CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-33645

    Last Modified: 3 Nov 2025

    The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak.

    Published: 9 Aug 2022
    8.1
    High

    CVE-2021-33644

    Last Modified: 3 Nov 2025

    An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longname, causing an out-of-bounds read.

    Published: 9 Aug 2022
    5.3
    Medium

    CVE-2022-35949

    Last Modified: 22 Apr 2025

    undici is an HTTP/1.1 client, written from scratch for Node.js.`undici` is vulnerable to SSRF (Server-side Request Forgery) when an application takes in **user input** into the `path/pathname` option of `undici.request`. If a user specifies a URL such as `http://127.0.0.1` or `//127.0.0.1` ```js const undici = require("undici") undici.request({origin: "http://example.com", pathname: "//127.0.0.1"}) ``` Instead of processing the request as `http://example.org//127.0.0.1` (or `http://example.org/http://127.0.0.1` when `http://127.0.0.1 is used`), it actually processes the request as `http://127.0.0.1/` and sends it to `http://127.0.0.1`. If a developer passes in user input into `path` parameter of `undici.request`, it can result in an _SSRF_ as they will assume that the hostname cannot change, when in actual fact it can change because the specified path parameter is combined with the base URL. This issue was fixed in `[email protected]`. The best workaround is to validate user input before passing it to the `undici.request` call.

    Published: 9 Aug 2022
    9.8
    Critical

    CVE-2022-32429

    Last Modified: 21 Nov 2024

    An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, leading to remote code execution.

    Published: 9 Aug 2022
    5.9
    Medium

    CVE-2022-34716

    Last Modified: 29 May 2025

    .NET Spoofing Vulnerability

    Published: 9 Aug 2022
    4.9
    Medium

    CVE-2022-35812

    Last Modified: 2 Jan 2025

    Azure Site Recovery Elevation of Privilege Vulnerability

    Published: 9 Aug 2022
    5.5
    Medium

    CVE-2023-1095

    Last Modified: 18 Mar 2025

    In nf_tables_updtable, if nf_tables_table_enable returns an error, nft_trans_destroy is called to free the transaction object. nft_trans_destroy() calls list_del(), but the transaction was never placed on a list -- the list head is all zeroes, this results in a NULL pointer dereference.

    Published: 9 Aug 2022
    7.5
    High

    CVE-2022-29804

    Last Modified: 21 Nov 2024

    Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.

    Published: 9 Aug 2022
    7.5
    High

    CVE-2022-38150

    Last Modified: 20 Oct 2025

    In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backend response status line. This is fixed in 7.0.3 and 7.1.1.

    Published: 9 Aug 2022
    —
    Unknown

    CVE-2017-7527

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 8 Aug 2022
    —
    Unknown

    CVE-2017-2657

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 8 Aug 2022
    —
    Unknown

    CVE-2017-2631

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 8 Aug 2022
    —
    Unknown

    CVE-2017-2597

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 8 Aug 2022
    —
    Unknown

    CVE-2017-2593

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 8 Aug 2022
    —
    Unknown

    CVE-2017-2588

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 8 Aug 2022
    —
    Unknown

    CVE-2017-15122

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 8 Aug 2022
    —
    Unknown

    CVE-2017-15109

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 8 Aug 2022
    —
    Unknown

    CVE-2017-15106

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 8 Aug 2022
    —
    Unknown

    CVE-2017-12152

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 8 Aug 2022
    —
    Unknown

    CVE-2022-37950

    Last Modified: 7 Nov 2023

    Not used in 2022

    Published: 8 Aug 2022
    —
    Unknown

    CVE-2022-37951

    Last Modified: 7 Nov 2023

    Not used in 2022

    Published: 8 Aug 2022
    —
    Unknown

    CVE-2022-37949

    Last Modified: 7 Nov 2023

    Not used in 2022

    Published: 8 Aug 2022
    —
    Unknown

    CVE-2022-37944

    Last Modified: 7 Nov 2023

    Not used in 2022

    Published: 8 Aug 2022
    —
    Unknown

    CVE-2022-37945

    Last Modified: 7 Nov 2023

    Not used in 2022

    Published: 8 Aug 2022
    —
    Unknown

    CVE-2022-37946

    Last Modified: 7 Nov 2023

    Not used in 2022

    Published: 8 Aug 2022
    —
    Unknown

    CVE-2022-37947

    Last Modified: 7 Nov 2023

    Not used in 2022

    Published: 8 Aug 2022
    —
    Unknown

    CVE-2022-37948

    Last Modified: 7 Nov 2023

    Not used in 2022

    Published: 8 Aug 2022
    —
    Unknown

    CVE-2022-37941

    Last Modified: 7 Nov 2023

    Not used in 2022

    Published: 8 Aug 2022
    —
    Unknown

    CVE-2022-37942

    Last Modified: 7 Nov 2023

    Not used in 2022

    Published: 8 Aug 2022
    —
    Unknown

    CVE-2022-37943

    Last Modified: 7 Nov 2023

    Not used in 2022

    Published: 8 Aug 2022
    9.8
    Critical

    CVE-2021-41615

    Last Modified: 21 Nov 2024

    websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparadise value, which does not follow the secret-data guideline for HTTP Digest Access Authentication in RFC 7616 section 3.3 (or RFC 2617 section 3.2.1). NOTE: 2.1.8 is a version from 2003; however, the affected websda.c code appears in multiple derivative works that may be used in 2021. Recent GoAhead software is unaffected.

