CVE Feed

    Dashboard / CVE

    8.6
    High

    CVE-2022-20847

    Last Modified: 21 Nov 2024

    A vulnerability in the DHCP processing functionality of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the improper processing of DHCP messages. An attacker could exploit this vulnerability by sending malicious DHCP messages to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

    Published: 30 Sept 2022
    5.3
    Medium

    CVE-2022-20844

    Last Modified: 21 Nov 2024

    A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unauthenticated, remote attacker to access the GUI of Cisco SD-AVC using a default static username and password combination. This vulnerability exists because the GUI is accessible on self-managed cloud installations or local server installations of Cisco vManage. An attacker could exploit this vulnerability by accessing the exposed GUI of Cisco SD-AVC. A successful exploit could allow the attacker to view managed device names, SD-AVC logs, and SD-AVC DNS server IP addresses.

    Published: 30 Sept 2022
    7.8
    High

    CVE-2022-20818

    Last Modified: 26 Feb 2026

    Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.

    Published: 30 Sept 2022
    6.5
    Medium

    CVE-2022-20810

    Last Modified: 21 Nov 2024

    A vulnerability in the Simple Network Management Protocol (SNMP) of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an authenticated, remote attacker to access sensitive information. This vulnerability is due to insufficient restrictions that allow a sensitive configuration detail to be disclosed. An attacker could exploit this vulnerability by retrieving data through SNMP read-only community access. A successful exploit could allow the attacker to view Service Set Identifier (SSID) preshared keys (PSKs) that are configured on the affected device.

    Published: 30 Sept 2022
    7.8
    High

    CVE-2022-20775

    Last Modified: 2 Mar 2026

    A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running a maliciously crafted command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdF

    Published: 30 Sept 2022
    7.4
    High

    CVE-2022-20769

    Last Modified: 21 Nov 2024

    A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error validation. An attacker could exploit this vulnerability by sending crafted packets to an affected device. A successful exploit could allow the attacker to cause the wireless LAN controller to crash, resulting in a DoS condition. Note: This vulnerability affects only devices that have Federal Information Processing Standards (FIPS) mode enabled.

    Published: 30 Sept 2022
    4.7
    Medium

    CVE-2022-20728

    Last Modified: 21 Nov 2024

    A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device. This vulnerability is due to a logic error on the AP that forwards packets that are destined to a wireless client if they are received on the native VLAN. An attacker could exploit this vulnerability by obtaining access to the native VLAN and directing traffic directly to the client through their MAC/IP combination. A successful exploit could allow the attacker to bypass VLAN separation and potentially also bypass any Layer 3 protection mechanisms that are deployed.

    Published: 30 Sept 2022
    6.1
    Medium

    CVE-2022-20662

    Last Modified: 21 Nov 2024

    A vulnerability in the smart card login authentication of Cisco Duo for macOS could allow an unauthenticated attacker with physical access to bypass authentication. This vulnerability exists because the assigned user of a smart card is not properly matched with the authenticating user. An attacker could exploit this vulnerability by configuring a smart card login to bypass Duo authentication. A successful exploit could allow the attacker to use any personal identity verification (PIV) smart card for authentication, even if the smart card is not assigned to the authenticating user.

    Published: 30 Sept 2022
    6.5
    Medium

    CVE-2022-40923

    Last Modified: 20 May 2025

    A vulnerability in the LIEF::MachO::SegmentCommand::virtual_address function of LIEF v0.12.1 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted MachO file.

    Published: 30 Sept 2022
    9.8
    Critical

    CVE-2022-40943

    Last Modified: 20 May 2025

    Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file.

    Published: 30 Sept 2022
    8.8
    High

    CVE-2022-40756

    Last Modified: 20 May 2025

    If folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15.11.005), Patch Update 4 for Zen 15 (v15.01.017), or Patch Update 5 for Zen 14 SP2 (v14.21.022), it can allow an attacker (with file read/write access) to remove specific security files in order to reset the master password and gain access to the database.

    Published: 30 Sept 2022
    6.1
    Medium

    CVE-2022-35155

    Last Modified: 12 Nov 2025

    Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the searchdata parameter.

