CVE Feed

    Dashboard / CVE

    9.1
    Critical

    CVE-2022-30935

    Last Modified: 21 May 2025

    An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This allows the attacker to get valid sessions for arbitrary users, and optionally reset their password. Tested and confirmed in a default installation of version 7.2.3. Earlier versions are affected, possibly earlier major versions as well.

    Published: 28 Sept 2022
    4.3
    Medium

    CVE-2022-32169

    Last Modified: 21 May 2025

    The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user can view the “OPEN” and “CLOSED” issues by “Admin” and the affected endpoint is “/issue”.

    Published: 28 Sept 2022
    4.3
    Medium

    CVE-2022-32170

    Last Modified: 21 May 2025

    The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized user can view the “projects“ created by “Admin” and the affected endpoint is “/api/project?user=${userId}”.

    Published: 28 Sept 2022
    7.8
    High

    CVE-2022-32168

    Last Modified: 21 May 2025

    Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.

    Published: 28 Sept 2022
    4.9
    Medium

    CVE-2022-3348

    Last Modified: 21 May 2025

    Just like in the previous report, an attacker could steal the account of different users. But in this case, it's a little bit more specific, because it is needed to be an editor in the same app as the victim.

    Published: 28 Sept 2022
    5.3
    Medium

    CVE-2022-3523

    Last Modified: 15 Apr 2025

    A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is an unknown function of the file mm/memory.c of the component Driver Handler. The manipulation leads to use after free. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211020.

    Published: 28 Sept 2022
    3.5
    Low

    CVE-2022-3333

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, was found in Zephyr Project Manager up to 3.2.4. Affected is an unknown function of the file /v1/tasks/create/ of the component REST Call Handler. The manipulation of the argument onanimationstart leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 3.2.5 is able to address this issue. It is recommended to upgrade the affected component. VDB-209370 is the identifier assigned to this vulnerability.

    Published: 28 Sept 2022
    6.3
    Medium

    CVE-2022-3332

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System. This affects an unknown part of the file router.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-209583.

    Published: 28 Sept 2022
    6.1
    Medium

    CVE-2022-39054

    Last Modified: 21 May 2025

    Cowell enterprise travel management system has insufficient filtering for special characters within web URL. An unauthenticated remote attacker can inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.

    Published: 28 Sept 2022
    6.1
    Medium

    CVE-2022-39053

    Last Modified: 21 May 2025

    Heimavista Rpage has insufficient filtering for platform web URL. An unauthenticated remote attacker can inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.

    Published: 28 Sept 2022
    6.1
    Medium

    CVE-2022-39035

    Last Modified: 21 May 2025

    Smart eVision has insufficient filtering for special characters in the POST Data parameter in the specific function. An unauthenticated remote attacker can inject JavaScript to perform XSS (Stored Cross-Site Scripting) attack.

    Published: 28 Sept 2022
    6.5
    Medium

    CVE-2022-39034

    Last Modified: 21 May 2025

    Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special characters in URLs. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication, access restricted paths and download system files.

    Published: 28 Sept 2022
    9.8
    Critical

    CVE-2022-39033

    Last Modified: 21 May 2025

    Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication, access restricted paths to download and delete arbitrary system files to disrupt service.

    Published: 28 Sept 2022
    8.8
    High

    CVE-2022-39032

    Last Modified: 21 May 2025

    Smart eVision has an improper privilege management vulnerability. A remote attacker with general user privilege can exploit this vulnerability to escalate to administrator privilege, and then perform arbitrary system command or disrupt service.

    Published: 28 Sept 2022
    5.3
    Medium

    CVE-2022-39031

    Last Modified: 21 May 2025

    Smart eVision has insufficient authorization for task acquisition function. An unauthorized remote attacker can exploit this vulnerability to acquire the Session IDs of other general users only.

    Published: 28 Sept 2022
    7.5
    High

    CVE-2022-39030

    Last Modified: 21 May 2025

    smart eVision has inadequate authorization for system information query function. An unauthenticated remote attacker, who is not explicitly authorized to access the information, can access sensitive information.

    Published: 28 Sept 2022
    6.5
    Medium

    CVE-2022-39029

    Last Modified: 21 May 2025

    Smart eVision has inadequate authorization for the database query function. A remote attacker with general user privilege, who is not explicitly authorized to access the information, can access sensitive information.

    Published: 28 Sept 2022
    5.9
    Medium

    CVE-2022-38699

    Last Modified: 21 May 2025

    Armoury Crate Service’s logging function has insufficient validation to check if the log file is a symbolic link. A physical attacker with general user privilege can modify the log file property to a symbolic link that points to arbitrary system file, causing the logging function to overwrite the system file and disrupt the system.

    Published: 28 Sept 2022
    8.6
    High

    CVE-2022-39264

    Last Modified: 23 Apr 2025

    nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vulnerable homeservers inserting malicious secrets, which could lead to man-in-the-middle attacks. Users can upgrade to version 0.10.2 to protect against this issue. As a workaround, one may apply the patch manually, avoid doing verifications of one's own devices, and/or avoid pressing the request button in the settings menu.

