CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2022-40359

    Last Modified: 22 May 2025

    Cross site scripting (XSS) vulnerability in kfm through 1.4.7 via crafted GET request to /kfm/index.php.

    Published: 23 Sept 2022
    5.4
    Medium

    CVE-2022-40358

    Last Modified: 22 May 2025

    An issue was discovered in AjaXplorer 4.2.3, allows attackers to cause cross site scripting vulnerabilities via a crafted svg file upload.

    Published: 23 Sept 2022
    8.2
    High

    CVE-2022-36338

    Last Modified: 5 May 2025

    An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM callout vulnerability in the SMM driver FwBlockServiceSmm, creating SMM, leads to arbitrary code execution. An attacker can replace the pointer to the UEFI boot service GetVariable with a pointer to malware, and then generate a software SMI.

    Published: 23 Sept 2022
    5.5
    Medium

    CVE-2022-35099

    Last Modified: 22 May 2025

    SWFTools commit 772e55a2 was discovered to contain a stack overflow via ImageStream::getPixel(unsigned char*) at /xpdf/Stream.cc.

    Published: 23 Sept 2022
    5.5
    Medium

    CVE-2022-35098

    Last Modified: 22 May 2025

    SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via GfxICCBasedColorSpace::getDefaultColor(GfxColor*) at /xpdf/GfxState.cc.

    Published: 23 Sept 2022
    5.5
    Medium

    CVE-2022-35097

    Last Modified: 22 May 2025

    SWFTools commit 772e55a2 was discovered to contain a segmentation violation via FoFiTrueType::writeTTF at /xpdf/FoFiTrueType.cc.

    Published: 23 Sept 2022
    5.5
    Medium

    CVE-2022-35096

    Last Modified: 23 May 2025

    SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via draw_stroke at /gfxpoly/stroke.c.

    Published: 23 Sept 2022
    5.5
    Medium

    CVE-2022-35095

    Last Modified: 23 May 2025

    SWFTools commit 772e55a2 was discovered to contain a segmentation violation via InfoOutputDev::type3D1 at /pdf/InfoOutputDev.cc.

    Published: 23 Sept 2022
    5.5
    Medium

    CVE-2022-35094

    Last Modified: 23 May 2025

    SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/Stream.cc.

    Published: 23 Sept 2022
    5.5
    Medium

    CVE-2022-35093

    Last Modified: 23 May 2025

    SWFTools commit 772e55a2 was discovered to contain a global buffer overflow via DCTStream::transformDataUnit at /xpdf/Stream.cc.

    Published: 23 Sept 2022
    5.5
    Medium

    CVE-2022-35092

    Last Modified: 22 May 2025

    SWFTools commit 772e55a2 was discovered to contain a segmentation violation via convert_gfxline at /gfxpoly/convert.c.

    Published: 23 Sept 2022
    5.5
    Medium

    CVE-2022-35091

    Last Modified: 22 May 2025

    SWFTools commit 772e55a2 was discovered to contain a floating point exception (FPE) via DCTStream::readMCURow() at /xpdf/Stream.cc.ow()

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40628

    Last Modified: 22 May 2025

    This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper control of code generation in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted device. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary commands on the targeted device.

    Published: 23 Sept 2022
    10
    Critical

    CVE-2022-2970

    Last Modified: 16 Apr 2025

    MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) does not sanitize input before memcpy is used, which could allow an attacker to crash the device or remotely execute arbitrary code.

    Published: 23 Sept 2022
    10
    Critical

    CVE-2022-2972

    Last Modified: 16 Apr 2025

    MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) is vulnerable to a stack-based buffer overflow, which could allow an attacker to crash the device or remotely execute arbitrary code.

    Published: 23 Sept 2022
    8.6
    High

    CVE-2022-2971

    Last Modified: 16 Apr 2025

    MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) accesses a resource using an incompatible type, which could allow an attacker to crash the server with a malicious payload.

    Published: 23 Sept 2022
    8.6
    High

    CVE-2022-2973

    Last Modified: 16 Apr 2025

    MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) uses a NULL pointer in certain situations. which could allow an attacker to crash the server.

    Published: 23 Sept 2022
    8.1
    High

    CVE-2022-38742

    Last Modified: 22 May 2025

    Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. An attacker could send a specifically crafted TFTP or HTTPS request, causing a heap-based buffer overflow that crashes the ThinServer process. If successfully exploited, this could expose the server to arbitrary remote code execution.

    Published: 23 Sept 2022
    3.4
    Low

    CVE-2022-40215

    Last Modified: 20 Feb 2025

    Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in Tabs plugin <= 3.7.1 at WordPress.

    Published: 23 Sept 2022
    6.1
    Medium

    CVE-2022-36417

    Last Modified: 20 Feb 2025

    Multiple Stored Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in 3D Tag Cloud plugin <= 3.8 at WordPress.

    Published: 23 Sept 2022
    4.3
    Medium

    CVE-2022-38134

    Last Modified: 20 Feb 2025

    Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.

    Published: 23 Sept 2022
    4.3
    Medium

    CVE-2022-38470

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-2070

    Last Modified: 22 May 2025

    In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf instruction. Because of that, an attacker could create a socket and connect with a remote IP:port by opening a shell and getting full access to the system. The exploit affects daemons dbmng and logsrv that are running on ports 8000 and 8001 by default.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-2025

    Last Modified: 22 May 2025

    an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction. The explotation of this vulnerability may lead an attacker to execute a shell with full access.

