CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2022-3124

    Last Modified: 21 Nov 2024

    The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from users. Furthermore, due to the lack of validation in the destination filename, this could allow allow them to change the content of arbitrary files on the web server

    Published: 3 Oct 2022
    5.4
    Medium

    CVE-2022-2839

    Last Modified: 21 Nov 2024

    The Zephyr Project Manager WordPress plugin before 3.2.55 does not have any authorisation as well as CSRF in all its AJAX actions, allowing unauthenticated users to call them either directly or via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored Cross-Site Scripting attacks against logged in admins.

    Published: 3 Oct 2022
    4.8
    Medium

    CVE-2022-2763

    Last Modified: 21 Nov 2024

    The WP Socializer WordPress plugin before 7.3 does not sanitise and escape some of its Icons settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 3 Oct 2022
    4.8
    Medium

    CVE-2022-2628

    Last Modified: 21 Nov 2024

    The DSGVO All in one for WP WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 3 Oct 2022
    6.5
    Medium

    CVE-2022-40123

    Last Modified: 21 Nov 2024

    mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx. This vulnerability allows authenticated attackers to read arbitrary files in the system.

    Published: 3 Oct 2022
    6.5
    Medium

    CVE-2022-40922

    Last Modified: 21 Nov 2024

    A vulnerability in the LIEF::MachO::BinaryParser::init_and_parse function of LIEF v0.12.1 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted MachO file.

    Published: 3 Oct 2022
    7.5
    High

    CVE-2022-38817

    Last Modified: 21 Nov 2024

    Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data.

    Published: 3 Oct 2022
    5.4
    Medium

    CVE-2022-32173

    Last Modified: 21 Nov 2024

    In OrchardCore rc1-11259 to v1.2.2 vulnerable to HTML injection, allow an authenticated user with an editor security role to inject a persistent HTML modal dialog component into the dashboard that will affect admin users.

    Published: 3 Oct 2022
    7.5
    High

    CVE-2022-43945

    Last Modified: 12 May 2026

    The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. NFSD tracks the number of pages held by each NFSD thread by combining the receive and send buffers of a remote procedure call (RPC) into a single array of pages. A client can force the send buffer to shrink by sending an RPC message over TCP with garbage data added at the end of the message. The RPC message with garbage data is still correctly formed according to the specification and is passed forward to handlers. Vulnerable code in NFSD is not expecting the oversized request and writes beyond the allocated buffer space. CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

    Published: 3 Oct 2022
    3.5
    Low

    CVE-2022-3543

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function unix_sock_destructor/unix_release_sock of the file net/unix/af_unix.c of the component BPF. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211043.

    Published: 3 Oct 2022
    7.2
    High

    CVE-2022-40886

    Last Modified: 21 Nov 2024

    DedeCMS 5.7.98 has a file upload vulnerability in the background.

    Published: 3 Oct 2022
    8.8
    High

    CVE-2022-41040

    Last Modified: 30 Oct 2025

    Microsoft Exchange Server Elevation of Privilege Vulnerability

    Published: 3 Oct 2022
    —
    Unknown

    CVE-2022-42293

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 3 Oct 2022
    —
    Unknown

    CVE-2022-42294

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 3 Oct 2022
    —
    Unknown

    CVE-2022-42295

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 3 Oct 2022
    —
    Unknown

    CVE-2022-42296

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 3 Oct 2022
    —
    Unknown

    CVE-2022-42297

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 3 Oct 2022
    —
    Unknown

    CVE-2022-42298

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 3 Oct 2022
    6.5
    Medium

    CVE-2022-36551

    Last Modified: 21 Nov 2024

    A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authenticated user to access arbitrary files on the system. Furthermore, self-registration is enabled by default in these versions of Label Studio enabling a remote attacker to create a new account and then exploit the SSRF.

    Published: 3 Oct 2022
    7.8
    High

    CVE-2022-41301

    Last Modified: 21 Nov 2024

    A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 3 Oct 2022
    8
    High

    CVE-2022-41082

    Last Modified: 30 Oct 2025

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Published: 3 Oct 2022
    7.8
    High

    CVE-2022-33886

    Last Modified: 21 Nov 2024

    A maliciously crafted MODEL and SLDPRT file can be used to write beyond the allocated buffer while parsing through Autodesk AutoCAD 2023, 2022, 2021, 2020, and Maya 2023 and 2022. The vulnerability exists because the application fails to handle crafted MODEL and SLDPRT files, which causes an unhandled exception. A malicious actor could leverage this vulnerability to execute arbitrary code.

