CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2022-39929

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39930

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39931

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39932

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39934

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39935

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39936

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39937

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39938

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39939

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39940

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39941

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39943

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    9.8
    Critical

    CVE-2022-31814

    Last Modified: 21 Nov 2024

    pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.

    Published: 5 Sept 2022
    8.8
    High

    CVE-2022-30331

    Last Modified: 21 Nov 2024

    The User-Defined Functions (UDF) feature in TigerGraph 3.6.0 allows installation of a query (in the GSQL query language) without proper validation. Consequently, an attacker can execute arbitrary C++ code. NOTE: the vendor's position is "GSQL was behaving as expected."

    Published: 5 Sept 2022
    6.5
    Medium

    CVE-2022-38751

    Last Modified: 21 Apr 2025

    Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.

    Published: 5 Sept 2022
    6.5
    Medium

    CVE-2022-38752

    Last Modified: 21 Nov 2024

    Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack-overflow.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39923

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    —
    Unknown

    CVE-2022-39942

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 5 Sept 2022
    7.3
    High

    CVE-2022-3118

    Last Modified: 14 Apr 2025

    A vulnerability was found in Sourcecodehero ERP System Project. It has been rated as critical. This issue affects some unknown processing of the file /pages/processlogin.php. The manipulation of the argument user leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-207845 was assigned to this vulnerability.

    Published: 4 Sept 2022
    6.5
    Medium

    CVE-2022-39196

    Last Modified: 21 Nov 2024

    Blackboard Learn 1.10.1 allows remote authenticated users to read unintended files by entering student credentials and then directly visiting a certain webapps/bbcms/execute/ URL. Note: The vendor disputes this stating this cannot be reproduced.

    Published: 4 Sept 2022
    4.7
    Medium

    CVE-2022-3303

    Last Modified: 21 May 2025

    A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL pointer dereference while handling the SNDCTL_DSP_SYNC ioctl. A privileged local user (root or member of the audio group) could use this flaw to crash the system, resulting in a denial of service condition

    Published: 4 Sept 2022
    7.8
    High

    CVE-2022-3099

    Last Modified: 3 Nov 2025

    Use After Free in GitHub repository vim/vim prior to 9.0.0360.

    Published: 3 Sept 2022
    7.2
    High

    CVE-2022-36754

    Last Modified: 21 Nov 2024

    Expense Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Home/debit_credit_p.

    Published: 2 Sept 2022
    7.5
    High

    CVE-2020-29260

    Last Modified: 21 Nov 2024

    libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup().

    Published: 2 Sept 2022
    5.5
    Medium

    CVE-2022-36647

    Last Modified: 21 Nov 2024

    PKUVCL davs2 v1.6.205 was discovered to contain a global buffer overflow via the function parse_sequence_header() at source/common/header.cc:269.

    Published: 2 Sept 2022
    9.8
    Critical

    CVE-2022-36642

    Last Modified: 21 Nov 2024

    A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control panel with high privilege because the cleartext storage of sensitive information which can be unlatched by exploiting the LFD vulnerability.

    Published: 2 Sept 2022
    9.8
    Critical

    CVE-2022-36640

    Last Modified: 5 Jul 2026

    influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If InfluxDB is being deployed on a publicly accessible endpoint, we strongly recommend authentication be enabled. Otherwise the data will be publicly available to any unauthenticated user. The default settings do NOT enable authentication and authorization."

    Published: 2 Sept 2022
    5.4
    Medium

    CVE-2022-36639

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in /client.php of Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.

    Published: 2 Sept 2022
    5.3
    Medium

    CVE-2022-36638

    Last Modified: 21 Nov 2024

    An access control issue in the component print.php of Garage Management System v1.0 allows unauthenticated attackers to access data for all existing orders.

    Published: 2 Sept 2022
    6.4
    Medium

    CVE-2022-31152

    Last Modified: 23 Apr 2025

    Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specification specifies a list of [event authorization rules](https://spec.matrix.org/v1.2/rooms/v9/#authorization-rules) which must be checked when determining if an event should be accepted into a room. In versions of Synapse up to and including version 1.61.0, some of these rules are not correctly applied. An attacker could craft events which would be accepted by Synapse but not a spec-conformant server, potentially causing divergence in the room state between servers. Administrators of homeservers with federation enabled are advised to upgrade to version 1.62.0 or higher. Federation can be disabled by setting [`federation_domain_whitelist`](https://matrix-org.github.io/synapse/latest/usage/configuration/config_documentation.html#federation_domain_whitelist) to an empty list (`[]`) as a workaround.

    Published: 2 Sept 2022
    7.6
    High

    CVE-2022-31196

    Last Modified: 22 Apr 2025

    Databasir is a database metadata management platform. Databasir <= 1.06 has Server-Side Request Forgery (SSRF) vulnerability. The SSRF is triggered by a sending a **single** HTTP POST request to create a databaseType. By supplying a `jdbcDriverFileUrl` that returns a non `200` response code, the url is executed, the response is logged (both in terminal and in database) and is included in the response. This would allow an attackers to obtain the real IP address and scan Intranet information. This issue was fixed in version 1.0.7.

    Published: 2 Sept 2022
    6.1
    Medium

    CVE-2022-35933

    Last Modified: 23 Apr 2025

    This package is a PrestaShop module that allows users to post reviews and rate products. There is a vulnerability where the attacker could steal an administrator's cookie. The issue is fixed in version 5.0.2.

