CVE Feed

    Dashboard / CVE

    9.6
    Critical

    CVE-2022-2662

    Last Modified: 16 Apr 2025

    Sequi PortBloque S has a improper authentication issues which may allow an attacker to bypass the authentication process and gain user-level access to the device.

    Published: 16 Aug 2022
    9.9
    Critical

    CVE-2022-2661

    Last Modified: 16 Apr 2025

    Sequi PortBloque S has an improper authorization vulnerability, which may allow a low-privileged user to perform administrative functions using specifically crafted requests.

    Published: 16 Aug 2022
    7.4
    High

    CVE-2022-37437

    Last Modified: 21 Nov 2024

    When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS certificate validation is not correctly performed and tested for the destination. The vulnerability only affects connections between Splunk Enterprise and an Ingest Actions Destination through Splunk Web and only applies to environments that have configured TLS certificate validation. It does not apply to Destinations configured directly in the outputs.conf configuration file. The vulnerability affects Splunk Enterprise version 9.0.0 and does not affect versions below 9.0.0, including the 8.1.x and 8.2.x versions.

    Published: 16 Aug 2022
    5.5
    Medium

    CVE-2022-37439

    Last Modified: 21 Nov 2024

    In Splunk Enterprise and Universal Forwarder versions in the following table, indexing a specially crafted ZIP file using the file monitoring input can result in a crash of the application. Attempts to restart the application would result in a crash and would require manually removing the malformed file.

    Published: 16 Aug 2022
    2.6
    Low

    CVE-2022-37438

    Last Modified: 21 Nov 2024

    In Splunk Enterprise versions in the following table, an authenticated user can craft a dashboard that could potentially leak information (for example, username, email, and real name) about Splunk users, when visited by another user through the drilldown component. The vulnerability requires user access to create and share dashboards using Splunk Web.

    Published: 16 Aug 2022
    5.3
    Medium

    CVE-2022-34259

    Last Modified: 23 Apr 2025

    Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.

    Published: 16 Aug 2022
    6.1
    Medium

    CVE-2022-34257

    Last Modified: 23 Apr 2025

    Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 16 Aug 2022
    7.2
    High

    CVE-2022-34253

    Last Modified: 23 Apr 2025

    Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution. Exploitation of this issue does not require user interaction.

    Published: 16 Aug 2022
    8.8
    High

    CVE-2022-34255

    Last Modified: 23 Apr 2025

    Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in Privilege escalation. An attacker with a low privilege account could leverage this vulnerability to perform an account takeover for a victim. Exploitation of this issue does not require user interaction.

    Published: 16 Aug 2022
    8.8
    High

    CVE-2022-34254

    Last Modified: 23 Apr 2025

    Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could be abused by an attacker to inject malicious scripts into the vulnerable endpoint. A low privileged attacker could leverage this vulnerability to read local files and to perform Stored XSS. Exploitation of this issue does not require user interaction.

    Published: 16 Aug 2022
    7.5
    High

    CVE-2022-34256

    Last Modified: 23 Apr 2025

    Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to access other user's data. Exploitation of this issue does not require user interaction.

    Published: 16 Aug 2022
    4.8
    Medium

    CVE-2022-34258

    Last Modified: 23 Apr 2025

    Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker with admin privileges to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 16 Aug 2022
    6.1
    Medium

    CVE-2020-14320

    Last Modified: 21 Nov 2024

    In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk.

    Published: 16 Aug 2022
    7.2
    High

    CVE-2020-1756

    Last Modified: 21 Nov 2024

    In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.

    Published: 16 Aug 2022
    5.3
    Medium

    CVE-2020-1755

    Last Modified: 21 Nov 2024

    In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

    Published: 16 Aug 2022
    7.5
    High

    CVE-2022-2833

    Last Modified: 21 Nov 2024

    Endless Infinite loop in Blender-thumnailing due to logical bugs.

    Published: 16 Aug 2022
    7.5
    High

    CVE-2022-2831

    Last Modified: 21 Nov 2024

    A flaw was found in Blender 3.3.0. An interger overflow in source/blender/blendthumb/src/blendthumb_extract.cc may lead to program crash or memory corruption.

    Published: 16 Aug 2022
    6.3
    Medium

    CVE-2022-2847

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, has been found in SourceCodester Guest Management System. This issue affects some unknown processing of the file /guestmanagement/front.php. The manipulation of the argument rid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206489 was assigned to this vulnerability.