    Published: 3 Oct 2022
    7.8
    High

    CVE-2022-33890

    Last Modified: 21 Nov 2024

    A maliciously crafted PCT or DWF file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 3 Oct 2022
    3.1
    Low

    CVE-2022-3649

    Last Modified: 21 Nov 2024

    A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_new_inode of the file fs/nilfs2/inode.c of the component BPF. The manipulation leads to use after free. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211992.

    Published: 3 Oct 2022
    7.8
    High

    CVE-2022-40764

    Last Modified: 21 Nov 2024

    Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the common practice of viewing untrusted files in the Visual Studio Code editor, for example. The original demonstration was with shell metacharacters in the vendor.json ignore field, affecting snyk-go-plugin before 1.19.1. This affects, for example, the Snyk TeamCity plugin (which does not update automatically) before 20220930.142957.

    Published: 3 Oct 2022
    5.5
    Medium

    CVE-2022-41420

    Last Modified: 21 Nov 2024

    nasm v2.16 was discovered to contain a stack overflow in the Ndisasm component

    Published: 3 Oct 2022
    5.3
    Medium

    CVE-2022-3594

    Last Modified: 14 Apr 2025

    A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function intr_callback of the file drivers/net/usb/r8152.c of the component BPF. The manipulation leads to logging of excessive data. The attack can be launched remotely. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211363.

    Published: 2 Oct 2022
    5.5
    Medium

    CVE-2023-1195

    Last Modified: 18 Mar 2025

    A use-after-free flaw was found in reconn_set_ipaddr_from_hostname in fs/cifs/connect.c in the Linux kernel. The issue occurs when it forgets to set the free pointer server->hostname to NULL, leading to an invalid pointer request.

    Published: 2 Oct 2022
    7.5
    High

    CVE-2022-42003

    Last Modified: 7 Oct 2026

    In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.

    Published: 2 Oct 2022
    6.1
    Medium

    CVE-2022-46456

    Last Modified: 10 Apr 2025

    NASM v2.16 was discovered to contain a global buffer overflow in the component dbgdbg_typevalue at /output/outdbg.c.

    Published: 2 Oct 2022
    6.5
    Medium

    CVE-2023-1192

    Last Modified: 27 Feb 2025

    A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS in the Linux Kernel. After CIFS transfers response data to a system call, there are still local variable points to the memory region, and if the system call frees it faster than CIFS uses it, CIFS will access a free memory region, leading to a denial of service.

    Published: 2 Oct 2022
    6.5
    Medium

    CVE-2023-1193

    Last Modified: 27 Feb 2025

    A use-after-free flaw was found in setup_async_work in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. This issue could allow an attacker to crash the system by accessing freed work.

    Published: 2 Oct 2022
    7.1
    High

    CVE-2023-1194

    Last Modified: 20 Mar 2025

    An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. When an attacker sends the CREATE command with a malformed payload to KSMBD, due to a missing check of `NameOffset` in the `parse_lease_state()` function, the `create_context` object can access invalid memory.

    Published: 2 Oct 2022
    7.5
    High

    CVE-2022-42004

    Last Modified: 21 Nov 2024

    In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.

    Published: 2 Oct 2022
    7.8
    High

    CVE-2022-44370

    Last Modified: 21 Nov 2024

    NASM v2.16 was discovered to contain a heap buffer overflow in the component quote_for_pmake() asm/nasm.c:856

    Published: 2 Oct 2022
    5.5
    Medium

    CVE-2022-3541

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical has been found in Linux Kernel. This affects the function spl2sw_nvmem_get_mac_address of the file drivers/net/ethernet/sunplus/spl2sw_driver.c of the component BPF. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier VDB-211041 was assigned to this vulnerability.

    Published: 1 Oct 2022
    9.1
    Critical

    CVE-2022-42002

    Last Modified: 21 Nov 2024

    SonicJS through 0.6.0 allows file overwrite. It has the following mutations that are used for updating files: fileCreate and fileUpdate. Both of these mutations can be called without any authentication to overwrite any files on a SonicJS application, leading to Arbitrary File Write and Delete.

