CVE Feed

    Dashboard / CVE

    7.7
    High

    CVE-2022-36035

    Last Modified: 23 Apr 2025

    Flux is a tool for keeping Kubernetes clusters in sync with sources of configuration (like Git repositories), and automating updates to configuration when there is new code to deploy. Flux CLI allows users to deploy Flux components into a Kubernetes cluster via command-line. The vulnerability allows other applications to replace the Flux deployment information with arbitrary content which is deployed into the target Kubernetes cluster instead. The vulnerability is due to the improper handling of user-supplied input, which results in a path traversal that can be controlled by the attacker. Users sharing the same shell between other applications and the Flux CLI commands could be affected by this vulnerability. In some scenarios no errors may be presented, which may cause end users not to realize that something is amiss. A safe workaround is to execute Flux CLI in ephemeral and isolated shell environments, which can ensure no persistent values exist from previous processes. However, upgrading to the latest version of the CLI is still the recommended mitigation strategy.

    Published: 31 Aug 2022
    5.3
    Medium

    CVE-2022-27911

    Last Modified: 25 Feb 2026

    An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused by the PSR12 changes.

    Published: 31 Aug 2022
    6.5
    Medium

    CVE-2022-37023

    Last Modified: 21 Nov 2024

    Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on Java 8 or Java 11. Any user wishing to protect against deserialization attacks involving REST APIs should upgrade to Apache Geode 1.15 and follow the documentation for details on enabling "validate-serializable-objects=true" and specifying any user classes that may be serialized/deserialized with "serializable-object-filter". Enabling "validate-serializable-objects" may impact performance.

    Published: 31 Aug 2022
    8.8
    High

    CVE-2022-37022

    Last Modified: 21 Nov 2024

    Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11. Any user wishing to protect against deserialization attacks involving JMX or RMI should upgrade to Apache Geode 1.15. Use of 1.15 on Java 11 will automatically protect JMX over RMI against deserialization attacks. This should have no impact on performance since it only affects JMX/RMI which Gfsh uses to communicate with the JMX Manager which is hosted on a Locator.

    Published: 31 Aug 2022
    9.8
    Critical

    CVE-2022-37021

    Last Modified: 21 Nov 2024

    Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. Any user still on Java 8 who wishes to protect against deserialization attacks involving JMX or RMI should upgrade to Apache Geode 1.15 and Java 11. If upgrading to Java 11 is not possible, then upgrade to Apache Geode 1.15 and specify "--J=-Dgeode.enableGlobalSerialFilter=true" when starting any Locators or Servers. Follow the documentation for details on specifying any user classes that may be serialized/deserialized with the "serializable-object-filter" configuration option. Using a global serial filter will impact performance.

    Published: 31 Aug 2022
    8.8
    High

    CVE-2022-39047

    Last Modified: 21 Nov 2024

    Freeciv before 2.6.7 and before 3.0.3 is prone to a buffer overflow vulnerability in the Modpack Installer utility's handling of the modpack URL.

    Published: 31 Aug 2022
    5.5
    Medium

    CVE-2022-3586

    Last Modified: 25 Jun 2025

    A flaw was found in the Linux kernel’s networking code. A use-after-free was found in the way the sch_sfb enqueue function used the socket buffer (SKB) cb field after the same SKB had been enqueued (and freed) into a child qdisc. This flaw allows a local, unprivileged user to crash the system, causing a denial of service.

    Published: 31 Aug 2022
    9.8
    Critical

    CVE-2022-37130

    Last Modified: 21 Nov 2024

    In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is met, setnum will be spliced into v10 by snprintf, and the system will be executed, resulting in a command injection vulnerability

    Published: 31 Aug 2022
    7.5
    High

    CVE-2022-36620

    Last Modified: 21 Nov 2024

    D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting.

    Published: 31 Aug 2022
    5.9
    Medium

    CVE-2022-38153

    Last Modified: 21 Nov 2024

    An issue was discovered in wolfSSL before 5.5.0 (when --enable-session-ticket is used); however, only version 5.3.0 is exploitable. Man-in-the-middle attackers or a malicious server can crash TLS 1.2 clients during a handshake. If an attacker injects a large ticket (more than 256 bytes) into a NewSessionTicket message in a TLS 1.2 handshake, and the client has a non-empty session cache, the session cache frees a pointer that points to unallocated memory, causing the client to crash with a "free(): invalid pointer" message. NOTE: It is likely that this is also exploitable during TLS 1.3 handshakes between a client and a malicious server. With TLS 1.3, it is not possible to exploit this as a man-in-the-middle.