    Published: 30 Sept 2022
    9.8
    Critical

    CVE-2022-35156

    Last Modified: 12 Nov 2025

    Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..

    Published: 30 Sept 2022
    7.8
    High

    CVE-2022-41975

    Last Modified: 20 May 2025

    RealVNC VNC Server before 6.11.0 and VNC Viewer before 6.22.826 on Windows allow local privilege escalation via MSI installer Repair mode.

    Published: 30 Sept 2022
    9.8
    Critical

    CVE-2022-40944

    Last Modified: 20 May 2025

    Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file.

    Published: 30 Sept 2022
    8.1
    High

    CVE-2021-33354

    Last Modified: 20 May 2025

    Directory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via modified file parameter.

    Published: 30 Sept 2022
    5.4
    Medium

    CVE-2022-28851

    Last Modified: 23 Apr 2025

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privilege access to AEM.

    Published: 30 Sept 2022
    6.1
    Medium

    CVE-2021-36855

    Last Modified: 20 Feb 2025

    Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro plugin <= 1.1.4 at WordPress.

    Published: 30 Sept 2022
    5.4
    Medium

    CVE-2021-36854

    Last Modified: 20 Feb 2025

    Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Booking Ultra Pro plugin <= 1.1.4 at WordPress.

    Published: 30 Sept 2022
    6.1
    Medium

    CVE-2022-36965

    Last Modified: 20 May 2025

    Insufficient sanitization of inputs in QoE application input field could lead to stored and Dom based XSS attack. This issue is fixed and released in SolarWinds Platform (2022.3.0).

    Published: 30 Sept 2022
    5.9
    Medium

    CVE-2022-32540

    Last Modified: 20 May 2025

    Information Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 versions 10.23 and 10.30 allows man-in-the-middle attacker to compromise confidential video stream. This is only applicable for UDP encryption when target system contains cameras with platform CPP13 or CPP14 and firmware version 8.x.

    Published: 30 Sept 2022
    4.3
    Medium

    CVE-2022-40316

    Last Modified: 20 May 2025

    The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.

    Published: 30 Sept 2022
    9.8
    Critical

    CVE-2022-40315

    Last Modified: 20 May 2025

    A limited SQL injection risk was identified in the "browse list of users" site administration page.

    Published: 30 Sept 2022
    7.1
    High

    CVE-2022-40313

    Last Modified: 20 May 2025

    Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.

    Published: 30 Sept 2022
    9.8
    Critical

    CVE-2022-40314

    Last Modified: 20 May 2025

    A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.

    Published: 30 Sept 2022
    5.4
    Medium

    CVE-2022-21826

    Last Modified: 21 Nov 2024

    Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length header and leaves the POST body on the TCP/TLS socket. This body ends up prefixing the next HTTP request sent down that connection, this means when someone loads website attacker may be able to make browser issue a POST to the application, enabling XSS.

    Published: 30 Sept 2022
    7.2
    High

    CVE-2022-41870

    Last Modified: 20 May 2025

    AP Manager in Innovaphone before 13r2 Service Release 17 allows command injection via a modified service ID during app upload.

    Published: 30 Sept 2022
    6.6
    Medium

    CVE-2022-1959

    Last Modified: 20 May 2025

    AppLock version 7.9.29 allows an attacker with physical access to the device to bypass biometric authentication. This is possible because the application did not correctly implement fingerprint validations.

    Published: 30 Sept 2022
    7.8
    High

    CVE-2022-40277

    Last Modified: 20 May 2025

    Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link in a malicious markdown file, via Joplin. This is possible because the application does not properly validate the schema/protocol of existing links in the markdown file before passing them to the 'shell.openExternal' function.

    Published: 30 Sept 2022
    7.8
    High

    CVE-2022-40274

    Last Modified: 20 May 2025

    Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Gridea. This is possible because the application has the 'nodeIntegration' option enabled.

    Published: 30 Sept 2022
    4.8
    Medium

    CVE-2021-36830

    Last Modified: 20 Feb 2025

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Comment Guestbook plugin <= 0.8.0 at WordPress.

