CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2022-2330

    Last Modified: 21 Nov 2024

    Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constructed XML file, which the DLP Agent doesn't parse correctly.

    Published: 30 Aug 2022
    5.4
    Medium

    CVE-2022-25646

    Last Modified: 21 Nov 2024

    All versions of package x-data-spreadsheet are vulnerable to Cross-site Scripting (XSS) due to missing sanitization of values inserted into the cells.

    Published: 30 Aug 2022
    8.8
    High

    CVE-2022-38118

    Last Modified: 21 Nov 2024

    OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user privilege can perform SQL-injection to access, modify, delete database, perform system operations and disrupt service.

    Published: 30 Aug 2022
    9.8
    Critical

    CVE-2022-38116

    Last Modified: 21 Nov 2024

    Le-yan Personnel and Salary Management System has hard-coded database account and password within the website source code. An unauthenticated remote attacker can access, modify system data or disrupt service.

    Published: 30 Aug 2022
    6.5
    Medium

    CVE-2022-26529

    Last Modified: 21 Nov 2024

    Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for segmented packets’ link parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service.

    Published: 30 Aug 2022
    6.5
    Medium

    CVE-2022-26528

    Last Modified: 21 Nov 2024

    Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the length of segmented packets’ shift parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service.

    Published: 30 Aug 2022
    6.5
    Medium

    CVE-2022-26527

    Last Modified: 21 Nov 2024

    Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the size of segmented packets’ reference parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service.

    Published: 30 Aug 2022
    6.5
    Medium

    CVE-2022-25635

    Last Modified: 21 Nov 2024

    Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for broadcast network packet length. An unauthenticated attacker in the adjacent network can exploit this vulnerability to disrupt service.

    Published: 30 Aug 2022
    7.8
    High

    CVE-2022-24106

    Last Modified: 21 Nov 2024

    In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.

    Published: 30 Aug 2022
    7.8
    High

    CVE-2022-24107

    Last Modified: 21 Nov 2024

    Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc.

    Published: 30 Aug 2022
    7.5
    High

    CVE-2022-39028

    Last Modified: 21 Nov 2024

    telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However, if the telnetd application has many crashes within a short time interval, the telnet service would become unavailable after inetd logs a "telnet/tcp server failing (looping), service terminated" error. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.

    Published: 30 Aug 2022
    5.3
    Medium

    CVE-2022-2663

    Last Modified: 21 Nov 2024

    An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly matches the message. A firewall may be able to be bypassed when users are using unencrypted IRC with nf_conntrack_irc configured.

    Published: 30 Aug 2022
    6.5
    Medium

    CVE-2022-28199

    Last Modified: 21 Nov 2024

    NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.

    Published: 30 Aug 2022
    7.8
    High

    CVE-2022-38784

    Last Modified: 21 Nov 2024

    Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2022-38171 in Xpdf.

    Published: 30 Aug 2022
    6.5
    Medium

    CVE-2021-46837

    Last Modified: 21 Nov 2024

    res_pjsip_t38 in Sangoma Asterisk 16.x before 16.16.2, 17.x before 17.9.3, and 18.x before 18.2.2, and Certified Asterisk before 16.8-cert7, allows an attacker to trigger a crash by sending an m=image line and zero port in a response to a T.38 re-invite initiated by Asterisk. This is a re-occurrence of the CVE-2019-15297 symptoms but not for exactly the same reason. The crash occurs because there is an append operation relative to the active topology, but this should instead be a replace operation.

    Published: 30 Aug 2022
    7.5
    High

    CVE-2022-25857

    Last Modified: 21 Nov 2024

    The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.

    Published: 30 Aug 2022
    5.3
    Medium

    CVE-2022-25887

    Last Modified: 21 Nov 2024

    The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.

    Published: 30 Aug 2022
    7.8
    High

    CVE-2022-3037

    Last Modified: 24 Sept 2026

    Use After Free in GitHub repository vim/vim prior to 9.0.0322.

