CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-36525

    Last Modified: 21 Nov 2024

    D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Buffer Overflow via authenticationcgi_main.

    Published: 15 Aug 2022
    7.5
    High

    CVE-2022-36524

    Last Modified: 21 Nov 2024

    D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh.

    Published: 15 Aug 2022
    9.8
    Critical

    CVE-2022-36523

    Last Modified: 21 Nov 2024

    D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to command injection via /htdocs/upnpinc/gena.php.

    Published: 15 Aug 2022
    8.2
    High

    CVE-2022-35624

    Last Modified: 21 Nov 2024

    In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented packets with SegO > SegN

    Published: 15 Aug 2022
    8.2
    High

    CVE-2022-35623

    Last Modified: 21 Nov 2024

    In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented control packets and access packets with the same SeqAuth

    Published: 15 Aug 2022
    8.8
    High

    CVE-2022-2824

    Last Modified: 25 Feb 2026

    Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.

    Published: 15 Aug 2022
    6.5
    Medium

    CVE-2022-2568

    Last Modified: 21 Nov 2024

    A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remove the superuser privileges.

    Published: 15 Aug 2022
    7.5
    High

    CVE-2022-33990

    Last Modified: 21 Nov 2024

    Misinterpretation of special domain name characters in dproxy-nexgen (aka dproxy nexgen) leads to cache poisoning because domain names and their associated IP addresses are cached in their misinterpreted form.

    Published: 15 Aug 2022
    5.3
    Medium

    CVE-2022-33991

    Last Modified: 21 Nov 2024

    dproxy-nexgen (aka dproxy nexgen) forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This leads to disabling of DNSSEC protection provided by upstream resolvers.

    Published: 15 Aug 2022
    5.3
    Medium

    CVE-2022-33989

    Last Modified: 21 Nov 2024

    dproxy-nexgen (aka dproxy nexgen) uses a static UDP source port (selected randomly only at boot time) in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.

    Published: 15 Aug 2022
    7.5
    High

    CVE-2022-33988

    Last Modified: 21 Nov 2024

    dproxy-nexgen (aka dproxy nexgen) re-uses the DNS transaction id (TXID) value from client queries, which allows attackers (able to send queries to the resolver) to conduct DNS cache-poisoning attacks because the TXID value is known to the attacker.

    Published: 15 Aug 2022
    9.8
    Critical

    CVE-2022-34294

    Last Modified: 21 Nov 2024

    totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.

    Published: 15 Aug 2022
    7.5
    High

    CVE-2022-33992

    Last Modified: 21 Nov 2024

    DNRD (aka Domain Name Relay Daemon) 2.20.3 forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This leads to disabling of DNSSEC protection provided by upstream resolvers.

    Published: 15 Aug 2022
    5.3
    Medium

    CVE-2022-33993

    Last Modified: 21 Nov 2024

    Misinterpretation of special domain name characters in DNRD (aka Domain Name Relay Daemon) 2.20.3 leads to cache poisoning because domain names and their associated IP addresses are cached in their misinterpreted form.

    Published: 15 Aug 2022
    9.8
    Critical

    CVE-2022-36262

    Last Modified: 21 Nov 2024

    An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying config.php.

    Published: 15 Aug 2022
    7
    High

    CVE-2022-2820

    Last Modified: 25 Feb 2026

    Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2.

    Published: 15 Aug 2022
    7.5
    High

    CVE-2022-2821

    Last Modified: 21 Nov 2024

    Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2.

    Published: 15 Aug 2022
    7.5
    High

    CVE-2022-2822

    Last Modified: 21 Nov 2024

    An attacker can freely brute force username and password and can takeover any account. An attacker could easily guess user passwords and gain access to user and administrative accounts.

    Published: 15 Aug 2022
    9.8
    Critical

    CVE-2022-2818

    Last Modified: 25 Feb 2026

    Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.

    Published: 15 Aug 2022
    5.5
    Medium

    CVE-2022-4842

    Last Modified: 8 Apr 2025

    A flaw NULL Pointer Dereference in the Linux kernel NTFS3 driver function attr_punch_hole() was found. A local user could use this flaw to crash the system.