    Published: 31 Aug 2022
    8.1
    High

    CVE-2022-3033

    Last Modified: 15 Apr 2025

    If a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <code>meta</code> tag having the <code>http-equiv="refresh"</code> attribute, and the content attribute specifying an URL, then Thunderbird started a network request to that URL, regardless of the configuration to block remote content. In combination with certain other HTML elements and attributes in the email, it was possible to execute JavaScript code included in the message in the context of the message compose document. The JavaScript code was able to perform actions including, but probably not limited to, read and modify the contents of the message compose document, including the quoted original message, which could potentially contain the decrypted plaintext of encrypted data in the crafted email. The contents could then be transmitted to the network, either to the URL specified in the META refresh tag, or to a different URL, as the JavaScript code could modify the URL specified in the document. This bug doesn't affect users who have changed the default Message Body display setting to 'simple html' or 'plain text'. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

    Published: 31 Aug 2022
    4.3
    Medium

    CVE-2022-3034

    Last Modified: 15 Apr 2025

    When receiving an HTML email that specified to load an <code>iframe</code> element from a remote location, a request to the remote document was sent. However, Thunderbird didn't display the document. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

    Published: 31 Aug 2022
    3.7
    Low

    CVE-2022-35252

    Last Modified: 5 May 2025

    When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.

    Published: 31 Aug 2022
    8.2
    High

    CVE-2022-36059

    Last Modified: 18 Feb 2025

    matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 19.4.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability to process data safely. Note that the matrix-js-sdk can appear to be operating normally but be excluding or corrupting runtime data presented to the consumer. This issue has been fixed in matrix-js-sdk 19.4.0 and users are advised to upgrade. Users unable to upgrade may mitigate this issue by redacting applicable events, waiting for the sync processor to store data, and restarting the client. Alternatively, redacting the applicable events and clearing all storage will often fix most perceived issues. In some cases, no workarounds are possible.

    Published: 31 Aug 2022
    7.5
    High

    CVE-2022-38152

    Last Modified: 21 Nov 2024

    An issue was discovered in wolfSSL before 5.5.0. When a TLS 1.3 client connects to a wolfSSL server and SSL_clear is called on its session, the server crashes with a segmentation fault. This occurs in the second session, which is created through TLS session resumption and reuses the initial struct WOLFSSL. If the server reuses the previous session structure (struct WOLFSSL) by calling wolfSSL_clear(WOLFSSL* ssl) on it, the next received Client Hello (that resumes the previous session) crashes the server. Note that this bug is only triggered when resuming sessions using TLS session resumption. Only servers that use wolfSSL_clear instead of the recommended SSL_free; SSL_new sequence are affected. Furthermore, wolfSSL_clear is part of wolfSSL's compatibility layer and is not enabled by default. It is not part of wolfSSL's native API.

    Published: 31 Aug 2022
    7.5
    High

    CVE-2022-39046

    Last Modified: 21 Nov 2024

    An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a portion of the contents of the heap.

    Published: 31 Aug 2022
    6.5
    Medium

    CVE-2022-3032

    Last Modified: 21 Nov 2024

    When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

    Published: 31 Aug 2022
    9.8
    Critical

    CVE-2022-36749

    Last Modified: 21 Nov 2024

    RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php. This vulnerability is exploited via a crafted payload injected into the file name of an uploaded file.

    Published: 30 Aug 2022
    6.1
    Medium

    CVE-2022-36748

    Last Modified: 21 Nov 2024

    PicUploader v2.6.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /master/index.php.

    Published: 30 Aug 2022
    6.1
    Medium

    CVE-2022-36747

    Last Modified: 21 Nov 2024

    Razor v0.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the function uploadchannel().

    Published: 30 Aug 2022
    6.1
    Medium

    CVE-2022-36746

    Last Modified: 21 Nov 2024

    LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component oxidized-cfg-check.inc.php.

    Published: 30 Aug 2022
    6.1
    Medium

    CVE-2022-36745

    Last Modified: 21 Nov 2024

    LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component print-customoid.php.

    Published: 30 Aug 2022
    7.5
    High

    CVE-2022-27563

    Last Modified: 21 Nov 2024

    An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service.

    Published: 30 Aug 2022
    6
    Medium

    CVE-2022-27560

    Last Modified: 21 Nov 2024

    HCL VersionVault Express exposes administrator credentials.

    Published: 30 Aug 2022
    4.8
    Medium

    CVE-2022-36657

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /librarian/edit_book_details.php.

    Published: 30 Aug 2022
    9.8
    Critical

    CVE-2022-36735

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /admin/delete.php.

    Published: 30 Aug 2022
    9.8
    Critical

    CVE-2022-36734

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /admin/delstu.php.

