CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-38823

    Last Modified: 21 Nov 2024

    In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample.

    Published: 16 Sept 2022
    9.8
    Critical

    CVE-2022-38826

    Last Modified: 21 Nov 2024

    In TOTOLINK T6 V4.1.5cu.709_B20210518, there is an execute arbitrary command in cstecgi.cgi.

    Published: 16 Sept 2022
    9.8
    Critical

    CVE-2022-38827

    Last Modified: 21 Nov 2024

    TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to Buffer Overflow via cstecgi.cgi

    Published: 16 Sept 2022
    9.8
    Critical

    CVE-2022-38828

    Last Modified: 21 Nov 2024

    TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to command injection via cstecgi.cgi

    Published: 16 Sept 2022
    8.8
    High

    CVE-2022-38808

    Last Modified: 21 Nov 2024

    ywoa v6.1 is vulnerable to SQL Injection via backend/oa/visual/exportExcel.do interface.

    Published: 16 Sept 2022
    8.8
    High

    CVE-2022-38843

    Last Modified: 21 Nov 2024

    EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server. Attacker may execute these malicious files to run unintended code on the server to compromise the server.

    Published: 16 Sept 2022
    8
    High

    CVE-2022-38844

    Last Modified: 21 Nov 2024

    CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloads capable of executing system commands. Admin user exporting contacts in CSV file may end up executing the malicious system commands on his system.

    Published: 16 Sept 2022
    6.1
    Medium

    CVE-2022-38845

    Last Modified: 21 Nov 2024

    Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending crafted csv file containing malicious JavaScript to authenticated user. Any authenticated user importing the crafted CSV file may end up running the malicious JavaScripting in the browser.

    Published: 16 Sept 2022
    5.9
    Medium

    CVE-2022-38846

    Last Modified: 21 Nov 2024

    EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attacker may capture the cookie from the insecure channel using MITM attack.

    Published: 16 Sept 2022
    6.1
    Medium

    CVE-2022-3223

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.3.1.

    Published: 16 Sept 2022
    4.3
    Medium

    CVE-2022-2913

    Last Modified: 3 Jun 2025

    The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spoof IP addresses on the allow list and bypass the need for captcha on the login screen.

    Published: 16 Sept 2022
    4.3
    Medium

    CVE-2022-2912

    Last Modified: 3 Jun 2025

    The Craw Data WordPress plugin through 1.0.0 does not implement nonce checks, which could allow attackers to make a logged in admin change the url value performing unwanted crawls on third-party sites (SSRF).

    Published: 16 Sept 2022
    5.3
    Medium

    CVE-2022-2877

    Last Modified: 21 Nov 2024

    The Titan Anti-spam & Security WordPress plugin before 7.3.1 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.

    Published: 16 Sept 2022
    4.8
    Medium

    CVE-2022-2887

    Last Modified: 21 Nov 2024

    The WP Server Health Stats WordPress plugin before 1.7.0 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 16 Sept 2022
    4.8
    Medium

    CVE-2022-2799

    Last Modified: 21 Nov 2024

    The Affiliates Manager WordPress plugin before 2.9.14 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 16 Sept 2022
    8
    High

    CVE-2022-2798

    Last Modified: 21 Nov 2024

    The Affiliates Manager WordPress plugin before 2.9.14 does not validate and sanitise the affiliate data, which could allow users registering as affiliate to perform CSV injection attacks against an admin exporting the data

    Published: 16 Sept 2022
    4.8
    Medium

    CVE-2022-2737

    Last Modified: 21 Nov 2024

    The WP STAGING WordPress plugin before 2.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 16 Sept 2022
    6.1
    Medium

    CVE-2022-2669

    Last Modified: 5 Jun 2025

    The WP Taxonomy Import WordPress plugin through 1.0.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

    Published: 16 Sept 2022
    6.1
    Medium

    CVE-2022-2655

    Last Modified: 21 Nov 2024

    The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

    Published: 16 Sept 2022
    6.1
    Medium

    CVE-2022-2654

    Last Modified: 5 Jun 2025

    The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core before 1.10) do not escape a parameter before outputting it back in attributes, leading to Reflected Cross-Site Scripting

    Published: 16 Sept 2022
    4.8
    Medium

    CVE-2022-2635

    Last Modified: 21 Nov 2024

    The Autoptimize WordPress plugin before 3.1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 16 Sept 2022
    4.8
    Medium

    CVE-2022-2575

    Last Modified: 21 Nov 2024

    The WBW Currency Switcher for WooCommerce WordPress plugin before 1.6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 16 Sept 2022
    4.8
    Medium

    CVE-2022-2351

    Last Modified: 21 Nov 2024

    The Post SMTP Mailer/Email Log WordPress plugin before 2.1.4 does not escape some of its settings before outputting them in the admins dashboard, allowing high privilege users to perform Cross-Site Scripting attacks against other users even when the unfiltered_html capability is disallowed.

