CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2022-35942

    Last Modified: 23 Apr 2025

    Improper input validation on the `contains` LoopBack filter may allow for arbitrary SQL injection. When the extended filter property `contains` is permitted to be interpreted by the Postgres connector, it is possible to inject arbitrary SQL which may affect the confidentiality and integrity of data stored on the connected database. A patch was released in version 5.5.1. This affects users who does any of the following: - Connect to the database via the DataSource with `allowExtendedProperties: true` setting OR - Uses the connector's CRUD methods directly OR - Uses the connector's other methods to interpret the LoopBack filter. Users who are unable to upgrade should do the following if applicable: - Remove `allowExtendedProperties: true` DataSource setting - Add `allowExtendedProperties: false` DataSource setting - When passing directly to the connector functions, manually sanitize the user input for the `contains` LoopBack filter beforehand.

    Published: 12 Aug 2022
    5.9
    Medium

    CVE-2022-35943

    Last Modified: 22 Apr 2025

    Shield is an authentication and authorization framework for CodeIgniter 4. This vulnerability may allow [SameSite Attackers](https://canitakeyoursubdomain.name/) to bypass the [CodeIgniter4 CSRF protection](https://codeigniter4.github.io/userguide/libraries/security.html) mechanism with CodeIgniter Shield. For this attack to succeed, the attacker must have direct (or indirect, e.g., XSS) control over a subdomain site (e.g., `https://a.example.com/`) of the target site (e.g., `http://example.com/`). Upgrade to **CodeIgniter v4.2.3 or later** and **Shield v1.0.0-beta.2 or later**. As a workaround: set `Config\Security::$csrfProtection` to `'session,'`remove old session data right after login (immediately after ID and password match) and regenerate CSRF token right after login (immediately after ID and password match)

    Published: 12 Aug 2022
    5.8
    Medium

    CVE-2022-35956

    Last Modified: 23 Apr 2025

    This Rails gem adds two methods to the ActiveRecord::Base class that allow you to update many records on a single database hit, using a case sql statement for it. Before version 0.1.3 `update_by_case` gem used custom sql strings, and it was not sanitized, making it vulnerable to sql injection. Upgrade to version >= 0.1.3 that uses `Arel` instead to construct the resulting sql statement, with sanitized sql.

    Published: 12 Aug 2022
    7.1
    High

    CVE-2022-35953

    Last Modified: 22 Apr 2025

    BookWyrm is a social network for tracking your reading, talking about books, writing reviews, and discovering what to read next. Some links in BookWyrm may be vulnerable to tabnabbing, a form of phishing that gives attackers an opportunity to redirect a user to a malicious site. The issue was patched in version 0.4.5.

    Published: 12 Aug 2022
    6.3
    Medium

    CVE-2022-2804

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Zoo Management System. It has been classified as critical. Affected is an unknown function of the file /pages/apply_vacancy.php. The manipulation of the argument filename leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-206250 is the identifier assigned to this vulnerability.

    Published: 12 Aug 2022
    6.3
    Medium

    CVE-2022-2803

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Zoo Management System and classified as critical. This issue affects some unknown processing of the file /pages/animals.php. The manipulation of the argument class_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206249 was assigned to this vulnerability.

    Published: 12 Aug 2022
    7.3
    High

    CVE-2022-2802

    Last Modified: 14 Apr 2025

    A vulnerability has been found in SourceCodester Gas Agency Management System and classified as critical. This vulnerability affects unknown code of the file gasmark/login.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-206248.

    Published: 12 Aug 2022
    6.3
    Medium

    CVE-2022-2801

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, was found in SourceCodester Automated Beer Parlour Billing System. This affects an unknown part of the component Login. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-206247.

    Published: 12 Aug 2022
    4.3
    Medium

    CVE-2022-2800

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in SourceCodester Gym Management System. Affected by this issue is some unknown functionality. The manipulation leads to clickjacking. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-206246 is the identifier assigned to this vulnerability.

    Published: 12 Aug 2022
    8.8
    High

    CVE-2022-2624

    Last Modified: 21 Nov 2024

    Heap buffer overflow in PDF in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted PDF file.

