CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2022-2861

    Last Modified: 21 May 2025

    Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts into WebUI via a crafted HTML page.

    Published: 26 Sept 2022
    6.5
    Medium

    CVE-2022-2860

    Last Modified: 21 May 2025

    Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to bypass cookie prefix restrictions via a crafted HTML page.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-2859

    Last Modified: 21 May 2025

    Use after free in Chrome OS Shell in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-2858

    Last Modified: 21 May 2025

    Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-2857

    Last Modified: 22 May 2025

    Use after free in Blink in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-2855

    Last Modified: 22 May 2025

    Use after free in ANGLE in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Sept 2022
    6.5
    Medium

    CVE-2022-2856

    Last Modified: 24 Oct 2025

    Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-2854

    Last Modified: 22 May 2025

    Use after free in SwiftShader in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-40784

    Last Modified: 22 May 2025

    Unlimited strcpy on user input when setting a locale file leads to stack buffer overflow in mIPC camera firmware 5.3.1.2003161406.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-40785

    Last Modified: 22 May 2025

    Unsanitized input when setting a locale file leads to shell injection in mIPC camera firmware 5.3.1.2003161406. This allows an attacker to gain remote code execution on cameras running the firmware when a victim logs into a specially crafted mobile app.

    Published: 26 Sept 2022
    9.8
    Critical

    CVE-2022-28722

    Last Modified: 27 May 2025

    Certain HP Print Products are potentially vulnerable to Buffer Overflow.

    Published: 26 Sept 2022
    9.8
    Critical

    CVE-2022-28721

    Last Modified: 27 May 2025

    Certain HP Print Products are potentially vulnerable to Remote Code Execution.

    Published: 26 Sept 2022
    8.4
    High

    CVE-2022-39245

    Last Modified: 23 Apr 2025

    Mist is the command-line interface for the makedeb Package Repository. Prior to version 0.9.5, a user-provided `sudo` binary via the `PATH` variable can allow a local user to run arbitrary commands on the user's system with root permissions. Versions 0.9.5 and later contain a patch. No known workarounds exist.

    Published: 26 Sept 2022
    8.4
    High

    CVE-2022-39243

    Last Modified: 22 Apr 2025

    NuProcess is an external process execution implementation for Java. In all the versions of NuProcess where it forks processes by using the JVM's Java_java_lang_UNIXProcess_forkAndExec method (1.2.0+), attackers can use NUL characters in their strings to perform command line injection. Java's ProcessBuilder isn't vulnerable because of a check in ProcessBuilder.start. NuProcess is missing that check. This vulnerability can only be exploited to inject command line arguments on Linux. Version 2.0.5 contains a patch. As a workaround, users of the library can sanitize command strings to remove NUL characters prior to passing them to NuProcess for execution.

    Published: 26 Sept 2022
    6.5
    Medium

    CVE-2021-41437

    Last Modified: 21 May 2025

    An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an authenticated victim visits it, the URL will give access to the cloud storage of the attacker.

    Published: 26 Sept 2022
    8.5
    High

    CVE-2022-39219

    Last Modified: 22 Apr 2025

    Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data to other types of databases. Versions 1.8.6-release and prior are vulnerable to authentication bypass when using HTTP basic authentication. This may allow group members who only have read permissions to write requests when they are normally forbidden from doing so. Version 1.8.7-release contains a patch. There are currently no known workarounds.

    Published: 26 Sept 2022
    9.8
    Critical

    CVE-2022-40485

    Last Modified: 21 May 2025

    Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /package_detail.php.

    Published: 26 Sept 2022
    9.8
    Critical

    CVE-2022-40484

    Last Modified: 21 May 2025

    Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_edit.php.

    Published: 26 Sept 2022
    9.8
    Critical

    CVE-2022-40483

    Last Modified: 21 May 2025

    Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /wedding_details.php.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-40404

    Last Modified: 21 May 2025

    Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/select.php.

    Published: 26 Sept 2022
    7.2
    High

    CVE-2022-40403

    Last Modified: 21 May 2025

    Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/feature_edit.php.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-40402

    Last Modified: 21 May 2025

    Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_assign.php.

    Published: 26 Sept 2022
    4.3
    Medium

    CVE-2022-3299

    Last Modified: 15 Apr 2025

    A vulnerability was found in Open5GS up to 2.4.10. It has been declared as problematic. Affected by this vulnerability is an unknown functionality in the library lib/sbi/client.c of the component AMF. The manipulation leads to denial of service. The attack can be launched remotely. The name of the patch is 724fa568435dae45ef0c3a48b2aabde052afae88. It is recommended to apply a patch to fix this issue. The identifier VDB-209545 was assigned to this vulnerability.

    Published: 26 Sept 2022
    4.8
    Medium

    CVE-2022-3135

    Last Modified: 21 May 2025

    The SEO Smart Links WordPress plugin through 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 26 Sept 2022
    7.5
    High

    CVE-2022-3119

    Last Modified: 21 May 2025

    The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unauthenticated attackers to update them and change the OAuth endpoints to ones they controls, allowing them to then be authenticated as admin if they know the correct email address

    Published: 26 Sept 2022
    4.3
    Medium

    CVE-2022-3098

    Last Modified: 22 May 2025

    The Login Block IPs WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 26 Sept 2022
    7.2
    High

    CVE-2022-3076

    Last Modified: 22 May 2025

    The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example.

