CVE Feed

    Dashboard / CVE

    4.4
    Medium

    CVE-2022-3144

    Last Modified: 8 Apr 2026

    The Wordfence Security – Firewall & Malware Scan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 7.6.0 via a setting on the options page due to insufficient escaping on the stored value. This makes it possible for authenticated users, with administrative privileges, to inject malicious web scripts into the setting that executes whenever a user accesses a page displaying the affected setting on sites running a vulnerable version.

    Published: 23 Sept 2022
    6.4
    Medium

    CVE-2022-2937

    Last Modified: 31 Jan 2025

    The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title & Description values that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, the plugin only allows administrators access to edit Image Hovers, however, if a site admin makes the plugin's features available to lower privileged users through the 'Who Can Edit?' setting then this can be exploited by those users.

    Published: 23 Sept 2022
    3.4
    Low

    CVE-2022-38703

    Last Modified: 20 Feb 2025

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Foundry Button Plugin MaxButtons plugin <= 9.2 at WordPress

    Published: 23 Sept 2022
    4.1
    Medium

    CVE-2022-40213

    Last Modified: 20 Feb 2025

    Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in GS Testimonial Slider plugin <= 1.9.6 at WordPress.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40860

    Last Modified: 22 May 2025

    Tenda AC15 router V15.03.05.19 contains a stack overflow vulnerability in the function formSetQosBand->FUN_0007dd20 with request /goform/SetNetControlList

    Published: 23 Sept 2022
    7.2
    High

    CVE-2022-40093

    Last Modified: 22 May 2025

    Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_tax.php.

    Published: 23 Sept 2022
    7.2
    High

    CVE-2022-40092

    Last Modified: 22 May 2025

    Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_payment.php.

    Published: 23 Sept 2022
    7.2
    High

    CVE-2022-40091

    Last Modified: 22 May 2025

    Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_packages.php.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40862

    Last Modified: 22 May 2025

    Tenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulnerability in the function fromNatStaticSetting with the request /goform/NatStaticSetting

    Published: 23 Sept 2022
    5.4
    Medium

    CVE-2022-38095

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.3 at WordPress.

    Published: 23 Sept 2022
    5.4
    Medium

    CVE-2022-36798

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Topdigitaltrends Mega Addons For WPBakery Page Builder plugin <= 4.2.7 at WordPress.

    Published: 23 Sept 2022
    4.1
    Medium

    CVE-2022-37339

    Last Modified: 20 Feb 2025

    Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Meet My Team plugin <= 2.0.5 at WordPress.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40864

    Last Modified: 22 May 2025

    Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function setSmartPowerManagement with the request /goform/PowerSaveSet

    Published: 23 Sept 2022
    6.7
    Medium

    CVE-2022-30121

    Last Modified: 22 May 2025

    The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is a security bug that allows a limited user to get escalated admin privileges on their system.

    Published: 23 Sept 2022
    —
    Unknown

    CVE-2022-35253

    Last Modified: 13 Feb 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 23 Sept 2022
    7.8
    High

    CVE-2022-35257

    Last Modified: 22 May 2025

    A local privilege escalation vulnerability in UI Desktop for Windows (Version 0.55.1.2 and earlier) allows a malicious actor with local access to a Windows device with UI Desktop to run arbitrary commands as SYSTEM.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40865

    Last Modified: 27 May 2025

    Tenda AC15 and AC18 routers V15.03.05.19 contain heap overflow vulnerabilities in the function setSchedWifi with the request /goform/openSchedWifi/

    Published: 23 Sept 2022
    4.1
    Medium

    CVE-2022-37338

    Last Modified: 20 Feb 2025

    Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Blossom Recipe Maker plugin <= 1.0.7 at WordPress.

    Published: 23 Sept 2022
    5.4
    Medium

    CVE-2022-37330

    Last Modified: 20 Feb 2025

    Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WHA Crossword plugin <= 1.1.10 at WordPress.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-40869

    Last Modified: 27 May 2025

    Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function fromDhcpListClient with a combined parameter "list*" ("%s%d","list").

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-3236

    Last Modified: 27 Oct 2025

    A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.

    Published: 23 Sept 2022
    7.7
    High

    CVE-2022-2347

    Last Modified: 12 May 2026

    There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a `wLength` greater than 4096 bytes, they can write beyond the heap-allocated request buffer.

    Published: 23 Sept 2022
    9
    Critical

    CVE-2022-2566

    Last Modified: 21 Apr 2025

    A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points()` goes through all entries in the loop and adds `sc->ctts_data[i].count` to `sc->sample_offsets_count`. This can lead to an integer overflow resulting in a small allocation with `av_calloc()`. An attacker can cause remote code execution via a malicious mp4 file. We recommend upgrading past commit c953baa084607dd1d84c3bfcce3cf6a87c3e6e05

    Published: 23 Sept 2022
    4.4
    Medium

    CVE-2022-40979

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable

    Published: 23 Sept 2022
    7.5
    High

    CVE-2022-38936

    Last Modified: 27 May 2025

    An issue has been found in PBC through 2022-8-27. A SEGV issue detected in the function pbc_wmessage_integer in src/wmessage.c:137.

