CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2022-36056

    Last Modified: 22 Apr 2025

    Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions prior to 1.12.0 a number of vulnerabilities have been found in cosign verify-blob, where Cosign would successfully verify an artifact when verification should have failed. First a cosign bundle can be crafted to successfully verify a blob even if the embedded rekorBundle does not reference the given signature. Second, when providing identity flags, the email and issuer of a certificate is not checked when verifying a Rekor bundle, and the GitHub Actions identity is never checked. Third, providing an invalid Rekor bundle without the experimental flag results in a successful verification. And fourth an invalid transparency log entry will result in immediate success for verification. Details and examples of these issues can be seen in the GHSA-8gw7-4j42-w388 advisory linked. Users are advised to upgrade to 1.12.0. There are no known workarounds for these issues.

    Published: 14 Sept 2022
    6.7
    Medium

    CVE-2022-20231

    Last Modified: 21 Nov 2024

    In smc_intc_request_fiq of arm_gic.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-211485702References: N/A

    Published: 14 Sept 2022
    4.6
    Medium

    CVE-2022-36113

    Last Modified: 23 Apr 2025

    Cargo is a package manager for the rust programming language. After a package is downloaded, Cargo extracts its source code in the ~/.cargo folder on disk, making it available to the Rust projects it builds. To record when an extraction is successful, Cargo writes "ok" to the .cargo-ok file at the root of the extracted source code once it extracted all the files. It was discovered that Cargo allowed packages to contain a .cargo-ok symbolic link, which Cargo would extract. Then, when Cargo attempted to write "ok" into .cargo-ok, it would actually replace the first two bytes of the file the symlink pointed to with ok. This would allow an attacker to corrupt one file on the machine using Cargo to extract the package. Note that by design Cargo allows code execution at build time, due to build scripts and procedural macros. The vulnerabilities in this advisory allow performing a subset of the possible damage in a harder to track down way. Your dependencies must still be trusted if you want to be protected from attacks, as it's possible to perform the same attacks with build scripts and procedural macros. The vulnerability is present in all versions of Cargo. Rust 1.64, to be released on September 22nd, will include a fix for it. Since the vulnerability is just a more limited way to accomplish what a malicious build scripts or procedural macros can do, we decided not to publish Rust point releases backporting the security fix. Patch files are available for Rust 1.63.0 are available in the wg-security-response repository for people building their own toolchain. Mitigations We recommend users of alternate registries to exercise care in which package they download, by only including trusted dependencies in their projects. Please note that even with these vulnerabilities fixed, by design Cargo allows arbitrary code execution at build time thanks to build scripts and procedural macros: a malicious dependency will be able to cause damage regardless of these vulnerabilities. crates.io implemented server-side checks to reject these kinds of packages years ago, and there are no packages on crates.io exploiting these vulnerabilities. crates.io users still need to exercise care in choosing their dependencies though, as remote code execution is allowed by design there as well.

    Published: 14 Sept 2022
    9.8
    Critical

    CVE-2022-37661

    Last Modified: 21 Nov 2024

    SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature.

    Published: 14 Sept 2022
    7.8
    High

    CVE-2022-20364

    Last Modified: 21 Nov 2024

    In sysmmu_unmap of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-233606615References: N/A

    Published: 14 Sept 2022
    5.4
    Medium

    CVE-2018-25047

    Last Modified: 3 Nov 2025

    In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user.

    Published: 14 Sept 2022
    4.8
    Medium

    CVE-2022-36114

    Last Modified: 23 Apr 2025

    Cargo is a package manager for the rust programming language. It was discovered that Cargo did not limit the amount of data extracted from compressed archives. An attacker could upload to an alternate registry a specially crafted package that extracts way more data than its size (also known as a "zip bomb"), exhausting the disk space on the machine using Cargo to download the package. Note that by design Cargo allows code execution at build time, due to build scripts and procedural macros. The vulnerabilities in this advisory allow performing a subset of the possible damage in a harder to track down way. Your dependencies must still be trusted if you want to be protected from attacks, as it's possible to perform the same attacks with build scripts and procedural macros. The vulnerability is present in all versions of Cargo. Rust 1.64, to be released on September 22nd, will include a fix for it. Since the vulnerability is just a more limited way to accomplish what a malicious build scripts or procedural macros can do, we decided not to publish Rust point releases backporting the security fix. Patch files are available for Rust 1.63.0 are available in the wg-security-response repository for people building their own toolchain. We recommend users of alternate registries to excercise care in which package they download, by only including trusted dependencies in their projects. Please note that even with these vulnerabilities fixed, by design Cargo allows arbitrary code execution at build time thanks to build scripts and procedural macros: a malicious dependency will be able to cause damage regardless of these vulnerabilities. crates.io implemented server-side checks to reject these kinds of packages years ago, and there are no packages on crates.io exploiting these vulnerabilities. crates.io users still need to excercise care in choosing their dependencies though, as the same concerns about build scripts and procedural macros apply here.

