CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2020-23557

    Last Modified: 21 Nov 2024

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000000755d.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2020-23556

    Last Modified: 21 Nov 2024

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e28.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2020-23555

    Last Modified: 21 Nov 2024

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e6e.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2020-23554

    Last Modified: 21 Nov 2024

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e20.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2020-23553

    Last Modified: 21 Nov 2024

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007d33.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2020-23552

    Last Modified: 21 Nov 2024

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e62.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2020-23551

    Last Modified: 21 Nov 2024

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e30.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2020-23550

    Last Modified: 21 Nov 2024

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e82.

    Published: 16 Sept 2022
    9.8
    Critical

    CVE-2022-36536

    Last Modified: 21 Nov 2024

    An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens.

    Published: 16 Sept 2022
    5.4
    Medium

    CVE-2022-36533

    Last Modified: 21 Nov 2024

    Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain a cross-site scripting (XSS) vulnerability.

    Published: 16 Sept 2022
    8.8
    High

    CVE-2022-36532

    Last Modified: 21 Nov 2024

    Bolt CMS contains a vulnerability in version 5.1.12 and below that allows an authenticated user with the ROLE_EDITOR privileges to upload and rename a malicious file to achieve remote code execution.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-35415

    Last Modified: 21 Nov 2024

    An improper input validation in NI System Configuration Manager before 22.5 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 16 Sept 2022
    6.5
    Medium

    CVE-2022-34002

    Last Modified: 21 Nov 2024

    The ‘document’ parameter of PDS Vista 7’s /application/documents/display.aspx page is vulnerable to a Local File Inclusion vulnerability which allows an low-privileged authenticated attacker to leak the configuration files and source code of the web application.

    Published: 16 Sept 2022
    10
    Critical

    CVE-2022-26959

    Last Modified: 21 Nov 2024

    There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version 6.3 application. The vulnerabilities exist in the userName parameter of the processlogin.jsp page in the /northstar/Portal/ directory and the userID parameter of the login.jsp page in the /northstar/iphone/ directory. Exploitation of the SQL injection vulnerabilities allows full access to the database which contains critical data for organization’s that make full use of the software suite.

    Published: 16 Sept 2022
    9.8
    Critical

    CVE-2021-40017

    Last Modified: 21 Nov 2024

    The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may result in out-of-bounds memory access.

    Published: 16 Sept 2022
    8.8
    High

    CVE-2022-36534

    Last Modified: 21 Nov 2024

    Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution (RCE) vulnerabilities via the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.php.

    Published: 16 Sept 2022
    9.8
    Critical

    CVE-2022-39002

    Last Modified: 21 Nov 2024

    Double free vulnerability in the storage module. Successful exploitation of this vulnerability will cause the memory to be freed twice.

    Published: 16 Sept 2022
    6.5
    Medium

    CVE-2022-40152

    Last Modified: 23 May 2025

    Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

    Published: 16 Sept 2022
    5.1
    Medium

    CVE-2022-3172

    Last Modified: 13 Feb 2025

    A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.

    Published: 16 Sept 2022
    6.5
    Medium

    CVE-2022-40149

    Last Modified: 21 Apr 2025

    Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

    Published: 16 Sept 2022
    6.5
    Medium

    CVE-2022-40150

    Last Modified: 21 Apr 2025

    Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by Out of memory. This effect may support a denial of service attack.

    Published: 16 Sept 2022
    6.5
    Medium

    CVE-2022-40151

    Last Modified: 23 May 2025

    Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

    Published: 16 Sept 2022
    4.9
    Medium

    CVE-2022-2863

    Last Modified: 21 Nov 2024

    The Migration, Backup, Staging WordPress plugin before 0.9.76 does not sanitise and validate a parameter before using it to read the content of a file, allowing high privilege users to read any file from the web server via a Traversal attack

    Published: 16 Sept 2022
    6.4
    Medium

    CVE-2022-36074

    Last Modified: 23 Apr 2025

    Nextcloud server is an open source personal cloud product. Affected versions of this package are vulnerable to Information Exposure which fails to strip the Authorization header on HTTP downgrade. This can lead to account access exposure and compromise. It is recommended that the Nextcloud Server is upgraded to 23.0.7 or 24.0.3. It is recommended that the Nextcloud Enterprise Server is upgraded to 22.2.11, 23.0.7 or 24.0.3. There are no known workarounds for this issue.