    Published: 23 Sept 2022
    5.9
    Medium

    CVE-2022-33683

    Last Modified: 22 May 2025

    Apache Pulsar Brokers and Proxies create an internal Pulsar Admin Client that does not verify peer TLS certificates, even when tlsAllowInsecureConnection is disabled via configuration. The Pulsar Admin Client's intra-cluster and geo-replication HTTPS connections are vulnerable to man in the middle attacks, which could leak authentication data, configuration data, and any other data sent by these clients. An attacker can only take advantage of this vulnerability by taking control of a machine 'between' the client and the server. The attacker must then actively manipulate traffic to perform the attack. This issue affects Apache Pulsar Broker and Proxy versions 2.7.0 to 2.7.4; 2.8.0 to 2.8.3; 2.9.0 to 2.9.2; 2.10.0; 2.6.4 and earlier.

    Published: 23 Sept 2022
    5.9
    Medium

    CVE-2022-33682

    Last Modified: 27 May 2025

    TLS hostname verification cannot be enabled in the Pulsar Broker's Java Client, the Pulsar Broker's Java Admin Client, the Pulsar WebSocket Proxy's Java Client, and the Pulsar Proxy's Admin Client leaving intra-cluster connections and geo-replication connections vulnerable to man in the middle attacks, which could leak credentials, configuration data, message data, and any other data sent by these clients. The vulnerability is for both the pulsar+ssl protocol and HTTPS. An attacker can only take advantage of this vulnerability by taking control of a machine 'between' the client and the server. The attacker must then actively manipulate traffic to perform the attack by providing the client with a cryptographically valid certificate for an unrelated host. This issue affects Apache Pulsar Broker, Proxy, and WebSocket Proxy versions 2.7.0 to 2.7.4; 2.8.0 to 2.8.3; 2.9.0 to 2.9.2; 2.10.0; 2.6.4 and earlier.

    Published: 23 Sept 2022
    6.5
    Medium

    CVE-2022-24280

    Last Modified: 22 May 2025

    Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection attempts that originate from the Pulsar Proxy's IP address. When the Apache Pulsar Proxy component is used, it is possible to attempt to open TCP/IP connections to any IP address and port that the Pulsar Proxy can connect to. An attacker could use this as a way for DoS attacks that originate from the Pulsar Proxy's IP address. It hasn’t been detected that the Pulsar Proxy authentication can be bypassed. The attacker will have to have a valid token to a properly secured Pulsar Proxy. This issue affects Apache Pulsar Proxy versions 2.7.0 to 2.7.4; 2.8.0 to 2.8.2; 2.9.0 to 2.9.1; 2.6.4 and earlier.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-3269

    Last Modified: 22 May 2025

    Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-26112

    Last Modified: 27 May 2025

    In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support. In order to avoid this, we disabled the groovy function support by default from Pinot release 0.11.0. See https://docs.pinot.apache.org/basics/releases/0.11.0

    Published: 23 Sept 2022
    4.2
    Medium

    CVE-2022-39238

    Last Modified: 23 Apr 2025

    Arvados is an open source platform for managing and analyzing biomedical big data. In versions prior to 2.4.3, when using Portable Authentication Modules (PAM) for user authentication, if a user presented valid credentials but the account is disabled or otherwise not allowed to access the host (such as an expired password), it would still be accepted for access to Arvados. Other authentication methods (LDAP, OpenID Connect) supported by Arvados are not affected by this flaw. This issue is patched in version 2.4.3. Workaround for this issue is to migrate to a different authentication method supported by Arvados, such as LDAP.

    Published: 23 Sept 2022
    6.1
    Medium

    CVE-2022-39239

    Last Modified: 23 Apr 2025

    netlify-ipx is an on-Demand image optimization for Netlify using ipx. In versions prior to 1.2.3, an attacker can bypass the source image domain allowlist by sending specially crafted headers, causing the handler to load and return arbitrary images. Because the response is cached globally, this image will then be served to visitors without requiring those headers to be set. XSS can be achieved by requesting a malicious SVG with embedded scripts, which would then be served from the site domain. Note that this does not apply to images loaded in `<img>` tags, as scripts do not execute in this context. The image URL can be set in the header independently of the request URL, meaning any site images that have not previously been cached can have their cache poisoned. This problem has been fixed in version 1.2.3. As a workaround, cached content can be cleared by re-deploying the site.