    Published: 14 Sept 2022
    8.1
    High

    CVE-2022-40674

    Last Modified: 30 May 2025

    libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

    Published: 14 Sept 2022
    8.8
    High

    CVE-2022-38305

    Last Modified: 21 Nov 2024

    AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 13 Sept 2022
    9.8
    Critical

    CVE-2022-38771

    Last Modified: 21 Nov 2024

    The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to send SCRIPT tags as injected input to the API request.

    Published: 13 Sept 2022
    5.3
    Medium

    CVE-2022-38770

    Last Modified: 21 Nov 2024

    The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch other users' data upon a successful login request.

    Published: 13 Sept 2022
    7.5
    High

    CVE-2022-38769

    Last Modified: 21 Nov 2024

    The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch cleartext passwords upon a successful login request.

    Published: 13 Sept 2022
    9.8
    Critical

    CVE-2022-38768

    Last Modified: 21 Nov 2024

    The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to bypass authorization.

    Published: 13 Sept 2022
    6.5
    Medium

    CVE-2022-37191

    Last Modified: 21 Nov 2024

    The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted POST request using [function] parameter value as LFI payload.

    Published: 13 Sept 2022
    8.8
    High

    CVE-2022-37190

    Last Modified: 21 Nov 2024

    CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.php.

    Published: 13 Sept 2022
    7.8
    High

    CVE-2022-31322

    Last Modified: 21 Nov 2024

    Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to escalate privileges via overwriting files using SUID flagged executables.

    Published: 13 Sept 2022
    6.5
    Medium

    CVE-2022-31324

    Last Modified: 21 Nov 2024

    An arbitrary file download vulnerability in the downloadAction() function of Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to download arbitrary files via a crafted POST request.

    Published: 13 Sept 2022
    9.8
    Critical

    CVE-2022-35413

    Last Modified: 21 Nov 2024

    WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential information (such as SSL keys) via an HTTPS request to the /webapi/ URI on port 443 or 5001.

    Published: 13 Sept 2022
    8.8
    High

    CVE-2022-35582

    Last Modified: 21 Nov 2024

    Penta Security Systems Inc WAPPLES 4.0.*, 5.0.0.*, 5.0.12.* are vulnerable to Incorrect Access Control. The operating system that WAPPLES runs on has a built-in non-privileged user penta with a predefined password. The password for this user, as well as its existence, is not disclosed in the documentation. Knowing the credentials, attackers can use this feature to gain uncontrolled access to the device and therefore are considered an undocumented possibility for remote control.

    Published: 13 Sept 2022
    5.4
    Medium

    CVE-2022-31861

    Last Modified: 21 Nov 2024

    Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.

    Published: 13 Sept 2022
    7.8
    High

    CVE-2022-34101

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can place a malicious DLL in a certain path to execute code and preform a privilege escalation attack.

    Published: 13 Sept 2022
    8.8
    High

    CVE-2022-34102

    Last Modified: 21 Nov 2024

    Insufficient access control vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can pause the uninstallation of an executable to gain a SYSTEM level command prompt.

    Published: 13 Sept 2022
    7.8
    High

    CVE-2022-38633

    Last Modified: 21 Nov 2024

    Genymotion Desktop v3.2.1 was discovered to contain a DLL hijacking vulnerability which allows attackers to escalate privileges and execute arbitrary code via a crafted binary.

    Published: 13 Sept 2022
    5.4
    Medium

    CVE-2021-36568

    Last Modified: 21 Nov 2024

    In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field name" and "Field description" are vulnerable to Cross Site Scripting Stored(XSS). This affects Moodle 3.11 and Moodle 3.10.4 and Moodle 3.9.7.

    Published: 13 Sept 2022
    7.8
    High

    CVE-2022-36768

    Last Modified: 21 Nov 2024

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to obtain root privileges. IBM X-Force ID: 232014.

    Published: 13 Sept 2022
    6.5
    Medium

    CVE-2022-35637

    Last Modified: 21 Nov 2024

    IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service after entering a malformed SQL statement into the Db2expln tool. IBM X-Force ID: 230823.

    Published: 13 Sept 2022
    7.8
    High

    CVE-2022-34356

    Last Modified: 21 Nov 2024

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to obtain root privileges. IBM X-Force ID: 230502.

    Published: 13 Sept 2022
    5.4
    Medium

    CVE-2022-34336

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229714.

    Published: 13 Sept 2022
    6.5
    Medium

    CVE-2022-22483

    Last Modified: 21 Nov 2024

    IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized access caused by improper privilege management when CREATE OR REPLACE command is used. IBM X-Force ID: 225979.

    Published: 13 Sept 2022
    5.3
    Medium

    CVE-2022-22330

    Last Modified: 21 Nov 2024

    IBM Control Desk 7.6.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 219126.

    Published: 13 Sept 2022
    4.3
    Medium

    CVE-2022-22329

    Last Modified: 21 Nov 2024

    IBM Control Desk 7.6.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 219124.

