CVE Feed

    Dashboard / CVE

    9
    Critical

    CVE-2021-44171

    Last Modified: 21 Nov 2024

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiOS version 6.0.0 through 6.0.14, FortiOS version 6.2.0 through 6.2.10, FortiOS version 6.4.0 through 6.4.8, FortiOS version 7.0.0 through 7.0.3 allows attacker to execute privileged commands on a linked FortiSwitch via diagnostic CLI commands.

    Published: 10 Oct 2022
    7.6
    High

    CVE-2022-36063

    Last Modified: 27 Oct 2025

    Azure RTOS USBx is a USB host, device, and on-the-go (OTG) embedded stack, fully integrated with Azure RTOS ThreadX and available for all Azure RTOS ThreadX–supported processors. Azure RTOS USBX implementation of host support for USB CDC ECM includes an integer underflow and a buffer overflow in the `_ux_host_class_cdc_ecm_mac_address_get` function which may be potentially exploited to achieve remote code execution or denial of service. Setting mac address string descriptor length to a `0` or `1` allows an attacker to introduce an integer underflow followed (string_length) by a buffer overflow of the `cdc_ecm -> ux_host_class_cdc_ecm_node_id` array. This may allow one to redirect the code execution flow or introduce a denial of service. The fix has been included in USBX release [6.1.12](https://github.com/azure-rtos/usbx/releases/tag/v6.1.12_rel). Improved mac address string descriptor length validation to check for unexpectedly small values may be used as a workaround.

    Published: 10 Oct 2022
    4.8
    Medium

    CVE-2022-3136

    Last Modified: 21 Nov 2024

    The Social Rocket WordPress plugin before 1.3.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 10 Oct 2022
    7.1
    High

    CVE-2022-3154

    Last Modified: 21 Nov 2024

    The Woo Billingo Plus WordPress plugin before 4.4.5.4, Integration for Billingo & Gravity Forms WordPress plugin before 1.0.4, Integration for Szamlazz.hu & Gravity Forms WordPress plugin before 1.2.7 are lacking CSRF checks in various AJAX actions, which could allow attackers to make logged in Shop Managers and above perform unwanted actions, such as deactivate the plugin's license

    Published: 10 Oct 2022
    4.8
    Medium

    CVE-2022-2448

    Last Modified: 21 Nov 2024

    The reSmush.it WordPress plugin before 0.4.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when unfiltered_html is disallowed.

    Published: 10 Oct 2022
    3.7
    Low

    CVE-2022-26121

    Last Modified: 21 Nov 2024

    An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path.

    Published: 10 Oct 2022
    4.8
    Medium

    CVE-2022-2823

    Last Modified: 21 Nov 2024

    The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.27.9 does not sanitise and escape some of its Gallery Image parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 10 Oct 2022
    9.8
    Critical

    CVE-2022-33874

    Last Modified: 21 Nov 2024

    An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in SSH login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute arbitrary command in the underlying shell.

    Published: 10 Oct 2022
    3.5
    Low

    CVE-2022-3442

    Last Modified: 15 Apr 2025

    A vulnerability was found in Crealogix EBICS 7.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /ebics-server/ebics.aspx. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.1 is able to address this issue. It is recommended to upgrade the affected component. VDB-210374 is the identifier assigned to this vulnerability.

    Published: 10 Oct 2022
    5.4
    Medium

    CVE-2022-40248

    Last Modified: 21 Nov 2024

    An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via form using the "Product Affected" field.

    Published: 10 Oct 2022
    7.8
    High

    CVE-2022-41747

    Last Modified: 21 Nov 2024

    An improper certification validation vulnerability in Trend Micro Apex One agents could allow a local attacker to load a DLL file with system service privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 10 Oct 2022
    6.5
    Medium

    CVE-2022-3208

    Last Modified: 21 Nov 2024

    The Simple File List WordPress plugin before 4.4.12 does not implement nonce checks, which could allow attackers to make a logged in admin create new page and change it's content via a CSRF attack.

    Published: 10 Oct 2022
    5.3
    Medium

    CVE-2022-2350

    Last Modified: 21 Nov 2024

    The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its settings, allowing unauthenticated attackers to block (or unblock) users at will.

