CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2022-3193

    Last Modified: 20 May 2025

    An HTML injection/reflected Cross-site scripting (XSS) vulnerability was found in the ovirt-engine. A parameter "error_description" fails to sanitize the entry, allowing the vulnerability to trigger on the Windows Service Accounts home pages.

    Published: 13 Sept 2022
    4.9
    Medium

    CVE-2022-35295

    Last Modified: 21 Nov 2024

    In SAP Host Agent (SAPOSCOL) - version 7.22, an attacker may use files created by saposcol to escalate privileges for themselves.

    Published: 13 Sept 2022
    8.8
    High

    CVE-2022-35823

    Last Modified: 11 Mar 2025

    Microsoft SharePoint Remote Code Execution Vulnerability

    Published: 13 Sept 2022
    6.5
    Medium

    CVE-2022-35837

    Last Modified: 11 Mar 2025

    Windows Graphics Component Information Disclosure Vulnerability

    Published: 13 Sept 2022
    7.8
    High

    CVE-2022-37956

    Last Modified: 11 Mar 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 13 Sept 2022
    7.5
    High

    CVE-2022-38013

    Last Modified: 27 May 2026

    .NET Core and Visual Studio Denial of Service Vulnerability

    Published: 13 Sept 2022
    8.5
    High

    CVE-2022-38342

    Last Modified: 21 Nov 2024

    Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a XML External Entity (XXE) vulnerability which allows authenticated attackers to perform data exfiltration or Server-Side Request Forgery (SSRF) attacks.

    Published: 13 Sept 2022
    9.8
    Critical

    CVE-2022-38538

    Last Modified: 21 Nov 2024

    Archery v1.7.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the checksum parameter in the report module.

    Published: 13 Sept 2022
    9.8
    Critical

    CVE-2022-38541

    Last Modified: 21 Nov 2024

    Archery v1.8.3 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_time and stop_time parameters in the my2sql interface.

    Published: 13 Sept 2022
    6.3
    Medium

    CVE-2022-3190

    Last Modified: 3 Nov 2025

    Infinite loop in the F5 Ethernet Trailer protocol dissector in Wireshark 3.6.0 to 3.6.7 and 3.4.0 to 3.4.15 allows denial of service via packet injection or crafted capture file

    Published: 13 Sept 2022
    3.3
    Low

    CVE-2022-37703

    Last Modified: 4 Nov 2025

    In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary. An attacker can abuse this vulnerability to know if a directory exists or not anywhere in the fs. The binary will use `opendir()` as root directly without checking the path, letting the attacker provide an arbitrary path.

    Published: 13 Sept 2022
    4.3
    Medium

    CVE-2022-38329

    Last Modified: 28 Mar 2025

    A CSRF vulnerability in Shopxian CMS 3.0.0 could allow an unauthenticated, remote attacker to craft a malicious link, potentially causing the administrator to perform unintended actions on an affected system. The vulnerability could allow attackers to modify or delete specific content through crafted requests, potentially leading to data loss and system integrity issues.

    Published: 13 Sept 2022
    7.2
    High

    CVE-2022-38304

    Last Modified: 21 Nov 2024

    Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /maintenance/manage_leave_type.php.

    Published: 12 Sept 2022
    7.2
    High

    CVE-2022-38303

    Last Modified: 21 Nov 2024

    Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /employees/manage_leave_type.php.

    Published: 12 Sept 2022
    7.2
    High

    CVE-2022-38302

    Last Modified: 21 Nov 2024

    Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /maintenance/manage_department.php.

    Published: 12 Sept 2022
    9.8
    Critical

    CVE-2022-38297

    Last Modified: 21 Nov 2024

    UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.

    Published: 12 Sept 2022
    4.3
    Medium

    CVE-2022-38299

    Last Modified: 21 Nov 2024

    An issue in the Elasticsearch plugin of Appsmith v1.7.11 allows attackers to connect disallowed hosts to the AWS/GCP internal metadata endpoint.

    Published: 12 Sept 2022
    8.8
    High

    CVE-2022-38298

    Last Modified: 21 Nov 2024

    Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming requests to the AWS internal metadata endpoint.

    Published: 12 Sept 2022
    7.5
    High

    CVE-2022-35572

    Last Modified: 21 Nov 2024

    On Linksys E5350 WiFi Router with firmware version 1.0.00.037 and lower, (and potentially other vendors/devices due to code reuse), the /SysInfo.htm URI does not require a session ID. This web page calls a show_sysinfo function which retrieves WPA passwords, SSIDs, MAC Addresses, serial numbers, WPS Pins, and hardware/firmware versions, and prints this information into the web page. This web page is visible when remote management is enabled. A user who has access to the web interface of the device can extract these secrets. If the device has remote management enabled and is connected directly to the internet, this vulnerability is exploitable over the internet without interaction.

