CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2022-32283

    Last Modified: 21 Nov 2024

    Browse restriction bypass vulnerability in Cabinet of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Cabinet via unspecified vectors.

    Published: 18 Aug 2022
    5.3
    Medium

    CVE-2022-30693

    Last Modified: 21 Nov 2024

    Information disclosure vulnerability in the system configuration of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to obtain the data of the product via unspecified vectors.

    Published: 18 Aug 2022
    6.1
    Medium

    CVE-2022-30604

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors.

    Published: 18 Aug 2022
    4.3
    Medium

    CVE-2022-29891

    Last Modified: 21 Nov 2024

    Browse restriction bypass vulnerability in Custom Ap of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Custom App via unspecified vectors.

    Published: 18 Aug 2022
    6.1
    Medium

    CVE-2022-29487

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors.

    Published: 18 Aug 2022
    6.1
    Medium

    CVE-2022-28715

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors.

    Published: 18 Aug 2022
    4.3
    Medium

    CVE-2022-25986

    Last Modified: 21 Nov 2024

    Browse restriction bypass vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Scheduler.

    Published: 18 Aug 2022
    7.5
    High

    CVE-2022-35198

    Last Modified: 21 Nov 2024

    Contract Management System v2.0 contains a weak default password which gives attackers to access database connection information.

    Published: 18 Aug 2022
    7.5
    High

    CVE-2022-35173

    Last Modified: 21 Nov 2024

    An issue was discovered in Nginx NJS v0.7.5. The JUMP offset for a break instruction was not set to a correct offset during code generation, leading to a segmentation violation.

    Published: 18 Aug 2022
    5.5
    Medium

    CVE-2022-35166

    Last Modified: 21 Nov 2024

    libjpeg commit 842c7ba was discovered to contain an infinite loop via the component JPEG::ReadInternal.

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-35164

    Last Modified: 21 Nov 2024

    LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via bit_copy_chain.

    Published: 18 Aug 2022
    5.5
    Medium

    CVE-2022-35165

    Last Modified: 21 Nov 2024

    An issue in AP4_SgpdAtom::AP4_SgpdAtom() of Bento4-1.6.0-639 allows attackers to cause a Denial of Service (DoS) via a crafted mp4 input.

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-35154

    Last Modified: 21 Nov 2024

    Shopro Mall System v1.3.8 was discovered to contain a SQL injection vulnerability via the value parameter.

    Published: 18 Aug 2022
    6.1
    Medium

    CVE-2021-30071

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 18 Aug 2022
    7.5
    High

    CVE-2021-30070

    Last Modified: 21 Nov 2024

    An issue was discovered in HestiaCP before v1.3.5. Attackers are able to arbitrarily install packages due to values taken from the pgk [] parameter in the update request being transmitted to the operating system's package manager.

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-35153

    Last Modified: 21 Nov 2024

    FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-35606

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameter 'customerCode.'

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-35605

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as 'users', 'pass', etc.

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-35603

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter searchTxt.

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-35602

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter user.

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-35601

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter searchTxt.

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-35599

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter productcode.

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-35598

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in ConnectionFactoryDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter username.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2022-21181

    Last Modified: 5 May 2025

    Improper input validation for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 18 Aug 2022
    7.5
    High

    CVE-2022-37060

    Last Modified: 17 Oct 2025

    FLIR AX8 thermal sensor cameras version up to and including 1.46.16 is vulnerable to Directory Traversal due to an improper access restriction. An unauthenticated, remote attacker can exploit this by sending a URI that contains directory traversal characters to disclose the contents of files located outside of the server's restricted path. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-37061

    Last Modified: 17 Oct 2025

    All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell commands as the root user through the id HTTP POST parameter in the res.php endpoint. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the root privileges. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.

    Published: 18 Aug 2022
    6.5
    Medium

    CVE-2021-44545

    Last Modified: 5 May 2025

    Improper input validation for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 18 Aug 2022
    6.1
    Medium

    CVE-2022-35278

    Last Modified: 15 Jun 2026

    In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.