    Published: 10 Oct 2022
    4.8
    Medium

    CVE-2022-2629

    Last Modified: 21 Nov 2024

    The Top Bar WordPress plugin before 3.0.4 does not sanitise and escape some of its settings before outputting them in frontend pages, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 10 Oct 2022
    5.5
    Medium

    CVE-2022-42703

    Last Modified: 21 Nov 2024

    mm/rmap.c in the Linux kernel before 5.19.7 has a use-after-free related to leaf anon_vma double reuse.

    Published: 9 Oct 2022
    6.3
    Medium

    CVE-2022-3436

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file edit-photo.php of the component Photo Handler. The manipulation leads to unrestricted upload. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-210367.

    Published: 9 Oct 2022
    3.5
    Low

    CVE-2022-3434

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been rated as problematic. Affected by this issue is the function prepare of the file /Admin/add-student.php. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-210356.

    Published: 8 Oct 2022
    6.5
    Medium

    CVE-2022-39281

    Last Modified: 23 Apr 2025

    fat_free_crm is a an open source, Ruby on Rails customer relationship management platform (CRM). In versions prior to 0.20.1 an authenticated user can perform a remote Denial of Service attack against Fat Free CRM via bucket access. The vulnerability has been patched in commit `c85a254` and will be available in release `0.20.1`. Users are advised to upgrade or to manually apply patch `c85a254`. There are no known workarounds for this issue.

    Published: 8 Oct 2022
    3.5
    Low

    CVE-2022-3606

    Last Modified: 3 Nov 2025

    A vulnerability was found in Linux Kernel. It has been classified as problematic. This affects the function find_prog_by_sec_insn of the file tools/lib/bpf/libbpf.c of the component BPF. The manipulation leads to null pointer dereference. It is recommended to apply a patch to fix this issue. The identifier VDB-211749 was assigned to this vulnerability.

    Published: 8 Oct 2022
    4.3
    Medium

    CVE-2022-3435

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fib_nh_match of the file net/ipv4/fib_semantics.c of the component IPv4 Handler. The manipulation leads to out-of-bounds read. It is possible to initiate the attack remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-210357 was assigned to this vulnerability.

    Published: 8 Oct 2022
    8.1
    High

    CVE-2022-21936

    Last Modified: 21 Nov 2024

    On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providing a valid password when using MVE SMP UI.

    Published: 7 Oct 2022
    6.5
    Medium

    CVE-2022-41291

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 236699.

    Published: 7 Oct 2022
    6.5
    Medium

    CVE-2022-36772

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that should only be available to a privileged user.

    Published: 7 Oct 2022
    5.5
    Medium

    CVE-2022-34308

    Last Modified: 21 Nov 2024

    IBM CICS TX 11.1 could allow a local user to cause a denial of service due to improper load handling. IBM X-Force ID: 229437.

    Published: 7 Oct 2022
    5.5
    Medium

    CVE-2022-30613

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.4 and 7.5 could disclose sensitive information via a local service to a privileged user. IBM X-Force ID: 227366.

    Published: 7 Oct 2022
    8.8
    High

    CVE-2022-22493

    Last Modified: 21 Nov 2024

    IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute setting. IBM X-Force ID: 226449.

    Published: 7 Oct 2022
    7.5
    High

    CVE-2022-22480

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.4 and 7.5 data node rebalancing does not function correctly when using encrypted hosts which could result in information disclosure. IBM X-Force ID: 225889.

    Published: 7 Oct 2022
    —
    Unknown

    CVE-2022-3428

    Last Modified: 2 Jul 2024

    reserved but not needed

    Published: 7 Oct 2022
    7.8
    High

    CVE-2022-33896

    Last Modified: 15 Apr 2025

    A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files. A specially-crafted malformed file can cause memory corruption by using memory before buffer start, which can lead to code execution. A victim would need to access a malicious file to trigger this vulnerability.

    Published: 7 Oct 2022
    5.5
    Medium

    CVE-2023-0597

    Last Modified: 12 Mar 2025

    A flaw possibility of memory leak in the Linux kernel cpu_entry_area mapping of X86 CPU data to memory was found in the way user can guess location of exception stack(s) or other important data. A local user could use this flaw to get access to some important data with expected location in memory.