    Published: 30 Aug 2022
    9.8
    Critical

    CVE-2022-36714

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Section parameter at /staff/lab.php.

    Published: 29 Aug 2022
    9.8
    Critical

    CVE-2022-36713

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Section parameter at /librarian/lab.php.

    Published: 29 Aug 2022
    9.8
    Critical

    CVE-2022-36712

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/studentdetails.php.

    Published: 29 Aug 2022
    9.8
    Critical

    CVE-2022-36711

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/bookdetails.php.

    Published: 29 Aug 2022
    9.8
    Critical

    CVE-2022-36709

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/edit_book_details.php.

    Published: 29 Aug 2022
    9.8
    Critical

    CVE-2022-36560

    Last Modified: 21 Nov 2024

    Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers are able to access the passcodes at /etc/srapi/config/system.conf and /usr/sbin/ssol-sshd.sh.

    Published: 29 Aug 2022
    9.8
    Critical

    CVE-2022-36558

    Last Modified: 21 Nov 2024

    Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able to access the passcord via the file /etc/ciel.cfg.

    Published: 29 Aug 2022
    9.8
    Critical

    CVE-2022-36559

    Last Modified: 21 Nov 2024

    Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi.

    Published: 29 Aug 2022
    9.8
    Critical

    CVE-2022-36557

    Last Modified: 21 Nov 2024

    Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers to execute arbitrary code via a crafted html file.

    Published: 29 Aug 2022
    9.8
    Critical

    CVE-2022-36556

    Last Modified: 21 Nov 2024

    Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08execute_ping_01.

    Published: 29 Aug 2022
    9.8
    Critical

    CVE-2022-36554

    Last Modified: 21 Nov 2024

    A command injection vulnerability in the CLI (Command Line Interface) implementation of Hytec Inter HWL-2511-SS v1.05 and below allows attackers to execute arbitrary commands with root privileges.

    Published: 29 Aug 2022
    9.8
    Critical

    CVE-2022-36555

    Last Modified: 21 Nov 2024

    Hytec Inter HWL-2511-SS v1.05 and below implements a SHA512crypt hash for the root account which can be easily cracked via a brute-force attack.

    Published: 29 Aug 2022
    9.8
    Critical

    CVE-2022-36553

    Last Modified: 21 Nov 2024

    Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi.

    Published: 29 Aug 2022
    8.8
    High

    CVE-2022-38625

    Last Modified: 21 Nov 2024

    Patlite NH-FB v1.46 and below was discovered to contain insufficient firmware validation during the upgrade firmware file upload process. This vulnerability allows authenticated attackers to create and upload their own custom-built firmware and inject malicious code. NOTE: the vendor's position is that this is a design choice, not a vulnerability

    Published: 29 Aug 2022
    5.4
    Medium

    CVE-2021-38934

    Last Modified: 21 Nov 2024

    IBM Engineering Test Management 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 210671.

    Published: 29 Aug 2022
    7.2
    High

    CVE-2020-26938

    Last Modified: 21 Nov 2024

    In oauth2-server (aka node-oauth2-server) through 3.1.1, the value of the redirect_uri parameter received during the authorization and token request is checked against an incorrect URI pattern ("[a-zA-Z][a-zA-Z0-9+.-]+:") before making a redirection. This allows a malicious client to pass an XSS payload through the redirect_uri parameter while making an authorization request. NOTE: this vulnerability is similar to CVE-2020-7741.

    Published: 29 Aug 2022
    6.2
    Medium

    CVE-2022-21385

    Last Modified: 21 Nov 2024

    A flaw in net_rds_alloc_sgs() in Oracle Linux kernels allows unprivileged local users to crash the machine. CVSS 3.1 Base Score 6.2 (Availability impacts). CVSS Vector (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

    Published: 29 Aug 2022
    8.8
    High

    CVE-2022-38772

    Last Modified: 21 Nov 2024

    Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that lead to remote code execution in the NMAP feature.

