CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2022-40716

    Last Modified: 27 May 2025

    HashiCorp Consul and Consul Enterprise up to 1.11.8, 1.12.4, and 1.13.1 do not check for multiple SAN URI values in a CSR on the internal RPC endpoint, enabling leverage of privileged access to bypass service mesh intentions. Fixed in 1.11.9, 1.12.5, and 1.13.2."

    Published: 23 Sept 2022
    8.6
    High

    CVE-2022-41318

    Last Modified: 14 Apr 2025

    A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.

    Published: 23 Sept 2022
    6.1
    Medium

    CVE-2022-41319

    Last Modified: 27 May 2025

    A Reflected Cross-Site Scripting (XSS) vulnerability affects the Veritas Desktop Laptop Option (DLO) application login page (aka the DLOServer/restore/login.jsp URI). This affects versions before 9.8 (e.g., 9.1 through 9.7).

    Published: 23 Sept 2022
    5.5
    Medium

    CVE-2022-4269

    Last Modified: 14 Apr 2025

    A flaw was found in the Linux kernel Traffic Control (TC) subsystem. Using a specific networking configuration (redirecting egress packets to ingress using TC action "mirred") a local unprivileged user could trigger a CPU soft lockup (ABBA deadlock) when the transport protocol in use (TCP or SCTP) does a retransmission, resulting in a denial of service condition.

    Published: 23 Sept 2022
    8.8
    High

    CVE-2022-40298

    Last Modified: 27 May 2025

    Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the AirMedia Windows Application, version 4.3.1.39. A low privileged user can initiate a repair of the system and gain a SYSTEM level shell.

    Published: 22 Sept 2022
    9.8
    Critical

    CVE-2022-38573

    Last Modified: 27 May 2025

    10-Strike Network Inventory Explorer v9.3 was discovered to contain a buffer overflow via the Add Computers function.

    Published: 22 Sept 2022
    7.8
    High

    CVE-2022-30426

    Last Modified: 27 May 2025

    There is a stack buffer overflow vulnerability, which could lead to arbitrary code execution in UEFI DXE driver on some Acer products. An attack could exploit this vulnerability to escalate privilege from ring 3 to ring 0, and hijack control flow during UEFI DXE execution. This affects Altos T110 F3 firmware version <= P13 (latest) and AP130 F2 firmware version <= P04 (latest) and Aspire 1600X firmware version <= P11.A3L (latest) and Aspire 1602M firmware version <= P11.A3L (latest) and Aspire 7600U firmware version <= P11.A4 (latest) and Aspire MC605 firmware version <= P11.A4L (latest) and Aspire TC-105 firmware version <= P12.B0L (latest) and Aspire TC-120 firmware version <= P11-A4 (latest) and Aspire U5-620 firmware version <= P11.A1 (latest) and Aspire X1935 firmware version <= P11.A3L (latest) and Aspire X3475 firmware version <= P11.A3L (latest) and Aspire X3995 firmware version <= P11.A3L (latest) and Aspire XC100 firmware version <= P11.B3 (latest) and Aspire XC600 firmware version <= P11.A4 (latest) and Aspire Z3-615 firmware version <= P11.A2L (latest) and Veriton E430G firmware version <= P21.A1 (latest) and Veriton B630_49 firmware version <= AAP02SR (latest) and Veriton E430 firmware version <= P11.A4 (latest) and Veriton M2110G firmware version <= P21.A3 (latest) and Veriton M2120G fir.

    Published: 22 Sept 2022
    6.1
    Medium

    CVE-2022-23458

    Last Modified: 22 Apr 2025

    Toast UI Grid is a component to display and edit data. Versions prior to 4.21.3 are vulnerable to cross-site scripting attacks when pasting specially crafted content into editable cells. This issue was fixed in version 4.21.3. There are no known workarounds.

    Published: 22 Sept 2022
    9.8
    Critical

    CVE-2022-36934

    Last Modified: 24 Sept 2025

    An integer overflow in WhatsApp could result in remote code execution in an established video call.

    Published: 22 Sept 2022
    9.8
    Critical

    CVE-2022-40089

    Last Modified: 27 May 2025

    A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow_url_include is set to On.

    Published: 22 Sept 2022
    6.1
    Medium

    CVE-2022-40088

    Last Modified: 27 May 2025

    Simple College Website v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /college_website/index.php?page=. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter.

    Published: 22 Sept 2022
    9.8
    Critical

    CVE-2022-40087

    Last Modified: 27 May 2025

    Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 22 Sept 2022
    9.8
    Critical

    CVE-2022-31937

    Last Modified: 27 May 2025

    Netgear N300 wireless router wnr2000v4-V1.0.0.70 was discovered to contain a stack overflow via strcpy in uhttpd.

    Published: 22 Sept 2022
    3.1
    Low

    CVE-2021-27774

    Last Modified: 27 May 2025

    User input included in error response, which could be used in a phishing attack.

    Published: 22 Sept 2022
    7.8
    High

    CVE-2022-37234

    Last Modified: 27 May 2025

    Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncpy.

    Published: 22 Sept 2022
    3.5
    Low

    CVE-2022-3274

    Last Modified: 22 May 2025

    Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.7.

    Published: 22 Sept 2022
    6
    Medium

    CVE-2022-35894

    Last Modified: 5 May 2025

    An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The SMI handler for the FwBlockServiceSmm driver uses an untrusted pointer as the location to copy data to an attacker-specified buffer, leading to information disclosure.

    Published: 22 Sept 2022
    7.5
    High

    CVE-2022-34026

    Last Modified: 27 May 2025

    ICEcoder v8.1 allows attackers to execute a directory traversal.

    Published: 22 Sept 2022
    6.5
    Medium

    CVE-2022-35039

    Last Modified: 27 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e20a0.

