification check part of the boot process of the affected device. To exploit this vulnerability, the attacker needs either unauthenticated physical access to the device or privileged access to the root shell on the device. Note: In Cisco IOS XE Software releases 16.11.1 and later, root shell access is protected by the Consent Token mechanism. However, an attacker with level-15 privileges could easily downgrade the Cisco IOS XE Software running on a device to a release where root shell access is more readily available.

    Published: 10 Oct 2022
    5.3
    Medium

    CVE-2022-20830

    Last Modified: 21 Nov 2024

    A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unauthenticated, remote attacker to access the GUI of Cisco SD-AVC without authentication. This vulnerability exists because the GUI is accessible on self-managed cloud installations or local server installations of Cisco vManage. An attacker could exploit this vulnerability by accessing the exposed GUI of Cisco SD-AVC. A successful exploit could allow the attacker to view managed device names, SD-AVC logs, and SD-AVC DNS server IP addresses.

    Published: 10 Oct 2022
    6.5
    Medium

    CVE-2022-3433

    Last Modified: 21 Nov 2024

    The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a denial of service.

    Published: 10 Oct 2022
    8.8
    High

    CVE-2022-38065

    Last Modified: 15 Apr 2025

    A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileges.

    Published: 10 Oct 2022
    9.1
    Critical

    CVE-2022-41746

    Last Modified: 21 Nov 2024

    A forced browsing vulnerability in Trend Micro Apex One could allow an attacker with access to the Apex One console on affected installations to escalate privileges and modify certain agent groupings. Please note: an attacker must first obtain the ability to log onto the Apex One web console in order to exploit this vulnerability.

    Published: 10 Oct 2022
    5.4
    Medium

    CVE-2022-3137

    Last Modified: 21 Nov 2024

    The Taskbuilder WordPress plugin before 1.0.8 does not validate and sanitise task's attachments, which could allow any authenticated user (such as subscriber) creating a task to perform Stored Cross-Site Scripting by attaching a malicious SVG file

    Published: 10 Oct 2022
    6.1
    Medium

    CVE-2021-25044

    Last Modified: 21 Nov 2024

    The Cryptocurrency Pricing list and Ticker WordPress plugin through 1.5 does not sanitise and escape the ccpw_setpage parameter before outputting it back in pages where its shortcode is embed, leading to a Reflected Cross-Site Scripting issue

    Published: 10 Oct 2022
    7.1
    High

    CVE-2022-48502

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 6.2. The ntfs3 subsystem does not properly check for correctness during disk reads, leading to an out-of-bounds read in ntfs_set_ea in fs/ntfs3/xattr.c.

    Published: 10 Oct 2022
    6.5
    Medium

    CVE-2021-35226

    Last Modified: 24 Feb 2026

    An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Information Service (SWIS). Exposed credentials are encrypted and require authenticated access with an NCM role.

    Published: 10 Oct 2022
    4.9
    Medium

    CVE-2022-2554

    Last Modified: 21 Nov 2024

    The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved to the Upload folder, which could allow high privilege users such as admin to move them outside to the web root directory via a path traversal attack for example

    Published: 10 Oct 2022
    5.9
    Medium

    CVE-2022-2891

    Last Modified: 21 Nov 2024

    The WP 2FA WordPress plugin before 2.3.0 uses comparison operators that don't mitigate time-based attacks, which could be abused to leak information about the authentication codes being compared.

    Published: 10 Oct 2022
    7.5
    High

    CVE-2022-29055

    Last Modified: 21 Nov 2024

    A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version 7.0.0 through 7.0.4, 2.0.0 through 2.0.9, 1.2.x allows a remote unauthenticated or authenticated attacker to crash the sslvpn daemon via an HTTP GET request.

    Published: 10 Oct 2022
    4.9
    Medium

    CVE-2022-2981

    Last Modified: 21 Nov 2024

    The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.

    Published: 10 Oct 2022
    4.3
    Medium

    CVE-2022-42724

    Last Modified: 21 Nov 2024

    app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have).

    Published: 10 Oct 2022
    7.5
    High

    CVE-2022-42725

    Last Modified: 21 Nov 2024

    Warpinator through 1.2.14 allows access outside of an intended directory, as demonstrated by symbolic directory links.

