CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2022-41844

    Last Modified: 20 May 2025

    An issue was discovered in Xpdf 4.04. There is a crash in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc, a different vulnerability than CVE-2018-16369 and CVE-2019-16088.

    Published: 30 Sept 2022
    —
    Unknown

    CVE-2022-41803

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 30 Sept 2022
    —
    Unknown

    CVE-2022-41782

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 30 Sept 2022
    4.6
    Medium

    CVE-2022-3565

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in Linux Kernel. Affected by this issue is the function del_timer of the file drivers/isdn/mISDN/l1oip_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211088.

    Published: 30 Sept 2022
    5.3
    Medium

    CVE-2022-21222

    Last Modified: 20 May 2025

    The package css-what before 2.1.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of insecure regular expression in the re_attr variable of index.js. The exploitation of this vulnerability could be triggered via the parse function.

    Published: 30 Sept 2022
    4.2
    Medium

    CVE-2022-41848

    Last Modified: 20 May 2025

    drivers/char/pcmcia/synclink_cs.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling ioctl, aka a race condition between mgslpc_ioctl and mgslpc_detach.

    Published: 30 Sept 2022
    4.7
    Medium

    CVE-2022-41850

    Last Modified: 8 Oct 2026

    roccat_report_event in drivers/hid/hid-roccat.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free in certain situations where a report is received while copying a report->value is in progress.

    Published: 30 Sept 2022
    —
    Unknown

    CVE-2022-41855

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Sept 2022
    —
    Unknown

    CVE-2022-41856

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Sept 2022
    —
    Unknown

    CVE-2022-41857

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Sept 2022
    9.8
    Critical

    CVE-2022-2778

    Last Modified: 20 May 2025

    In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.

    Published: 30 Sept 2022
    7.5
    High

    CVE-2022-3364

    Last Modified: 20 May 2025

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.

    Published: 29 Sept 2022
    6.5
    Medium

    CVE-2022-39232

    Last Modified: 23 Apr 2025

    Discourse is an open source discussion platform. Starting with version 2.9.0.beta5 and prior to version 2.9.0.beta10, an incomplete quote can generate a JavaScript error which will crash the current page in the browser in some cases. Version 2.9.0.beta10 added a fix and tests to ensure incomplete quotes won't break the app. As a workaround, the quote can be fixed via the rails console.

    Published: 29 Sept 2022
    4.3
    Medium

    CVE-2022-39226

    Last Modified: 23 Apr 2025

    Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, a malicious actor can add large payloads of text into the Location and Website fields of a user profile, which causes issues for other users when loading that profile. A fix to limit the length of user input for these fields is included in version 2.8.9 on the `stable` branch and version 2.9.0.beta10 on the `beta` and `tests-passed` branches. There are no known workarounds.

    Published: 29 Sept 2022
    7.2
    High

    CVE-2022-36068

    Last Modified: 23 Apr 2025

    Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, a moderator can create new and edit existing themes by using the API when they should not be able to do so. The problem is patched in version 2.8.9 on the `stable` branch and version 2.9.0.beta10 on the `beta` and `tests-passed` branches. There are no known workarounds.

    Published: 29 Sept 2022
    9.1
    Critical

    CVE-2022-36066

    Last Modified: 23 Apr 2025

    Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, admins can upload a maliciously crafted Zip or Gzip Tar archive to write files at arbitrary locations and trigger remote code execution. The problem is patched in version 2.8.9 on the `stable` branch and version 2.9.0.beta10 on the `beta` and `tests-passed` branches. There are no known workarounds.

    Published: 29 Sept 2022
    8
    High

    CVE-2022-40472

    Last Modified: 20 May 2025

    ZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build: 20220721.14829 was discovered to contain a CSV injection vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the Content text field of the Add New Message module.

    Published: 29 Sept 2022
    9.8
    Critical

    CVE-2022-33880

    Last Modified: 20 May 2025

    hms-staff.php in Projectworlds Hospital Management System Mini-Project through 2018-06-17 allows SQL injection via the type parameter.

    Published: 29 Sept 2022
    5.4
    Medium

    CVE-2022-35137

    Last Modified: 20 May 2025

    DGIOT Lightweight industrial IoT v4.5.4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.

    Published: 29 Sept 2022
    9.6
    Critical

    CVE-2022-39266

    Last Modified: 23 Apr 2025

    isolated-vm is a library for nodejs which gives the user access to v8's Isolate interface. In versions 4.3.6 and prior, if the untrusted v8 cached data is passed to the API through CachedDataOptions, attackers can bypass the sandbox and run arbitrary code in the nodejs process. Version 4.3.7 changes the documentation to warn users that they should not accept `cachedData` payloads from a user.

    Published: 29 Sept 2022
    —
    Unknown

    CVE-2022-41811

    Last Modified: 7 Nov 2023

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2022. Notes: none.

    Published: 29 Sept 2022
    —
    Unknown

    CVE-2022-41812

    Last Modified: 7 Nov 2023

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2022. Notes: none.

    Published: 29 Sept 2022
    —
    Unknown

    CVE-2022-41809

    Last Modified: 7 Nov 2023

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2022. Notes: none.

    Published: 29 Sept 2022
    —
    Unknown

    CVE-2022-41810

    Last Modified: 7 Nov 2023

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2022. Notes: none.

    Published: 29 Sept 2022
    9.8
    Critical

    CVE-2022-29503

    Last Modified: 15 Apr 2025

    A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An attacker can create threads to trigger this vulnerability.

