CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2022-40577

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40578

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40581

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40582

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40583

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40584

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40585

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40586

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40587

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40588

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40589

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40590

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40591

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40592

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40593

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40594

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40595

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40596

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40597

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40598

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40599

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40601

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40579

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40580

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    —
    Unknown

    CVE-2022-40600

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 12 Sept 2022
    5.4
    Medium

    CVE-2022-37796

    Last Modified: 21 Nov 2024

    In Simple Online Book Store System 1.0 in /admin_book.php the Title, Author, and Description parameters are vulnerable to Cross Site Scripting(XSS).

    Published: 11 Sept 2022
    9.8
    Critical

    CVE-2022-37794

    Last Modified: 21 Nov 2024

    In Library Management System 1.0 the /card/in-card.php file id_no parameters are vulnerable to SQL injection.

    Published: 11 Sept 2022
    6.1
    Medium

    CVE-2022-40325

    Last Modified: 21 Nov 2024

    SysAid Help Desk before 22.1.65 allows XSS via the Asset Dashboard, aka FR# 67262.

    Published: 11 Sept 2022
    6.1
    Medium

    CVE-2022-40324

    Last Modified: 21 Nov 2024

    SysAid Help Desk before 22.1.65 allows XSS via the Linked SRs field, aka FR# 67258.

    Published: 11 Sept 2022
    6.1
    Medium

    CVE-2022-40323

    Last Modified: 21 Nov 2024

    SysAid Help Desk before 22.1.65 allows XSS in the Password Services module, aka FR# 67241.

    Published: 11 Sept 2022
    6.1
    Medium

    CVE-2022-40322

    Last Modified: 21 Nov 2024

    SysAid Help Desk before 22.1.65 allows XSS, aka FR# 66542 and 65579.

    Published: 11 Sept 2022
    5.4
    Medium

    CVE-2022-25295

    Last Modified: 21 Nov 2024

    This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next query parameter. The application uses url.Parse(r.FormValue("next")) to extract path and eventually redirect user to a relative URL, but if next parameter starts with multiple backslashes like \\\\\\example.com, browser will redirect user to http://example.com.

    Published: 11 Sept 2022
    5.3
    Medium

    CVE-2022-26049

    Last Modified: 21 Nov 2024

    This affects the package com.diffplug.gradle:goomph before 3.37.2. It allows a malicious zip file to potentially break out of the expected destination directory, writing contents into arbitrary locations on the file system. Overwriting certain files/directories could allow an attacker to achieve remote code execution on a target system by exploiting this vulnerability. **Note:** This could have allowed a malicious zip file to extract itself into an arbitrary directory. The only file that Goomph extracts is the p2 bootstrapper and eclipse metadata files hosted at eclipse.org, which are not malicious, so the only way this vulnerability could have affected you is if you had set a custom bootstrap zip, and that zip was malicious.

    Published: 11 Sept 2022
    9.8
    Critical

    CVE-2022-39135

    Last Modified: 21 Nov 2024

    Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity references in their configuration, making them vulnerable to a potential XML External Entity (XXE) attack. Therefore any client exposing these operators, typically by using Oracle dialect (the first three) or MySQL dialect (the last one), is affected by this vulnerability (the extent of it will depend on the user under which the application is running). From Apache Calcite 1.32.0 onwards, Document Type Declarations and XML External Entity resolution are disabled on the impacted operators.

    Published: 11 Sept 2022
    7.5
    High

    CVE-2021-37819

    Last Modified: 21 Nov 2024

    PDF Labs pdftk-java v3.2.3 was discovered to contain an infinite loop via the component /text/pdf/PdfReader.java.

    Published: 9 Sept 2022
    8.8
    High

    CVE-2022-40320

    Last Modified: 21 Nov 2024

    cfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read.

    Published: 9 Sept 2022
    9.1
    Critical

    CVE-2022-38638

    Last Modified: 21 Nov 2024

    Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.

    Published: 9 Sept 2022
    8.8
    High

    CVE-2022-36110

    Last Modified: 18 May 2026

    Netmaker makes networks with WireGuard. Prior to version 0.15.1, Improper Authorization functions lead to non-privileged users running privileged API calls. If someone adds users to the Netmaker platform who do not have admin privileges, they can use their auth tokens to run admin-level functions via the API. This problem has been patched in v0.15.1.

