CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2022-30144

    Last Modified: 2 Jan 2025

    Windows Bluetooth Service Remote Code Execution Vulnerability

    Published: 9 Aug 2022
    6.5
    Medium

    CVE-2022-30134

    Last Modified: 2 Jan 2025

    Microsoft Exchange Server Information Disclosure Vulnerability

    Published: 9 Aug 2022
    9.8
    Critical

    CVE-2022-30133

    Last Modified: 2 Jan 2025

    Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability

    Published: 9 Aug 2022
    8
    High

    CVE-2022-24516

    Last Modified: 2 Jan 2025

    Microsoft Exchange Server Elevation of Privilege Vulnerability

    Published: 9 Aug 2022
    8
    High

    CVE-2022-24477

    Last Modified: 2 Jan 2025

    Microsoft Exchange Server Elevation of Privilege Vulnerability

    Published: 9 Aug 2022
    9.8
    Critical

    CVE-2022-35525

    Last Modified: 21 Nov 2024

    WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameter led_switch, which leads to command injection in page /ledonoff.shtml.

    Published: 9 Aug 2022
    8
    High

    CVE-2022-21980

    Last Modified: 2 Jan 2025

    Microsoft Exchange Server Elevation of Privilege Vulnerability

    Published: 9 Aug 2022
    4.8
    Medium

    CVE-2022-21979

    Last Modified: 2 Jan 2025

    Microsoft Exchange Server Information Disclosure Vulnerability

    Published: 9 Aug 2022
    9.8
    Critical

    CVE-2022-35526

    Last Modified: 21 Nov 2024

    WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 login.cgi has no filtering on parameter key, which leads to command injection in page /login.shtml.

    Published: 9 Aug 2022
    9.8
    Critical

    CVE-2022-35533

    Last Modified: 21 Nov 2024

    WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 qos.cgi has no filtering on parameters: cli_list and cli_num, which leads to command injection in page /qos.shtml.

    Published: 9 Aug 2022
    9.8
    Critical

    CVE-2022-35534

    Last Modified: 21 Nov 2024

    WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameter hiddenSSID32g and SSID2G2, which leads to command injection in page /wifi_multi_ssid.shtml.

    Published: 9 Aug 2022
    9.8
    Critical

    CVE-2022-35535

    Last Modified: 21 Nov 2024

    WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameter macAddr, which leads to command injection in page /wifi_mesh.shtml.

    Published: 9 Aug 2022
    9.8
    Critical

    CVE-2022-35536

    Last Modified: 21 Nov 2024

    WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 qos.cgi has no filtering on parameters: qos_bandwith and qos_dat, which leads to command injection in page /qos.shtml.

    Published: 9 Aug 2022
    9.8
    Critical

    CVE-2022-35537

    Last Modified: 21 Nov 2024

    WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameters: mac_5g and Newname, which leads to command injection in page /wifi_mesh.shtml.

    Published: 9 Aug 2022
    9.8
    Critical

    CVE-2022-35538

    Last Modified: 21 Nov 2024

    WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameters: delete_list, delete_al_mac, b_delete_list and b_delete_al_mac, which leads to command injection in page /wifi_mesh.shtml.

    Published: 9 Aug 2022
    5.4
    Medium

    CVE-2022-35509

    Last Modified: 16 Jun 2026

    An issue was discovered in EyouCMS 1.5.8. There is a Storage XSS vulnerability that can allows an attacker to execute arbitrary Web scripts or HTML by injecting a special payload via the title parameter in the foreground contribution, allowing the attacker to obtain sensitive information.

