CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2022-37316

    Last Modified: 21 Nov 2024

    Archer Platform 6.8 before 6.11 P3 (6.11.0.3) contains an improper API access control vulnerability in a multi-instance system that could potentially present unauthorized metadata to an authenticated user of the affected system. 6.10 P3 HF1 (6.10.0.3.1) is also a fixed release.

    Published: 25 Aug 2022
    7
    High

    CVE-2022-37318

    Last Modified: 21 Nov 2024

    Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious JavaScript code to the vulnerable web application. This code is then reflected to the victim and gets executed by the web browser in the context of the vulnerable web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.

    Published: 25 Aug 2022
    7.6
    High

    CVE-2022-37317

    Last Modified: 21 Nov 2024

    Archer Platform 6.x before 6.11 P3 contain an HTML injection vulnerability. An authenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious code in the context of the web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-28747

    Last Modified: 21 Nov 2024

    Key reuse in GoSecure Titan Inbox Detection & Response (IDR) through 2022-04-05 leads to remote code execution. To exploit this vulnerability, an attacker must craft and sign a serialized payload.

    Published: 25 Aug 2022
    6.1
    Medium

    CVE-2022-31798

    Last Modified: 21 Nov 2024

    Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin account or a user account.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-31499

    Last Modified: 21 Nov 2024

    Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.

    Published: 25 Aug 2022
    8.2
    High

    CVE-2022-31269

    Last Modified: 21 Nov 2024

    Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)

    Published: 25 Aug 2022
    8.8
    High

    CVE-2022-36721

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Textbook parameter at /admin/modify.php.

    Published: 25 Aug 2022
    8.8
    High

    CVE-2022-36720

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/modify1.php.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-36719

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the ok parameter at /admin/history.php.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-36715

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/search.php.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-36716

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/changestock.php.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2021-43329

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in license_update.php in Mumara Classic through 2.93 allows a remote unauthenticated attacker to execute arbitrary SQL commands via the license parameter.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-36697

    Last Modified: 21 Nov 2024

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_waste.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-36696

    Last Modified: 21 Nov 2024

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockout.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-36695

    Last Modified: 21 Nov 2024

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockin.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-36692

    Last Modified: 21 Nov 2024

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.

    Published: 25 Aug 2022
    9.8
    Critical

    CVE-2022-36693

    Last Modified: 21 Nov 2024

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_item.

    Published: 25 Aug 2022
    8.8
    High

    CVE-2022-36700

    Last Modified: 21 Nov 2024

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /items/manage_item.php.

    Published: 25 Aug 2022
    8.8
    High

    CVE-2022-36701

    Last Modified: 21 Nov 2024

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /items/view_item.php.

    Published: 25 Aug 2022
    8.8
    High

    CVE-2022-36698

    Last Modified: 21 Nov 2024

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /categories/view_category.php.

    Published: 25 Aug 2022
    8.8
    High

    CVE-2022-36703

    Last Modified: 21 Nov 2024

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /stocks/manage_stockin.php.

    Published: 25 Aug 2022
    8.8
    High

    CVE-2022-36699

    Last Modified: 21 Nov 2024

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /categories/manage_category.php.

    Published: 25 Aug 2022
    8
    High

    CVE-2022-2997

    Last Modified: 21 Nov 2024

    Session Fixation in GitHub repository snipe/snipe-it prior to 6.0.10.

    Published: 25 Aug 2022
    5.5
    Medium

    CVE-2020-27802

    Last Modified: 11 Apr 2025

    An floating point exception was discovered in the elf_lookup function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2020-27801

    Last Modified: 11 Apr 2025

    A heap-based buffer over-read was discovered in the get_le64 function in bele.h in UPX 4.0.0 via a crafted Mach-O file.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2020-27800

    Last Modified: 11 Apr 2025

    A heap-based buffer over-read was discovered in the get_le32 function in bele.h in UPX 4.0.0 via a crafted Mach-O file.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2020-27799

    Last Modified: 11 Apr 2025

    A heap-based buffer over-read was discovered in the acc_ua_get_be32 function in miniacc.h in UPX 4.0.0 via a crafted Mach-O file.

    Published: 25 Aug 2022
    5.5
    Medium

    CVE-2020-27798

    Last Modified: 11 Apr 2025

    An invalid memory address reference was discovered in the adjABS function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.

    Published: 25 Aug 2022
    5.5
    Medium

    CVE-2020-27797

    Last Modified: 11 Apr 2025

    An invalid memory address reference was discovered in the elf_lookup function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2020-27796

    Last Modified: 11 Apr 2025

    A heap-based buffer over-read was discovered in the invert_pt_dynamic function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.

    Published: 25 Aug 2022
    5.4
    Medium

    CVE-2022-36527

    Last Modified: 21 Nov 2024

    Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the post title text field under the publish blog module.

    Published: 25 Aug 2022
    8.8
    High

    CVE-2022-20824

    Last Modified: 21 Nov 2024

    A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation of specific values that are within a Cisco Discovery Protocol message. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges or cause the Cisco Discovery Protocol process to crash and restart multiple times, which would cause the affected device to reload, resulting in a DoS condition. Note: Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).

    Published: 25 Aug 2022
    8.6
    High

    CVE-2022-20823

    Last Modified: 21 Nov 2024

    A vulnerability in the OSPF version 3 (OSPFv3) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incomplete input validation of specific OSPFv3 packets. An attacker could exploit this vulnerability by sending a malicious OSPFv3 link-state advertisement (LSA) to an affected device. A successful exploit could allow the attacker to cause the OSPFv3 process to crash and restart multiple times, causing the affected device to reload and resulting in a DoS condition. Note: The OSPFv3 feature is disabled by default. To exploit this vulnerability, an attacker must be able to establish a full OSPFv3 neighbor state with an affected device. For more information about exploitation conditions, see the Details section of this advisory.

