CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2022-25903

    Last Modified: 21 Nov 2024

    The package opcua from 0.0.0 are vulnerable to Denial of Service (DoS) via the ExtensionObjects and Variants objects, when it allows unlimited nesting levels, which could result in a stack overflow even if the message size is less than the maximum allowed.

    Published: 24 Aug 2022
    7.5
    High

    CVE-2022-32793

    Last Modified: 30 May 2025

    Multiple out-of-bounds write issues were addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6. An app may be able to disclose kernel memory.

    Published: 24 Aug 2022
    7.5
    High

    CVE-2022-27812

    Last Modified: 21 Nov 2024

    Flooding SNS firewall versions 3.7.0 to 3.7.29, 3.11.0 to 3.11.17, 4.2.0 to 4.2.10, and 4.3.0 to 4.3.6 with specific forged traffic, can lead to SNS DoS.

    Published: 24 Aug 2022
    8.8
    High

    CVE-2022-32893

    Last Modified: 23 Oct 2025

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

    Published: 24 Aug 2022
    7.5
    High

    CVE-2022-32743

    Last Modified: 22 Aug 2025

    Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.

    Published: 24 Aug 2022
    —
    Unknown

    CVE-2022-38735

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 24 Aug 2022
    —
    Unknown

    CVE-2022-38736

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 24 Aug 2022
    —
    Unknown

    CVE-2022-38737

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 24 Aug 2022
    —
    Unknown

    CVE-2022-38738

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 24 Aug 2022
    —
    Unknown

    CVE-2022-38739

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 24 Aug 2022
    —
    Unknown

    CVE-2022-38740

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 24 Aug 2022
    —
    Unknown

    CVE-2022-38741

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 24 Aug 2022
    7.8
    High

    CVE-2022-3170

    Last Modified: 21 Nov 2024

    An out-of-bounds access issue was found in the Linux kernel sound subsystem. It could occur when the 'id->name' provided by the user did not end with '\0'. A privileged local user could pass a specially crafted name through ioctl() interface and crash the system or potentially escalate their privileges on the system.

    Published: 24 Aug 2022
    7.8
    High

    CVE-2022-32894

    Last Modified: 23 Oct 2025

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.

    Published: 24 Aug 2022
    8.2
    High

    CVE-2022-38132

    Last Modified: 21 Nov 2024

    Command injection vulnerability in Linksys MR8300 router while Registration to DDNS Service. By specifying username and password, an attacker connected to the router's web interface can execute arbitrary OS commands. The username and password fields are not sanitized correctly and are used as URL construction arguments, allowing URL redirection to an arbitrary server, downloading an arbitrary script file, and eventually executing the file in the device. This issue affects: Linksys MR8300 Router 1.0.

    Published: 23 Aug 2022
    —
    Unknown

    CVE-2020-35516

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 23 Aug 2022
    —
    Unknown

    CVE-2020-35515

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 23 Aug 2022
    6.1
    Medium

    CVE-2022-38463

    Last Modified: 21 Nov 2024

    ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.

    Published: 23 Aug 2022
    6.1
    Medium

    CVE-2022-38172

    Last Modified: 21 Nov 2024

    ServiceNow through San Diego Patch 3 allows XSS via the name field during creation of a new dashboard for the Performance Analytics dashboard.

    Published: 23 Aug 2022
    9.8
    Critical

    CVE-2022-35115

    Last Modified: 21 Nov 2024

    IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /webmail/server/webmail.php.

    Published: 23 Aug 2022
    7.3
    High

    CVE-2022-1513

    Last Modified: 21 Nov 2024

    A potential vulnerability was reported in Lenovo PCManager prior to version 5.0.10.4191 that may allow code execution when visiting a specially crafted website.

    Published: 23 Aug 2022
    6.5
    Medium

    CVE-2022-38665

    Last Modified: 21 Nov 2024

    Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

    Published: 23 Aug 2022
    5.4
    Medium

    CVE-2022-38664

    Last Modified: 21 Nov 2024

    Jenkins Job Configuration History Plugin 1165.v8cc9fd1f4597 and earlier does not escape the job name on the System Configuration History page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure job names.

    Published: 23 Aug 2022
    6.5
    Medium

    CVE-2022-37428

    Last Modified: 21 Nov 2024

    PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upon a Thrown Exception, leading to a denial of service (daemon crash) via a DNS query that leads to an answer with specific properties.

    Published: 23 Aug 2022
    3.5
    Low

    CVE-2022-28883

    Last Modified: 21 Nov 2024

    A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl unpack function crashes. This can lead to a possible scanning engine crash. The exploit can be triggered remotely by an attacker.

    Published: 23 Aug 2022
    4.3
    Medium

    CVE-2022-28882

    Last Modified: 21 Nov 2024

    A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aegen.dll will go into an infinite loop when unpacking PE files. This eventually leads to scanning engine crash. The exploit can be triggered remotely by an attacker.