    Published: 15 Aug 2022
    5.3
    Medium

    CVE-2022-2535

    Last Modified: 21 Nov 2024

    The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited to published posts only, allowing unauthenticated users to make a crafted query disclosing private/draft/pending post titles along with their permalink

    Published: 15 Aug 2022
    4.8
    Medium

    CVE-2022-2384

    Last Modified: 21 Nov 2024

    The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 15 Aug 2022
    8.8
    High

    CVE-2022-2381

    Last Modified: 21 Nov 2024

    The E Unlocked - Student Result WordPress plugin through 1.0.4 is lacking CSRF and validation when uploading the School logo, which could allow attackers to make a logged in admin upload arbitrary files, such as PHP via a CSRF attack

    Published: 15 Aug 2022
    7.5
    High

    CVE-2022-2379

    Last Modified: 21 Nov 2024

    The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated users to retrieve information related to the courses, exams, departments as well as student's grades and PII such as email address, physical address, phone number etc

    Published: 15 Aug 2022
    6.1
    Medium

    CVE-2022-2378

    Last Modified: 21 Nov 2024

    The Easy Student Results WordPress plugin through 2.2.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

    Published: 15 Aug 2022
    7.2
    High

    CVE-2022-2354

    Last Modified: 21 Nov 2024

    The WP-DBManager WordPress plugin before 2.80.8 does not prevent administrators from running arbitrary commands on the server in multisite installations, where only super-administrators should.

    Published: 15 Aug 2022
    9.8
    Critical

    CVE-2022-2314

    Last Modified: 21 Nov 2024

    The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.

    Published: 15 Aug 2022
    9.8
    Critical

    CVE-2022-2180

    Last Modified: 21 Nov 2024

    The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any authorization or csrf checks, allowing an unauthenticated attacker to upload arbitrary files including php source files, leading to possible remote code execution (RCE).

    Published: 15 Aug 2022
    4.8
    Medium

    CVE-2022-2152

    Last Modified: 21 Nov 2024

    The Duplicate Page and Post WordPress plugin before 2.8 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 15 Aug 2022
    6.1
    Medium

    CVE-2022-2116

    Last Modified: 21 Nov 2024

    The Contact Form DB WordPress plugin before 1.8.0 does not sanitise and escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting

    Published: 15 Aug 2022
    3.5
    Low

    CVE-2022-2814

    Last Modified: 15 Apr 2025

    A vulnerability has been found in SourceCodester Simple and Nice Shopping Cart Script and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /mkshope/login.php. The manipulation of the argument msg leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206401 was assigned to this vulnerability.

    Published: 15 Aug 2022
    7.8
    High

    CVE-2022-38222

    Last Modified: 21 Nov 2024

    There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04. It can be triggered by sending a crafted PDF file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.

    Published: 15 Aug 2022
    9.8
    Critical

    CVE-2022-38221

    Last Modified: 21 Nov 2024

    A buffer overflow in the FTcpListener thread in The Isle Evrima (the dedicated server on Windows and Linux) 0.9.88.07 before 2022-08-12 allows a remote attacker to crash any server with an accessible RCON port, or possibly execute arbitrary code.

    Published: 15 Aug 2022
    —
    Unknown

    CVE-2022-38287

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 15 Aug 2022
    7.5
    High

    CVE-2020-21365

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configurations.

    Published: 15 Aug 2022
    7.8
    High

    CVE-2022-2819

    Last Modified: 21 Nov 2024

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211.

    Published: 15 Aug 2022
    —
    Unknown

    CVE-2022-38322

    Last Modified: 12 Aug 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 15 Aug 2022
    6.7
    Medium

    CVE-2023-4394

    Last Modified: 27 Feb 2025

    A use-after-free flaw was found in btrfs_get_dev_args_from_path in fs/btrfs/volumes.c in btrfs file-system in the Linux Kernel. This flaw allows a local attacker with special privileges to cause a system crash or leak internal kernel information

    Published: 15 Aug 2022
    7.8
    High

    CVE-2022-38223

    Last Modified: 4 Nov 2025

    There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.

    Published: 15 Aug 2022
    4.3
    Medium

    CVE-2022-2813

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, was found in SourceCodester Guest Management System. Affected is an unknown function. The manipulation leads to cleartext storage of passwords in the database. The identifier of this vulnerability is VDB-206400.

    Published: 14 Aug 2022
    7.3
    High

    CVE-2022-2812

    Last Modified: 14 Apr 2025

    A vulnerability classified as critical was found in SourceCodester Guest Management System. This vulnerability affects unknown code of the file index.php. The manipulation of the argument username/pass leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-206398 is the identifier assigned to this vulnerability.

    Published: 14 Aug 2022
    3.5
    Low

    CVE-2022-2811

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in SourceCodester Guest Management System. This affects an unknown part of the file myform.php. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206397 was assigned to this vulnerability.