    Published: 15 Sept 2022
    7.5
    High

    CVE-2022-27561

    Last Modified: 21 Nov 2024

    There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf).

    Published: 15 Sept 2022
    2.6
    Low

    CVE-2022-36075

    Last Modified: 23 Apr 2025

    Nextcloud files access control is a nextcloud app to manage access control for files. Users with limited access can see file names in certain cases where they do not have privilege to do so. This issue has been addressed and it is recommended that the Nextcloud Files Access Control app is upgraded to 1.12.2, 1.13.1 or 1.14.1. There are no known workarounds for this issue

    Published: 15 Sept 2022
    7.5
    High

    CVE-2022-39213

    Last Modified: 22 Apr 2025

    go-cvss is a Go module to manipulate Common Vulnerability Scoring System (CVSS). In affected versions when a full CVSS v2.0 vector string is parsed using `ParseVector`, an Out-of-Bounds Read is possible due to a lack of tests. The Go module will then panic. The problem is patched in tag `v0.4.0`, by the commit `d9d478ff0c13b8b09ace030db9262f3c2fe031f4`. Users are advised to upgrade. Users unable to upgrade may avoid this issue by parsing only CVSS v2.0 vector strings that do not have all attributes defined (e.g. `AV:N/AC:L/Au:N/C:P/I:P/A:C/E:U/RL:OF/RC:C/CDP:MH/TD:H/CR:M/IR:M/AR:M`). As stated in [SECURITY.md](https://github.com/pandatix/go-cvss/blob/master/SECURITY.md), the CPE v2.3 to refer to this Go module is `cpe:2.3:a:pandatix:go_cvss:*:*:*:*:*:*:*:*`. The entry has already been requested to the NVD CPE dictionary.

    Published: 15 Sept 2022
    8.3
    High

    CVE-2022-39215

    Last Modified: 22 Apr 2025

    Tauri is a framework for building binaries for all major desktop platforms. Due to missing canonicalization when `readDir` is called recursively, it was possible to display directory listings outside of the defined `fs` scope. This required a crafted symbolic link or junction folder inside an allowed path of the `fs` scope. No arbitrary file content could be leaked. The issue has been resolved in version 1.0.6 and the implementation now properly checks if the requested (sub) directory is a symbolic link outside of the defined `scope`. Users are advised to upgrade. Users unable to upgrade should disable the `readDir` endpoint in the `allowlist` inside the `tauri.conf.json`.

    Published: 15 Sept 2022
    8.1
    High

    CVE-2022-29240

    Last Modified: 23 Apr 2025

    Scylla is a real-time big data database that is API-compatible with Apache Cassandra and Amazon DynamoDB. When decompressing CQL frame received from user, Scylla assumes that user-provided uncompressed length is correct. If user provides fake length, that is greater than the real one, part of decompression buffer won't be overwritten, and will be left uninitialized. This can be exploited in several ways, depending on the privileges of the user. 1. The main exploit is that an attacker with access to CQL port, but no user account, can bypass authentication, but only if there are other legitimate clients making connections to the cluster, and they use LZ4. 2. Attacker that already has a user account on the cluster can read parts of uninitialized memory, which can contain things like passwords of other users or fragments of other queries / results, which leads to authorization bypass and sensitive information disclosure. The bug has been patched in the following versions: Scylla Enterprise: 2020.1.14, 2021.1.12, 2022.1.0. Scylla Open Source: 4.6.7, 5.0.3. Users unable to upgrade should make sure none of their drivers connect to cluster using LZ4 compression, and that Scylla CQL port is behind firewall. Additionally make sure no untrusted client can connect to Scylla, by setting up authentication and applying workarounds from previous point (firewall, no lz4 compression).