    Published: 12 Sept 2022
    8.1
    High

    CVE-2022-36173

    Last Modified: 21 Nov 2024

    FreshService macOS Agent < 4.4.0 and FreshServce Linux Agent < 3.4.0 are vulnerable to TLS Man-in-The-Middle via the FreshAgent client and scheduled update service.

    Published: 12 Sept 2022
    8.1
    High

    CVE-2022-36174

    Last Modified: 21 Nov 2024

    FreshService Windows Agent < 2.11.0 and FreshService macOS Agent < 4.2.0 and FreshService Linux Agent < 3.3.0. are vulnerable to Broken integrity checking via the FreshAgent client and scheduled update service.

    Published: 12 Sept 2022
    6.5
    Medium

    CVE-2021-44425

    Last Modified: 21 Nov 2024

    An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.3. An unnecessarily open listening port on a machine in the LAN of an attacker, opened by the Anydesk Windows client when using the tunneling feature, allows the attacker unauthorized access to the local machine's AnyDesk tunneling protocol stack (and also to any remote destination machine software that is listening to the AnyDesk tunneled port).

    Published: 12 Sept 2022
    8.8
    High

    CVE-2021-44426

    Last Modified: 21 Nov 2024

    An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.5. An upload of an arbitrary file to a victim's local ~/Downloads/ directory is possible if the victim is using the AnyDesk Windows client to connect to a remote machine, if an attacker is also connected remotely with AnyDesk to the same remote machine. The upload is done without any approval or action taken by the victim.

    Published: 12 Sept 2022
    9.8
    Critical

    CVE-2022-38296

    Last Modified: 21 Nov 2024

    Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.

    Published: 12 Sept 2022
    6.1
    Medium

    CVE-2022-38295

    Last Modified: 21 Nov 2024

    Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Add New Group function.

    Published: 12 Sept 2022
    9.8
    Critical

    CVE-2022-38292

    Last Modified: 21 Nov 2024

    SLiMS Senayan Library Management System v9.4.2 was discovered to contain multiple Server-Side Request Forgeries via the components /bibliography/marcsru.php and /bibliography/z3950sru.php.

    Published: 12 Sept 2022
    6.1
    Medium

    CVE-2022-38291

    Last Modified: 21 Nov 2024

    SLiMS Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Search function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search bar.

    Published: 12 Sept 2022
    7.3
    High

    CVE-2022-39200

    Last Modified: 23 Apr 2025

    Dendrite is a Matrix homeserver written in Go. In affected versions events retrieved from a remote homeserver using the `/get_missing_events` path did not have their signatures verified correctly. This could potentially allow a remote homeserver to provide invalid/modified events to Dendrite via this endpoint. Note that this does not apply to events retrieved through other endpoints (e.g. `/event`, `/state`) as they have been correctly verified. Homeservers that have federation disabled are not vulnerable. The problem has been fixed in Dendrite 0.9.8. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 12 Sept 2022
    7.2
    High

    CVE-2022-38606

    Last Modified: 21 Nov 2024

    Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editcategory.php.

    Published: 12 Sept 2022
    7.2
    High

    CVE-2022-38610

    Last Modified: 21 Nov 2024

    Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editclient.php.

    Published: 12 Sept 2022
    7.2
    High

    CVE-2022-38605

    Last Modified: 21 Nov 2024

    Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_event.php.

    Published: 12 Sept 2022
    6.3
    Medium

    CVE-2022-36102

    Last Modified: 23 Apr 2025

    Shopware is an open source e-commerce software. In affected versions if backend admin controllers are called with a certain notation, the ACL could be bypassed. Users could execute actions, which they are normally not able to do. Users are advised to update to the current version (5.7.15). Users can get the update via the Auto-Updater or directly via the download overview. There are no known workarounds for this issue.

    Published: 12 Sept 2022
    5.4
    Medium

    CVE-2022-36101

    Last Modified: 23 Apr 2025

    Shopware is an open source e-commerce software. In affected versions the request for the customer detail view in the backend administration contained sensitive data like the hashed password and the session ID. These fields are now explicitly unset in version 5.7.15. Users are advised to update and may get the update either via the Auto-Updater or directly via the download overview. There are no known workarounds for this issue.

    Published: 12 Sept 2022
    8.5
    High

    CVE-2022-29490

    Last Modified: 21 Nov 2024

    Improper Authorization vulnerability exists in the Workplace X WebUI of the Hitachi Energy MicroSCADA X SYS600 allows an authenticated user to execute any MicroSCADA internal scripts irrespective of the authenticated user's role. This issue affects: Hitachi Energy MicroSCADA X SYS600 version 10 to version 10.3.1. cpe:2.3:a:hitachienergy:microscada_x_sys600:10:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.1.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3.1:*:*:*:*:*:*:*

    Published: 12 Sept 2022
    7.8
    High

    CVE-2022-2979

    Last Modified: 16 Apr 2025

    Opening a specially crafted file could cause the affected product to fail to release its memory reference potentially resulting in arbitrary code execution.