    Published: 30 Sept 2022
    4.8
    Medium

    CVE-2021-36839

    Last Modified: 20 Feb 2025

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Follow Buttons Bar plugin <= 4.73 at WordPress.

    Published: 30 Sept 2022
    8.8
    High

    CVE-2022-36961

    Last Modified: 20 May 2025

    A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this for privilege escalation or remote code execution.

    Published: 30 Sept 2022
    5.4
    Medium

    CVE-2022-23726

    Last Modified: 20 May 2025

    PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authentication return large amounts of sensitive environmental and application information.

    Published: 30 Sept 2022
    7.2
    High

    CVE-2022-41440

    Last Modified: 20 May 2025

    Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editcategory.php.

    Published: 30 Sept 2022
    7.2
    High

    CVE-2022-41439

    Last Modified: 20 May 2025

    Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/edituser.php.

    Published: 30 Sept 2022
    7.2
    High

    CVE-2022-41437

    Last Modified: 20 May 2025

    Billing System Project v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/createProduct.php.

    Published: 30 Sept 2022
    6.1
    Medium

    CVE-2022-37461

    Last Modified: 20 May 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or the (2) groupID, (3) offset, or (4) limit parameter to an Administrative Panel (Group and Users) page. There is a risk of an attacker retrieving patient information.

    Published: 30 Sept 2022
    7.5
    High

    CVE-2022-3371

    Last Modified: 20 May 2025

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.

    Published: 30 Sept 2022
    7.5
    High

    CVE-2022-2529

    Last Modified: 20 May 2025

    sflow decode package does not employ sufficient packet sanitisation which can lead to a denial of service attack. Attackers can craft malformed packets causing the process to consume large amounts of memory resulting in a denial of service.

    Published: 30 Sept 2022
    4.9
    Medium

    CVE-2022-2922

    Last Modified: 20 May 2025

    Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0.

    Published: 30 Sept 2022
    3.5
    Low

    CVE-2022-3544

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, was found in Linux Kernel. Affected is the function damon_sysfs_add_target of the file mm/damon/sysfs.c of the component Netfilter. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211044.

    Published: 30 Sept 2022
    3.3
    Low

    CVE-2022-3542

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 30 Sept 2022
    5.3
    Medium

    CVE-2022-24373

    Last Modified: 20 May 2025

    The package react-native-reanimated before 3.0.0-rc.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper usage of regular expression in the parser of Colors.js.

    Published: 30 Sept 2022
    5.5
    Medium

    CVE-2022-41845

    Last Modified: 20 May 2025

    An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_Array<AP4_ElstEntry>::EnsureCapacity in Core/Ap4Array.h.

    Published: 30 Sept 2022
    5.5
    Medium

    CVE-2022-41846

    Last Modified: 20 May 2025

    An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_DataBuffer::ReallocateBuffer in Core/Ap4DataBuffer.cpp.

    Published: 30 Sept 2022
    5.5
    Medium

    CVE-2022-41847

    Last Modified: 20 May 2025

    An issue was discovered in Bento4 1.6.0-639. A memory leak exists in AP4_StdcFileByteStream::Create(AP4_FileByteStream*, char const*, AP4_FileByteStream::Mode, AP4_ByteStream*&) in System/StdC/Ap4StdCFileByteStream.cpp.

    Published: 30 Sept 2022
    5.5
    Medium

    CVE-2022-41841

    Last Modified: 20 May 2025

    An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_File::ParseStream in Core/Ap4File.cpp, which is called from AP4_File::AP4_File.

    Published: 30 Sept 2022
    5.5
    Medium

    CVE-2022-41842

    Last Modified: 20 May 2025

    An issue was discovered in Xpdf 4.04. There is a crash in gfseek(_IO_FILE*, long, int) in goo/gfile.cc.

    Published: 30 Sept 2022
    5.5
    Medium

    CVE-2022-41843

    Last Modified: 20 May 2025

    An issue was discovered in Xpdf 4.04. There is a crash in convertToType0 in fofi/FoFiType1C.cc, a different vulnerability than CVE-2022-38928.

    Published: 30 Sept 2022