    Published: 18 Aug 2022
    7
    High

    CVE-2022-36023

    Last Modified: 23 Apr 2025

    Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. If a gateway client application sends a malformed request to a gateway peer it may crash the peer node. Version 2.4.6 checks for the malformed gateway request and returns an error to the gateway client. There are no known workarounds, users must upgrade to version 2.4.6.

    Published: 18 Aug 2022
    6.5
    Medium

    CVE-2021-23168

    Last Modified: 5 May 2025

    Out of bounds read for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2021-23223

    Last Modified: 5 May 2025

    Improper initialization for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2022-21229

    Last Modified: 5 May 2025

    Improper buffer restrictions for some Intel(R) NUC 9 Extreme Laptop Kit drivers before version 2.2.0.22 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 18 Aug 2022
    8
    High

    CVE-2022-21225

    Last Modified: 5 May 2025

    Improper neutralization in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 18 Aug 2022
    6.8
    Medium

    CVE-2022-28697

    Last Modified: 5 May 2025

    Improper access control in firmware for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-30601

    Last Modified: 5 May 2025

    Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable information disclosure and escalation of privilege via network access.

    Published: 18 Aug 2022
    5.5
    Medium

    CVE-2022-30944

    Last Modified: 5 May 2025

    Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via local access.

    Published: 18 Aug 2022
    7.5
    High

    CVE-2021-32862

    Last Modified: 21 Nov 2024

    The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to cross-site scripting (XSS) vulnerabilities if these HTML notebooks are served by a web server (eg: nbviewer).

    Published: 18 Aug 2022
    7.8
    High

    CVE-2022-37047

    Last Modified: 21 Nov 2024

    The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_ipv6_next at common/get.c:713. NOTE: this is different from CVE-2022-27940.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2022-37048

    Last Modified: 21 Nov 2024

    The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_l2len_protocol at common/get.c:344. NOTE: this is different from CVE-2022-27941.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2022-37049

    Last Modified: 21 Nov 2024

    The component tcpprep in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in parse_mpls at common/get.c:150. NOTE: this is different from CVE-2022-27942.

    Published: 18 Aug 2022
    7.5
    High

    CVE-2022-37422

    Last Modified: 21 Nov 2024

    Payara through 5.2022.2 allows directory traversal without authentication. This affects Payara Server, Payara Micro, and Payara Server Embedded.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2021-37409

    Last Modified: 5 May 2025

    Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 18 Aug 2022
    6.1
    Medium

    CVE-2022-35151

    Last Modified: 21 Nov 2024

    kkFileView v4.1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the urls and currentUrl parameters at /controller/OnlinePreviewController.java.

    Published: 17 Aug 2022
    8.8
    High

    CVE-2022-28752

    Last Modified: 21 Nov 2024

    Zoom Rooms for Conference Rooms for Windows versions before 5.11.0 are susceptible to a Local Privilege Escalation vulnerability. A local low-privileged malicious user could exploit this vulnerability to escalate their privileges to the SYSTEM user.

    Published: 17 Aug 2022
    8.8
    High

    CVE-2022-28751

    Last Modified: 21 Nov 2024

    The Zoom Client for Meetings for MacOS (Standard and for IT Admin) before version 5.11.3 contains a vulnerability in the package signature validation during the update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

    Published: 17 Aug 2022
    6.5
    Medium

    CVE-2022-35148

    Last Modified: 21 Nov 2024

    maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html.

    Published: 17 Aug 2022
    9.8
    Critical

    CVE-2022-23747

    Last Modified: 21 Nov 2024

    In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed during music playback.

    Published: 17 Aug 2022
    9.8
    Critical

    CVE-2022-35147

    Last Modified: 21 Nov 2024

    DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request.

    Published: 17 Aug 2022
    6.1
    Medium

    CVE-2022-35133

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in CherryTree v0.99.30 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field when creating a node.

    Published: 17 Aug 2022
    9.1
    Critical

    CVE-2022-35122

    Last Modified: 21 Nov 2024

    An access control issue in Ecowitt GW1100 Series Weather Stations <=GW1100B_v2.1.5 allows unauthenticated attackers to access sensitive information including device and local WiFi passwords.

    Published: 17 Aug 2022