CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2022-27664

    Last Modified: 21 Nov 2024

    In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.

    Published: 6 Sept 2022
    7.8
    High

    CVE-2022-3134

    Last Modified: 24 Sept 2026

    Use After Free in GitHub repository vim/vim prior to 9.0.0389.

    Published: 6 Sept 2022
    5.3
    Medium

    CVE-2022-38367

    Last Modified: 21 Nov 2024

    The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all users from Jira by making an HTTP request to the affected endpoint.

    Published: 5 Sept 2022
    7.2
    High

    CVE-2021-28398

    Last Modified: 21 Nov 2024

    A privileged attacker in GeoNetwork before 3.12.0 and 4.x before 4.0.4 can use the directory harvester before-script to execute arbitrary OS commands remotely on the hosting infrastructure. A User Administrator or Administrator account is required to perform this. This occurs in the runBeforeScript method in harvesters/src/main/java/org/fao/geonet/kernel/harvest/harvester/localfilesystem/LocalFilesystemHarvester.java. The earliest affected version is 3.4.0.

    Published: 5 Sept 2022
    8.6
    High

    CVE-2022-39838

    Last Modified: 21 Nov 2024

    Systematic FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via a UNC share pathname, and also allows absolute path traversal to local pathnames.

    Published: 5 Sept 2022
    6.3
    Medium

    CVE-2022-3122

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file medicine_details.php. The manipulation of the argument medicine leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-207854 is the identifier assigned to this vulnerability.

    Published: 5 Sept 2022
    4.3
    Medium

    CVE-2022-3121

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Online Employee Leave Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/addemployee.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The identifier VDB-207853 was assigned to this vulnerability.

    Published: 5 Sept 2022
    5.4
    Medium

    CVE-2022-3127

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.2.8.

    Published: 5 Sept 2022
    5.5
    Medium

    CVE-2022-2775

    Last Modified: 21 Nov 2024

    The Fast Flow WordPress plugin before 1.2.13 does not sanitise and escape some of its Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 5 Sept 2022
    4.3
    Medium

    CVE-2022-2657

    Last Modified: 21 Nov 2024

    The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in multiple AJAX actions, which could allow any authenticated users, such as subscriber to call them and suspend vendors (reporter by the submitter) or update arbitrary order status (identified by WPScan when verifying the issue) for example. Other unauthenticated attacks are also possible, either directly or via CSRF

    Published: 5 Sept 2022
    5.4
    Medium

    CVE-2022-2597

    Last Modified: 21 Nov 2024

    The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoints, allowing users with a role as low as contributor to call them and inject arbitrary CSS in arbitrary saved layouts

    Published: 5 Sept 2022
    7.2
    High

    CVE-2022-2565

    Last Modified: 21 Nov 2024

    The Simple Payment Donations & Subscriptions WordPress plugin before 4.2.1 does not sanitise and escape user input given in its forms, which could allow unauthenticated attackers to perform Cross-Site Scripting attacks against admins

    Published: 5 Sept 2022
    6.1
    Medium

    CVE-2022-2543

    Last Modified: 21 Nov 2024

    The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoints, allowing unauthenticated users to call them and inject arbitrary CSS in arbitrary saved layouts

    Published: 5 Sept 2022
    5.3
    Medium

    CVE-2022-2376

    Last Modified: 21 Nov 2024

    The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users

    Published: 5 Sept 2022
    4.8
    Medium

    CVE-2022-2271

    Last Modified: 21 Nov 2024

    The WP Database Backup WordPress plugin before 5.9 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 5 Sept 2022
    7.5
    High

    CVE-2022-2083

    Last Modified: 21 Nov 2024

    The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which could be used by attackers to gain unauthorized access to the site.

    Published: 5 Sept 2022
    8.8
    High

    CVE-2022-2830

    Last Modified: 21 Nov 2024

    Deserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console allows an attacker to pass unsafe commands to the environment. This issue affects: Bitdefender GravityZone Console On-Premise versions prior to 6.29.2-1. Bitdefender GravityZone Cloud Console versions prior to 6.27.2-2.

    Published: 5 Sept 2022
    6.1
    Medium

    CVE-2022-3123

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a.

    Published: 5 Sept 2022
    7.5
    High

    CVE-2022-38370

    Last Modified: 21 Nov 2024

    Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue.