    Published: 23 Sept 2022
    3.7
    Low

    CVE-2022-39231

    Last Modified: 23 Apr 2025

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 4.10.16, or from 5.0.0 to 5.2.6, validation of the authentication adapter app ID for _Facebook_ and _Spotify_ may be circumvented. Configurations which allow users to authenticate using the Parse Server authentication adapter where `appIds` is set as a string instead of an array of strings authenticate requests from an app with a different app ID than the one specified in the `appIds` configuration. For this vulnerability to be exploited, an attacker needs to be assigned an app ID by the authentication provider which is a sub-set of the server-side configured app ID. This issue is patched in versions 4.10.16 and 5.2.7. There are no known workarounds.

    Published: 23 Sept 2022
    6.5
    Medium

    CVE-2022-39230

    Last Modified: 23 Apr 2025

    fhir-works-on-aws-authz-smart is an implementation of the authorization interface from the FHIR Works interface. Versions 3.1.1 and 3.1.2 are subject to Exposure of Sensitive Information to an Unauthorized Actor. This issue allows a client of the API to retrieve more information than the client’s OAuth scope permits when making “search-type” requests. This issue would not allow a client to retrieve information about individuals other than those the client was already authorized to access. Users of fhir-works-on-aws-authz-smart 3.1.1 or 3.1.2 should upgrade to version 3.1.3 or higher immediately. Versions 3.1.0 and below are unaffected. There is no workaround for this issue.

    Published: 23 Sept 2022
    4.3
    Medium

    CVE-2022-39225

    Last Modified: 23 Apr 2025

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 4.10.15, or 5.0.0 and above prior to 5.2.6, a user can write to the session object of another user if the session object ID is known. For example, an attacker can assign the session object to their own user by writing to the `user` field and then read any custom fields of that session object. Note that assigning a session to another user does not usually change the privileges of either of the two users, and a user cannot assign their own session to another user. This issue is patched in version 4.10.15 and above, and 5.2.6 and above. To mitigate this issue in unpatched versions add a `beforeSave` trigger to the `_Session` class and prevent writing if the requesting user is different from the user in the session object.

    Published: 23 Sept 2022
    7.8
    High

    CVE-2022-41322

    Last Modified: 1 Jun 2025

    In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.

    Published: 23 Sept 2022
    6.5
    Medium

    CVE-2022-41320

    Last Modified: 27 May 2025

    Veritas System Recovery (VSR) versions 18 and 21 store a network destination password in the Windows registry during configuration of the backup configuration. This vulnerability could provide a Windows user (who has sufficient privileges) to access a network file system that they were not authorized to access.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-37232

    Last Modified: 27 May 2025

    Netgear N300 wireless router wnr2000v4-V1.0.0.70 is vulnerable to Buffer Overflow via uhttpd. There is a stack overflow vulnerability caused by strcpy.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-37235

    Last Modified: 27 May 2025

    Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncat

    Published: 23 Sept 2022
    5.5
    Medium

    CVE-2022-3278

    Last Modified: 22 May 2025

    NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0552.

    Published: 23 Sept 2022
    7.8
    High

    CVE-2022-32814

    Last Modified: 27 May 2025

    A type confusion issue was addressed with improved state handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.

    Published: 23 Sept 2022
    7.1
    High

    CVE-2021-41803

    Last Modified: 27 May 2025

    HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1.11.9, 1.12.5, and 1.13.2."

    Published: 23 Sept 2022
    8.1
    High

    CVE-2020-36604

    Last Modified: 27 May 2025

    hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function.

    Published: 23 Sept 2022
    9.1
    Critical

    CVE-2022-35255

    Last Modified: 30 Apr 2025

    A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.

    Published: 23 Sept 2022
    6.5
    Medium

    CVE-2022-35256

    Last Modified: 30 Apr 2025

    The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

    Published: 23 Sept 2022
    9.8
    Critical

    CVE-2022-36944

    Last Modified: 27 May 2025

    Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0 functions) via a gadget chain.

    Published: 23 Sept 2022
    9.1
    Critical

    CVE-2022-39227

    Last Modified: 21 Nov 2024

    python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key. Depending on the application, this may for example enable the attacker to spoof other user's identities, hijack their sessions, or bypass authentication. Users should upgrade to version 3.3.4. There are no known workarounds.

    Published: 23 Sept 2022
    6.5
    Medium

    CVE-2022-41317

    Last Modified: 14 Apr 2025

    An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, there can be Exposure of Sensitive Information about clients using the proxy via an HTTPS request to an internal cache manager URL. This is fixed in 5.7.

    Published: 23 Sept 2022
    5.5
    Medium

    CVE-2022-32849

    Last Modified: 27 May 2025

    An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to access sensitive user information.

    Published: 23 Sept 2022
    7.5
    High

    CVE-2022-40188

    Last Modified: 27 May 2025

    Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must return large NS sets or address sets.

    Published: 23 Sept 2022