CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-41852

    Last Modified: 13 Feb 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 6 Oct 2022
    7.8
    High

    CVE-2022-26235

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in the Remisol Advance v2.0.12.1 and below for the Normand Message Server. On installation, the permissions set by Remisol Advance allow non-privileged users to overwrite and/or manipulate executables and libraries that run as the elevated SYSTEM user on Windows.

    Published: 6 Oct 2022
    5.5
    Medium

    CVE-2022-26236

    Last Modified: 21 Nov 2024

    The default privileges for the running service Normand Remisol Advance Launcher in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.

    Published: 6 Oct 2022
    5.5
    Medium

    CVE-2022-26237

    Last Modified: 21 Nov 2024

    The default privileges for the running service Normand Viewer Service in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.

    Published: 6 Oct 2022
    5.5
    Medium

    CVE-2022-26238

    Last Modified: 21 Nov 2024

    The default privileges for the running service Normand Service Manager in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.

    Published: 6 Oct 2022
    5.5
    Medium

    CVE-2022-26239

    Last Modified: 21 Nov 2024

    The default privileges for the running service Normand License Manager in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows unprivileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.

    Published: 6 Oct 2022
    5.3
    Medium

    CVE-2022-2781

    Last Modified: 21 Nov 2024

    In affected versions of Octopus Server it was identified that the same encryption process was used for both encrypting session cookies and variables.

    Published: 6 Oct 2022
    7.5
    High

    CVE-2022-27810

    Last Modified: 21 Nov 2024

    It was possible to trigger an infinite recursion condition in the error handler when Hermes executed specific maliciously formed JavaScript. This condition was only possible to trigger in dev-mode (when asserts were enabled). This issue affects Hermes versions prior to v0.12.0.

    Published: 6 Oct 2022
    5.3
    Medium

    CVE-2022-2783

    Last Modified: 21 Nov 2024

    In affected versions of Octopus Server it was identified that a session cookie could be used as the CSRF token

    Published: 6 Oct 2022
    7.5
    High

    CVE-2022-3389

    Last Modified: 21 Nov 2024

    Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10.

    Published: 6 Oct 2022
    7.5
    High

    CVE-2022-37603

    Last Modified: 15 May 2025

    A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.

    Published: 6 Oct 2022
    6.3
    Medium

    CVE-2022-39237

    Last Modified: 23 Apr 2025

    syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` package did not verify that the hash algorithm(s) used are cryptographically secure when verifying digital signatures. A patch is available in version >= v2.8.1 of the module. Users are encouraged to upgrade. Users unable to upgrade may independently validate that the hash algorithm(s) used for metadata digest(s) and signature hash are cryptographically secure.

    Published: 6 Oct 2022
    4.8
    Medium

    CVE-2022-39273

    Last Modified: 23 Apr 2025

    FlyteAdmin is the control plane for the data processing platform Flyte. Users who enable the default Flyte’s authorization server without changing the default clientid hashes will be exposed to the public internet. In an effort to make enabling authentication easier for Flyte administrators, the default configuration for Flyte Admin allows access for Flyte Propeller even after turning on authentication via a hardcoded hashed password. This password is also set on the default Flyte Propeller configmap in the various Flyte Helm charts. Users who enable auth but do not override this setting in Flyte Admin’s configuration may unbeknownst to them be allowing public traffic in by way of this default password with attackers effectively impersonating propeller. This only applies to users who have not specified the ExternalAuthorizationServer setting. Usage of an external auth server automatically turns off this default configuration and are not susceptible to this vulnerability. This issue has been addressed in version 1.1.44. Users should manually set the staticClients in the selfAuthServer section of their configuration if they intend to rely on Admin’s internal auth server. Again, users who use an external auth server are automatically protected from this vulnerability.

    Published: 6 Oct 2022
    5.9
    Medium

    CVE-2022-39280

    Last Modified: 23 Apr 2025

    dparse is a parser for Python dependency files. dparse in versions before 0.5.2 contain a regular expression that is vulnerable to a Regular Expression Denial of Service. All the users parsing index server URLs with dparse are impacted by this vulnerability. A patch has been applied in version `0.5.2`, all the users are advised to upgrade to `0.5.2` as soon as possible. Users unable to upgrade should avoid passing index server URLs in the source file to be parsed.

    Published: 6 Oct 2022
    5.4
    Medium

    CVE-2022-39988

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Centreon 22.04.0 allows attackers to execute arbitrary web script or HTML via a crafted payload injected into the Service>Templates service_alias parameter.

    Published: 6 Oct 2022
    6.5
    Medium

    CVE-2022-40160

    Last Modified: 21 Nov 2024

    ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocation. The CVE was then allocated by Google in breach of the CNA rules. After review by the JXPath maintainers, the original report was found to be invalid.

    Published: 6 Oct 2022
    9.8
    Critical

    CVE-2022-40494

    Last Modified: 17 Apr 2025

    NPS before v0.26.10 was discovered to contain an authentication bypass vulnerability via constantly generating and sending the Auth key and Timestamp parameters.

