CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-37125

    Last Modified: 21 Nov 2024

    D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.

    Published: 31 Aug 2022
    6.1
    Medium

    CVE-2022-2898

    Last Modified: 16 Apr 2025

    Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow a denial-of-service condition.

    Published: 31 Aug 2022
    7.8
    High

    CVE-2022-2896

    Last Modified: 16 Apr 2025

    Measuresoft ScadaPro Server (All Versions) allows use after free while processing a specific project file.

    Published: 31 Aug 2022
    7.8
    High

    CVE-2022-2894

    Last Modified: 16 Apr 2025

    Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. The controls may allow seven untrusted pointer deference instances while processing a specific project file.

    Published: 31 Aug 2022
    7.8
    High

    CVE-2022-2897

    Last Modified: 16 Apr 2025

    Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow privilege escalation..

    Published: 31 Aug 2022
    7.8
    High

    CVE-2022-2895

    Last Modified: 16 Apr 2025

    Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. These controls may allow two stack-based buffer overflow instances while processing a specific project file.

    Published: 31 Aug 2022
    7.8
    High

    CVE-2022-2892

    Last Modified: 16 Apr 2025

    Measuresoft ScadaPro Server (Versions prior to 6.8.0.1) uses an unmaintained ActiveX control, which may allow an out-of-bounds write condition while processing a specific project file.

    Published: 31 Aug 2022
    9.8
    Critical

    CVE-2022-36201

    Last Modified: 21 Nov 2024

    Doctor’s Appointment System v1.0 is vulnerable to Blind SQLi via settings.php.

    Published: 31 Aug 2022
    9.8
    Critical

    CVE-2022-36202

    Last Modified: 21 Nov 2024

    Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter.

    Published: 31 Aug 2022
    6.1
    Medium

    CVE-2022-36203

    Last Modified: 21 Nov 2024

    Doctor's Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) via the admin panel. In addition, it leads to takeover the administrator account by stealing the cookie via XSS.

    Published: 31 Aug 2022
    8.1
    High

    CVE-2022-34383

    Last Modified: 21 Nov 2024

    Dell Edge Gateway 5200 (EGW) versions before 1.03.10 contain an operating system command injection vulnerability. A local malicious user may potentially exploit this vulnerability by using an SMI to bypass PMC mitigation and gain arbitrary code execution during SMM.

    Published: 31 Aug 2022
    7.3
    High

    CVE-2022-34373

    Last Modified: 21 Nov 2024

    Dell Command | Integration Suite for System Center, versions prior to 6.2.0, contains arbitrary file write vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability in order to perform an arbitrary write as system.

    Published: 31 Aug 2022
    6.3
    Medium

    CVE-2022-31233

    Last Modified: 21 Nov 2024

    Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user may potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to.

    Published: 31 Aug 2022
    7.2
    High

    CVE-2022-36582

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in the component /php_action/createProduct.php of Garage Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 31 Aug 2022
    7.5
    High

    CVE-2022-36581

    Last Modified: 21 Nov 2024

    Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /admin/login.php.

    Published: 31 Aug 2022
    7.2
    High

    CVE-2022-36580

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering System v2.3.2 allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 31 Aug 2022
    7.2
    High

    CVE-2022-1841

    Last Modified: 21 Nov 2024

    In subsys/net/ip/tcp.c , function tcp_flags , when the incoming parameter flags is ECN or CWR , the buf will out-of-bounds write a byte zero.

    Published: 31 Aug 2022
    4.3
    Medium

    CVE-2022-36048

    Last Modified: 23 Apr 2025

    Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. When displaying messages with embedded remote images, Zulip normally loads the image preview via a go-camo proxy server. However, an attacker who can send messages could include a crafted URL that tricks the server into embedding a remote image reference directly. This could allow the attacker to infer the viewer’s IP address and browser fingerprinting information. This vulnerability is fixed in Zulip Server 5.6. Zulip organizations with image and link previews [disabled](https://zulip.com/help/allow-image-link-previews) are not affected.