    Published: 28 Sept 2022
    8.6
    High

    CVE-2022-39251

    Last Modified: 23 Apr 2025

    Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker cooperating with a malicious homeserver could employ this vulnerability to perform a targeted attack in order to send fake to-device messages appearing to originate from another user. This can allow, for example, to inject the key backup secret during a self-verification, to make a targeted device start using a malicious key backup spoofed by the homeserver. These attacks are possible due to a protocol confusion vulnerability that accepts to-device messages encrypted with Megolm instead of Olm. Starting with version 19.7.0, matrix-js-sdk has been modified to only accept Olm-encrypted to-device messages. Out of caution, several other checks have been audited or added. This attack requires coordination between a malicious home server and an attacker, so those who trust their home servers do not need a workaround.

    Published: 28 Sept 2022
    5.8
    Medium

    CVE-2022-2196

    Last Modified: 7 Aug 2026

    A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) advertising eIBRS support to L1. An attacker at L2 with code execution can execute code on an indirect branch on the host machine. We recommend upgrading to Kernel 6.2 or applying the relevant stable backports (v5.4.233, v5.10.170, v5.15.96, v6.1.14).

    Published: 28 Sept 2022
    4.3
    Medium

    CVE-2022-2760

    Last Modified: 21 May 2025

    In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have access to view in an error message when a resource is part of another Space.

    Published: 28 Sept 2022
    7.5
    High

    CVE-2022-28813

    Last Modified: 21 May 2025

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of an SQL-injection to gain access to a volatile temporary database with the current states of the device.

    Published: 28 Sept 2022
    7.5
    High

    CVE-2022-39261

    Last Modified: 23 Apr 2025

    Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a user input. It is possible to use the `source` or `include` statement to read arbitrary files from outside the templates' directory when using a namespace like `@somewhere/../some.file`. In such a case, validation is bypassed. Versions 1.44.7, 2.15.3, and 3.4.3 contain a fix for validation of such template names. There are no known workarounds aside from upgrading.

    Published: 28 Sept 2022
    9.8
    Critical

    CVE-2022-40929

    Last Modified: 21 May 2025

    XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).

    Published: 28 Sept 2022
    3.7
    Low

    CVE-2021-43980

    Last Modified: 21 May 2025

    The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.

    Published: 28 Sept 2022
    7.8
    High

    CVE-2022-1270

    Last Modified: 21 May 2025

    In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.

    Published: 28 Sept 2022
    6.1
    Medium

    CVE-2022-32166

    Last Modified: 21 May 2025

    In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

    Published: 28 Sept 2022
    4.3
    Medium

    CVE-2022-39236

    Last Modified: 23 Apr 2025

    Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Starting with version 17.1.0-rc.1, improperly formed beacon events can disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding or corrupting runtime data presented to the consumer. This is patched in matrix-js-sdk v19.7.0. Redacting applicable events, waiting for the sync processor to store data, and restarting the client are possible workarounds. Alternatively, redacting the applicable events and clearing all storage will fix the further perceived issues. Downgrading to an unaffected version, noting that such a version may be subject to other vulnerabilities, will additionally resolve the issue.

    Published: 28 Sept 2022
    7.5
    High

    CVE-2022-39249

    Last Modified: 23 Apr 2025

    Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in others. This attack is possible due to the matrix-js-sdk implementing a too permissive key forwarding strategy on the receiving end. Starting with version 19.7.0, the default policy for accepting key forwards has been made more strict in the matrix-js-sdk. matrix-js-sdk will now only accept forwarded keys in response to previously issued requests and only from own, verified devices. The SDK now sets a `trusted` flag on the decrypted message upon decryption, based on whether the key used to decrypt the message was received from a trusted source. Clients need to ensure that messages decrypted with a key with `trusted = false` are decorated appropriately, for example, by showing a warning for such messages. This attack requires coordination between a malicious homeserver and an attacker, and those who trust your homeservers do not need a workaround.

    Published: 28 Sept 2022
    8.6
    High

    CVE-2022-39250

    Last Modified: 23 Apr 2025

    Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver could interfere with the verification flow between two users, injecting its own cross-signing user identity in place of one of the users’ identities. This would lead to the other device trusting/verifying the user identity under the control of the homeserver instead of the intended one. The vulnerability is a bug in the matrix-js-sdk, caused by checking and signing user identities and devices in two separate steps, and inadequately fixing the keys to be signed between those steps. Even though the attack is partly made possible due to the design decision of treating cross-signing user identities as Matrix devices on the server side (with their device ID set to the public part of the user identity key), no other examined implementations were vulnerable. Starting with version 19.7.0, the matrix-js-sdk has been modified to double check that the key signed is the one that was verified instead of just referencing the key by ID. An additional check has been made to report an error when one of the device ID matches a cross-signing key. As this attack requires coordination between a malicious homeserver and an attacker, those who trust their homeservers do not need a particular workaround.

