CVE Feed

    Dashboard / CVE

    8.6
    High

    CVE-2022-2132

    Last Modified: 21 Nov 2024

    A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.

    Published: 29 Aug 2022
    5.5
    Medium

    CVE-2022-2953

    Last Modified: 21 Nov 2024

    LibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 48d6ece8.

    Published: 29 Aug 2022
    7.8
    High

    CVE-2022-38511

    Last Modified: 21 Nov 2024

    TOTOLINK A810R V5.9c.4050_B20190424 was discovered to contain a command injection vulnerability via the component downloadFile.cgi.

    Published: 28 Aug 2022
    7.8
    High

    CVE-2022-38510

    Last Modified: 21 Nov 2024

    Tenda_TX9pro V22.03.02.10 was discovered to contain a buffer overflow via the component httpd/SetNetControlList.

    Published: 28 Aug 2022
    7.8
    High

    CVE-2022-36615

    Last Modified: 21 Nov 2024

    TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

    Published: 28 Aug 2022
    7.8
    High

    CVE-2022-36616

    Last Modified: 21 Nov 2024

    TOTOLINK A810R V4.1.2cu.5182_B20201026 and V5.9c.4050_B20190424 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

    Published: 28 Aug 2022
    7.8
    High

    CVE-2022-36614

    Last Modified: 21 Nov 2024

    TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

    Published: 28 Aug 2022
    7.8
    High

    CVE-2022-36612

    Last Modified: 21 Nov 2024

    TOTOLINK A950RG V4.1.2cu.5204_B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

    Published: 28 Aug 2022
    7.8
    High

    CVE-2022-36613

    Last Modified: 21 Nov 2024

    TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

    Published: 28 Aug 2022
    7.8
    High

    CVE-2022-36611

    Last Modified: 21 Nov 2024

    TOTOLINK A800R V4.1.2cu.5137_B20200730 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

    Published: 28 Aug 2022
    7.8
    High

    CVE-2022-36610

    Last Modified: 21 Nov 2024

    TOTOLINK A720R V4.1.5cu.532_B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

    Published: 28 Aug 2022
    6.1
    Medium

    CVE-2022-36573

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Pagekit CMS v1.0.18 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Markdown text box under /blog/post/edit.

    Published: 28 Aug 2022
    9.8
    Critical

    CVE-2022-36572

    Last Modified: 21 Nov 2024

    Sinsiu Sinsiu Enterprise Website System v1.1.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /upload/admin.php?/deal/.

    Published: 28 Aug 2022
    9.8
    Critical

    CVE-2022-36708

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /student/bookdetails.php.

    Published: 28 Aug 2022
    9.8
    Critical

    CVE-2022-36706

    Last Modified: 21 Nov 2024

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /stocks/manage_stockout.php.

    Published: 28 Aug 2022
    —
    Unknown

    CVE-2022-36707

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-2214. Reason: This candidate is a reservation duplicate of CVE-2022-2214. Notes: All CVE users should reference CVE-2022-2214 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Aug 2022
    9.8
    Critical

    CVE-2022-36705

    Last Modified: 21 Nov 2024

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /stocks/manage_waste.php.

    Published: 28 Aug 2022
    8.8
    High

    CVE-2022-36704

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /librarian/studentdetails.php.

    Published: 28 Aug 2022
    7.5
    High

    CVE-2022-38562

    Last Modified: 21 Nov 2024

    Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the lan parameter.

    Published: 28 Aug 2022
    7.5
    High

    CVE-2022-38564

    Last Modified: 21 Nov 2024

    Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow vulnerability in the function formSetPicListItem. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adItemUID parameter.

    Published: 28 Aug 2022
    7.5
    High

    CVE-2022-38565

    Last Modified: 21 Nov 2024

    Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailpwd parameter.

    Published: 28 Aug 2022
    7.5
    High

    CVE-2022-38566

    Last Modified: 21 Nov 2024

    Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailname parameter.

    Published: 28 Aug 2022
    7.5
    High

    CVE-2022-38567

    Last Modified: 21 Nov 2024

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow vulnerability in the function formSetAdConfigInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the authIPs parameter.

    Published: 28 Aug 2022
    7.5
    High

    CVE-2022-38563

    Last Modified: 21 Nov 2024

    Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the MACAddr parameter.

    Published: 28 Aug 2022
    7.5
    High

    CVE-2022-38568

    Last Modified: 21 Nov 2024

    Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the hostname parameter.

    Published: 28 Aug 2022
    7.5
    High

    CVE-2022-38569

    Last Modified: 21 Nov 2024

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelAd.