    Published: 9 Aug 2022
    4.6
    Medium

    CVE-2022-30574

    Last Modified: 21 Nov 2024

    The ftlserver component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, TIBCO FTL - Enterprise Edition, TIBCO FTL - Enterprise Edition, TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, TIBCO eFTL - Enterprise Edition, and TIBCO eFTL - Enterprise Edition contains a difficult to exploit vulnerability that allows a low privileged attacker with local access to obtain user credentials to the affected system. Affected releases are TIBCO Software Inc.'s TIBCO FTL - Community Edition: versions 6.0.0 through 6.8.0, TIBCO FTL - Developer Edition: versions 6.0.1 through 6.8.0, TIBCO FTL - Enterprise Edition: versions 6.0.0 through 6.7.3, TIBCO FTL - Enterprise Edition: version 6.8.0, TIBCO eFTL - Community Edition: versions 6.0.0 through 6.8.0, TIBCO eFTL - Developer Edition: versions 6.0.1 through 6.8.0, TIBCO eFTL - Enterprise Edition: versions 6.0.0 through 6.7.3, and TIBCO eFTL - Enterprise Edition: version 6.8.0.

    Published: 9 Aug 2022
    6.7
    Medium

    CVE-2022-30573

    Last Modified: 21 Nov 2024

    The ftlserver component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, TIBCO FTL - Enterprise Edition, and TIBCO FTL - Enterprise Edition contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a privilege escalation on the affected ftlserver. Affected releases are TIBCO Software Inc.'s TIBCO FTL - Community Edition: versions 6.0.0 through 6.8.0, TIBCO FTL - Developer Edition: versions 6.0.1 through 6.8.0, TIBCO FTL - Enterprise Edition: versions 6.0.0 through 6.7.3, and TIBCO FTL - Enterprise Edition: version 6.8.0.

    Published: 9 Aug 2022
    5.3
    Medium

    CVE-2022-2586

    Last Modified: 20 Aug 2026

    It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

    Published: 9 Aug 2022
    5.3
    Medium

    CVE-2022-2585

    Last Modified: 21 Nov 2024

    It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free.

    Published: 9 Aug 2022
    5.3
    Medium

    CVE-2022-2588

    Last Modified: 22 May 2025

    It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if its handle had the value 0.

    Published: 9 Aug 2022
    9.8
    Critical

    CVE-2022-35491

    Last Modified: 21 Nov 2024

    TOTOLINK A3002RU V3.0.0-B20220304.1804 has a hardcoded password for root in /etc/shadow.sample.

    Published: 9 Aug 2022
    9.8
    Critical

    CVE-2022-35426

    Last Modified: 21 Nov 2024

    UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file.

    Published: 9 Aug 2022
    8.8
    High

    CVE-2022-37024

    Last Modified: 21 Nov 2024

    Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allow authenticated users to make database changes that lead to remote code execution.

    Published: 9 Aug 2022
    5.4
    Medium

    CVE-2022-2734

    Last Modified: 21 Nov 2024

    Improper Restriction of Rendered UI Layers or Frames in GitHub repository openemr/openemr prior to 7.0.0.1.

    Published: 9 Aug 2022
    8.3
    High

    CVE-2022-2732

    Last Modified: 25 Feb 2026

    Missing Authorization in GitHub repository openemr/openemr prior to 7.0.0.1.

    Published: 9 Aug 2022
    6.1
    Medium

    CVE-2022-2733

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.

    Published: 9 Aug 2022
    6.1
    Medium

    CVE-2022-2731

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.

    Published: 9 Aug 2022
    5.4
    Medium

    CVE-2022-2729

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - DOM in GitHub repository openemr/openemr prior to 7.0.0.1.

    Published: 9 Aug 2022
    6.5
    Medium

    CVE-2022-2730

    Last Modified: 21 Nov 2024

    Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.

    Published: 9 Aug 2022
    6.3
    Medium

    CVE-2022-2728

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Gym Management System. It has been rated as critical. Affected by this issue is some unknown functionality of the file /mygym/admin/index.php. The manipulation of the argument edit_tran leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-205856.

    Published: 9 Aug 2022
    6.3
    Medium

    CVE-2022-2727

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Gym Management System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /mygym/admin/login.php. The manipulation of the argument admin_email/admin_pass leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-205855.

    Published: 9 Aug 2022
    4.6
    Medium

    CVE-2022-3625

    Last Modified: 21 Nov 2024

    A vulnerability was found in Linux Kernel. It has been classified as critical. This affects the function devlink_param_set/devlink_param_get of the file net/core/devlink.c of the component IPsec. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier VDB-211929 was assigned to this vulnerability.

