CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2022-2172

    Last Modified: 21 Nov 2024

    The LinkWorth WordPress plugin before 3.3.4 does not implement nonce checks, which could allow attackers to make a logged in admin change settings via a CSRF attack.

    Published: 22 Aug 2022
    7.2
    High

    CVE-2022-25812

    Last Modified: 21 Nov 2024

    The Transposh WordPress Translation WordPress plugin before 1.0.8 does not validate its debug settings, which could allow allowing high privilege users such as admin to perform RCE

    Published: 22 Aug 2022
    7.2
    High

    CVE-2022-25811

    Last Modified: 21 Nov 2024

    The Transposh WordPress Translation WordPress plugin through 1.0.8 does not sanitise and escape the order and orderby parameters before using them in a SQL statement, leading to a SQL injection

    Published: 22 Aug 2022
    6.5
    Medium

    CVE-2022-25810

    Last Modified: 21 Nov 2024

    The Transposh WordPress Translation WordPress plugin through 1.0.8 exposes a couple of sensitive actions such has “tp_reset” under the Utilities tab (/wp-admin/admin.php?page=tp_utils), which can be used/executed as the lowest-privileged user. Basically all Utilities functionalities are vulnerable this way, which involves resetting configurations and backup/restore operations.

    Published: 22 Aug 2022
    6.1
    Medium

    CVE-2022-1932

    Last Modified: 21 Nov 2024

    The Rezgo Online Booking WordPress plugin before 4.1.8 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site Scripting, which can be exploited either via a LFI in an AJAX action, or direct call to the affected file

    Published: 22 Aug 2022
    4.8
    Medium

    CVE-2022-1322

    Last Modified: 21 Nov 2024

    The Coming Soon - Under Construction WordPress plugin through 1.1.9 does not sanitize and escape some of its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 22 Aug 2022
    4.3
    Medium

    CVE-2022-1251

    Last Modified: 21 Nov 2024

    The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request.

    Published: 22 Aug 2022
    4.8
    Medium

    CVE-2022-0446

    Last Modified: 21 Nov 2024

    The Simple Banner WordPress plugin before 2.12.0 does not properly sanitize its "Simple Banner Text" Settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 22 Aug 2022
    5.4
    Medium

    CVE-2021-24912

    Last Modified: 21 Nov 2024

    The Transposh WordPress Translation WordPress plugin before 1.0.8 does not have CSRF check in its tp_translation AJAX action, which could allow attackers to make authorised users add a translation. Given the lack of sanitisation in the tk0 parameter, this could lead to a Stored Cross-Site Scripting issue which will be executed in the context of a logged in admin

    Published: 22 Aug 2022
    5.4
    Medium

    CVE-2021-24911

    Last Modified: 21 Nov 2024

    The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the tk0 parameter from the tp_translation AJAX action, leading to Stored Cross-Site Scripting, which will trigger in the admin dashboard of the plugin. The minimum role needed to perform such attack depends on the plugin "Who can translate ?" setting.

    Published: 22 Aug 2022
    6.1
    Medium

    CVE-2021-24910

    Last Modified: 21 Nov 2024

    The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is installed) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

    Published: 22 Aug 2022
    6.1
    Medium

    CVE-2022-34857

    Last Modified: 20 Feb 2025

    Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPress

    Published: 22 Aug 2022
    4.3
    Medium

    CVE-2022-36346

    Last Modified: 20 Feb 2025

    Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Max Foundry MaxButtons plugin <= 9.2 at WordPress.

    Published: 22 Aug 2022
    9.8
    Critical

    CVE-2022-34149

    Last Modified: 20 Feb 2025

    Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.

    Published: 22 Aug 2022
    9.8
    Critical

    CVE-2022-34858

    Last Modified: 20 Feb 2025

    Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress.

    Published: 22 Aug 2022
    4.1
    Medium

    CVE-2022-33900

    Last Modified: 28 Apr 2026

    PHP Object Injection vulnerability in Easy Digital Downloads plugin <= 3.0.1 at WordPress.

    Published: 22 Aug 2022
    4.5
    Medium

    CVE-2022-35656

    Last Modified: 21 Nov 2024

    Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly.

    Published: 22 Aug 2022
    6.1
    Medium

    CVE-2022-35655

    Last Modified: 21 Nov 2024

    Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.

    Published: 22 Aug 2022
    4.2
    Medium

    CVE-2022-34347

    Last Modified: 21 Mar 2025

    Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.