    Published: 6 Oct 2022
    9.1
    Critical

    CVE-2022-40895

    Last Modified: 21 Nov 2024

    In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to affect the integrity of a device via a User Enumeration vulnerability. The vulnerability is due to insecure design, where a difference in forgot password utility could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. This affects NeDi 1.0.7 for OS X 1.0.7 <= and NeDi for Suse 1.0.7 <= and NeDi for FreeBSD 1.0.7 <=.

    Published: 6 Oct 2022
    8.8
    High

    CVE-2022-41517

    Last Modified: 21 Nov 2024

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLanguageCfg function

    Published: 6 Oct 2022
    9.8
    Critical

    CVE-2022-41518

    Last Modified: 21 Nov 2024

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the UploadFirmwareFile function at /cgi-bin/cstecgi.cgi.

    Published: 6 Oct 2022
    8.8
    High

    CVE-2022-41520

    Last Modified: 21 Nov 2024

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the File parameter in the UploadCustomModule function.

    Published: 6 Oct 2022
    8.8
    High

    CVE-2022-41521

    Last Modified: 21 Nov 2024

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the sPort/ePort parameter in the setIpPortFilterRules function.

    Published: 6 Oct 2022
    9.8
    Critical

    CVE-2022-41522

    Last Modified: 21 Nov 2024

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an unauthenticated stack overflow via the "main" function.

    Published: 6 Oct 2022
    9.8
    Critical

    CVE-2022-41525

    Last Modified: 21 Nov 2024

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the OpModeCfg function at /cgi-bin/cstecgi.cgi.

    Published: 6 Oct 2022
    8.8
    High

    CVE-2022-41526

    Last Modified: 21 Nov 2024

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the ip parameter in the setDiagnosisCfg function.

    Published: 6 Oct 2022
    8.8
    High

    CVE-2022-41527

    Last Modified: 21 Nov 2024

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the pppoeUser parameter in the setOpModeCfg function.

    Published: 6 Oct 2022
    8.8
    High

    CVE-2022-41528

    Last Modified: 21 Nov 2024

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.

    Published: 6 Oct 2022
    7.5
    High

    CVE-2022-41556

    Last Modified: 21 Nov 2024

    A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is fixed in 1.4.67.

    Published: 6 Oct 2022
    8.8
    High

    CVE-2021-40556

    Last Modified: 21 Nov 2024

    A stack overflow vulnerability exists in the httpd service in ASUS RT-AX56U Router Version 3.0.0.4.386.44266. This vulnerability is caused by the strcat function called by "caupload" input handle function allowing the user to enter 0xFFFF bytes into the stack. This vulnerability allows an attacker to execute commands remotely. The vulnerability requires authentication.

    Published: 6 Oct 2022
    5.4
    Medium

    CVE-2022-3002

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

    Published: 6 Oct 2022
    7.5
    High

    CVE-2022-39244

    Last Modified: 4 Nov 2025

    PJSIP is a free and open source multimedia communication library written in C. In versions of PJSIP prior to 2.13 the PJSIP parser, PJMEDIA RTP decoder, and PJMEDIA SDP parser are affeced by a buffer overflow vulnerability. Users connecting to untrusted clients are at risk. This issue has been patched and is available as commit c4d3498 in the master branch and will be included in releases 2.13 and later. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 6 Oct 2022
    9.8
    Critical

    CVE-2022-37888

    Last Modified: 21 Nov 2024

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute arbitrary code as a privileged user on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InnstantOS that address these security vulnerabilities.

    Published: 6 Oct 2022
    9.3
    Critical

    CVE-2022-39222

    Last Modified: 22 Apr 2025

    Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex instances with public clients (and by extension, clients accepting tokens issued by those Dex instances) are affected by this vulnerability if they are running a version prior to 2.35.0. An attacker can exploit this vulnerability by making a victim navigate to a malicious website and guiding them through the OIDC flow, stealing the OAuth authorization code in the process. The authorization code then can be exchanged by the attacker for a token, gaining access to applications accepting that token. Version 2.35.0 has introduced a fix for this issue. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 6 Oct 2022
    7.2
    High

    CVE-2022-39265

    Last Modified: 22 Apr 2025

    MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mail_parameters setting value, in connection with the configured mail program's options and behavior, may allow access to sensitive information and Remote Code Execution (RCE). The vulnerable module requires Admin CP access with the `_Can manage settings?_` permission and may depend on configured file permissions. MyBB 1.8.31 resolves this issue with the commit `0cd318136a`. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 6 Oct 2022
    9.1
    Critical

    CVE-2022-39269

    Last Modified: 6 May 2026

    PJSIP is a free and open source multimedia communication library written in C. When processing certain packets, PJSIP may incorrectly switch from using SRTP media transport to using basic RTP upon SRTP restart, causing the media to be sent insecurely. The vulnerability impacts all PJSIP users that use SRTP. The patch is available as commit d2acb9a in the master branch of the project and will be included in version 2.13. Users are advised to manually patch or to upgrade. There are no known workarounds for this vulnerability.