    Published: 16 Sept 2022
    8.8
    High

    CVE-2022-1194

    Last Modified: 21 Nov 2024

    The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability.

    Published: 16 Sept 2022
    9.8
    Critical

    CVE-2022-25708

    Last Modified: 4 Jun 2025

    Memory corruption in WLAN due to buffer copy without checking size of input while parsing keys in Snapdragon Connectivity, Snapdragon Mobile

    Published: 16 Sept 2022
    8.2
    High

    CVE-2022-25706

    Last Modified: 21 Nov 2024

    Information disclosure in Bluetooth driver due to buffer over-read while reading l2cap length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 16 Sept 2022
    8.4
    High

    CVE-2022-25696

    Last Modified: 21 Nov 2024

    Memory corruption in display due to time-of-check time-of-use race condition during map or unmap in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 16 Sept 2022
    8.4
    High

    CVE-2022-25693

    Last Modified: 21 Nov 2024

    Memory corruption in graphics due to use-after-free while graphics profiling in Snapdragon Connectivity, Snapdragon Mobile

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-25690

    Last Modified: 21 Nov 2024

    Information disclosure in WLAN due to improper validation of array index while parsing crafted ANQP action frames in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

    Published: 16 Sept 2022
    7.3
    High

    CVE-2022-25688

    Last Modified: 21 Nov 2024

    Memory corruption in video due to buffer overflow while parsing ps video clips in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 16 Sept 2022
    7.3
    High

    CVE-2022-25686

    Last Modified: 21 Nov 2024

    Memory corruption in video module due to buffer overflow while processing WAV file in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-25670

    Last Modified: 21 Nov 2024

    Denial of service in WLAN HOST due to buffer over read while unpacking frames in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-25669

    Last Modified: 21 Nov 2024

    Denial of service in video due to buffer over read while parsing MP4 clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 16 Sept 2022
    8.4
    High

    CVE-2022-25656

    Last Modified: 21 Nov 2024

    Possible integer overflow and memory corruption due to improper validation of buffer size sent to write to console when computing the payload size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 16 Sept 2022
    6.7
    Medium

    CVE-2022-25654

    Last Modified: 21 Nov 2024

    Memory corruption in kernel due to improper input validation while processing ION commands in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

    Published: 16 Sept 2022
    9
    Critical

    CVE-2022-25652

    Last Modified: 21 Nov 2024

    Cryptographic issues in BSP due to improper hash verification in Snapdragon Wired Infrastructure and Networking

    Published: 16 Sept 2022
    6.8
    Medium

    CVE-2022-25653

    Last Modified: 21 Nov 2024

    Information disclosure in video due to buffer over-read while processing avi file in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 16 Sept 2022
    9.4
    Critical

    CVE-2022-22105

    Last Modified: 21 Nov 2024

    Memory corruption in bluetooth due to integer overflow while processing HFP-UNIT profile in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music

    Published: 16 Sept 2022
    8.4
    High

    CVE-2022-22095

    Last Modified: 21 Nov 2024

    Memory corruption in synx driver due to use-after-free condition in the synx driver due to accessing object handles without acquiring lock in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-22094

    Last Modified: 21 Nov 2024

    memory corruption in Kernel due to race condition while getting mapping reference in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-22093

    Last Modified: 21 Nov 2024

    Memory corruption or temporary denial of service due to improper handling of concurrent hypervisor operations to attach or detach IRQs from virtual interrupt sources in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-22092

    Last Modified: 21 Nov 2024

    Memory corruption in kernel due to use after free issue in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-22091

    Last Modified: 21 Nov 2024

    Improper authorization of a replayed LTE security mode command can lead to a denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 16 Sept 2022
    8.4
    High

    CVE-2022-22081

    Last Modified: 21 Nov 2024

    Memory corruption in audio module due to integer overflow in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wearables

    Published: 16 Sept 2022
    8.4
    High

    CVE-2022-22089

    Last Modified: 21 Nov 2024

    Memory corruption in audio while playing record due to improper list handling in two threads in Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wearables

    Published: 16 Sept 2022
    8.4
    High

    CVE-2022-22074

    Last Modified: 21 Nov 2024

    Memory Corruption during wma file playback due to integer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 16 Sept 2022
    8.4
    High

    CVE-2022-22066

    Last Modified: 21 Nov 2024

    Memory corruption occurs while processing command received from HLOS due to improper length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 16 Sept 2022
    7.8
    High

    CVE-2020-23560

    Last Modified: 21 Nov 2024

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000001bcab.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2020-23559

    Last Modified: 21 Nov 2024

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000007d7f.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2020-23558

    Last Modified: 21 Nov 2024

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000007f4b.

    Published: 16 Sept 2022