    Published: 26 Sept 2022
    4.8
    Medium

    CVE-2022-3074

    Last Modified: 22 May 2025

    The Slider Hero WordPress plugin before 8.4.4 does not escape the slider Name, which could allow high-privileged users to perform Cross-Site Scripting attacks.

    Published: 26 Sept 2022
    4.8
    Medium

    CVE-2022-3070

    Last Modified: 22 May 2025

    The Generate PDF WordPress plugin before 3.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 26 Sept 2022
    6.1
    Medium

    CVE-2022-3062

    Last Modified: 22 May 2025

    The Simple File List WordPress plugin before 4.4.12 does not escape parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting

    Published: 26 Sept 2022
    4.8
    Medium

    CVE-2022-3069

    Last Modified: 22 May 2025

    The WordLift WordPress plugin before 3.37.2 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 26 Sept 2022
    5.4
    Medium

    CVE-2022-3025

    Last Modified: 22 May 2025

    The Bitcoin / Altcoin Faucet WordPress plugin through 1.6.0 does not have any CSRF check when saving its settings, allowing attacker to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

    Published: 26 Sept 2022
    7.5
    High

    CVE-2022-2987

    Last Modified: 22 May 2025

    The Ldap WP Login / Active Directory Integration WordPress plugin before 3.0.2 does not have any authorisation and CSRF checks when updating it's settings (which are hooked to the init action), allowing unauthenticated attackers to update them. Attackers could set their own LDAP server to be used to authenticated users, therefore bypassing the current authentication

    Published: 26 Sept 2022
    4.9
    Medium

    CVE-2022-2926

    Last Modified: 21 May 2025

    The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory

    Published: 26 Sept 2022
    7.2
    High

    CVE-2022-2903

    Last Modified: 21 May 2025

    The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

    Published: 26 Sept 2022
    4.3
    Medium

    CVE-2022-2405

    Last Modified: 21 May 2025

    The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowing any authenticated users, such as subscribers to delete arbitrary Popup

    Published: 26 Sept 2022
    6.1
    Medium

    CVE-2022-2404

    Last Modified: 21 May 2025

    The WP Popup Builder WordPress plugin before 1.2.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

    Published: 26 Sept 2022
    7.2
    High

    CVE-2022-2352

    Last Modified: 21 May 2025

    The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations for example.

    Published: 26 Sept 2022
    5.4
    Medium

    CVE-2022-1755

    Last Modified: 21 May 2025

    The SVG Support WordPress plugin before 2.5 does not properly handle SVG added via an URL, which could allow users with a role as low as author to perform Cross-Site Scripting attacks

    Published: 26 Sept 2022
    5.3
    Medium

    CVE-2022-1613

    Last Modified: 21 May 2025

    The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations in certain situations.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2021-24890

    Last Modified: 21 May 2025

    The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action, available to both unauthenticated and authenticated users, and does not validate user input in any way, which could allow unauthenticated users to put arbitrary PHP code in a file

    Published: 26 Sept 2022
    7.2
    High

    CVE-2022-40927

    Last Modified: 21 May 2025

    Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_designation.

    Published: 26 Sept 2022
    7.2
    High

    CVE-2022-40926

    Last Modified: 21 May 2025

    Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_leave_type.

    Published: 26 Sept 2022
    7.5
    High

    CVE-2022-3295

    Last Modified: 21 May 2025

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.

    Published: 26 Sept 2022
    7.2
    High

    CVE-2022-40928

    Last Modified: 21 May 2025

    Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_application.

    Published: 26 Sept 2022
    7.2
    High

    CVE-2022-40925

    Last Modified: 21 May 2025

    Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_event" file of the "Events" module in the background management system.

    Published: 26 Sept 2022
    7.2
    High

    CVE-2022-40924

    Last Modified: 6 Feb 2026

    Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_animal" file of the "Animals" module in the background management system.

    Published: 26 Sept 2022
    2.4
    Low

    CVE-2022-3301

    Last Modified: 21 May 2025

    Improper Cleanup on Thrown Exception in GitHub repository ikus060/rdiffweb prior to 2.4.8.

    Published: 26 Sept 2022
    6.5
    Medium

    CVE-2022-38970

    Last Modified: 21 May 2025

    ieGeek IG20 hipcam RealServer V1.0 is vulnerable to Incorrect Access Control. The algorithm used to generate device IDs (UIDs) for devices that utilize Shenzhen Yunni Technology iLnkP2P suffers from a predictability flaw that allows remote attackers to establish direct connections to arbitrary devices.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-36159

    Last Modified: 21 May 2025

    Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN Manager interface and open the telnet port then sniff the traffic or inject any malware.

    Published: 26 Sept 2022