    Published: 12 Aug 2022
    8.8
    High

    CVE-2022-2623

    Last Modified: 21 Nov 2024

    Use after free in Offline in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.

    Published: 12 Aug 2022
    6.5
    Medium

    CVE-2022-2622

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in Safe Browsing in Google Chrome on Windows prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a crafted file.

    Published: 12 Aug 2022
    8.8
    High

    CVE-2022-2621

    Last Modified: 21 Nov 2024

    Use after free in Extensions in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interactions.

    Published: 12 Aug 2022
    8.8
    High

    CVE-2022-2620

    Last Modified: 21 Nov 2024

    Use after free in WebUI in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.

    Published: 12 Aug 2022
    4.3
    Medium

    CVE-2022-2619

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in Settings in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted HTML page.

    Published: 12 Aug 2022
    6.5
    Medium

    CVE-2022-2618

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in Internals in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a malicious file .

    Published: 12 Aug 2022
    8.8
    High

    CVE-2022-2617

    Last Modified: 21 Nov 2024

    Use after free in Extensions API in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interactions.

    Published: 12 Aug 2022
    6.5
    Medium

    CVE-2022-2616

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to spoof the contents of the Omnibox (URL bar) via a crafted Chrome Extension.

    Published: 12 Aug 2022
    6.5
    Medium

    CVE-2022-2615

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 12 Aug 2022
    8.8
    High

    CVE-2022-2614

    Last Modified: 21 Nov 2024

    Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 12 Aug 2022
    8.8
    High

    CVE-2022-2613

    Last Modified: 21 Nov 2024

    Use after free in Input in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to enage in specific user interactions to potentially exploit heap corruption via specific UI interactions.

    Published: 12 Aug 2022
    6.5
    Medium

    CVE-2022-2612

    Last Modified: 21 Nov 2024

    Side-channel information leakage in Keyboard input in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 12 Aug 2022
    4.3
    Medium

    CVE-2022-2611

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Fullscreen API in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 12 Aug 2022
    6.5
    Medium

    CVE-2022-2610

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Background Fetch in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 12 Aug 2022
    8.8
    High

    CVE-2022-2609

    Last Modified: 21 Nov 2024

    Use after free in Nearby Share in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.

    Published: 12 Aug 2022
    8.8
    High

    CVE-2022-2608

    Last Modified: 21 Nov 2024

    Use after free in Overview Mode in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.

    Published: 12 Aug 2022
    8.8
    High

    CVE-2022-2607

    Last Modified: 21 Nov 2024

    Use after free in Tab Strip in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.

    Published: 12 Aug 2022
    8.8
    High

    CVE-2022-2606

    Last Modified: 21 Nov 2024

    Use after free in Managed devices API in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who convinced a user to enable a specific Enterprise policy to potentially exploit heap corruption via a crafted HTML page.

    Published: 12 Aug 2022
    6.5
    Medium

    CVE-2022-2605

    Last Modified: 21 Nov 2024

    Out of bounds read in Dawn in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 12 Aug 2022
    8.8
    High

    CVE-2022-2604

    Last Modified: 21 Nov 2024

    Use after free in Safe Browsing in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 12 Aug 2022
    8.8
    High

    CVE-2022-2603

    Last Modified: 21 Nov 2024

    Use after free in Omnibox in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 12 Aug 2022
    9.8
    Critical

    CVE-2022-2587

    Last Modified: 21 Nov 2024

    Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prior to 102.0.5005.125 allowed a remote attacker to potentially exploit heap corruption via crafted audio metadata.

    Published: 12 Aug 2022
    6.3
    Medium

    CVE-2022-2797

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical was found in SourceCodester Student Information System. Affected by this vulnerability is an unknown functionality of the file /admin/students/view_student.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The identifier VDB-206245 was assigned to this vulnerability.

    Published: 12 Aug 2022
    7.8
    High

    CVE-2021-29117

    Last Modified: 10 Apr 2025

    A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) allows an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.