    Published: 15 Sept 2022
    5.4
    Medium

    CVE-2022-38814

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the auth_settings component of FiberHome AN5506-02-B vRP2521 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the sncfg_loid text field.

    Published: 15 Sept 2022
    9.8
    Critical

    CVE-2022-38326

    Last Modified: 21 Nov 2024

    Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the page parameter at /goform/NatStaticSetting.

    Published: 15 Sept 2022
    9.8
    Critical

    CVE-2022-38325

    Last Modified: 21 Nov 2024

    Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the filePath parameter at /goform/expandDlnaFile.

    Published: 15 Sept 2022
    7.5
    High

    CVE-2022-37260

    Last Modified: 21 Nov 2024

    A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the input variable in main.js.

    Published: 15 Sept 2022
    7.2
    High

    CVE-2022-38535

    Last Modified: 21 Nov 2024

    TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg function.

    Published: 15 Sept 2022
    7.2
    High

    CVE-2022-38534

    Last Modified: 21 Nov 2024

    TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setdiagnosicfg function.

    Published: 15 Sept 2022
    9.8
    Critical

    CVE-2022-37861

    Last Modified: 21 Nov 2024

    There is a remote code execution (RCE) vulnerability in Tenhot TWS-100 V4.0-201809201424 router device. It is necessary to know that the device account password is allowed to escape the execution system command through the network tools in the network diagnostic component.

    Published: 15 Sept 2022
    9.8
    Critical

    CVE-2022-37264

    Last Modified: 21 Nov 2024

    Prototype pollution vulnerability in stealjs steal 2.2.4 via the optionName variable in main.js.

    Published: 15 Sept 2022
    7.5
    High

    CVE-2022-37262

    Last Modified: 21 Nov 2024

    A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the source and sourceWithComments variable in main.js.

    Published: 15 Sept 2022
    5.5
    Medium

    CVE-2022-38890

    Last Modified: 21 Nov 2024

    Nginx NJS v0.7.7 was discovered to contain a segmentation violation via njs_utf8_next at src/njs_utf8.h

    Published: 15 Sept 2022
    7.8
    High

    CVE-2022-40663

    Last Modified: 29 Apr 2025

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Viewer 1.2100.1483.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF images. Crafted data in a TIF image can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15697.

    Published: 15 Sept 2022
    7.8
    High

    CVE-2022-40662

    Last Modified: 30 Apr 2025

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Viewer 1.2100.1483.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF images. Crafted data in a TIF image can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15351.

    Published: 15 Sept 2022
    7.8
    High

    CVE-2022-40661

    Last Modified: 10 Apr 2025

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Viewer 1.2100.1483.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of BMP images. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15134.

    Published: 15 Sept 2022
    7.8
    High

    CVE-2022-40660

    Last Modified: 11 Apr 2025

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Viewer 1.2100.1483.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PSD images. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15135.

    Published: 15 Sept 2022
    7.8
    High

    CVE-2022-40659

    Last Modified: 11 Apr 2025

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Viewer 1.2100.1483.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF images. Crafted data in a TIF file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15214.

    Published: 15 Sept 2022
    7.8
    High

    CVE-2022-40658

    Last Modified: 11 Apr 2025

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Viewer 1.2100.1483.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF images. Crafted data in a TIF file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15166.

    Published: 15 Sept 2022
    7.8
    High

    CVE-2022-40657

    Last Modified: 23 Apr 2025

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Viewer 1.2100.1483.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PSD files. Crafted data in a PSD file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15073.

    Published: 15 Sept 2022
    7.8
    High

    CVE-2022-40655

    Last Modified: 3 Apr 2025

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Viewer 1.2100.1483.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ND2 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15071.

    Published: 15 Sept 2022
    7.8
    High

    CVE-2022-40656

    Last Modified: 10 Apr 2025

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Viewer 13.2.0.21165. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ND2 files. Crafted data in a ND2 file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15072.

    Published: 15 Sept 2022
    7.8
    High

    CVE-2022-40654

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_T files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18351.

    Published: 15 Sept 2022
    7.8
    High

    CVE-2022-40653

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18349.

    Published: 15 Sept 2022