    Published: 22 Aug 2022
    6.1
    Medium

    CVE-2022-35654

    Last Modified: 21 Nov 2024

    Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.

    Published: 22 Aug 2022
    4.8
    Medium

    CVE-2021-36857

    Last Modified: 20 Feb 2025

    Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in wpshopmart Testimonial Builder plugin <= 1.6.1 at WordPress.

    Published: 22 Aug 2022
    4.3
    Medium

    CVE-2021-36852

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress.

    Published: 22 Aug 2022
    4.8
    Medium

    CVE-2021-36847

    Last Modified: 20 Feb 2025

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WebbaPlugins Webba Booking plugin <= 4.2.21 at WordPress.

    Published: 22 Aug 2022
    7.5
    High

    CVE-2022-37133

    Last Modified: 21 Nov 2024

    D-link DIR-816 A2_v1.10CNB04.img reboots the router without authentication via /goform/doReboot. No authentication is required, and reboot is executed when the function returns at the end.

    Published: 22 Aug 2022
    4.3
    Medium

    CVE-2022-34772

    Last Modified: 21 Nov 2024

    Tabit - password enumeration. Description: Tabit - password enumeration. The passwords for the Tabit system is a 4 digit OTP. One can resend OTP and try logging in indefinitely. Once again, this is an example of OWASP: API4 - Rate limiting.

    Published: 22 Aug 2022
    5.5
    Medium

    CVE-2022-34776

    Last Modified: 21 Nov 2024

    Tabit - giftcard stealth. Several APIs on the web system display, without authorization, sensitive information such as health statements, previous bills in a specific restaurant, alcohol consumption and smoking habits. Each of the described APIs, has in its URL one or more MongoDB ID which is not so simple to enumerate. However, they each receive a 'tiny URL' in tabits domain, in the form of https://tbit.be/{suffix} with suffix being a 5 character long string containing numbers, lower and upper case letters. It is not so simple to enumerate them all, but really easy to find some that work and lead to a personal endpoint. Furthermore, the redirect URL disclosed the MongoDB IDs discussed above, and we could use them to query other endpoints disclosing more personal information.

    Published: 22 Aug 2022
    6.3
    Medium

    CVE-2022-34775

    Last Modified: 21 Nov 2024

    Tabit - Excessive data exposure. Another endpoint mapped by the tiny url, was one for reservation cancellation, containing the MongoDB ID of the reservation, and organization. This can be used to query the http://tgm-api.tabit.cloud/rsv/management/{reservationId}?organization={orgId} API which returns a lot of data regarding the reservation (OWASP: API3): Name, mail, phone number, the number of visits of the user to this specific restaurant, the money he spent there, the money he spent on alcohol, whether he left a deposit etc. This information can easily be used for a phishing attack.

    Published: 22 Aug 2022
    6.3
    Medium

    CVE-2022-34774

    Last Modified: 21 Nov 2024

    Tabit - Arbitrary account modification. One of the endpoints mapped by the tiny URL, was a page where an adversary can modify personal details, such as email addresses and phone numbers of a specific user in a restaurant's loyalty program. Possibly allowing account takeover (the mail can be used to reset password).

    Published: 22 Aug 2022
    9.8
    Critical

    CVE-2022-37134

    Last Modified: 21 Nov 2024

    D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrname will be decrypted by base64, and the result will be stored in v94, which does not check the size of l2tp_usrname, resulting in stack overflow.

    Published: 22 Aug 2022
    4.9
    Medium

    CVE-2022-34773

    Last Modified: 21 Nov 2024

    Tabit - HTTP Method manipulation. https://bridge.tabit.cloud/configuration/addresses-query - can be POST-ed to add addresses to the DB. This is an example of OWASP:API8 – Injection.

    Published: 22 Aug 2022
    4.6
    Medium

    CVE-2022-34770

    Last Modified: 21 Nov 2024

    Tabit - sensitive information disclosure. Several APIs on the web system display, without authorization, sensitive information such as health statements, previous bills in a specific restaurant, alcohol consumption and smoking habits. Each of the described API’s, has in its URL one or more MongoDB ID which is not so simple to enumerate. However, they each receive a ‘tiny URL’ in Tabit’s domain, in the form of https://tbit.be/{suffix} with suffix being a 5 characters long string containing numbers, lower- and upper-case letters. It is not so simple to enumerate them all, but really easy to find some that work and lead to a personal endpoint. This is both an example of OWASP: API4 - rate limiting and OWASP: API1 - Broken object level authorization. Furthermore, the redirect URL disclosed the MongoDB IDs discussed above, and we could use them to query other endpoints disclosing more personal information. For example: The URL https://tabitisrael.co.il/online-reservations/health-statement?orgId={org_id}&healthStatementId={health_statement_id} is used to invite friends to fill a health statement before attending the restaurant. We can use the health_statement_id to access the https://tgm-api.tabit.cloud/health-statement/{health_statement_id} API which disclose medical information as well as id number.