    Published: 29 Sept 2022
    —
    Unknown

    CVE-2022-29504

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2022. Notes: none

    Published: 29 Sept 2022
    6.1
    Medium

    CVE-2022-40879

    Last Modified: 20 May 2025

    kkFileView v4.1.0 is vulnerable to Cross Site Scripting (XSS) via the parameter 'errorMsg.'

    Published: 29 Sept 2022
    9.8
    Critical

    CVE-2022-40887

    Last Modified: 20 May 2025

    SourceCodester Best Student Result Management System 1.0 is vulnerable to SQL Injection.

    Published: 29 Sept 2022
    7.5
    High

    CVE-2022-39168

    Last Modified: 20 May 2025

    IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID: 235422.

    Published: 29 Sept 2022
    6.1
    Medium

    CVE-2022-40931

    Last Modified: 20 May 2025

    dutchcoders Transfer.sh 1.4.0 is vulnerable to Cross Site Scripting (XSS).

    Published: 29 Sept 2022
    7.5
    High

    CVE-2022-38732

    Last Modified: 20 May 2025

    SnapCenter versions prior to 4.7 shipped without Content Security Policy (CSP) implemented which could allow certain types of attacks that otherwise would be prevented.

    Published: 29 Sept 2022
    8.6
    High

    CVE-2022-39254

    Last Modified: 23 Apr 2025

    matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a users requests a room key from their devices, the software correctly remember the request. Once they receive a forwarded room key, they accept it without checking who the room key came from. This allows homeservers to try to insert room keys of questionable validity, potentially mounting an impersonation attack. Version 0.20 fixes the issue.

    Published: 29 Sept 2022
    8.6
    High

    CVE-2022-39252

    Last Modified: 23 Apr 2025

    matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encryption library. Prior to version 0.6, when a user requests a room key from their devices, the software correctly remembers the request. When the user receives a forwarded room key, the software accepts it without checking who the room key came from. This allows homeservers to try to insert room keys of questionable validity, potentially mounting an impersonation attack. Version 0.6 fixes this issue.

    Published: 29 Sept 2022
    5.4
    Medium

    CVE-2022-40408

    Last Modified: 20 May 2025

    FeehiCMS v2.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted payload injected into the Comment box under the Single Page module.

    Published: 29 Sept 2022
    8.8
    High

    CVE-2022-40407

    Last Modified: 20 May 2025

    A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file.

    Published: 29 Sept 2022
    7.5
    High

    CVE-2022-40890

    Last Modified: 21 May 2025

    A vulnerability in /src/amf/amf-context.c in Open5GS 2.4.10 and earlier leads to AMF denial of service.

    Published: 29 Sept 2022
    5.5
    Medium

    CVE-2022-40363

    Last Modified: 21 May 2025

    A buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 allows attackers to cause a Denial of Service (DoS) via a crafted NFC file.

    Published: 29 Sept 2022
    7.8
    High

    CVE-2022-40126

    Last Modified: 21 May 2025

    A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privileges and execute arbitrary commands when Service Mode is activated.

    Published: 29 Sept 2022
    9.8
    Critical

    CVE-2022-40475

    Last Modified: 21 May 2025

    TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection via the component /cgi-bin/downloadFile.cgi.

    Published: 29 Sept 2022
    5.4
    Medium

    CVE-2022-3355

    Last Modified: 20 May 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.8.3.

    Published: 29 Sept 2022
    7.2
    High

    CVE-2022-40048

    Last Modified: 20 May 2025

    Flatpress v1.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the Upload File function.

    Published: 29 Sept 2022
    6.5
    Medium

    CVE-2022-35888

    Last Modified: 20 May 2025

    Ampere Altra and Ampere Altra Max devices through 2022-07-15 allow attacks via Hertzbleed, which is a power side-channel attack that extracts secret information from the CPU by correlating the power consumption with data being processed on the system.

    Published: 29 Sept 2022
    8.1
    High

    CVE-2022-41828

    Last Modified: 20 May 2025

    In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class type when instantiating an object from a class name.

    Published: 29 Sept 2022
    7.5
    High

    CVE-2022-39173

    Last Modified: 20 May 2025

    In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handshake. This occurs when an attacker supposedly resumes a previous TLS session. During the resumption Client Hello a Hello Retry Request must be triggered. Both Client Hellos are required to contain a list of duplicate cipher suites to trigger the buffer overflow. In total, two Client Hellos have to be sent: one in the resumed session, and a second one as a response to a Hello Retry Request message.

    Published: 29 Sept 2022
    7.8
    High

    CVE-2022-3352

    Last Modified: 20 May 2025

    Use After Free in GitHub repository vim/vim prior to 9.0.0614.

    Published: 29 Sept 2022
    4.3
    Medium

    CVE-2022-3621

    Last Modified: 15 Apr 2025

    A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_bmap_lookup_at_level of the file fs/nilfs2/inode.c of the component nilfs2. The manipulation leads to null pointer dereference. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211920.

    Published: 29 Sept 2022
    4.3
    Medium

    CVE-2022-3326

    Last Modified: 20 May 2025

    Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.9.

    Published: 28 Sept 2022
    6.5
    Medium

    CVE-2022-31629

    Last Modified: 4 Nov 2025

    In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.

    Published: 28 Sept 2022
    2.3
    Low

    CVE-2022-31628

    Last Modified: 20 May 2025

    In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

    Published: 28 Sept 2022
    7.8
    High

    CVE-2022-40710

    Last Modified: 21 Nov 2024

    A link following vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 28 Sept 2022