    Published: 13 Sept 2022
    6.1
    Medium

    CVE-2022-39814

    Last Modified: 21 Nov 2024

    In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter.

    Published: 13 Sept 2022
    9.8
    Critical

    CVE-2022-39815

    Last Modified: 21 Nov 2024

    In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated users to execute commands on the operating system.

    Published: 13 Sept 2022
    6.5
    Medium

    CVE-2022-39816

    Last Modified: 21 Nov 2024

    In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit configuration page. Exploitation requires an authenticated attacker.

    Published: 13 Sept 2022
    8.8
    High

    CVE-2022-39817

    Last Modified: 21 Nov 2024

    In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker. Through the injection of arbitrary SQL statements, a potential authenticated attacker can modify query syntax and perform unauthorized (and unexpected) operations against the remote database.

    Published: 13 Sept 2022
    8.8
    High

    CVE-2022-39819

    Last Modified: 21 Nov 2024

    In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This allows authenticated users to execute commands on the operating system.

    Published: 13 Sept 2022
    9.8
    Critical

    CVE-2022-38637

    Last Modified: 21 Nov 2024

    Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password parameters on the Login page.

    Published: 13 Sept 2022
    7.5
    High

    CVE-2022-39821

    Last Modified: 21 Nov 2024

    In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical information, such as cleartext user credentials, in world-readable files in the filesystem.

    Published: 13 Sept 2022
    8.8
    High

    CVE-2022-40623

    Last Modified: 21 Nov 2024

    The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 does not utilize anti-CSRF tokens, which, when combined with other issues (such as CVE-2022-35518), can lead to remote, unauthenticated command execution.

    Published: 13 Sept 2022
    8.8
    High

    CVE-2022-40622

    Last Modified: 21 Nov 2024

    The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and does not not use session tokens. Therefore, if an attacker changes their IP address to match the logged-in administrator's, or is behind the same NAT as the logged in administrator, session takeover is possible.

    Published: 13 Sept 2022
    7.5
    High

    CVE-2022-40621

    Last Modified: 21 Nov 2024

    Because the WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 and earlier communicates over HTTP and not HTTPS, and because the hashing mechanism does not rely on a server-supplied key, it is possible for an attacker with sufficient network access to capture the hashed password of a logged on user and use it in a classic Pass-the-Hash style attack.

    Published: 13 Sept 2022
    5.5
    Medium

    CVE-2022-38497

    Last Modified: 21 Nov 2024

    LIEF commit 365a16a was discovered to contain a segmentation violation via the component CoreFile.tcc:69.

    Published: 13 Sept 2022
    5.5
    Medium

    CVE-2022-38496

    Last Modified: 21 Nov 2024

    LIEF commit 365a16a was discovered to contain a reachable assertion abort via the component BinaryStream.hpp.

    Published: 13 Sept 2022
    7.8
    High

    CVE-2022-38495

    Last Modified: 21 Nov 2024

    LIEF commit 365a16a was discovered to contain a heap-buffer overflow via the function print_binary at /c/macho_reader.c.

    Published: 13 Sept 2022
    5.5
    Medium

    CVE-2022-38307

    Last Modified: 21 Nov 2024

    LIEF commit 5d1d643 was discovered to contain a segmentation violation via the function LIEF::MachO::SegmentCommand::file_offset() at /MachO/SegmentCommand.cpp.

    Published: 13 Sept 2022
    7.8
    High

    CVE-2022-38306

    Last Modified: 21 Nov 2024

    LIEF commit 5d1d643 was discovered to contain a heap-buffer overflow in the component /core/CorePrPsInfo.tcc.

    Published: 13 Sept 2022
    8.8
    High

    CVE-2022-32555

    Last Modified: 5 Jun 2025

    Unisys Data Exchange Management Studio before 6.0.IC2 and 7.x before 7.0.IC1 doesn't have an Anti-CSRF token to authenticate the POST request. Thus, a cross-site request forgery attack could occur.

    Published: 13 Sept 2022
    7
    High

    CVE-2022-3182

    Last Modified: 21 Nov 2024

    Improper Access Control vulnerability in the Duo SMS two-factor of Devolutions Remote Desktop Manager 2022.2.14 and earlier allows attackers to bypass the application lock. This issue affects: Devolutions Remote Desktop Manager version 2022.2.14 and prior versions.

    Published: 13 Sept 2022
    5.2
    Medium

    CVE-2022-32244

    Last Modified: 21 Nov 2024

    Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retrieve (non-personal) system data, modify system data but can't make the system unavailable. This needs the attacker to have high privilege access to the same physical/logical network to access information which would otherwise be restricted, leading to low impact on confidentiality and high impact on integrity of the application.

    Published: 13 Sept 2022
    5.5
    Medium

    CVE-2022-20399

    Last Modified: 21 Nov 2024

    In the SEPolicy configuration of system apps, there is a possible access to the 'ip' utility due to an insecure default value. This could lead to local information disclosure of network data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-219808546References: Upstream kernel

    Published: 13 Sept 2022