    Published: 31 Aug 2022
    7.2
    High

    CVE-2022-36571

    Last Modified: 21 Nov 2024

    Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the mask parameter at /goform/WanParameterSetting.

    Published: 31 Aug 2022
    7.2
    High

    CVE-2022-36570

    Last Modified: 21 Nov 2024

    Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the time parameter at /goform/SetLEDCfg.

    Published: 31 Aug 2022
    8.8
    High

    CVE-2022-36569

    Last Modified: 21 Nov 2024

    Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCfg.

    Published: 31 Aug 2022
    8.8
    High

    CVE-2022-36568

    Last Modified: 21 Nov 2024

    Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the list parameter at /goform/setPptpUserList.

    Published: 31 Aug 2022
    5.3
    Medium

    CVE-2022-36046

    Last Modified: 23 Apr 2025

    Next.js is a React framework that can provide building blocks to create web applications. All of the following must be true to be affected by this CVE: Next.js version 12.2.3, Node.js version above v15.0.0 being used with strict `unhandledRejection` exiting AND using next start or a [custom server](https://nextjs.org/docs/advanced-features/custom-server). Deployments on Vercel ([vercel.com](https://vercel.com/)) are not affected along with similar environments where `next-server` isn't being shared across requests.

    Published: 31 Aug 2022
    9.8
    Critical

    CVE-2022-37128

    Last Modified: 21 Nov 2024

    In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.

    Published: 31 Aug 2022
    6.5
    Medium

    CVE-2022-38812

    Last Modified: 21 Nov 2024

    AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter.

    Published: 31 Aug 2022
    8.8
    High

    CVE-2022-37184

    Last Modified: 21 Nov 2024

    The application manage_website.php on Garage Management System 1.0 is vulnerable to Shell File Upload. The already authenticated malicious user, can upload a dangerous RCE or LCE exploit file.

    Published: 31 Aug 2022
    9.8
    Critical

    CVE-2022-36566

    Last Modified: 21 Nov 2024

    Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function.

    Published: 31 Aug 2022
    6.1
    Medium

    CVE-2022-37183

    Last Modified: 21 Nov 2024

    Piwigo 12.3.0 is vulnerable to Cross Site Scripting (XSS) via /search/1940/created-monthly-list.

    Published: 31 Aug 2022
    7.5
    High

    CVE-2022-2043

    Last Modified: 16 Apr 2025

    MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that can cause the device to become unresponsive.

    Published: 31 Aug 2022
    8.2
    High

    CVE-2022-2044

    Last Modified: 16 Apr 2025

    MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that may allow an attacker to overwrite values in memory, causing a denial-of-service condition or potentially bricking the device.

    Published: 31 Aug 2022
    9.6
    Critical

    CVE-2022-2485

    Last Modified: 16 Apr 2025

    Any attempt (good or bad) to log into AutomationDirect Stride Field I/O with a web browser may result in the device responding with its password in the communication packets.

    Published: 31 Aug 2022
    7.8
    High

    CVE-2022-2866

    Last Modified: 16 Apr 2025

    FATEK FvDesigner version 1.5.103 and prior is vulnerable to an out-of-bounds write while processing project files. If a valid user is tricked into using maliciously crafted project files, an attacker could achieve arbitrary code execution.

    Published: 31 Aug 2022
    10
    Critical

    CVE-2022-21941

    Last Modified: 21 Nov 2024

    All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to the system.

    Published: 31 Aug 2022
    7.5
    High

    CVE-2022-2004

    Last Modified: 16 Apr 2025

    AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to prevent access from DirectSoft and other devices, causing a denial-of-service condition. This issue affects: AutomationDirect DirectLOGIC D0-06 series CPUs D0-06DD1 versions prior to 2.72; D0-06DD2 versions prior to 2.72; D0-06DR versions prior to 2.72; D0-06DA versions prior to 2.72; D0-06AR versions prior to 2.72; D0-06AA versions prior to 2.72; D0-06DD1-D versions prior to 2.72; D0-06DD2-D versions prior to 2.72; D0-06DR-D versions prior to 2.72;