    Published: 6 Oct 2022
    5.4
    Medium

    CVE-2022-39270

    Last Modified: 23 Apr 2025

    DiscoTOC is a Discourse theme component that generates a table of contents for topics. Users that can create topics in TOC-enabled categories (and have sufficient trust level - configured in component's settings) are able to inject arbitrary HTML on that topic's page. The issue has been fixed on the `main` branch. Admins can update the theme component through the admin UI (Customize -> Themes -> Components -> DiscoTOC -> Check for Updates). Alternatively, admins can temporarily disable the DiscoTOC theme component.

    Published: 6 Oct 2022
    7.5
    High

    CVE-2022-39274

    Last Modified: 22 Apr 2025

    LoRaMac-node is a reference implementation and documentation of a LoRa network node. Versions of LoRaMac-node prior to 4.7.0 are vulnerable to a buffer overflow. Improper size validation of the incoming radio frames can lead to an 65280-byte out-of-bounds write. The function `ProcessRadioRxDone` implicitly expects incoming radio frames to have at least a payload of one byte or more. An empty payload leads to a 1-byte out-of-bounds read of user controlled content when the payload buffer is reused. This allows an attacker to craft a FRAME_TYPE_PROPRIETARY frame with size -1 which results in an 65280-byte out-of-bounds memcopy likely with partially controlled attacker data. Corrupting a large part if the data section is likely to cause a DoS. If the large out-of-bounds write does not immediately crash the attacker may gain control over the execution due to now controlling large parts of the data section. Users are advised to upgrade either by updating their package or by manually applying the patch commit `e851b079`.

    Published: 6 Oct 2022
    5.3
    Medium

    CVE-2022-39275

    Last Modified: 23 Apr 2025

    Saleor is a headless, GraphQL commerce platform. In affected versions some GraphQL mutations were not properly checking the ID type input which allowed to access database objects that the authenticated user may not be allowed to access. This vulnerability can be used to expose the following information: Estimating database row counts from tables with a sequential primary key or Exposing staff user and customer email addresses and full name through the `assignNavigation()` mutation. This issue has been patched in main and backported to multiple releases (3.7.17, 3.6.18, 3.5.23, 3.4.24, 3.3.26, 3.2.14, 3.1.24). Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 6 Oct 2022
    4.3
    Medium

    CVE-2022-39279

    Last Modified: 23 Apr 2025

    discourse-chat is a plugin for the Discourse message board which adds chat functionality. In versions prior to 0.9 some places render a chat channel's name and description in an unsafe way, allowing staff members to cause an cross site scripting (XSS) attack by inserting unsafe HTML into them. Version 0.9 has addressed this issue. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 6 Oct 2022
    2.6
    Low

    CVE-2022-39284

    Last Modified: 22 Apr 2025

    CodeIgniter is a PHP full-stack web framework. In versions prior to 4.2.7 setting `$secure` or `$httponly` value to `true` in `Config\Cookie` is not reflected in `set_cookie()` or `Response::setCookie()`. As a result cookie values are erroneously exposed to scripts. It should be noted that this vulnerability does not affect session cookies. Users are advised to upgrade to v4.2.7 or later. Users unable to upgrade are advised to manually construct their cookies either by setting the options in code or by constructing Cookie objects. Examples of each workaround are available in the linked GHSA.

    Published: 6 Oct 2022
    7.2
    High

    CVE-2022-41355

    Last Modified: 21 Nov 2024

    Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /leave_system/classes/Master.php?f=delete_department.

    Published: 6 Oct 2022
    8.8
    High

    CVE-2022-41524

    Last Modified: 21 Nov 2024

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the week, sTime, and eTime parameters in the setParentalRules function.

    Published: 6 Oct 2022
    8
    High

    CVE-2022-41853

    Last Modified: 21 Apr 2025

    Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.

    Published: 6 Oct 2022
    7.2
    High

    CVE-2022-42241

    Last Modified: 21 Nov 2024

    Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_message.

    Published: 6 Oct 2022
    7.2
    High

    CVE-2022-42242

    Last Modified: 21 Nov 2024

    Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_booking.

    Published: 6 Oct 2022
    7.2
    High

    CVE-2022-42249

    Last Modified: 21 Nov 2024

    Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/view_storage.php?id=.

    Published: 6 Oct 2022
    9.1
    Critical

    CVE-2022-42457

    Last Modified: 21 Nov 2024

    Generex CS141 through 2.10 allows remote command execution by administrators via a web interface that reaches run_update in /usr/bin/gxserve-update.sh (e.g., command execution can occur via a reverse shell installed by install.sh).

    Published: 6 Oct 2022
    6.5
    Medium

    CVE-2022-26240

    Last Modified: 21 Nov 2024

    The default privileges for the running service Normand Message Buffer in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.

    Published: 6 Oct 2022
    8.8
    High

    CVE-2022-2986

    Last Modified: 21 Nov 2024

    Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.

    Published: 6 Oct 2022
    9.8
    Critical

    CVE-2022-3273

    Last Modified: 21 Nov 2024

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.

    Published: 6 Oct 2022