    Published: 9 Sept 2022
    7.5
    High

    CVE-2022-31006

    Last Modified: 23 Apr 2025

    indy-node is the server portion of Hyperledger Indy, a distributed ledger purpose-built for decentralized identity. In vulnerable versions of indy-node, an attacker can max out the number of client connections allowed by the ledger, leaving the ledger unable to be used for its intended purpose. However, the ledger content will not be impacted and the ledger will resume functioning after the attack. This attack exploits the trade-off between resilience and availability. Any protection against abusive client connections will also prevent the network being accessed by certain legitimate users. As a result, validator nodes must tune their firewall rules to ensure the right trade-off for their network's expected users. The guidance to network operators for the use of firewall rules in the deployment of Indy networks has been modified to better protect against denial of service attacks by increasing the cost and complexity in mounting such attacks. The mitigation for this vulnerability is not in the Hyperledger Indy code per se, but rather in the individual deployments of Indy. The mitigations should be applied to all deployments of Indy, and are not related to a particular release.

    Published: 9 Sept 2022
    5.4
    Medium

    CVE-2022-38639

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Community Posting field.

    Published: 9 Sept 2022
    9.8
    Critical

    CVE-2021-44835

    Last Modified: 21 Nov 2024

    An issue was discovered in Active Intelligent Visualization 5. The Vdc header is used in a SQL query without being sanitized. This causes SQL injection.

    Published: 9 Sept 2022
    5.5
    Medium

    CVE-2021-40648

    Last Modified: 21 Nov 2024

    In man2html 1.6g, a filename can be created to overwrite the previous size parameter of the next chunk and the fd, bk, fd_nextsize, bk_nextsize of the current chunk. The next chunk is then freed later on, causing a freeing of an arbitrary amount of memory.

    Published: 9 Sept 2022
    5.5
    Medium

    CVE-2021-40647

    Last Modified: 21 Nov 2024

    In man2html 1.6g, a specific string being read in from a file will overwrite the size parameter in the top chunk of the heap. This at least causes the program to segmentation abort if the heap size parameter isn't aligned correctly. In version before GLIBC version 2.29 and aligned correctly, it allows arbitrary write anywhere in the programs memory.

    Published: 9 Sept 2022
    7.8
    High

    CVE-2022-3133

    Last Modified: 21 Nov 2024

    OS Command Injection in GitHub repository jgraph/drawio prior to 20.3.0.

    Published: 9 Sept 2022
    5.3
    Medium

    CVE-2022-36109

    Last Modified: 23 Apr 2025

    Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. This bug is fixed in Moby (Docker Engine) 20.10.18. Running containers should be stopped and restarted for the permissions to be fixed. For users unable to upgrade, this problem can be worked around by not using the `"USER $USERNAME"` Dockerfile instruction. Instead by calling `ENTRYPOINT ["su", "-", "user"]` the supplementary groups will be set up properly.

    Published: 9 Sept 2022
    5.4
    Medium

    CVE-2022-40317

    Last Modified: 21 Nov 2024

    OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element.

    Published: 9 Sept 2022
    6.1
    Medium

    CVE-2022-39810

    Last Modified: 21 Nov 2024

    An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/ndatasource/validateconnection/ajaxprocessor.jsp via the driver parameter. Session hijacking or similar attacks would not be possible.

    Published: 9 Sept 2022
    6.1
    Medium

    CVE-2022-39809

    Last Modified: 21 Nov 2024

    An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/mediation_secure_vault/properties/ajaxprocessor.jsp via the name parameter. Session hijacking or similar attacks would not be possible.

    Published: 9 Sept 2022
    7.5
    High

    CVE-2022-38614

    Last Modified: 21 Nov 2024

    An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files via modifying the PATH parameter.

    Published: 9 Sept 2022
    8.8
    High

    CVE-2022-38615

    Last Modified: 21 Nov 2024

    SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/service_group.jsf.

    Published: 9 Sept 2022