    Published: 14 Aug 2022
    6.1
    Medium

    CVE-2022-36007

    Last Modified: 22 Apr 2025

    Venice is a Clojure inspired sandboxed Lisp dialect with excellent Java interoperability. A partial path traversal issue exists within the functions `load-file` and `load-resource`. These functions can be limited to load files from a list of load paths. Assuming Venice has been configured with the load paths: `[ "/Users/foo/resources" ]` When passing **relative** paths to these two vulnerable functions everything is fine: `(load-resource "test.png")` => loads the file "/Users/foo/resources/test.png" `(load-resource "../resources-alt/test.png")` => rejected, outside the load path When passing **absolute** paths to these two vulnerable functions Venice may return files outside the configured load paths: `(load-resource "/Users/foo/resources/test.png")` => loads the file "/Users/foo/resources/test.png" `(load-resource "/Users/foo/resources-alt/test.png")` => loads the file "/Users/foo/resources-alt/test.png" !!! The latter call suffers from the _Partial Path Traversal_ vulnerability. This issue’s scope is limited to absolute paths whose name prefix matches a load path. E.g. for a load-path `"/Users/foo/resources"`, the actor can cause loading a resource also from `"/Users/foo/resources-alt"`, but not from `"/Users/foo/images"`. Versions of Venice before and including v1.10.17 are affected by this issue. Upgrade to Venice >= 1.10.18, if you are on a version < 1.10.18. There are currently no known workarounds.

    Published: 14 Aug 2022
    7.9
    High

    CVE-2022-36006

    Last Modified: 23 Apr 2025

    Arvados is an open source platform for managing, processing, and sharing genomic and other large scientific and biomedical data. A remote code execution (RCE) vulnerability in the Arvados Workbench allows authenticated attackers to execute arbitrary code via specially crafted JSON payloads. This exists in all versions up to 2.4.1 and is fixed in 2.4.2. This vulnerability is specific to the Ruby on Rails Workbench application (“Workbench 1”). We do not believe any other Arvados components, including the TypesScript browser-based Workbench application (“Workbench 2”) or API Server, are vulnerable to this attack. For versions of Arvados earlier than 2.4.2: remove the Ruby-based "Workbench 1" app ("apt-get remove arvados-workbench") from your installation as a workaround.

    Published: 14 Aug 2022
    7.9
    High

    CVE-2022-35961

    Last Modified: 23 Apr 2025

    OpenZeppelin Contracts is a library for secure smart contract development. The functions `ECDSA.recover` and `ECDSA.tryRecover` are vulnerable to a kind of signature malleability due to accepting EIP-2098 compact signatures in addition to the traditional 65 byte signature format. This is only an issue for the functions that take a single `bytes` argument, and not the functions that take `r, v, s` or `r, vs` as separate arguments. The potentially affected contracts are those that implement signature reuse or replay protection by marking the signature itself as used rather than the signed message or a nonce included in it. A user may take a signature that has already been submitted, submit it again in a different form, and bypass this protection. The issue has been patched in 4.7.3.

    Published: 14 Aug 2022
    —
    Unknown

    CVE-2022-35958

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-37458. Reason: This candidate is a reservation duplicate of CVE-2022-37458. Notes: All CVE users should reference CVE-2022-37458 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Aug 2022
    5
    Medium

    CVE-2022-35954

    Last Modified: 23 Apr 2025

    The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` function uses a well known delimiter that attackers can use to break out of that specific variable and assign values to other arbitrary variables. Workflows that write untrusted values to the `GITHUB_ENV` file may cause the path or other environment variables to be modified without the intention of the workflow or action author. Users should upgrade to `@actions/core v1.9.1`. If you are unable to upgrade the `@actions/core` package, you can modify your action to ensure that any user input does not contain the delimiter `_GitHubActionsFileCommandDelimeter_` before calling `core.exportVariable`.

    Published: 13 Aug 2022
    8.8
    High

    CVE-2022-37401

    Last Modified: 21 Nov 2024

    Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where master key was poorly encoded resulting in weakening its entropy from 128 to 43 bits making the stored passwords vulnerable to a brute force attack if an attacker has access to the users stored config. This issue affects: Apache OpenOffice versions prior to 4.1.13. Reference: CVE-2022-26307 - LibreOffice

    Published: 13 Aug 2022
    8.8
    High

    CVE-2022-37400

    Last Modified: 21 Nov 2024

    Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vulnerable if an attacker has access to the user's configuration data. This issue affects: Apache OpenOffice versions prior to 4.1.13. Reference: CVE-2022-26306 - LibreOffice

    Published: 13 Aug 2022
    5.5
    Medium

    CVE-2022-38533

    Last Modified: 21 Nov 2024

    In GNU Binutils before 2.40, there is a heap-buffer-overflow in the error function bfd_getl32 when called from the strip_main function in strip-new via a crafted file.

    Published: 13 Aug 2022