    Published: 23 Sept 2022
    5.3
    Medium

    CVE-2022-40194

    Last Modified: 20 Feb 2025

    Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress

    Published: 23 Sept 2022
    6.3
    Medium

    CVE-2021-45035

    Last Modified: 22 May 2025

    Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by default. This could allow an attacker that has access to the network to perform a MITM attack in order to obtain the user´s credentials.

    Published: 23 Sept 2022
    6.2
    Medium

    CVE-2022-38061

    Last Modified: 20 Feb 2025

    Authenticated (author+) CSV Injection vulnerability in Export Post Info plugin <= 1.2.0 at WordPress.

    Published: 23 Sept 2022
    4.8
    Medium

    CVE-2022-40672

    Last Modified: 20 Feb 2025

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CPO Shortcodes plugin <= 1.5.0 at WordPress.

    Published: 23 Sept 2022
    7.2
    High

    CVE-2022-40861

    Last Modified: 22 May 2025

    Tenda AC18 router V15.03.05.19 contains a stack overflow vulnerability in the formSetQosBand->FUN_0007db78 function with the request /goform/SetNetControlList/

    Published: 23 Sept 2022
    4.8
    Medium

    CVE-2022-40195

    Last Modified: 20 Feb 2025

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PCA Predict plugin <= 1.0.3 at WordPress.

    Published: 23 Sept 2022
    5.4
    Medium

    CVE-2022-38085

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Read more By Adam plugin <= 1.1.8 at WordPress.

    Published: 23 Sept 2022
    4.8
    Medium

    CVE-2022-37342

    Last Modified: 20 Feb 2025

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability Add Shortcodes Actions And Filters plugin <= 2.0.9 at WordPress.

    Published: 23 Sept 2022
    5.4
    Medium

    CVE-2022-36388

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in YDS Support Ticket System plugin <= 1.0 at WordPress.

    Published: 23 Sept 2022
    6.1
    Medium

    CVE-2022-40193

    Last Modified: 28 Apr 2026

    Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in Awesome Filterable Portfolio plugin <= 1.9.7 at WordPress.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40855

    Last Modified: 22 May 2025

    Tenda W20E router V15.11.0.6 contains a stack overflow in the function formSetPortMapping with post request 'goform/setPortMapping/'. This vulnerability allows attackers to cause a Denial of Service (DoS) or Remote Code Execution (RCE) via the portMappingServer, portMappingProtocol, portMappingWan, porMappingtInternal, and portMappingExternal parameters.

    Published: 23 Sept 2022
    6.5
    Medium

    CVE-2022-35238

    Last Modified: 20 Feb 2025

    Unauthenticated Plugin Settings Change vulnerability in Awesome Filterable Portfolio plugin <= 1.9.7 at WordPress.

    Published: 23 Sept 2022
    5.4
    Medium

    CVE-2022-38460

    Last Modified: 20 Feb 2025

    Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in NOTICE BOARD plugin <= 1.1 at WordPress.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40866

    Last Modified: 22 May 2025

    Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formSetDebugCfg with request /goform/setDebugCfg/

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40867

    Last Modified: 22 May 2025

    Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formIPMacBindDel with the request /goform/delIpMacBind/

    Published: 23 Sept 2022
    3.4
    Low

    CVE-2022-37328

    Last Modified: 20 Feb 2025

    Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in Themes Awesome History Timeline plugin <= 1.0.5 at WordPress.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40868

    Last Modified: 22 May 2025

    Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formDelDhcpRule with the request /goform/delDhcpRules/

    Published: 23 Sept 2022
    5.4
    Medium

    CVE-2022-36791

    Last Modified: 20 Feb 2025

    Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Awesome UG Torro Forms plugin <= 1.0.16 at WordPress.

    Published: 23 Sept 2022
    4.3
    Medium

    CVE-2022-40310

    Last Modified: 20 Feb 2025

    Authenticated (subscriber+) Race Condition vulnerability in Rate my Post – WP Rating System plugin <= 3.3.4 at WordPress allows attackers to increase/decrease votes.

    Published: 23 Sept 2022
    4.3
    Medium

    CVE-2022-40671

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Rate my Post – WP Rating System plugin <= 3.3.4 at WordPress.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40854

    Last Modified: 22 May 2025

    Tenda AC18 router contained a stack overflow vulnerability in /goform/fast_setting_wifi_set

    Published: 23 Sept 2022
    3.1
    Low

    CVE-2022-3257

    Last Modified: 6 Dec 2024

    Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.

    Published: 23 Sept 2022
    9.1
    Critical

    CVE-2022-23144

    Last Modified: 22 May 2025

    There is a broken access control vulnerability in ZTE ZXvSTB product. Due to improper permission control, attackers could use this vulnerability to delete the default application type, which affects normal use of system.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40851

    Last Modified: 22 May 2025

    Tenda AC15 V15.03.05.19 contained a stack overflow via the function fromAddressNat.

    Published: 23 Sept 2022
    7.8
    High

    CVE-2022-27492

    Last Modified: 22 May 2025

    An integer underflow in WhatsApp could have caused remote code execution when receiving a crafted video file.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40853

    Last Modified: 22 May 2025

    Tenda AC15 router V15.03.05.19 contains a stack overflow via the list parameter at /goform/fast_setting_wifi_set

    Published: 23 Sept 2022