    Published: 8 Aug 2022
    7.5
    High

    CVE-2022-34293

    Last Modified: 21 Nov 2024

    wolfSSL before 5.4.0 allows remote attackers to cause a denial of service via DTLS because a check for return-routability can be skipped.

    Published: 8 Aug 2022
    9.1
    Critical

    CVE-2022-36264

    Last Modified: 21 Nov 2024

    In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists an Unauthenticated remote Arbitrary File Upload vulnerability which allows overwriting arbitrary files. A malicious actor can remotely upload a file of their choice and overwrite any file in the system by manipulating the filename and append a relative path that will be interpreted during the upload process. Using this method, it is possible to rewrite any file in the system or upload a new file.

    Published: 8 Aug 2022
    7.2
    High

    CVE-2022-36265

    Last Modified: 21 Nov 2024

    In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Hidden system command web page. After performing a reverse engineering of the firmware, it was discovered that a hidden page not listed in the administration management interface allows a user to execute Linux commands on the device with root privileges. An authenticated malicious threat actor can use this page to fully compromise the device.

    Published: 8 Aug 2022
    6.1
    Medium

    CVE-2022-36266

    Last Modified: 21 Nov 2024

    In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a stored XSS vulnerability. As the binary file /home/www/cgi-bin/login.cgi does not check if the user is authenticated, a malicious actor can craft a specific request on the login.cgi endpoint that contains a base32 encoded XSS payload that will be accepted and stored. A successful attack will results in the injection of malicious scripts into the user settings page.

    Published: 8 Aug 2022
    9.8
    Critical

    CVE-2022-36267

    Last Modified: 21 Nov 2024

    In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can be called without user authentication when crafting a malicious http request by injecting code in one of the parameters allowing for remote code execution. This vulnerability is exploited via the binary file /home/www/cgi-bin/diagnostics.cgi that accepts unauthenticated requests and unsanitized data. As a result, a malicious actor can craft a specific request and interact remotely with the device.

    Published: 8 Aug 2022
    9.8
    Critical

    CVE-2022-2713

    Last Modified: 27 Mar 2026

    Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.

    Published: 8 Aug 2022
    7
    High

    CVE-2022-2590

    Last Modified: 21 Nov 2024

    A race condition was found in the way the Linux kernel's memory subsystem handled the copy-on-write (COW) breakage of private read-only shared memory mappings. This flaw allows an unprivileged, local user to gain write access to read-only memory mappings, increasing their privileges on the system.

    Published: 8 Aug 2022
    6.1
    Medium

    CVE-2022-35493

    Last Modified: 8 Jul 2026

    A Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose Ecommerce Store Website version 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the get_products?search parameter.

    Published: 8 Aug 2022
    9.8
    Critical

    CVE-2022-35490

    Last Modified: 21 Nov 2024

    Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, users are invalidated and logins prevented. An attacker might work around this prevention, enabling them to send more than the configured amount of requests before the user invalidation takes place.

    Published: 8 Aug 2022
    6.5
    Medium

    CVE-2022-35489

    Last Modified: 21 Nov 2024

    In Zammad 5.2.0, customers who have secondary organizations assigned were able to see all organizations of the system rather than only those to which they are assigned.

    Published: 8 Aug 2022
    7.5
    High

    CVE-2022-35488

    Last Modified: 21 Nov 2024

    In Zammad 5.2.0, an attacker could manipulate the rate limiting in the 'forgot password' feature of Zammad, and thereby send many requests for a known account to cause Denial Of Service by many generated emails which would also spam the victim.

    Published: 8 Aug 2022
    7.5
    High

    CVE-2022-35487

    Last Modified: 21 Nov 2024

    Zammad 5.2.0 suffers from Incorrect Access Control. Zammad did not correctly perform authorization on certain attachment endpoints. This could be abused by an unauthenticated attacker to gain access to attachments, such as emails or attached files.

    Published: 8 Aug 2022
    9.8
    Critical

    CVE-2022-2460

    Last Modified: 3 Sept 2025

    The WPDating WordPress plugin before 7.4.0 does not properly escape user input before concatenating it to certain SQL queries, leading to multiple SQL injection vulnerabilities exploitable by unauthenticated users

    Published: 8 Aug 2022
    4.8
    Medium

    CVE-2022-2426

    Last Modified: 21 Nov 2024

    The Thinkific Uploader WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks against other administrators.

    Published: 8 Aug 2022
    4.8
    Medium

    CVE-2022-2425

    Last Modified: 21 Nov 2024

    The WP DS Blog Map WordPress plugin through 3.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 8 Aug 2022
    4.8
    Medium

    CVE-2022-2424

    Last Modified: 21 Nov 2024

    The Google Maps Anywhere WordPress plugin through 1.2.6.3 does not sanitise and escape any of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 8 Aug 2022
    4.8
    Medium

    CVE-2022-2423

    Last Modified: 21 Nov 2024

    The DW Promobar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 8 Aug 2022
    4.8
    Medium

    CVE-2022-2412

    Last Modified: 21 Nov 2024

    The Better Tag Cloud WordPress plugin through 0.99.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 8 Aug 2022
    4.8
    Medium

    CVE-2022-2411

    Last Modified: 21 Nov 2024

    The Auto More Tag WordPress plugin through 4.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 8 Aug 2022