    Published: 7 Oct 2022
    5.5
    Medium

    CVE-2022-3707

    Last Modified: 7 Mar 2025

    A double-free memory flaw was found in the Linux kernel. The Intel GVT-g graphics driver triggers VGA card system resource overload, causing a fail in the intel_gvt_dma_map_guest_page function. This issue could allow a local user to crash the system.

    Published: 7 Oct 2022
    8.8
    High

    CVE-2022-36634

    Last Modified: 21 Nov 2024

    An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a crafted HTTP request.

    Published: 7 Oct 2022
    9.8
    Critical

    CVE-2022-37890

    Last Modified: 21 Nov 2024

    Unauthenticated buffer overflow vulnerabilities exist within the Aruba InstantOS and ArubaOS 10 web management interface. Successful exploitation results in the execution of arbitrary commands on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InnstantOS that address these security vulnerabilities.

    Published: 7 Oct 2022
    9.1
    Critical

    CVE-2022-39289

    Last Modified: 22 Apr 2025

    ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log contents to user without privileges, allows insertion, modification, deletion of logs without System Privileges. Users are advised yo upgrade as soon as possible. Users unable to upgrade should disable database logging.

    Published: 7 Oct 2022
    4.4
    Medium

    CVE-2022-39853

    Last Modified: 21 Nov 2024

    A use after free vulnerability in perf-mgr driver prior to SMR Oct-2022 Release 1 allows attacker to cause memory access fault.

    Published: 7 Oct 2022
    5.9
    Medium

    CVE-2022-39861

    Last Modified: 21 Nov 2024

    Unprotected Receiver in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to record video without camera privilege.

    Published: 7 Oct 2022
    4
    Medium

    CVE-2022-39877

    Last Modified: 20 May 2025

    Improper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.

    Published: 7 Oct 2022
    9.8
    Critical

    CVE-2022-40825

    Last Modified: 21 Nov 2024

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

    Published: 7 Oct 2022
    9.8
    Critical

    CVE-2022-40832

    Last Modified: 21 Nov 2024

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php having() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

    Published: 7 Oct 2022
    7.2
    High

    CVE-2022-41514

    Last Modified: 21 Nov 2024

    Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_loan.

    Published: 7 Oct 2022
    7.2
    High

    CVE-2022-42073

    Last Modified: 21 Nov 2024

    Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editclient.php?id=.

    Published: 7 Oct 2022
    7.2
    High

    CVE-2022-42074

    Last Modified: 21 Nov 2024

    Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editcategory.php?id=.

    Published: 7 Oct 2022
    9.8
    Critical

    CVE-2022-42075

    Last Modified: 21 Nov 2024

    Wedding Planner v1.0 is vulnerable to arbitrary code execution.

    Published: 7 Oct 2022
    7.2
    High

    CVE-2022-42092

    Last Modified: 21 Nov 2024

    Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispute this and argue that advanced permissions are required.

    Published: 7 Oct 2022
    7.8
    High

    CVE-2021-40163

    Last Modified: 21 Nov 2024

    A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through Autodesk Image Processing component.

    Published: 7 Oct 2022
    7.8
    High

    CVE-2021-40164

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow could occur while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.

    Published: 7 Oct 2022
    6.1
    Medium

    CVE-2020-15855

    Last Modified: 21 Nov 2024

    Two cross-site scripting vulnerabilities were fixed in Bodhi 5.6.1.

    Published: 7 Oct 2022
    6.7
    Medium

    CVE-2022-26474

    Last Modified: 21 Nov 2024

    In sensorhub, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07129717; Issue ID: ALPS07129717.

    Published: 7 Oct 2022
    9.1
    Critical

    CVE-2022-31680

    Last Modified: 21 Nov 2024

    The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on the underlying operating system that hosts the vCenter Server.

    Published: 7 Oct 2022
    6.7
    Medium

    CVE-2022-32590

    Last Modified: 21 Nov 2024

    In wlan, there is a possible use after free due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07299425; Issue ID: ALPS07299425.

    Published: 7 Oct 2022