    Published: 2 Sept 2022
    7.5
    High

    CVE-2022-3065

    Last Modified: 21 Nov 2024

    Improper Access Control in GitHub repository jgraph/drawio prior to 20.2.8.

    Published: 2 Sept 2022
    9.8
    Critical

    CVE-2021-27693

    Last Modified: 21 Nov 2024

    Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.

    Published: 2 Sept 2022
    7.8
    High

    CVE-2022-34382

    Last Modified: 21 Nov 2024

    Dell Command Update, Dell Update and Alienware Update versions prior to 4.6.0 contains a Local Privilege Escalation Vulnerability in the custom catalog configuration. A local malicious user may potentially exploit this vulnerability in order to elevate their privileges.

    Published: 2 Sept 2022
    5.5
    Medium

    CVE-2022-34378

    Last Modified: 21 Nov 2024

    Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3, contain a relative path traversal vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to denial of service.

    Published: 2 Sept 2022
    8.1
    High

    CVE-2022-34371

    Last Modified: 21 Nov 2024

    Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3, contain an unprotected transport of credentials vulnerability. A malicious unprivileged network attacker could potentially exploit this vulnerability, leading to full system compromise.

    Published: 2 Sept 2022
    8.1
    High

    CVE-2022-34369

    Last Modified: 21 Nov 2024

    Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3 , contain an insertion of sensitive information in log files vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to exposure of this sensitive data.

    Published: 2 Sept 2022
    8.3
    High

    CVE-2022-36071

    Last Modified: 22 Apr 2025

    SFTPGo is configurable SFTP server with optional HTTP/S, FTP/S and WebDAV support. SFTPGo WebAdmin and WebClient support login using TOTP (Time-based One Time Passwords) as a secondary authentication factor. Because TOTPs are often configured on mobile devices that can be lost, stolen or damaged, SFTPGo also supports recovery codes. These are a set of one time use codes that can be used instead of the TOTP. In SFTPGo versions from version 2.2.0 to 2.3.3 recovery codes can be generated before enabling two-factor authentication. An attacker who knows the user's password could potentially generate some recovery codes and then bypass two-factor authentication after it is enabled on the account at a later time. This issue has been fixed in version 2.3.4. Recovery codes can now only be generated after enabling two-factor authentication and are deleted after disabling it.

    Published: 2 Sept 2022
    8.8
    High

    CVE-2022-36076

    Last Modified: 22 Apr 2025

    NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. Due to an unnecessarily strict conditional in the code handling the first step of the SSO process, the pre-existing logic that added (and later checked) a nonce was inadvertently rendered opt-in instead of opt-out. This re-exposed a vulnerability in that a specially crafted Man-in-the-Middle (MITM) attack could theoretically take over another user account during the single sign-on process. The issue has been fully patched in version 1.17.2.

    Published: 2 Sept 2022
    8.8
    High

    CVE-2022-36078

    Last Modified: 22 Apr 2025

    Binary provides encoding/decoding in Borsh and other formats. The vulnerability is a memory allocation vulnerability that can be exploited to allocate slices in memory with (arbitrary) excessive size value, which can either exhaust available memory or crash the whole program. When using `github.com/gagliardetto/binary` to parse unchecked (or wrong type of) data from untrusted sources of input (e.g. the blockchain) into slices, it's possible to allocate memory with excessive size. When `dec.Decode(&val)` method is used to parse data into a structure that is or contains slices of values, the length of the slice was previously read directly from the data itself without any checks on the size of it, and then a slice was allocated. This could lead to an overflow and an allocation of memory with excessive size value. Users should upgrade to `v0.7.1` or higher. A workaround is not to rely on the `dec.Decode(&val)` function to parse the data, but to use a custom `UnmarshalWithDecoder()` method that reads and checks the length of any slice.

    Published: 2 Sept 2022
    8.4
    High

    CVE-2022-25680

    Last Modified: 21 Nov 2024

    Memory corruption in multimedia due to buffer overflow while processing count variable from client in Snapdragon Auto

    Published: 2 Sept 2022
    7.3
    High

    CVE-2022-25668

    Last Modified: 21 Nov 2024

    Memory corruption in video driver due to double free while parsing ASF clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 2 Sept 2022
    7.3
    High

    CVE-2022-25659

    Last Modified: 21 Nov 2024

    Memory corruption due to buffer overflow while parsing MKV clips with invalid bitmap size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 2 Sept 2022
    7.3
    High

    CVE-2022-25658

    Last Modified: 21 Nov 2024

    Memory corruption due to incorrect pointer arithmetic when attempting to change the endianness in video parser function in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 2 Sept 2022
    7.3
    High

    CVE-2022-25657

    Last Modified: 21 Nov 2024

    Memory corruption due to buffer overflow occurs while processing invalid MKV clip which has invalid seek header in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 2 Sept 2022
    8.4
    High

    CVE-2022-22106

    Last Modified: 21 Nov 2024

    Memory corruption in multimedia due to improper length check while copying the data in Snapdragon Auto

    Published: 2 Sept 2022
    8.4
    High

    CVE-2022-22104

    Last Modified: 21 Nov 2024

    Memory corruption in multimedia due to improper check on the messages received. in Snapdragon Auto

    Published: 2 Sept 2022
    8.4
    High

    CVE-2022-22102

    Last Modified: 21 Nov 2024

    Memory corruption in multimedia due to incorrect type conversion while adding data in Snapdragon Auto

    Published: 2 Sept 2022