    Published: 12 Sept 2022
    5.4
    Medium

    CVE-2022-38135

    Last Modified: 20 Feb 2025

    Broken Access Control vulnerability in Dean Oakley's Photospace Gallery plugin <= 2.3.5 at WordPress allows users with subscriber or higher role to change plugin settings.

    Published: 12 Sept 2022
    7.1
    High

    CVE-2022-31226

    Last Modified: 21 Nov 2024

    Dell BIOS versions contain a Stack-based Buffer Overflow vulnerability. A local authenticated malicious user could potentially exploit this vulnerability by sending excess data to a function in order to gain arbitrary code execution on the system.

    Published: 12 Sept 2022
    3
    Low

    CVE-2022-31225

    Last Modified: 21 Nov 2024

    Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administrator user could potentially exploit this vulnerability in order to change the state of the system or cause unexpected failures.

    Published: 12 Sept 2022
    2
    Low

    CVE-2022-31224

    Last Modified: 21 Nov 2024

    Dell BIOS versions contain an Improper Protection Against Voltage and Clock Glitches vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by triggering a fault condition in order to change the behavior of the system.

    Published: 12 Sept 2022
    2.3
    Low

    CVE-2022-31223

    Last Modified: 21 Nov 2024

    Dell BIOS versions contain an Improper Neutralization of Null Byte vulnerability. A local authenticated administrator user could potentially exploit this vulnerability by sending unexpected null bytes in order to read memory on the system.

    Published: 12 Sept 2022
    2.3
    Low

    CVE-2022-31222

    Last Modified: 21 Nov 2024

    Dell BIOS versions contain a Missing Release of Resource after Effective Lifetime vulnerability. A local authenticated administrator user could potentially exploit this vulnerability by consuming excess memory in order to cause the application to crash.

    Published: 12 Sept 2022
    2.3
    Low

    CVE-2022-31221

    Last Modified: 21 Nov 2024

    Dell BIOS versions contain an Information Exposure vulnerability. A local authenticated administrator user could potentially exploit this vulnerability in order access sensitive state information on the system.

    Published: 12 Sept 2022
    3
    Low

    CVE-2022-31220

    Last Modified: 21 Nov 2024

    Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administrator user could potentially exploit this vulnerability in order to change the state of the system or cause unexpected failures.

    Published: 12 Sept 2022
    7.5
    High

    CVE-2022-1700

    Last Modified: 21 Nov 2024

    Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), which is also leveraged by Forcepoint One Endpoint (F1E), Web Security Content Gateway, Email Security with DLP enabled, and Cloud Security Gateway prior to June 20, 2022. The XML parser in the Policy Engine was found to be improperly configured to support external entities and external DTD (Document Type Definitions), which can lead to an XXE attack. This issue affects: Forcepoint Data Loss Prevention (DLP) versions prior to 8.8.2. Forcepoint One Endpoint (F1E) with Policy Engine versions prior to 8.8.2. Forcepoint Web Security Content Gateway versions prior to 8.5.5. Forcepoint Email Security with DLP enabled versions prior to 8.5.5. Forcepoint Cloud Security Gateway prior to June 20, 2022.

    Published: 12 Sept 2022
    9.8
    Critical

    CVE-2022-37300

    Last Modified: 21 Nov 2024

    A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Expert Including all Unity Pro versions (former name of EcoStruxure Control Expert) (V15.0 SP1 and prior), EcoStruxure Process Expert, Including all versions of EcoStruxure Hybrid DCS (former name of EcoStruxure Process Expert) (V2021 and prior), Modicon M340 CPU (part numbers BMXP34*) (V3.40 and prior), Modicon M580 CPU (part numbers BMEP* and BMEH*) (V3.20 and prior).

    Published: 12 Sept 2022
    9.8
    Critical

    CVE-2022-37860

    Last Modified: 21 Nov 2024

    The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection vulnerability.

    Published: 12 Sept 2022
    7.8
    High

    CVE-2022-3178

    Last Modified: 21 Nov 2024

    Buffer Over-read in GitHub repository gpac/gpac prior to 2.1.0-DEV.

    Published: 12 Sept 2022
    7.5
    High

    CVE-2022-37835

    Last Modified: 21 Nov 2024

    Torguard VPN 4.8, has a vulnerability that allows an attacker to dump sensitive information, such as credentials and information about the server, without admin privileges.

    Published: 12 Sept 2022
    5.5
    Medium

    CVE-2022-34110

    Last Modified: 21 Nov 2024

    An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to download arbitrary files regardless of file type or size.

    Published: 12 Sept 2022
    7.1
    High

    CVE-2022-34109

    Last Modified: 21 Nov 2024

    An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to write arbitrary files to the directory \PromoPhoto\, regardless of file type or size.

    Published: 12 Sept 2022