    Published: 30 Sept 2022
    8.1
    High

    CVE-2022-39268

    Last Modified: 23 Apr 2025

    ### Impact In a CSRF attack, an innocent end user is tricked by an attacker into submitting a web request that they did not intend. This may cause actions to be performed on the website that can include inadvertent client or server data leakage, change of session state, or manipulation of an end user's account. ### Patch Upgrade to v2022.09.10 to patch this vulnerability. ### Workarounds Rebuild and redeploy the Orchest `auth-server` with this commit: https://github.com/orchest/orchest/commit/c2587a963cca742c4a2503bce4cfb4161bf64c2d ### References https://en.wikipedia.org/wiki/Cross-site_request_forgery https://cwe.mitre.org/data/definitions/352.html ### For more information If you have any questions or comments about this advisory: * Open an issue in https://github.com/orchest/orchest * Email us at [email protected]

    Published: 30 Sept 2022
    6.5
    Medium

    CVE-2022-34429

    Last Modified: 21 Nov 2024

    Dell Hybrid Client below 1.8 version contains a Zip Slip Vulnerability in UI. A guest privilege attacker could potentially exploit this vulnerability, leading to system files modification.

    Published: 30 Sept 2022
    5
    Medium

    CVE-2022-34428

    Last Modified: 20 May 2025

    Dell Hybrid Client prior to version 1.8 contains a Regular Expression Denial of Service Vulnerability in the UI. An adversary with WMS group admin access could potentially exploit this vulnerability, leading to temporary denial-of-service.

    Published: 30 Sept 2022
    3.8
    Low

    CVE-2021-36865

    Last Modified: 20 Feb 2025

    Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz.

    Published: 30 Sept 2022
    7.4
    High

    CVE-2022-20945

    Last Modified: 21 Nov 2024

    A vulnerability in the 802.11 association frame validation of Cisco Catalyst 9100 Series Access Points (APs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of certain parameters within association request frames received by the AP. An attacker could exploit this vulnerability by sending a crafted 802.11 association request to a nearby device. An exploit could allow the attacker to unexpectedly reload the device, resulting in a DoS condition.

    Published: 30 Sept 2022
    6.7
    Medium

    CVE-2022-20930

    Last Modified: 21 Nov 2024

    A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite and possibly corrupt files on an affected system. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting arbitrary commands that are executed as the root user account. A successful exploit could allow the attacker to overwrite arbitrary system files, which could result in a denial of service (DoS) condition.

    Published: 30 Sept 2022
    8.6
    High

    CVE-2022-20919

    Last Modified: 21 Nov 2024

    A vulnerability in the processing of malformed Common Industrial Protocol (CIP) packets that are sent to Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient input validation during processing of CIP packets. An attacker could exploit this vulnerability by sending a malformed CIP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to unexpectedly reload, resulting in a DoS condition.

    Published: 30 Sept 2022
    8.8
    High

    CVE-2022-40341

    Last Modified: 20 May 2025

    mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PNG file.

    Published: 30 Sept 2022
    8.6
    High

    CVE-2022-20856

    Last Modified: 21 Nov 2024

    A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) Mobility messages in Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a logic error and improper management of resources related to the handling of CAPWAP Mobility messages. An attacker could exploit this vulnerability by sending crafted CAPWAP Mobility packets to an affected device. A successful exploit could allow the attacker to exhaust resources on the affected device. This would cause the device to reload, resulting in a DoS condition.

    Published: 30 Sept 2022
    7.9
    High

    CVE-2022-20855

    Last Modified: 21 Nov 2024

    A vulnerability in the self-healing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst Access Points could allow an authenticated, local attacker to escape the restricted controller shell and execute arbitrary commands on the underlying operating system of the access point. This vulnerability is due to improper checks throughout the restart of certain system processes. An attacker could exploit this vulnerability by logging on to an affected device and executing certain CLI commands. A successful exploit could allow the attacker to execute arbitrary commands on the underlying OS as root. To successfully exploit this vulnerability, an attacker would need valid credentials for a privilege level 15 user of the wireless controller.

    Published: 30 Sept 2022
    5.5
    Medium

    CVE-2022-20851

    Last Modified: 21 Nov 2024

    A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI API. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges. To exploit this vulnerability, an attacker must have valid Administrator privileges on the affected device.

    Published: 30 Sept 2022
    5.5
    Medium

    CVE-2022-20850

    Last Modified: 21 Nov 2024

    A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenticated, local attacker to delete arbitrary files from the file system of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting arbitrary file path information when using commands in the CLI of an affected device. A successful exploit could allow the attacker to delete arbitrary files from the file system of the affected device.

    Published: 30 Sept 2022
    8.6
    High

    CVE-2022-20848

    Last Modified: 21 Nov 2024

    A vulnerability in the UDP processing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst 9100 Series Access Points could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the improper processing of UDP datagrams. An attacker could exploit this vulnerability by sending malicious UDP datagrams to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

    Published: 30 Sept 2022