    Published: 23 Aug 2022
    —
    Unknown

    CVE-2021-3771

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 23 Aug 2022
    4.3
    Medium

    CVE-2022-36389

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress.

    Published: 23 Aug 2022
    5.4
    Medium

    CVE-2022-36405

    Last Modified: 20 Feb 2025

    Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in amCharts: Charts and Maps plugin <= 1.4 at WordPress.

    Published: 23 Aug 2022
    4.8
    Medium

    CVE-2022-36347

    Last Modified: 20 Feb 2025

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alpine Press Alpine PhotoTile for Pinterest plugin <= 1.3.1 at WordPress.

    Published: 23 Aug 2022
    5.4
    Medium

    CVE-2022-36292

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress.

    Published: 23 Aug 2022
    7.2
    High

    CVE-2022-36285

    Last Modified: 20 Feb 2025

    Authenticated Arbitrary File Upload vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at WordPress.

    Published: 23 Aug 2022
    4.3
    Medium

    CVE-2022-35726

    Last Modified: 28 Apr 2026

    Broken Authentication vulnerability in yotuwp Video Gallery plugin <= 1.3.4.5 at WordPress.

    Published: 23 Aug 2022
    8.8
    High

    CVE-2022-36379

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) leading to plugin settings update in YooMoney ЮKassa для WooCommerce plugin <= 2.3.0 at WordPress.

    Published: 23 Aug 2022
    7.6
    High

    CVE-2022-36394

    Last Modified: 20 Feb 2025

    Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress.

    Published: 23 Aug 2022
    5.4
    Medium

    CVE-2022-36341

    Last Modified: 20 Feb 2025

    Authenticated (subscriber+) plugin settings change leading to Stored Cross-Site Scripting (XSS) vulnerability in Akash soni's AS – Create Pinterest Pinboard Pages plugin <= 1.0 at WordPress.

    Published: 23 Aug 2022
    5.4
    Medium

    CVE-2022-36288

    Last Modified: 21 Mar 2025

    Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.

    Published: 23 Aug 2022
    4.9
    Medium

    CVE-2022-35235

    Last Modified: 20 Feb 2025

    Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.

    Published: 23 Aug 2022
    4.8
    Medium

    CVE-2022-36282

    Last Modified: 20 Feb 2025

    Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Roman Pronskiy's Search Exclude plugin <= 1.2.6 at WordPress.

    Published: 23 Aug 2022
    5.4
    Medium

    CVE-2022-34658

    Last Modified: 21 Mar 2025

    Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.

    Published: 23 Aug 2022
    7.7
    High

    CVE-2022-33142

    Last Modified: 20 Feb 2025

    Authenticated (subscriber+) Denial Of Service (DoS) vulnerability in WordPlus WordPress Better Messages plugin <= 1.9.10.57 at WordPress.

    Published: 23 Aug 2022
    8.8
    High

    CVE-2022-34868

    Last Modified: 28 Apr 2026

    Authenticated Arbitrary Settings Update vulnerability in YooMoney ЮKassa для WooCommerce plugin <= 2.3.0 at WordPress.

    Published: 23 Aug 2022
    6.5
    Medium

    CVE-2022-35242

    Last Modified: 20 Feb 2025

    Unauthenticated plugin settings change vulnerability in 59sec THE Leads Management System: 59sec LITE plugin <= 3.4.1 at WordPress.

    Published: 23 Aug 2022
    6.1
    Medium

    CVE-2022-29476

    Last Modified: 20 Feb 2025

    Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in 8 Degree Themes otification Bar for WordPress plugin <= 1.1.8 at WordPress.

    Published: 23 Aug 2022
    4.8
    Medium

    CVE-2022-34648

    Last Modified: 20 Feb 2025

    Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at WordPress.

    Published: 23 Aug 2022
    4.3
    Medium

    CVE-2022-2965

    Last Modified: 21 Nov 2024

    Improper Restriction of Rendered UI Layers or Frames in GitHub repository notrinos/notrinoserp prior to 0.7.

    Published: 23 Aug 2022
    9.8
    Critical

    CVE-2022-37111

    Last Modified: 21 Nov 2024

    BlueCMS 1.6 has SQL injection in line 132 of admin/article.php

    Published: 23 Aug 2022
    9.8
    Critical

    CVE-2022-37112

    Last Modified: 21 Nov 2024

    BlueCMS 1.6 has SQL injection in line 55 of admin/model.php

    Published: 23 Aug 2022
    9.8
    Critical

    CVE-2022-37113

    Last Modified: 21 Nov 2024

    Bluecms 1.6 has SQL injection in line 132 of admin/area.php

    Published: 23 Aug 2022
    9.8
    Critical

    CVE-2022-37223

    Last Modified: 21 Nov 2024

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list.

    Published: 23 Aug 2022