    Published: 5 Sept 2022
    8.8
    High

    CVE-2022-38369

    Last Modified: 21 Nov 2024

    Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.

    Published: 5 Sept 2022
    8.1
    High

    CVE-2022-3008

    Last Modified: 21 Apr 2025

    The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. This function allows for command injection by using backticks. An attacker could craft an untrusted path input that would result in a path expansion. We recommend upgrading to 2.6.0 or past commit 52ff00a38447f06a17eab1caa2cf0730a119c751

    Published: 5 Sept 2022
    7.3
    High

    CVE-2022-3120

    Last Modified: 14 Apr 2025

    A vulnerability classified as critical was found in SourceCodester Clinics Patient Management System. Affected by this vulnerability is an unknown functionality of the file index.php of the component Login. The manipulation of the argument user_name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-207847.

    Published: 5 Sept 2022
    6.8
    Medium

    CVE-2022-39051

    Last Modified: 21 Nov 2024

    Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package

    Published: 5 Sept 2022
    4.6
    Medium

    CVE-2022-39050

    Last Modified: 21 Nov 2024

    An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be run later by any other agent when clicking the customer URL link. Then the stored JavaScript is executed in the context of OTRS. The same issue applies for the usage of external data sources e.g. database or ldap

    Published: 5 Sept 2022
    3.5
    Low

    CVE-2022-39049

    Last Modified: 21 Nov 2024

    An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS.

    Published: 5 Sept 2022
    7.8
    High

    CVE-2022-39843

    Last Modified: 21 Nov 2024

    123elf Lotus 1-2-3 before 1.0.0rc3 for Linux, and Lotus 1-2-3 R3 for UNIX and other platforms through 9.8.2, allow attackers to execute arbitrary code via a crafted worksheet. This occurs because of a stack-based buffer overflow in the cell format processing routines, as demonstrated by a certain function call from process_fmt() that can be reached via a w3r_format element in a wk3 document.

    Published: 5 Sept 2022
    4.8
    Medium

    CVE-2022-39839

    Last Modified: 21 Nov 2024

    Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a forum post.

    Published: 5 Sept 2022
    4.8
    Medium

    CVE-2022-39840

    Last Modified: 21 Nov 2024

    Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a direct message (DM).

    Published: 5 Sept 2022
    7.8
    High

    CVE-2022-39831

    Last Modified: 21 Nov 2024

    An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact. This issue is different from CVE-2018-20230.

    Published: 5 Sept 2022
    7.8
    High

    CVE-2022-39832

    Last Modified: 21 Nov 2024

    An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_string in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 5 Sept 2022
    7.5
    High

    CVE-2022-39828

    Last Modified: 21 Nov 2024

    sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_private_key, leading to a denial of service.

    Published: 5 Sept 2022
    7.5
    High

    CVE-2022-39829

    Last Modified: 21 Nov 2024

    There is a NULL pointer dereference in aes256_encrypt in Samsung mTower through 0.3.0 due to a missing check on the return value of EVP_CIPHER_CTX_new.

    Published: 5 Sept 2022
    7.5
    High

    CVE-2022-39830

    Last Modified: 21 Nov 2024

    sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_public_key_affine_coordinates, leading to a denial of service.

    Published: 5 Sept 2022
    8.9
    High

    CVE-2022-39824

    Last Modified: 21 Nov 2024

    Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server via the currentItem property of the list widget, e.g., to perform DoS attacks or achieve an information leak.

    Published: 5 Sept 2022
    4.4
    Medium

    CVE-2023-2860

    Last Modified: 5 Mar 2025

    An out-of-bounds read vulnerability was found in the SR-IPv6 implementation in the Linux kernel. The flaw exists within the processing of seg6 attributes. The issue results from the improper validation of user-supplied data, which can result in a read past the end of an allocated buffer. This flaw allows a privileged local user to disclose sensitive information on affected installations of the Linux kernel.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39933

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    6.5
    Medium

    CVE-2022-38749

    Last Modified: 21 Nov 2024

    Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.

    Published: 5 Sept 2022
    6.5
    Medium

    CVE-2022-38750

    Last Modified: 21 Nov 2024

    Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39916

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39917

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39918

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39919

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39920

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39921

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39922

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39924

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39925

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39926

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39927

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39928

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022