    Published: 25 Aug 2022
    6.7
    Medium

    CVE-2022-20865

    Last Modified: 21 Nov 2024

    A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The attacker would need to have Administrator privileges on the device. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input to the affected command. A successful exploit could allow the attacker to execute commands on the underlying operating system with root privileges.

    Published: 25 Aug 2022
    8.8
    High

    CVE-2022-20921

    Last Modified: 21 Nov 2024

    A vulnerability in the API implementation of Cisco ACI Multi-Site Orchestrator (MSO) could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to improper authorization on specific APIs. An attacker could exploit this vulnerability by sending crafted HTTP requests. A successful exploit could allow an attacker who is authenticated with non-Administrator privileges to elevate to Administrator privileges on an affected device.

    Published: 25 Aug 2022
    5.9
    Medium

    CVE-2021-43767

    Last Modified: 21 Nov 2024

    Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use 'cert' authentication, a man-in-the-middle attacker can inject false responses to the client's first few queries. Despite the use of SSL certificate verification and encryption, Odyssey will pass these results to client as if they originated from valid server. This is similar to CVE-2021-23222 for PostgreSQL.

    Published: 25 Aug 2022
    8.1
    High

    CVE-2021-43766

    Last Modified: 21 Nov 2024

    Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common Name for client authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2021-23214 for PostgreSQL.

    Published: 25 Aug 2022
    7.5
    High

    CVE-2021-42523

    Last Modified: 21 Nov 2024

    There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'err_msg' of 'sqlite3_exec' is not releasing after use, while libxml2 emphasizes that the caller needs to release it.

    Published: 25 Aug 2022
    7.5
    High

    CVE-2021-42522

    Last Modified: 21 Nov 2024

    There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was caused by the incorrect use of libxml2 API. The vendor forgot to call 'g_free()' to release the return value of 'xmlGetProp()'.

    Published: 25 Aug 2022
    5.5
    Medium

    CVE-2021-4022

    Last Modified: 21 Nov 2024

    A vulnerability was found in rizin. The bug involves an ELF64 binary for the HPPA architecture. When a specially crafted binarygets analysed by rizin, it causes rizin to crash by freeing an uninitialized (and potentially user controlled, depending on the build) memory address.

    Published: 25 Aug 2022
    4.7
    Medium

    CVE-2022-37952

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability exists in the iHistorian Data Display of WorkstationST (<v07.09.15) could allow an attacker to compromise a victim's browser. WorkstationST is only deployed in specific, controlled environments rendering attack complexity significantly higher than if the attack were conducted on the software in isolation. WorkstationST v07.09.15 can be found in ControlST v07.09.07 SP8 and greater.

    Published: 25 Aug 2022
    4.7
    Medium

    CVE-2022-37953

    Last Modified: 21 Nov 2024

    An HTTP response splitting vulnerability exists in the AM Gateway Challenge-Response dialog of WorkstationST (<v07.09.15) and could allow an attacker to compromise a victim's browser/session. WorkstationST is only deployed in specific, controlled environments rendering attack complexity significantly higher than if the attack were conducted on the software in isolation. WorkstationST v07.09.15 can be found in ControlST v07.09.07 SP8 and greater.

    Published: 25 Aug 2022
    5.3
    Medium

    CVE-2022-23235

    Last Modified: 21 Nov 2024

    Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.10P1 are susceptible to a vulnerability which could allow an attacker to discover cluster, node and Active IQ Unified Manager specific information via AutoSupport telemetry data that is sent even when AutoSupport has been disabled.

    Published: 25 Aug 2022
    6.5
    Medium

    CVE-2022-23715

    Last Modified: 21 Nov 2024

    A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystore settings values in logs such as the audit log or deployment logs in the Logging and Monitoring cluster. The affected APIs are PATCH /api/v1/user and PATCH /deployments/{deployment_id}/elasticsearch/{ref_id}/keystore

    Published: 25 Aug 2022
    5.4
    Medium

    CVE-2022-36358

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in SEO Scout plugin <= 0.9.83 at WordPress allows attackers to trick users with administrative rights to unintentionally change the plugin settings.

    Published: 25 Aug 2022
    8.6
    High

    CVE-2022-2465

    Last Modified: 16 Apr 2025

    Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Deserialization of Untrusted Data vulnerability. ISaGRAF Workbench does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a local user in ISaGRAF Workbench, may result in remote code execution. This vulnerability requires user interaction to be successfully exploited.

    Published: 25 Aug 2022
    7.7
    High

    CVE-2022-2464

    Last Modified: 16 Apr 2025

    Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. Crafted malicious files can allow an attacker to traverse the file system when opened by ISaGRAF Workbench. If successfully exploited, an attacker could overwrite existing files and create additional files with the same permissions of the ISaGRAF Workbench software. User interaction is required for this exploit to be successful.

    Published: 25 Aug 2022
    6.1
    Medium

    CVE-2022-2463

    Last Modified: 16 Apr 2025

    Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. A crafted malicious .7z exchange file may allow an attacker to gain the privileges of the ISaGRAF Workbench software when opened. If the software is running at the SYSTEM level, then the attacker will gain admin level privileges. User interaction is required for this exploit to be successful.

    Published: 25 Aug 2022
    —
    Unknown

    CVE-2021-4042

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 25 Aug 2022