CVE Feed

    Dashboard / CVE

    8
    High

    CVE-2022-36158

    Last Modified: 21 May 2025

    Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which allows malicious actors to execute Linux commands with root privilege via a hidden web page (/usr/www/ja/mnt_cmd.cgi).

    Published: 26 Sept 2022
    6.1
    Medium

    CVE-2022-38553

    Last Modified: 21 May 2025

    Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.

    Published: 26 Sept 2022
    7.3
    High

    CVE-2022-21797

    Last Modified: 21 Nov 2024

    The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.

    Published: 26 Sept 2022
    7.3
    High

    CVE-2022-21169

    Last Modified: 21 May 2025

    The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization.

    Published: 26 Sept 2022
    7.8
    High

    CVE-2022-41347

    Last Modified: 21 May 2025

    An issue was discovered in Zimbra Collaboration (ZCS) 8.8.x and 9.x (e.g., 8.8.15). The Sudo configuration permits the zimbra user to execute the NGINX binary as root with arbitrary parameters. As part of its intended functionality, NGINX can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-3195

    Last Modified: 22 May 2025

    Out of bounds write in Storage in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-3196

    Last Modified: 21 May 2025

    Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-3197

    Last Modified: 21 May 2025

    Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-3198

    Last Modified: 21 May 2025

    Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-3200

    Last Modified: 21 May 2025

    Heap buffer overflow in Internals in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-2852

    Last Modified: 22 May 2025

    Use after free in FedCM in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-2853

    Last Modified: 22 May 2025

    Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Sept 2022
    5.4
    Medium

    CVE-2022-3024

    Last Modified: 22 May 2025

    The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscribers to call it and add/delete/edit Bonds. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

    Published: 26 Sept 2022
    9.8
    Critical

    CVE-2022-41352

    Last Modified: 3 Nov 2025

    An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-3199

    Last Modified: 21 May 2025

    Use after free in Frames in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 26 Sept 2022
    5.4
    Medium

    CVE-2022-3201

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)

    Published: 26 Sept 2022
    4.2
    Medium

    CVE-2022-41849

    Last Modified: 21 Nov 2024

    drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a USB device while calling open(), aka a race condition between ufx_ops_open and ufx_usb_disconnect.

    Published: 25 Sept 2022
    6.5
    Medium

    CVE-2022-3165

    Last Modified: 14 May 2025

    An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, resulting in a denial of service.

    Published: 25 Sept 2022
    7.5
    High

    CVE-2022-41343

    Last Modified: 22 May 2025

    registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a @font-face rule.

    Published: 25 Sept 2022
    7.8
    High

    CVE-2022-3296

    Last Modified: 24 Sept 2026

    Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.

    Published: 25 Sept 2022
    7.8
    High

    CVE-2022-3297

    Last Modified: 24 Sept 2026

    Use After Free in GitHub repository vim/vim prior to 9.0.0579.

    Published: 25 Sept 2022
    7.5
    High

    CVE-2022-41340

    Last Modified: 22 May 2025

    The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signature forgery.

    Published: 24 Sept 2022
    9.4
    Critical

    CVE-2022-23463

    Last Modified: 22 Apr 2025

    Nepxion Discovery is a solution for Spring Cloud. Discover is vulnerable to SpEL Injection in discovery-commons. DiscoveryExpressionResolver’s eval method is evaluating expression with a StandardEvaluationContext, allowing the expression to reach and interact with Java classes such as java.lang.Runtime, leading to Remote Code Execution. There is no patch available for this issue at time of publication. There are no known workarounds.

    Published: 24 Sept 2022
    4.3
    Medium

    CVE-2022-23464

    Last Modified: 22 Apr 2025

    Nepxion Discovery is a solution for Spring Cloud. Discovery is vulnerable to a potential Server-Side Request Forgery (SSRF). RouterResourceImpl uses RestTemplate’s getForEntity to retrieve the contents of a URL containing user-controlled input, potentially resulting in Information Disclosure. There is no patch available for this issue at time of publication. There are no known workarounds.

    Published: 24 Sept 2022
    5.4
    Medium

    CVE-2022-23461

    Last Modified: 22 Apr 2025

    Jodit Editor is a WYSIWYG editor written in pure TypeScript without the use of additional libraries. Jodit Editor is vulnerable to XSS attacks when pasting specially constructed input. This issue has not been fully patched. There are no known workarounds.