    Published: 10 Oct 2022
    4.8
    Medium

    CVE-2022-3207

    Last Modified: 21 Nov 2024

    The Simple File List WordPress plugin before 4.4.12 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 10 Oct 2022
    6.1
    Medium

    CVE-2022-3209

    Last Modified: 21 Nov 2024

    The soledad WordPress theme before 8.2.5 does not sanitise the {id,datafilter[type],...} parameters in its penci_more_slist_post_ajax AJAX action, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

    Published: 10 Oct 2022
    4.8
    Medium

    CVE-2022-3220

    Last Modified: 21 Nov 2024

    The Advanced Comment Form WordPress plugin before 1.2.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 10 Oct 2022
    —
    Unknown

    CVE-2022-42737

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Oct 2022
    —
    Unknown

    CVE-2022-42738

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Oct 2022
    —
    Unknown

    CVE-2022-42739

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Oct 2022
    9.8
    Critical

    CVE-2022-33872

    Last Modified: 21 Nov 2024

    An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute arbitrary command in the underlying shell.

    Published: 10 Oct 2022
    6.8
    Medium

    CVE-2022-33873

    Last Modified: 21 Nov 2024

    An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Console login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to execute arbitrary command in the underlying shell.

    Published: 10 Oct 2022
    6.1
    Medium

    CVE-2022-3438

    Last Modified: 21 Nov 2024

    Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.

    Published: 10 Oct 2022
    —
    Unknown

    CVE-2022-42740

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Oct 2022
    —
    Unknown

    CVE-2022-42741

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Oct 2022
    —
    Unknown

    CVE-2022-42742

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Oct 2022
    6.7
    Medium

    CVE-2022-35844

    Last Modified: 21 Nov 2024

    An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to commands of the certificate import feature.

    Published: 10 Oct 2022
    8.1
    High

    CVE-2022-35846

    Last Modified: 21 Nov 2024

    An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiTester Telnet port 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to guess the credentials of an admin user via a brute force attack.

    Published: 10 Oct 2022
    7.5
    High

    CVE-2022-39288

    Last Modified: 23 Apr 2025

    fastify is a fast and low overhead web framework, for Node.js. Affected versions of fastify are subject to a denial of service via malicious use of the Content-Type header. An attacker can send an invalid Content-Type header that can cause the application to crash. This issue has been addressed in commit `fbb07e8d` and will be included in release version 4.8.1. Users are advised to upgrade. Users unable to upgrade may manually filter out http content with malicious Content-Type headers.

    Published: 10 Oct 2022
    7.5
    High

    CVE-2022-39292

    Last Modified: 23 Apr 2025

    Slack Morphism is a modern client library for Slack Web/Events API/Socket Mode and Block Kit. Debug logs expose sensitive URLs for Slack webhooks that contain private information. The problem is fixed in version 1.3.2 which redacts sensitive URLs for webhooks. As a workaround, people who use Slack webhooks may disable or filter debug logs.

    Published: 10 Oct 2022
    5.4
    Medium

    CVE-2022-40257

    Last Modified: 21 Nov 2024

    An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via a crafted email with HTML content in the Subject field.

    Published: 10 Oct 2022
    7
    High

    CVE-2022-41744

    Last Modified: 21 Nov 2024

    A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One Vulnerability Protection integrated component could allow a local attacker to escalate privileges and turn a specific working directory into a mount point on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 10 Oct 2022
    7
    High

    CVE-2022-41745

    Last Modified: 21 Nov 2024

    An Out-of-Bounds access vulnerability in Trend Micro Apex One could allow a local attacker to create a specially crafted message to cause memory corruption on a certain service process which could lead to local privilege escalation on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 10 Oct 2022
    6.7
    Medium

    CVE-2022-41748

    Last Modified: 21 Nov 2024

    A registry permissions vulnerability in the Trend Micro Apex One Data Loss Prevention (DLP) module could allow a local attacker with administrative credentials to bypass certain elements of the product's anti-tampering mechanisms on affected installations. Please note: an attacker must first obtain administrative credentials on the target system in order to exploit this vulnerability.

    Published: 10 Oct 2022
    7.8
    High

    CVE-2022-41749

    Last Modified: 21 Nov 2024

    An origin validation error vulnerability in Trend Micro Apex One agents could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 10 Oct 2022