CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2022-28598

    Last Modified: 21 Nov 2024

    Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users.

    Published: 22 Aug 2022
    5.5
    Medium

    CVE-2022-39190

    Last Modified: 21 Nov 2024

    An issue was discovered in net/netfilter/nf_tables_api.c in the Linux kernel before 5.19.6. A denial of service can occur upon binding to an already bound chain.

    Published: 21 Aug 2022
    4.8
    Medium

    CVE-2022-2885

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

    Published: 21 Aug 2022
    8.8
    High

    CVE-2022-30036

    Last Modified: 21 Nov 2024

    MA Lighting grandMA2 Light has a password of root for the root account. NOTE: The vendor's position is that the product was designed for isolated networks. Also, the successor product, grandMA3, is not affected by this vulnerability.

    Published: 21 Aug 2022
    8.8
    High

    CVE-2022-2921

    Last Modified: 21 Nov 2024

    Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository notrinos/notrinoserp prior to v0.7. This results in privilege escalation to a system administrator account. An attacker can gain access to protected functionality such as create/update companies, install/update languages, install/activate extensions, install/activate themes and other permissive actions.

    Published: 21 Aug 2022
    7.5
    High

    CVE-2022-38493

    Last Modified: 21 Nov 2024

    Rhonabwy 0.9.99 through 1.1.x before 1.1.7 doesn't check the RSA private key length before RSA-OAEP decryption. This allows attackers to cause a Denial of Service via a crafted JWE (JSON Web Encryption) token.

    Published: 20 Aug 2022
    6.3
    Medium

    CVE-2022-2909

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /mkshop/Men/profile.php. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206845 was assigned to this vulnerability.

    Published: 20 Aug 2022
    9.8
    Critical

    CVE-2022-34916

    Last Modified: 21 Nov 2024

    Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol.

    Published: 20 Aug 2022
    9.8
    Critical

    CVE-2022-36030

    Last Modified: 23 Apr 2025

    Project-nexus is a general-purpose blog website framework. Affected versions are subject to SQL injection due to a lack of sensitization of user input. This issue has not yet been patched. Users are advised to restrict user input and to upgrade when a new release becomes available.

    Published: 19 Aug 2022
    5.3
    Medium

    CVE-2022-35692

    Last Modified: 23 Apr 2025

    Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to leak minor information of another user's account detials. Exploitation of this issue does not require user interaction.

    Published: 19 Aug 2022
    —
    Unknown

    CVE-2020-36256

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 19 Aug 2022
    9.1
    Critical

    CVE-2020-27794

    Last Modified: 21 Nov 2024

    A double free issue was discovered in radare2 in cmd_info.c:cmd_info(). Successful exploitation could lead to modification of unexpected memory locations and potentially causing a crash.

    Published: 19 Aug 2022
    7.5
    High

    CVE-2020-27793

    Last Modified: 21 Nov 2024

    An off-by-one overflow flaw was found in radare2 due to mismatched array length in core_java.c. This could allow an attacker to cause a crash, and perform a denail of service attack.

    Published: 19 Aug 2022
    7.5
    High

    CVE-2020-27795

    Last Modified: 21 Nov 2024

    A segmentation fault was discovered in radare2 with adf command. In libr/core/cmd_anal.c, when command "adf" has no or wrong argument, anal_fcn_data (core, input + 1) --> RAnalFunction *fcn = r_anal_get_fcn_in (core->anal, core->offset, -1); returns null pointer for fcn causing segmentation fault later in ensure_fcn_range (fcn).

    Published: 19 Aug 2022
    5.9
    Medium

    CVE-2022-2793

    Last Modified: 16 Apr 2025

    Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no authentication or authorization of data packets after establishing a connection for the SRTP protocol.

    Published: 19 Aug 2022
    6.1
    Medium

    CVE-2022-35554

    Last Modified: 21 Nov 2024

    Multiple reflected XSS vulnerabilities occur when handling error message of BPC SmartVista version 3.28.0 allowing an attacker to execute javascript code at client side.

    Published: 19 Aug 2022
    4.7
    Medium

    CVE-2022-2789

    Last Modified: 16 Apr 2025

    Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of Data Authenticity, and can display logic that is different than the compiled logic.