    Published: 16 Aug 2022
    3.5
    Low

    CVE-2022-2844

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in MotoPress Timetable and Event Schedule up to 1.4.06. This affects an unknown part of the file /wp/?cpmvc_id=1&cpmvc_do_action=mvparse&f=datafeed&calid=1&month_index=1&method=adddetails&id=2 of the component Calendar Handler. The manipulation of the argument Subject/Location/Description leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-206487.

    Published: 16 Aug 2022
    3.5
    Low

    CVE-2022-2843

    Last Modified: 15 Apr 2025

    A vulnerability was found in MotoPress Timetable and Event Schedule. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /wp-admin/admin-ajax.php of the component Quick Edit. The manipulation of the argument post_title with the input <img src=x onerror=alert`2`> leads to cross site scripting. The attack may be launched remotely. VDB-206486 is the identifier assigned to this vulnerability.

    Published: 16 Aug 2022
    6.5
    Medium

    CVE-2021-39087

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow an authenticated user to obtain sensitive information due to improper permission controls. IBM X-Force ID: 216109.

    Published: 16 Aug 2022
    5.3
    Medium

    CVE-2021-39086

    Last Modified: 21 Nov 2024

    IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 215889.

    Published: 16 Aug 2022
    9.8
    Critical

    CVE-2021-39085

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 215888.

    Published: 16 Aug 2022
    5.4
    Medium

    CVE-2021-39035

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213965.

    Published: 16 Aug 2022
    8.7
    High

    CVE-2022-30576

    Last Modified: 21 Nov 2024

    The Web Console component of TIBCO Software Inc.'s TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - Estore Edition, and TIBCO Statistica Trial contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Data Science - Workbench: versions 14.0.0 and below, TIBCO Statistica: versions 14.0.0 and below, TIBCO Statistica - Estore Edition: versions 14.0.0 and below, and TIBCO Statistica Trial: versions 14.0.0 and below.

    Published: 16 Aug 2022
    7.3
    High

    CVE-2022-30575

    Last Modified: 21 Nov 2024

    The Web Console component of TIBCO Software Inc.'s TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - Estore Edition, and TIBCO Statistica Trial contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected system or the victim's local system. Affected releases are TIBCO Software Inc.'s TIBCO Data Science - Workbench: versions 14.0.0 and below, TIBCO Statistica: versions 14.0.0 and below, TIBCO Statistica - Estore Edition: versions 14.0.0 and below, and TIBCO Statistica Trial: versions 14.0.0 and below.

    Published: 16 Aug 2022
    5.4
    Medium

    CVE-2022-38189

    Last Modified: 10 Apr 2025

    A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser.

    Published: 16 Aug 2022
    7.5
    High

    CVE-2022-38184

    Last Modified: 10 Apr 2025

    There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs.

    Published: 16 Aug 2022
    6.1
    Medium

    CVE-2022-38192

    Last Modified: 10 Apr 2025

    A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser.

    Published: 16 Aug 2022
    6.1
    Medium

    CVE-2022-38193

    Last Modified: 10 Apr 2025

    There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass strings which could potentially cause arbitrary code execution.

    Published: 16 Aug 2022
    6.7
    Medium

    CVE-2022-38194

    Last Modified: 10 Apr 2025

    In Esri Portal for ArcGIS versions 10.8.1, a system property is not properly encrypted. This may lead to a local user reading sensitive information from a properties file.

    Published: 16 Aug 2022
    9.8
    Critical

    CVE-2022-36242

    Last Modified: 21 Nov 2024

    Clinic's Patient Management System v1.0 is vulnerable to SQL Injection via /pms/update_medicine.php?id=.

    Published: 16 Aug 2022
    8.8
    High

    CVE-2022-38362

    Last Modified: 21 Nov 2024

    Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.

    Published: 16 Aug 2022
    9.8
    Critical

    CVE-2022-36599

    Last Modified: 21 Nov 2024

    Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.

    Published: 16 Aug 2022
    9.8
    Critical

    CVE-2022-36272

    Last Modified: 21 Nov 2024

    Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter.

    Published: 16 Aug 2022
    9.8
    Critical

    CVE-2022-36273

    Last Modified: 21 Nov 2024

    Tenda AC9 V15.03.2.21_cn is vulnerable to command injection via goform/SetSysTimeCfg.