    Published: 12 Aug 2022
    5.5
    Medium

    CVE-2021-29112

    Last Modified: 10 Apr 2025

    An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) which allow an unauthenticated attacker to induce an information disclosure issue in the context of the current user.

    Published: 12 Aug 2022
    5.5
    Medium

    CVE-2021-29118

    Last Modified: 10 Apr 2025

    An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) which allow an unauthenticated attacker to induce an information disclosure issue in the context of the current user.

    Published: 12 Aug 2022
    8.3
    High

    CVE-2022-37397

    Last Modified: 21 Nov 2024

    An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password.

    Published: 12 Aug 2022
    7.5
    High

    CVE-2022-35980

    Last Modified: 23 Apr 2025

    OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. Versions 2.0.0.0 and 2.1.0.0 of the security plugin are affected by an information disclosure vulnerability. Requests to an OpenSearch cluster configured with advanced access control features document level security (DLS), field level security (FLS), and/or field masking will not be filtered when the query's search pattern matches an aliased index. OpenSearch Dashboards creates an alias to `.kibana` by default, so filters with the index pattern of `*` to restrict access to documents or fields will not be applied. This issue allows requests to access sensitive information when customer have acted to restrict access that specific information. OpenSearch 2.2.0, which is compatible with OpenSearch Security 2.2.0.0, contains the fix for this issue. There is no recommended work around.

    Published: 12 Aug 2022
    4.8
    Medium

    CVE-2021-42751

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the description of a rule node.

    Published: 12 Aug 2022
    4.8
    Medium

    CVE-2021-42750

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the title of a rule node.

    Published: 12 Aug 2022
    4.8
    Medium

    CVE-2022-35585

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) issue in the ForkCMS version 5.9.3 allows remote attackers to inject JavaScript via the "start_date" Parameter

    Published: 12 Aug 2022
    4.8
    Medium

    CVE-2022-35587

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publish_on_date" Parameter

    Published: 12 Aug 2022
    4.8
    Medium

    CVE-2022-35589

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publish_on_time" Parameter.

    Published: 12 Aug 2022
    4.8
    Medium

    CVE-2022-35590

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) issue in the ForkCMS version 5.9.3 allows remote attackers to inject JavaScript via the "end_date" Parameter

    Published: 12 Aug 2022
    3.5
    Low

    CVE-2022-35932

    Last Modified: 23 Apr 2025

    Nextcloud Talk is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.7, 13.0.7, and 14.0.3, password protected conversations are susceptible to brute force attacks if the attacker has the link/conversation token. It is recommended that the Nextcloud Talk application is upgraded to 12.2.7, 13.0.7 or 14.0.3. There are currently no known workarounds available apart from not having password protected conversations.

    Published: 12 Aug 2022
    7.5
    High

    CVE-2022-37423

    Last Modified: 21 Nov 2024

    Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to sibling directories via apoc.log.stream.

    Published: 12 Aug 2022
    6.1
    Medium

    CVE-2022-2390

    Last Modified: 21 Apr 2025

    Apps developed with Google Play Services SDK incorrectly had the mutability flag set to PendingIntents that were passed to the Notification service. As Google Play services SDK is so widely used, this bug affects many applications. For an application affected, this bug will let the attacker, gain the access to all non-exported providers and/or gain the access to other providers the victim has permissions. We recommend upgrading to version 18.0.2 of the Play Service SDK as well as rebuilding and redeploying apps.

    Published: 12 Aug 2022
    5.3
    Medium

    CVE-2022-38180

    Last Modified: 21 Nov 2024

    In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases

    Published: 12 Aug 2022
    4.7
    Medium

    CVE-2022-38179

    Last Modified: 21 Nov 2024

    JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack

    Published: 12 Aug 2022
    6.3
    Medium

    CVE-2022-2779

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical was found in SourceCodester Gas Agency Management System. Affected by this vulnerability is an unknown functionality of the file /gasmark/assets/myimages/oneWord.php. The manipulation of the argument shell leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206173 was assigned to this vulnerability.

    Published: 12 Aug 2022