    Published: 22 Sept 2022
    6.5
    Medium

    CVE-2022-35038

    Last Modified: 27 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b064d.

    Published: 22 Sept 2022
    6.5
    Medium

    CVE-2022-35037

    Last Modified: 27 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6adb1e.

    Published: 22 Sept 2022
    6.5
    Medium

    CVE-2022-35036

    Last Modified: 27 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e1fc8.

    Published: 22 Sept 2022
    6.5
    Medium

    CVE-2022-35035

    Last Modified: 27 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b559f.

    Published: 22 Sept 2022
    6.5
    Medium

    CVE-2022-35034

    Last Modified: 27 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e7e3d.

    Published: 22 Sept 2022
    6.5
    Medium

    CVE-2022-35032

    Last Modified: 27 May 2025

    OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6b6a8f.

    Published: 22 Sept 2022
    6.5
    Medium

    CVE-2022-35031

    Last Modified: 27 May 2025

    OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x703969.

    Published: 22 Sept 2022
    6.5
    Medium

    CVE-2022-35030

    Last Modified: 27 May 2025

    OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fe954.

    Published: 22 Sept 2022
    6.5
    Medium

    CVE-2022-35029

    Last Modified: 27 May 2025

    OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6babea.

    Published: 22 Sept 2022
    6.5
    Medium

    CVE-2022-35028

    Last Modified: 27 May 2025

    OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fbbb6.

    Published: 22 Sept 2022
    6.5
    Medium

    CVE-2022-35027

    Last Modified: 27 May 2025

    OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fe9a7.

    Published: 22 Sept 2022
    6.5
    Medium

    CVE-2022-35026

    Last Modified: 27 May 2025

    OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fbc0b.

    Published: 22 Sept 2022
    6.5
    Medium

    CVE-2022-35025

    Last Modified: 27 May 2025

    OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x5266a8.

    Published: 22 Sept 2022
    6.5
    Medium

    CVE-2022-35024

    Last Modified: 27 May 2025

    OTFCC commit 617837b was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S.

    Published: 22 Sept 2022
    6.5
    Medium

    CVE-2022-35023

    Last Modified: 27 May 2025

    OTFCC commit 617837b was discovered to contain a segmentation violation via /lib/x86_64-linux-gnu/libc.so.6+0xbb384.

    Published: 22 Sept 2022
    6.5
    Medium

    CVE-2022-35022

    Last Modified: 27 May 2025

    OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6badae.

    Published: 22 Sept 2022
    6.5
    Medium

    CVE-2022-35021

    Last Modified: 27 May 2025

    OTFCC commit 617837b was discovered to contain a global buffer overflow via /release-x64/otfccdump+0x718693.

    Published: 22 Sept 2022
    5.3
    Medium

    CVE-2021-39190

    Last Modified: 23 Apr 2025

    The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is publicly accessible in read-only mode. This issue is patched in version 2.3.0. No known workarounds exist.

    Published: 22 Sept 2022
    7.2
    High

    CVE-2022-40935

    Last Modified: 27 May 2025

    Online Pet Shop We App v1.0 is vulnerable to SQL Injection via /pet_shop/classes/Master.php?f=delete_category,id.

    Published: 22 Sept 2022
    7.2
    High

    CVE-2022-40934

    Last Modified: 27 May 2025

    Online Pet Shop We App v1.0 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_sub_category,id

    Published: 22 Sept 2022
    7.2
    High

    CVE-2022-40933

    Last Modified: 27 May 2025

    Online Pet Shop We App v1.0 by oretnom23 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_order,id.

    Published: 22 Sept 2022
    7.2
    High

    CVE-2022-40932

    Last Modified: 27 May 2025

    In Zoo Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of the "gallery" file of the "Gallery" module in the background management system.

    Published: 22 Sept 2022
    8.2
    High

    CVE-2022-35408

    Last Modified: 27 May 2025

    An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM callout vulnerability in the SMM driver in UsbLegacyControlSmm leads to possible arbitrary code execution in SMM and escalation of privileges. An attacker could overwrite the function pointers in the EFI_BOOT_SERVICES table before the USB SMI handler triggers. (This is not exploitable from code running in the operating system.)

    Published: 22 Sept 2022
    7.2
    High

    CVE-2022-40447

    Last Modified: 27 May 2025

    ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php.

    Published: 22 Sept 2022
    7.2
    High

    CVE-2022-40446

    Last Modified: 27 May 2025

    ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&groupid=.

    Published: 22 Sept 2022
    5.3
    Medium

    CVE-2022-40444

    Last Modified: 27 May 2025

    ZZCMS 2022 was discovered to contain a full path disclosure vulnerability via the page /admin/index.PHP? _server.

    Published: 22 Sept 2022
    5.3
    Medium

    CVE-2022-40443

    Last Modified: 27 May 2025

    An absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GET request sent to /one/siteinfo.php.

    Published: 22 Sept 2022
    4.3
    Medium

    CVE-2022-3267

    Last Modified: 23 May 2025

    Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.

    Published: 22 Sept 2022
    9.8
    Critical

    CVE-2022-3268

    Last Modified: 23 May 2025

    Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.

    Published: 22 Sept 2022
    6.1
    Medium

    CVE-2022-2266

    Last Modified: 20 May 2026

    University Library Automation System developed by Yordam Bilgi Teknolojileri before version 19.2 has an unauthenticated Reflected XSS vulnerability. This has been fixed in the version 19.2

    Published: 22 Sept 2022
    7.5
    High

    CVE-2022-40705

    Last Modified: 21 Nov 2024

    An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files over HTTP. This issue affects Apache SOAP version 2.2 and later versions. It is unknown whether previous versions are also affected. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 22 Sept 2022