    Published: 16 Aug 2022
    9.8
    Critical

    CVE-2022-30264

    Last Modified: 21 Nov 2024

    The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications between a master terminal and RTUs. Opcode 203 of this protocol allows a master terminal to transfer files to and from the flash filesystem and carrying out arbitrary file and directory read, write, and delete operations.

    Published: 16 Aug 2022
    6.1
    Medium

    CVE-2022-36530

    Last Modified: 21 Nov 2024

    An issue was discovered in rageframe2 2.6.37. There is a XSS vulnerability in the user agent related parameters of the info.php page.

    Published: 16 Aug 2022
    7.8
    High

    CVE-2021-30490

    Last Modified: 21 Nov 2024

    upsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binary that enable an Authenticated User to modify files, allowing for privilege escalation.

    Published: 16 Aug 2022
    5.5
    Medium

    CVE-2022-29959

    Last Modified: 21 Nov 2024

    Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. This environment provides access control functionality through user authentication and privilege management. The credentials for various users are stored insecurely in the SecUsers.ini file by using a simple string transformation rather than a cryptographic mechanism.

    Published: 16 Aug 2022
    5.3
    Medium

    CVE-2022-2838

    Last Modified: 21 Nov 2024

    In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced external entities allowing the injection of arbitrary definitions which is able to access local files and expose their contents via HTTP requests.

    Published: 16 Aug 2022
    7.8
    High

    CVE-2022-2978

    Last Modified: 21 Nov 2024

    A flaw use after free in the Linux kernel NILFS file system was found in the way user triggers function security_inode_alloc to fail with following call to function nilfs_mdt_destroy. A local user could use this flaw to crash the system or potentially escalate their privileges on the system.

    Published: 16 Aug 2022
    7.2
    High

    CVE-2022-36381

    Last Modified: 21 Nov 2024

    OS command injection vulnerability in Nintendo Wi-Fi Network Adaptor WAP-001 All versions allows an attacker with an administrative privilege to execute arbitrary OS commands via unspecified vectors.

    Published: 16 Aug 2022
    9.8
    Critical

    CVE-2022-36344

    Last Modified: 21 Nov 2024

    An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of the Windows service if it is placed in a certain path. Affected products are bundled with the following product series: Office and Office Integrated Software, ATOK, Hanako, JUST PDF, Shuriken, Homepage Builder, JUST School, JUST Smile Class, JUST Smile, JUST Frontier, JUST Jump, and Tri-De DetaProtect.

    Published: 16 Aug 2022
    7.2
    High

    CVE-2022-36293

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in Nintendo Wi-Fi Network Adaptor WAP-001 All versions allows an attacker with an administrative privilege to execute arbitrary code via unspecified vectors.

    Published: 16 Aug 2022
    7.5
    High

    CVE-2022-35734

    Last Modified: 21 Nov 2024

    'Hulu / フールー' App for Android from version 3.0.47 to the version prior to 3.1.2 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app.

    Published: 16 Aug 2022
    8.8
    High

    CVE-2022-35239

    Last Modified: 21 Nov 2024

    The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an insufficient verification vulnerability when uploading files. If this vulnerability is exploited, arbitrary PHP code may be executed if a remote authenticated attacker uploads a specially crafted PHP file.

    Published: 16 Aug 2022
    4.8
    Medium

    CVE-2022-34156

    Last Modified: 21 Nov 2024

    'Hulu / フールー' App for iOS versions prior to 3.0.81 improperly verifies server certificates, which may allow an attacker to eavesdrop on an encrypted communication via a man-in-the-middle attack.

    Published: 16 Aug 2022
    7.5
    High

    CVE-2022-33939

    Last Modified: 21 Nov 2024

    CENTUM VP / CS 3000 controller FCS (CP31, CP33, CP345, CP401, and CP451) contains an issue in processing communication packets, which may lead to resource consumption. If this vulnerability is exploited, an attacker may cause a denial of service (DoS) condition in ADL communication by sending a specially crafted packet to the affected product.

    Published: 16 Aug 2022
    7.5
    High

    CVE-2022-38216

    Last Modified: 21 Nov 2024

    An integer overflow exists in Mapbox's closed source gl-native library prior to version 10.6.1, which is bundled with multiple Mapbox products including open source libraries. The overflow is caused by large image height and width values when creating a new Image and allows for out of bounds writes, potentially crashing the Mapbox process.

    Published: 16 Aug 2022