    Published: 9 Aug 2022
    6.3
    Medium

    CVE-2022-2726

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical has been found in SEMCMS. This affects an unknown part of the file Ant_Check.php. The manipulation of the argument DID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-205839.

    Published: 9 Aug 2022
    3.5
    Low

    CVE-2022-2725

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Company Website CMS. It has been rated as problematic. Affected by this issue is some unknown functionality of the file add-blog.php. The manipulation leads to cross site scripting. The attack may be launched remotely. VDB-205838 is the identifier assigned to this vulnerability.

    Published: 9 Aug 2022
    6.3
    Medium

    CVE-2022-2724

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Employee Management System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /process/aprocess.php. The manipulation of the argument mailuid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205837 was assigned to this vulnerability.

    Published: 9 Aug 2022
    6.3
    Medium

    CVE-2022-2723

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Employee Management System. It has been classified as critical. Affected is an unknown function of the file /process/eprocess.php. The manipulation of the argument mailuid/pwd leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-205836.

    Published: 9 Aug 2022
    6.3
    Medium

    CVE-2022-2722

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Simple Student Information System and classified as critical. This issue affects some unknown processing of the file manage_course.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-205835.

    Published: 9 Aug 2022
    7.5
    High

    CVE-2022-36125

    Last Modified: 6 Mar 2026

    It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which addresses this issue.

    Published: 9 Aug 2022
    7.5
    High

    CVE-2022-36124

    Last Modified: 23 Jun 2026

    It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which addresses this issue.

    Published: 9 Aug 2022
    7.5
    High

    CVE-2022-35724

    Last Modified: 21 Nov 2024

    It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which addresses this issue.

    Published: 9 Aug 2022
    6.3
    Medium

    CVE-2022-2715

    Last Modified: 15 Apr 2025

    A vulnerability has been found in SourceCodester Employee Management System and classified as critical. This vulnerability affects unknown code of the file eloginwel.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-205834 is the identifier assigned to this vulnerability.

    Published: 9 Aug 2022
    5.6
    Medium

    CVE-2021-46778

    Last Modified: 21 Nov 2024

    Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By measuring the contention level on scheduler queues an attacker may potentially leak sensitive information.

    Published: 9 Aug 2022
    5.5
    Medium

    CVE-2022-26373

    Last Modified: 5 May 2025

    Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

    Published: 9 Aug 2022
    5.5
    Medium

    CVE-2022-21233

    Last Modified: 5 May 2025

    Improper isolation of shared resources in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.

    Published: 9 Aug 2022
    7.5
    High

    CVE-2022-25907

    Last Modified: 21 Nov 2024

    The package ts-deepmerge before 2.0.2 are vulnerable to Prototype Pollution due to missing sanitization of the merge function.

    Published: 9 Aug 2022
    9.1
    Critical

    CVE-2021-33643

    Last Modified: 23 Jun 2026

    An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds read.

    Published: 9 Aug 2022
    5.3
    Medium

    CVE-2022-35948

    Last Modified: 22 Apr 2025

    undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type` header. Example: ``` import { request } from 'undici' const unsanitizedContentTypeInput = 'application/json\r\n\r\nGET /foo2 HTTP/1.1' await request('http://localhost:3000, { method: 'GET', headers: { 'content-type': unsanitizedContentTypeInput }, }) ``` The above snippet will perform two requests in a single `request` API call: 1) `http://localhost:3000/` 2) `http://localhost:3000/foo2` This issue was patched in Undici v5.8.1. Sanitize input when sending content-type headers using user input as a workaround.

    Published: 9 Aug 2022
    4.7
    Medium

    CVE-2022-34704

    Last Modified: 27 Aug 2025

    Windows Defender Credential Guard Information Disclosure Vulnerability

    Published: 9 Aug 2022
    7.5
    High

    CVE-2021-33646

    Last Modified: 3 Nov 2025

    The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak.

    Published: 9 Aug 2022