    Published: 19 Aug 2022
    5.9
    Medium

    CVE-2022-2790

    Last Modified: 16 Apr 2025

    Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryptographic Signature, and does not properly verify compiled logic (PDT files) and data blocks data (BLD/BLK files).

    Published: 19 Aug 2022
    6.6
    Medium

    CVE-2022-2792

    Last Modified: 16 Apr 2025

    Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and stores project data in a directory with improper access control lists.

    Published: 19 Aug 2022
    5.5
    Medium

    CVE-2022-36233

    Last Modified: 21 Nov 2024

    Tenda AC9 V15.03.2.13 is vulnerable to Buffer Overflow via httpd, form_fast_setting_wifi_set. httpd.

    Published: 19 Aug 2022
    8.1
    High

    CVE-2022-36171

    Last Modified: 21 Nov 2024

    MapGIS IGServer 10.5.6.11 is vulnerable to Arbitrary file deletion.

    Published: 19 Aug 2022
    8.8
    High

    CVE-2022-36157

    Last Modified: 21 Nov 2024

    XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account.

    Published: 19 Aug 2022
    3.9
    Low

    CVE-2022-2788

    Last Modified: 16 Apr 2025

    Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip attack, through an upload procedure which enables attackers to implant a malicious .BLZ file on the PLC. The file can transfer through the engineering station onto Windows in a way that executes the malicious code.

    Published: 19 Aug 2022
    9.8
    Critical

    CVE-2022-37175

    Last Modified: 21 Nov 2024

    Tenda ac15 firmware V15.03.05.18 httpd server has stack buffer overflow in /goform/formWifiBasicSet.

    Published: 19 Aug 2022
    6.5
    Medium

    CVE-2022-36031

    Last Modified: 22 Apr 2025

    Directus is a free and open-source data platform for headless content management. The Directus process can be aborted by having an authorized user update the `filename_disk` value to a folder and accessing that file through the `/assets` endpoint. This vulnerability has been patched and release v9.15.0 contains the fix. Users are advised to upgrade. Users unable to upgrade may prevent this problem by making sure no (untrusted) non-admin users have permissions to update the `filename_disk` field on `directus_files`.

    Published: 19 Aug 2022
    5
    Medium

    CVE-2022-36009

    Last Modified: 23 Apr 2025

    gomatrixserverlib is a Go library for matrix protocol federation. Dendrite is a Matrix homeserver written in Go, an alternative to Synapse. The power level parsing within gomatrixserverlib was failing to parse the `"events_default"` key of the `m.room.power_levels` event, defaulting the event default power level to zero in all cases. Power levels are the matrix terminology for user access level. In rooms where the `"events_default"` power level had been changed, this could result in events either being incorrectly authorised or rejected by Dendrite servers. gomatrixserverlib contains a fix as of commit `723fd49` and Dendrite 0.9.3 has been updated accordingly. Matrix rooms where the `"events_default"` power level has not been changed from the default of zero are not vulnerable. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 19 Aug 2022
    8.8
    High

    CVE-2022-36170

    Last Modified: 21 Nov 2024

    MapGIS 10.5 Pro IGServer has hardcoded credentials in the front-end and can lead to escalation of privileges and arbitrary file deletion.

    Published: 19 Aug 2022
    7.1
    High

    CVE-2022-36008

    Last Modified: 23 Apr 2025

    Frontier is Substrate's Ethereum compatibility layer. A security issue was discovered affecting parsing of the RPC result of the exit reason in case of EVM reversion. In release build, this would cause the exit reason being incorrectly parsed and returned by RPC. In debug build, this would cause an overflow panic. No action is needed unless you have a bridge node that needs to distinguish different reversion exit reasons and you used RPC for this. There are currently no known workarounds.

    Published: 19 Aug 2022
    5.9
    Medium

    CVE-2022-23460

    Last Modified: 28 Oct 2025

    Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx json parsing may lead to stack exhaustion in an address sanitized (ASAN) build. This issue may lead to Denial of Service if the program using the jsonxx library crashes. This issue exists on the current commit of the jsonxx project and the project itself has been archived. Updates are not expected. Users are advised to find a replacement.