    Published: 24 Sept 2022
    9.1
    Critical

    CVE-2022-36025

    Last Modified: 23 Apr 2025

    Besu is a Java-based Ethereum client. In versions newer than 22.1.3 and prior to 22.7.1, Besu is subject to an Incorrect Conversion between Numeric Types. An error in 32 bit signed and unsigned types in the calculation of available gas in the CALL operations (including DELEGATECALL) results in incorrect gas being passed into called contracts and incorrect gas being returned after call execution. Where the amount of gas makes a difference in the success or failure, or if the gas is a negative 64 bit value, the execution will result in a different state root than expected, resulting in a consensus failure in networks with multiple EVM implementations. In networks with a single EVM implementation this can be used to execute with significantly more gas than then transaction requested, possibly exceeding gas limitations. This issue is patched in version 22.7.1. As a workaround, reverting to version 22.1.3 or earlier will prevent incorrect execution.

    Published: 24 Sept 2022
    5.4
    Medium

    CVE-2022-39240

    Last Modified: 25 Apr 2025

    MyGraph is a permission management system. Versions prior to 1.0.4 are vulnerable to a storage XSS vulnerability leading to Remote Code Execution. This issue is patched in version 1.0.4. There is no known workaround.

    Published: 24 Sept 2022
    5.3
    Medium

    CVE-2022-39242

    Last Modified: 23 Apr 2025

    Frontier is an Ethereum compatibility layer for Substrate. Prior to commit d3beddc6911a559a3ecc9b3f08e153dbe37a8658, the worst case weight was always accounted as the block weight for all cases. In case of large EVM gas refunds, this can lead to block spamming attacks -- the adversary can construct blocks with transactions that have large amount of refunds or unused gases with reverts, and as a result inflate up the chain gas prices. The impact of this issue is limited in that the spamming attack would still be costly for any adversary, and it has no ability to alter any chain state. This issue has been patched in commit d3beddc6911a559a3ecc9b3f08e153dbe37a8658. There are no known workarounds.

    Published: 24 Sept 2022
    9.8
    Critical

    CVE-2022-40122

    Last Modified: 22 May 2025

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/edit_customer_action.php.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40121

    Last Modified: 22 May 2025

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/manage_customers.php.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40120

    Last Modified: 22 May 2025

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net-banking/customer_transactions.php.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40118

    Last Modified: 22 May 2025

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/send_funds_action.php.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40119

    Last Modified: 22 May 2025

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net-banking/transactions.php.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40116

    Last Modified: 21 May 2025

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/beneficiary.php.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40117

    Last Modified: 22 May 2025

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/delete_customer.php.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40115

    Last Modified: 21 May 2025

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/delete_beneficiary.php.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40114

    Last Modified: 21 May 2025

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/edit_customer.php.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40113

    Last Modified: 22 May 2025

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/send_funds.php.

    Published: 23 Sept 2022
    —
    Unknown

    CVE-2022-40669

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none

    Published: 23 Sept 2022
    —
    Unknown

    CVE-2022-40665

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none

    Published: 23 Sept 2022
    —
    Unknown

    CVE-2022-40666

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none

    Published: 23 Sept 2022
    —
    Unknown

    CVE-2022-40667

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none

    Published: 23 Sept 2022
    —
    Unknown

    CVE-2022-40668

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none

    Published: 23 Sept 2022
    7.1
    High

    CVE-2022-32831

    Last Modified: 22 May 2025

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary may result in unexpected termination or disclosure of process memory.

    Published: 23 Sept 2022
    5.5
    Medium

    CVE-2022-32841

    Last Modified: 22 May 2025

    The issue was addressed with improved memory handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. Processing a maliciously crafted image may result in disclosure of process memory.

    Published: 23 Sept 2022
    7.1
    High

    CVE-2022-32851

    Last Modified: 22 May 2025

    An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary may result in unexpected termination or disclosure of process memory.

    Published: 23 Sept 2022
    5.5
    Medium

    CVE-2022-32848

    Last Modified: 22 May 2025

    A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to capture a user’s screen.

    Published: 23 Sept 2022
    5.5
    Medium

    CVE-2022-32825

    Last Modified: 22 May 2025

    The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5. An app may be able to disclose kernel memory.

    Published: 23 Sept 2022
    5.5
    Medium

    CVE-2022-32828

    Last Modified: 22 May 2025

    The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, tvOS 15.6, macOS Monterey 12.5. An app may be able to disclose kernel memory.

    Published: 23 Sept 2022
    6.7
    Medium

    CVE-2022-32832

    Last Modified: 27 May 2025

    The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app with root privileges may be able to execute arbitrary code with kernel privileges.

    Published: 23 Sept 2022