    Published: 22 Aug 2022
    5.5
    Medium

    CVE-2022-34771

    Last Modified: 21 Nov 2024

    Tabit - arbitrary SMS send on Tabits behalf. The resend OTP API of tabit allows an adversary to send messages on tabits behalf to anyone registered on the system - the API receives the parameters: phone number, and CustomMessage, We can use that API to craft malicious messages to any user of the system. In addition, the API probably has some kind of template injection potential. When entering {{OTP}} in the custom message field it is formatted into an OTP.

    Published: 22 Aug 2022
    7.2
    High

    CVE-2021-37289

    Last Modified: 21 Nov 2024

    Insecure Permissions in administration interface in Planex MZK-DP150N 1.42 and 1.43 allows attackers to execute system command as root via etc_ro/web/syscmd.asp.

    Published: 22 Aug 2022
    5.4
    Medium

    CVE-2022-2890

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

    Published: 22 Aug 2022
    6.1
    Medium

    CVE-2022-2932

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository bustle/mobiledoc-kit prior to 0.14.2.

    Published: 22 Aug 2022
    5.4
    Medium

    CVE-2022-1340

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

    Published: 22 Aug 2022
    7.8
    High

    CVE-2022-2930

    Last Modified: 21 Nov 2024

    Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.

    Published: 22 Aug 2022
    9.8
    Critical

    CVE-2022-2927

    Last Modified: 21 Nov 2024

    Weak Password Requirements in GitHub repository notrinos/notrinoserp prior to 0.7.

    Published: 22 Aug 2022
    2.7
    Low

    CVE-2022-2841

    Last Modified: 15 Apr 2025

    A vulnerability was found in CrowdStrike Falcon 6.31.14505.0/6.42.15610/6.44.15806. It has been classified as problematic. Affected is an unknown function of the component Uninstallation Handler. The manipulation leads to missing authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 6.40.15409, 6.42.15611 and 6.44.15807 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-206880.

    Published: 22 Aug 2022
    6.1
    Medium

    CVE-2022-36251

    Last Modified: 21 Nov 2024

    Clinic's Patient Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via patients.php.

    Published: 22 Aug 2022
    9.8
    Critical

    CVE-2022-36198

    Last Modified: 21 Nov 2024

    Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin/pass-bwdates-reports-details.php, buspassms/admin/changeimage.php, buspassms/admin/search-pass.php, buspassms/admin/edit-category-detail.php, and buspassms/admin/edit-pass-detail.php

    Published: 22 Aug 2022
    7.4
    High

    CVE-2021-28861

    Last Modified: 17 Dec 2025

    Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

    Published: 22 Aug 2022
    7.8
    High

    CVE-2022-25942

    Last Modified: 15 Apr 2025

    An out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 22 Aug 2022
    5.5
    Medium

    CVE-2022-2923

    Last Modified: 21 Nov 2024

    NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0240.

    Published: 22 Aug 2022
    7.1
    High

    CVE-2022-2989

    Last Modified: 5 Jun 2025

    An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.

    Published: 22 Aug 2022
    7.1
    High

    CVE-2022-2990

    Last Modified: 21 Nov 2024

    An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.

    Published: 22 Aug 2022
    9.8
    Critical

    CVE-2022-35583

    Last Modified: 18 Mar 2025

    wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.

    Published: 22 Aug 2022
    —
    Unknown

    CVE-2022-38636

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 22 Aug 2022
    6.5
    Medium

    CVE-2022-40090

    Last Modified: 21 Nov 2024

    An issue was discovered in function TIFFReadDirectory libtiff before 4.4.0 allows attackers to cause a denial of service via crafted TIFF file.

    Published: 22 Aug 2022
    7.8
    High

    CVE-2022-25972

    Last Modified: 21 Nov 2024

    An out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 22 Aug 2022