    Published: 19 Aug 2022
    8.1
    High

    CVE-2022-23459

    Last Modified: 28 Oct 2025

    Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx use of the Value class may lead to memory corruption via a double free or via a use after free. The value class has a default assignment operator which may be used with pointer types which may point to alterable data where the pointer itself is not updated. This issue exists on the current commit of the jsonxx project. The project itself has been archived and updates are not expected. Users are advised to find a replacement.

    Published: 19 Aug 2022
    9.1
    Critical

    CVE-2022-22489

    Last Modified: 21 Nov 2024

    IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 226339.

    Published: 19 Aug 2022
    6.1
    Medium

    CVE-2022-0542

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.7.0.

    Published: 19 Aug 2022
    8.8
    High

    CVE-2022-36579

    Last Modified: 21 Nov 2024

    Wellcms 2.2.0 is vulnerable to Cross Site Request Forgery (CSRF).

    Published: 19 Aug 2022
    9.8
    Critical

    CVE-2022-36578

    Last Modified: 21 Nov 2024

    jizhicms v2.3.1 has SQL injection in the background.

    Published: 19 Aug 2022
    8.8
    High

    CVE-2022-36577

    Last Modified: 21 Nov 2024

    An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin.

    Published: 19 Aug 2022
    5.4
    Medium

    CVE-2022-37254

    Last Modified: 21 Nov 2024

    DolphinPHP 1.5.1 is vulnerable to Cross Site Scripting (XSS) via Background - > System - > system function - > configuration management.

    Published: 19 Aug 2022
    8.8
    High

    CVE-2022-36225

    Last Modified: 21 Nov 2024

    EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.

    Published: 19 Aug 2022
    8.8
    High

    CVE-2022-36224

    Last Modified: 21 Nov 2024

    XunRuiCMS V4.5.6 is vulnerable to Cross Site Request Forgery (CSRF).

    Published: 19 Aug 2022
    7.3
    High

    CVE-2022-36263

    Last Modified: 27 Jun 2025

    StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute arbitrary code via a crafted .exe file.

    Published: 19 Aug 2022
    9.8
    Critical

    CVE-2022-36606

    Last Modified: 21 Nov 2024

    Ywoa before v6.1 was discovered to contain a SQL injection vulnerability via /oa/setup/checkPool?database.

    Published: 19 Aug 2022
    9.8
    Critical

    CVE-2022-36605

    Last Modified: 21 Nov 2024

    Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter.

    Published: 19 Aug 2022
    9.8
    Critical

    CVE-2022-35201

    Last Modified: 21 Nov 2024

    Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.

    Published: 19 Aug 2022
    5.9
    Medium

    CVE-2022-34624

    Last Modified: 21 Nov 2024

    Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request.

    Published: 19 Aug 2022
    6.5
    Medium

    CVE-2022-34621

    Last Modified: 21 Nov 2024

    Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords and other attributes via modification of the user_id parameter.

    Published: 19 Aug 2022
    9.8
    Critical

    CVE-2022-34615

    Last Modified: 21 Nov 2024

    Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the application via brute-force attacks.

    Published: 19 Aug 2022
    9.8
    Critical

    CVE-2022-36220

    Last Modified: 21 Nov 2024

    Kiosk breakout (without quit password) in Safe Exam Browser (Windows) <3.4.0, which allows an attacker to achieve code execution via the browsers' print dialog.

    Published: 19 Aug 2022
    5.4
    Medium

    CVE-2022-1021

    Last Modified: 21 Nov 2024

    Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0.

    Published: 19 Aug 2022
    5
    Medium

    CVE-2022-2886

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipulation leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-206688.

    Published: 19 Aug 2022
    8.8
    High

    CVE-2022-35909

    Last Modified: 21 Nov 2024

    In Jellyfin before 10.8, the /users endpoint has incorrect access control for admin functionality.

    Published: 19 Aug 2022
    5.4
    Medium

    CVE-2022-35910

    Last Modified: 21 Nov 2024

    In Jellyfin before 10.8, stored XSS allows theft of an admin access token.

    Published: 19 Aug 2022