    Published: 29 Aug 2022
    9.8
    Critical

    CVE-2022-32993

    Last Modified: 21 Nov 2024

    TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh.

    Published: 29 Aug 2022
    4.8
    Medium

    CVE-2022-3035

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11.

    Published: 29 Aug 2022
    5.9
    Medium

    CVE-2022-36037

    Last Modified: 23 Apr 2025

    kirby is a content management system (CMS) that adapts to many different projects and helps you build your own ideal interface. Cross-site scripting (XSS) is a type of vulnerability that allows execution of any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. If bad actors gain access to your group of authenticated Panel users they can escalate their privileges via the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. The multiselect field allows selection of tags from an autocompleted list. Unfortunately, the Panel in Kirby 3.5 used HTML rendering for the raw option value. This allowed **attackers with influence on the options source** to store HTML code. The browser of the victim who visited a page with manipulated multiselect options in the Panel will then have rendered this malicious HTML code when the victim opened the autocomplete dropdown. Users are *not* affected by this vulnerability if you don't use the multiselect field or don't use it with options that can be manipulated by attackers. The problem has been patched in Kirby 3.5.8.1.

    Published: 29 Aug 2022
    3.6
    Low

    CVE-2022-36036

    Last Modified: 22 Apr 2025

    mdx-mermaid provides plug and play access to Mermaid in MDX. There is a potential for an arbitrary javascript injection in versions less than 1.3.0 and 2.0.0-rc1. Modify any mermaid code blocks with arbitrary code and it will execute when the component is loaded by MDXjs. This vulnerability was patched in version(s) 1.3.0 and 2.0.0-rc2. There are currently no known workarounds.

    Published: 29 Aug 2022
    6.5
    Medium

    CVE-2022-2638

    Last Modified: 21 Nov 2024

    The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be removed on the system which is supposed to be the CSV file. This could allow high privilege users to delete arbitrary file from the server

    Published: 29 Aug 2022
    6.1
    Medium

    CVE-2022-2599

    Last Modified: 21 Nov 2024

    The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.21.83 does not sanitise and escape some parameters before outputting them back in an admin dashboard, leading to Reflected Cross-Site Scripting

    Published: 29 Aug 2022
    7.2
    High

    CVE-2022-2559

    Last Modified: 21 Nov 2024

    The Fluent Support WordPress plugin before 1.5.8 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection vulnerability exploitable by high privilege users

    Published: 29 Aug 2022
    4.8
    Medium

    CVE-2022-2374

    Last Modified: 21 Nov 2024

    The Simply Schedule Appointments WordPress plugin before 1.5.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 29 Aug 2022
    6.1
    Medium

    CVE-2022-2537

    Last Modified: 21 Nov 2024

    The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters before outputting them back in an attributes of an admin page, leading to Reflected Cross-Site Scripting.

    Published: 29 Aug 2022
    6.1
    Medium

    CVE-2022-2538

    Last Modified: 21 Nov 2024

    The WP Hide & Security Enhancer WordPress plugin before 1.8 does not escape a parameter before outputting it back in an attribute of a backend page, leading to a Reflected Cross-Site Scripting

    Published: 29 Aug 2022
    2.7
    Low

    CVE-2022-2556

    Last Modified: 21 Nov 2024

    The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example

    Published: 29 Aug 2022
    5.3
    Medium

    CVE-2022-2373

    Last Modified: 21 Nov 2024

    The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address

    Published: 29 Aug 2022
    7.2
    High

    CVE-2022-2261

    Last Modified: 21 Nov 2024

    The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue.

    Published: 29 Aug 2022
    4.3
    Medium

    CVE-2022-2267

    Last Modified: 21 Nov 2024

    The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as subscriber) to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example

    Published: 29 Aug 2022