    Published: 28 Sept 2022
    8.8
    High

    CVE-2022-40497

    Last Modified: 21 May 2025

    Wazuh v3.6.1 - v3.13.5, v4.0.0 - v4.2.7, and v4.3.0 - v4.3.7 were discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Response endpoint.

    Published: 27 Sept 2022
    9.8
    Critical

    CVE-2021-41433

    Last Modified: 21 May 2025

    SQL Injection vulnerability exists in version 1.0 of the Resumes Management and Job Application Website application login form by EGavilan Media that allows authentication bypass through login.php.

    Published: 27 Sept 2022
    4.7
    Medium

    CVE-2021-27862

    Last Modified: 4 Nov 2025

    Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length and Ethernet to Wifi frame conversion (and optionally VLAN0 headers).

    Published: 27 Sept 2022
    5.3
    Medium

    CVE-2022-39835

    Last Modified: 21 May 2025

    An issue was discovered in Gajim through 1.4.7. The vulnerability allows attackers, via crafted XML stanzas, to correct messages that were not sent by them. The attacker needs to be part of the group chat or single chat. The fixed version is 1.5.0.

    Published: 27 Sept 2022
    7.8
    High

    CVE-2022-38932

    Last Modified: 21 May 2025

    readelf in ToaruOS 2.0.1 has a global overflow allowing RCE when parsing a crafted ELF file.

    Published: 27 Sept 2022
    5.4
    Medium

    CVE-2022-37028

    Last Modified: 30 May 2025

    ISAMS 22.2.3.2 is prone to stored Cross-site Scripting (XSS) attack on the title field for groups, allowing an attacker to store a JavaScript payload that will be executed when another user uses the application.

    Published: 27 Sept 2022
    5.4
    Medium

    CVE-2022-38335

    Last Modified: 21 May 2025

    Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template modules.

    Published: 27 Sept 2022
    9.8
    Critical

    CVE-2022-40877

    Last Modified: 21 May 2025

    Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter.

    Published: 27 Sept 2022
    8.8
    High

    CVE-2022-40878

    Last Modified: 21 May 2025

    In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (RCE).

    Published: 27 Sept 2022
    6.5
    Medium

    CVE-2022-40816

    Last Modified: 21 May 2025

    Zammad 5.2.1 is vulnerable to Incorrect Access Control. Zammad's asset handling mechanism has logic to ensure that customer users are not able to see personal information of other users. This logic was not effective when used through a web socket connection, so that a logged-in attacker would be able to fetch personal data of other users by querying the Zammad API. This issue is fixed in , 5.2.2.

    Published: 27 Sept 2022
    4.3
    Medium

    CVE-2022-40817

    Last Modified: 21 May 2025

    Zammad 5.2.1 has a fine-grained permission model that allows to configure read-only access to tickets. However, agents were still wrongly able to perform some operations on such tickets, like adding and removing links, tags. and related answers. This issue has been fixed in 5.2.2.

    Published: 27 Sept 2022
    8.1
    High

    CVE-2022-39258

    Last Modified: 22 Apr 2025

    mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger API template to spoof Authorize links. This could redirect a victim to an attacker controller place to steal Swagger authorization credentials or create a phishing page to steal other information. The issue has been fixed with the 2022-09 mailcow Mootember Update. As a workaround, one may delete the Swapper API Documentation from their e-mail server.

    Published: 27 Sept 2022
    9
    Critical

    CVE-2022-39256

    Last Modified: 23 Apr 2025

    Orckestra C1 CMS is a .NET based Web Content Management System. A vulnerability in versions prior to 6.13 allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated user may perform the actions unknowingly by visiting a specially crafted site. This issue is patched in C1 CMS v6.13. There are no known workarounds.

    Published: 27 Sept 2022
    1.8
    Low

    CVE-2022-23006

    Last Modified: 21 May 2025

    A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk ibi that could allow an attacker accessing the system locally to read information from /etc/version file. This vulnerability can only be exploited by chaining it with another issue. If an attacker is able to carry out a remote code execution attack, they can gain access to the vulnerable file, due to the presence of insecure functions in code. User interaction is required for exploitation. Exploiting the vulnerability could result in exposure of information, ability to modify files, memory access errors, or system crashes.

    Published: 27 Sept 2022
    7.5
    High

    CVE-2022-3323

    Last Modified: 21 May 2025

    An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet endpoint, which listens on TCP port 8080 by default. An unauthenticated remote attacker can craft a special column_value parameter in the setConfiguration action to bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform SQL injection. For example, the attacker can exploit the vulnerability to retrieve the iView admin password.

    Published: 27 Sept 2022
    7.2
    High

    CVE-2022-40354

    Last Modified: 21 May 2025

    Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_booking.php.

    Published: 27 Sept 2022
    7.2
    High

    CVE-2022-40353

    Last Modified: 22 May 2025

    Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/up_booking.php.

    Published: 27 Sept 2022
    7.2
    High

    CVE-2022-40352

    Last Modified: 22 May 2025

    Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_traveller.php.

    Published: 27 Sept 2022
    8.8
    High

    CVE-2022-37209

    Last Modified: 22 May 2025

    JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

    Published: 27 Sept 2022