    Published: 28 Aug 2022
    7.5
    High

    CVE-2022-38571

    Last Modified: 21 Nov 2024

    Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow in the function formSetGuideListItem.

    Published: 28 Aug 2022
    7.5
    High

    CVE-2022-38570

    Last Modified: 21 Nov 2024

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelPushedAd. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adPushUID parameter.

    Published: 28 Aug 2022
    9.8
    Critical

    CVE-2022-38555

    Last Modified: 21 Nov 2024

    Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.

    Published: 28 Aug 2022
    9.8
    Critical

    CVE-2022-37055

    Last Modified: 9 Dec 2025

    D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,

    Published: 28 Aug 2022
    9.8
    Critical

    CVE-2022-37056

    Last Modified: 9 Dec 2025

    D-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin, hnap_main,

    Published: 28 Aug 2022
    9.8
    Critical

    CVE-2022-37057

    Last Modified: 9 Dec 2025

    D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin, ssdpcgi_main.

    Published: 28 Aug 2022
    9.8
    Critical

    CVE-2022-37053

    Last Modified: 21 Nov 2024

    TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.

    Published: 28 Aug 2022
    9.8
    Critical

    CVE-2022-38556

    Last Modified: 21 Nov 2024

    Trendnet TEW733GR v1.03B01 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.

    Published: 28 Aug 2022
    9.8
    Critical

    CVE-2022-38557

    Last Modified: 21 Nov 2024

    D-Link DIR845L v1.00-v1.03 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.

    Published: 28 Aug 2022
    9.8
    Critical

    CVE-2022-36756

    Last Modified: 21 Nov 2024

    DIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php.

    Published: 28 Aug 2022
    9.8
    Critical

    CVE-2022-36755

    Last Modified: 21 Nov 2024

    D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php.

    Published: 28 Aug 2022
    6.5
    Medium

    CVE-2022-3017

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 0.10.38.

    Published: 28 Aug 2022
    7.8
    High

    CVE-2022-3016

    Last Modified: 21 Nov 2024

    Use After Free in GitHub repository vim/vim prior to 9.0.0286.

    Published: 28 Aug 2022
    7.5
    High

    CVE-2022-38794

    Last Modified: 21 Nov 2024

    Zaver through 2020-12-15 allows directory traversal via the GET /.. substring.

    Published: 27 Aug 2022
    9.8
    Critical

    CVE-2022-38792

    Last Modified: 21 Nov 2024

    The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code execution backdoor inserted by a third party.

    Published: 27 Aug 2022
    4.3
    Medium

    CVE-2022-2787

    Last Modified: 21 Nov 2024

    Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of service on the schroot service for all users that may start a schroot session.

    Published: 27 Aug 2022
    3.5
    Low

    CVE-2022-3015

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in oretnom23 Fast Food Ordering System. This issue affects some unknown processing of the file admin/?page=reports. The manipulation of the argument date leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-207425 was assigned to this vulnerability.

    Published: 27 Aug 2022
    3.5
    Low

    CVE-2022-3014

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic was found in SourceCodester Simple Task Managing System. This vulnerability affects unknown code. The manipulation of the argument student_add leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-207424.

    Published: 27 Aug 2022
    6.3
    Medium

    CVE-2022-3013

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical has been found in SourceCodester Simple Task Managing System. This affects an unknown part of the file /loginVaLidation.php. The manipulation of the argument login leads to sql injection. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-207423.

    Published: 27 Aug 2022
    6.3
    Medium

    CVE-2022-3012

    Last Modified: 15 Apr 2025

    A vulnerability was found in oretnom23 Fast Food Ordering System. It has been rated as critical. Affected by this issue is some unknown functionality of the file ffos/admin/reports/index.php. The manipulation of the argument date leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-207422 is the identifier assigned to this vulnerability.

    Published: 27 Aug 2022
    5.5
    Medium

    CVE-2022-3213

    Last Modified: 21 Nov 2024

    A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service.

    Published: 27 Aug 2022
    5.4
    Medium

    CVE-2022-36548

    Last Modified: 11 Dec 2025

    Edoc-doctor-appointment-system v1.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability at /patient/settings.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field.

    Published: 26 Aug 2022
    6.1
    Medium

    CVE-2022-36547

    Last Modified: 16 Dec 2025

    Edoc-doctor-appointment-system v1.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /patient/index.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search field.

    Published: 26 Aug 2022
    8.8
    High

    CVE-2022-36546

    Last Modified: 16 Dec 2025

    Edoc-doctor-appointment-system v1.0.1 was discovered to contain a Cross-Site Request Forgery (CSRF) via /patient/settings.php.

    Published: 26 Aug 2022