    Published: 30 Aug 2022
    9.8
    Critical

    CVE-2022-36733

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /admin/del.php.

    Published: 30 Aug 2022
    9.8
    Critical

    CVE-2022-36732

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /librarian/dele.php.

    Published: 30 Aug 2022
    9.8
    Critical

    CVE-2022-36731

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /librarian/delstu.php.

    Published: 30 Aug 2022
    9.8
    Critical

    CVE-2022-36730

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /librarian/delete.php.

    Published: 30 Aug 2022
    8.8
    High

    CVE-2022-34375

    Last Modified: 21 Nov 2024

    Dell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to unintentional access to path outside of restricted directory.

    Published: 30 Aug 2022
    8.8
    High

    CVE-2022-34374

    Last Modified: 21 Nov 2024

    Dell Container Storage Modules 1.2 contains an OS command injection in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to to execute arbitrary OS commands on the affected system.

    Published: 30 Aug 2022
    6.1
    Medium

    CVE-2022-34368

    Last Modified: 21 Nov 2024

    Dell EMC NetWorker 19.2.1.x 19.3.x, 19.4.x, 19.5.x, 19.6.x and 19.7.0.0 contain an Improper Handling of Insufficient Permissions or Privileges vulnerability. Authenticated non admin user could exploit this vulnerability and gain access to restricted resources.

    Published: 30 Aug 2022
    5.4
    Medium

    CVE-2022-33935

    Last Modified: 21 Nov 2024

    Dell EMC Data Protection Advisor versions 19.6 and earlier, contains a Stored Cross Site Scripting, an attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a victim user accesses the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery.

    Published: 30 Aug 2022
    8.6
    High

    CVE-2022-31232

    Last Modified: 21 Nov 2024

    SmartFabric storage software version 1.0.0 contains a Command-Injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access and perform actions on the affected system.

    Published: 30 Aug 2022
    7.8
    High

    CVE-2022-37173

    Last Modified: 21 Nov 2024

    An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacking attack on C:\Program.exe.

    Published: 30 Aug 2022
    8.8
    High

    CVE-2022-36565

    Last Modified: 21 Nov 2024

    Incorrect access control in the install directory (C:\Wamp64) of Wamp v3.2.6 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.

    Published: 30 Aug 2022
    7.8
    High

    CVE-2022-37172

    Last Modified: 21 Nov 2024

    Incorrect access control in the install directory (C:\msys64) of Msys2 v20220603 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.

    Published: 30 Aug 2022
    8.8
    High

    CVE-2022-36564

    Last Modified: 21 Nov 2024

    Incorrect access control in the install directory (C:\Strawberry) of StrawberryPerl v5.32.1.1 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.

    Published: 30 Aug 2022
    8.8
    High

    CVE-2022-36563

    Last Modified: 21 Nov 2024

    Incorrect access control in the install directory (C:\RailsInstaller) of Rubyinstaller2 v3.1.2 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.

    Published: 30 Aug 2022
    8.8
    High

    CVE-2022-36562

    Last Modified: 21 Nov 2024

    Incorrect access control in the install directory (C:\Ruby31-x64) of Rubyinstaller2 v3.1.2 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.

    Published: 30 Aug 2022
    5.5
    Medium

    CVE-2022-36561

    Last Modified: 21 Nov 2024

    XPDF v4.0.4 was discovered to contain a segmentation violation via the component /xpdf/AcroForm.cc:538.

    Published: 30 Aug 2022
    6.1
    Medium

    CVE-2021-29864

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager 6.0 and 6.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 206089

    Published: 30 Aug 2022
    7.5
    High

    CVE-2022-37237

    Last Modified: 21 Nov 2024

    An attacker can send malicious RTMP requests to make the ZLMediaKit server crash remotely. Affected version is below commit 7d8b212a3c3368bc2f6507cb74664fc419eb9327.

    Published: 30 Aug 2022
    9.8
    Critical

    CVE-2022-37176

    Last Modified: 21 Nov 2024

    Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability which allows attackers to remove the Wi-Fi password and force the device into open security mode via a crafted packet sent to goform/setWizard.

    Published: 30 Aug 2022
    7.5
    High

    CVE-2022-36552

    Last Modified: 21 Nov 2024

    Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which allows attackers to steal all data such as source code and system files via a crafted GET request.

    Published: 30 Aug 2022
    9.8
    Critical

    CVE-2022-37149

    Last Modified: 21 Nov 2024

    WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi. This vulnerability allows attackers to execute arbitrary commands via the username parameter.

    Published: 30 Aug 2022
    —
    Unknown

    CVE-2022-3063

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 30 Aug 2022
    —
    Unknown

    CVE-2022-3022

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 30 Aug 2022