    Published: 31 Aug 2022
    7.7
    High

    CVE-2022-2003

    Last Modified: 16 Apr 2025

    AutomationDirect DirectLOGIC is vulnerable to a specifically crafted serial message to the CPU serial port that will cause the PLC to respond with the PLC password in cleartext. This could allow an attacker to access and make unauthorized changes. This issue affects: AutomationDirect DirectLOGIC D0-06 series CPUs D0-06DD1 versions prior to 2.72; D0-06DD2 versions prior to 2.72; D0-06DR versions prior to 2.72; D0-06DA versions prior to 2.72; D0-06AR versions prior to 2.72; D0-06AA versions prior to 2.72; D0-06DD1-D versions prior to 2.72; D0-06DD2-D versions prior to 2.72; D0-06DR-D versions prior to 2.72;

    Published: 31 Aug 2022
    5.5
    Medium

    CVE-2022-28625

    Last Modified: 21 Nov 2024

    A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7.0 or 6.60.01. A low privileged user could locally exploit this vulnerability to disclose sensitive information resulting in a complete loss of confidentiality, integrity, and availability. To exploit this vulnerability, HPE OneView must be configured with credential access to external repositories. HPE has provided a software update to resolve this vulnerability in HPE OneView.

    Published: 31 Aug 2022
    6.1
    Medium

    CVE-2022-26331

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exploited resulting in Information Disclosure, or Self Cross-Site Scripting (XSS). This issue affects: Micro Focus ArcSight Logger versions prior to v7.2.2 version and prior versions.

    Published: 31 Aug 2022
    6.5
    Medium

    CVE-2022-26330

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exploited resulting in Information Disclosure, or Self Cross-Site Scripting (XSS). This issue affects: Micro Focus ArcSight Logger versions prior to v7.2.2 version and prior versions.

    Published: 31 Aug 2022
    7.5
    High

    CVE-2022-37122

    Last Modified: 21 Nov 2024

    Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' GET parameter through the 'logdownload.cgi' Bash script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks.

    Published: 31 Aug 2022
    9.8
    Critical

    CVE-2022-30318

    Last Modified: 21 Nov 2024

    Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell ControlEdge hardcoded credentials issue. The affected components are characterized as: SSH. The potential impact is: Remote code execution, manipulate configuration, denial of service. The Honeywell ControlEdge PLC and RTU product line exposes an SSH service on port 22/TCP. Login as root to this service is permitted and credentials for the root user are hardcoded without automatically changing them upon first commissioning. The credentials for the SSH service are hardcoded in the firmware. The credentials grant an attacker access to a root shell on the PLC/RTU, allowing for remote code execution, configuration manipulation and denial of service.

    Published: 31 Aug 2022
    5.5
    Medium

    CVE-2022-2759

    Last Modified: 16 Apr 2025

    Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. This may allow an attacker to view sensitive documents and information on the affected host.

    Published: 31 Aug 2022
    6.5
    Medium

    CVE-2022-2758

    Last Modified: 16 Apr 2025

    Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (LSIS) Co. Ltd LS Electric XG5000 software prior to V4.0 and LS Electric PLCs: all versions of XGK-CPUU/H/A/S/E prior to V3.50, all versions of XGI-CPUU/UD/H/S/E prior to V3.20, all versions of XGR-CPUH prior to V1.80, all versions of XGB-XBMS prior to V3.00, all versions of XGB-XBCH prior to V1.90, and all versions of XGB-XECH prior to V1.30. This would allow an attacker to identify and decrypt the password of the affected PLCs by sniffing the PLC’s communication traffic.

    Published: 31 Aug 2022
    7.8
    High

    CVE-2022-1405

    Last Modified: 16 Apr 2025

    CNCSoft: All versions prior to 1.01.32 does not properly sanitize input while processing a specific project file, allowing a possible stack-based buffer overflow condition.

    Published: 31 Aug 2022
    3.3
    Low

    CVE-2022-1404

    Last Modified: 16 Apr 2025

    Delta Electronics CNCSoft (All versions prior to 1.01.32) does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds read condition.

    Published: 31 Aug 2022
    7.8
    High

    CVE-2022-2006

    Last Modified: 16 Apr 2025

    AutomationDirect DirectLOGIC has a DLL vulnerability in the install directory that may allow an attacker to execute code during the installation process. This issue affects: AutomationDirect C-more EA9 EA9-T6CL versions prior to 6.73; EA9-T6CL-R versions prior to 6.73; EA9-T7CL versions prior to 6.73; EA9-T7CL-R versions prior to 6.73; EA9-T8CL versions prior to 6.73; EA9-T10CL versions prior to 6.73; EA9-T10WCL versions prior to 6.73; EA9-T12CL versions prior to 6.73; EA9-T15CL versions prior to 6.73; EA9-RHMI versions prior to 6.73; EA9-PGMSW versions prior to 6.73;

    Published: 31 Aug 2022
    7.5
    High

    CVE-2022-2005

    Last Modified: 16 Apr 2025

    AutomationDirect C-more EA9 HTTP webserver uses an insecure mechanism to transport credentials from client to web server, which may allow an attacker to obtain the login credentials and login as a valid user. This issue affects: AutomationDirect C-more EA9 EA9-T6CL versions prior to 6.73; EA9-T6CL-R versions prior to 6.73; EA9-T7CL versions prior to 6.73; EA9-T7CL-R versions prior to 6.73; EA9-T8CL versions prior to 6.73; EA9-T10CL versions prior to 6.73; EA9-T10WCL versions prior to 6.73; EA9-T12CL versions prior to 6.73; EA9-T15CL versions prior to 6.73; EA9-RHMI versions prior to 6.73; EA9-PGMSW versions prior to 6.73;

    Published: 31 Aug 2022
    5.5
    Medium

    CVE-2022-1325

    Last Modified: 21 Nov 2024

    A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy header field values it is possible to trick the application into allocating huge buffer sizes like 64 Gigabyte upon reading the file from disk or from a virtual buffer.

    Published: 31 Aug 2022
    7.8
    High

    CVE-2022-1888

    Last Modified: 16 Apr 2025

    Alpha7 PC Loader (All versions) is vulnerable to a stack-based buffer overflow while processing a specifically crafted project file, which may allow an attacker to execute arbitrary code.

    Published: 31 Aug 2022
    9.1
    Critical

    CVE-2022-30317

    Last Modified: 21 Nov 2024

    Honeywell Experion LX through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0055, there is a Honeywell Experion LX Control Data Access (CDA) EpicMo protocol with unauthenticated functionality issue. The affected components are characterized as: Honeywell Control Data Access (CDA) EpicMo (55565/TCP). The potential impact is: Firmware manipulation, Denial of service. The Honeywell Experion LX Distributed Control System (DCS) utilizes the Control Data Access (CDA) EpicMo protocol (55565/TCP) for device diagnostics and maintenance purposes. This protocol does not have any authentication features, allowing any attacker capable of communicating with the ports in question to invoke (a subset of) desired functionality. There is no authentication functionality on the protocol in question. An attacker capable of invoking the protocols' functionalities could issue firmware download commands potentially allowing for firmware manipulation and reboot devices causing denial of service.

    Published: 31 Aug 2022
    9
    Critical

    CVE-2022-36045

    Last Modified: 23 Apr 2025

    NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interactions and real-time notifications. `utils.generateUUID`, a helper function available in essentially all versions of NodeBB (as far back as v1.0.1 and potentially earlier) used a cryptographically insecure Pseudo-random number generator (`Math.random()`), which meant that a specially crafted script combined with multiple invocations of the password reset functionality could enable an attacker to correctly calculate the reset code for an account they do not have access to. This vulnerability impacts all installations of NodeBB. The vulnerability allows for an attacker to take over any account without the involvement of the victim, and as such, the remediation should be applied immediately (either via NodeBB upgrade or cherry-pick of the specific changeset. The vulnerability has been patched in version 2.x and 1.19.x. There is no known workaround, but the patch sets listed above will fully patch the vulnerability.

    Published: 31 Aug 2022