CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2022-2682

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in SourceCodester Alphaware Simple E-Commerce System. Affected by this issue is some unknown functionality of the file stockin.php. The manipulation of the argument id with the input '"><script>alert(/xss/)</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-205670 is the identifier assigned to this vulnerability.

    Published: 5 Aug 2022
    3.5
    Low

    CVE-2022-2681

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic was found in SourceCodester Online Student Admission System. Affected by this vulnerability is an unknown functionality of the file edit-profile.php of the component Student User Page. The manipulation with the input <script>alert(/xss/)</script> leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205669 was assigned to this vulnerability.

    Published: 5 Aug 2022
    6.3
    Medium

    CVE-2022-2680

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical has been found in SourceCodester Church Management System 1.0. Affected is an unknown function of the file /login.php. The manipulation of the argument username with the input ' OR (SELECT 7064 FROM(SELECT COUNT(*),CONCAT(0x71627a7671,(SELECT (ELT(7064=7064,1))),0x716b707871,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)-- jURL leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-205668.

    Published: 5 Aug 2022
    6.3
    Medium

    CVE-2022-2679

    Last Modified: 25 Nov 2025

    A vulnerability was found in SourceCodester Interview Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /viewReport.php. The manipulation of the argument id with the input (UPDATEXML(9729,CONCAT(0x2e,0x716b707071,(SELECT (ELT(9729=9729,1))),0x7162766a71),7319)) leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-205667.

    Published: 5 Aug 2022
    6.3
    Medium

    CVE-2022-2678

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Alphaware Simple E-Commerce System. It has been declared as critical. This vulnerability affects unknown code of the file admin_feature.php of the component Background Management Page. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-205666 is the identifier assigned to this vulnerability.

    Published: 5 Aug 2022
    6.3
    Medium

    CVE-2022-2677

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been classified as critical. This affects an unknown part of the file index.php. The manipulation of the argument username with the input ' AND (SELECT 4955 FROM (SELECT(SLEEP(5)))RSzF) AND 'htiy'='htiy leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205665 was assigned to this vulnerability.

    Published: 5 Aug 2022
    6.3
    Medium

    CVE-2022-2676

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Electronic Medical Records System and classified as critical. Affected by this issue is some unknown functionality of the component POST Request Handler. The manipulation of the argument user_email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-205664.

    Published: 5 Aug 2022
    4.8
    Medium

    CVE-2022-35163

    Last Modified: 21 Nov 2024

    Complete Online Job Search System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the U_NAME parameter at /category/controller.php?action=edit.

    Published: 5 Aug 2022
    4.8
    Medium

    CVE-2022-35162

    Last Modified: 21 Nov 2024

    Complete Online Job Search System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the CATEGORY parameter at /category/controller.php?action=edit.

    Published: 5 Aug 2022
    6.5
    Medium

    CVE-2022-2675

    Last Modified: 21 Nov 2024

    Using off-the-shelf commodity hardware, the Unitree Go 1 robotics platform version H0.1.7 and H0.1.9 (using firmware version 0.1.35) can be powered down by an attacker within normal RF range without authentication. Other versions may be affected, such as the A1.

    Published: 5 Aug 2022
    7.8
    High

    CVE-2022-27535

    Last Modified: 21 Nov 2024

    Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its 'Delete All Service Data And Reports' feature by the local authenticated attacker.

    Published: 5 Aug 2022
    5.8
    Medium

    CVE-2021-28511

    Last Modified: 2 Jun 2026

    This advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impact of this vulnerability is that the security ACL drop rule might be bypassed if a NAT ACL rule filter with permit action matches the packet flow. This could allow a host with an IP address in a range that matches the range allowed by a NAT ACL and a range denied by a Security ACL to be forwarded incorrectly as it should have been denied by the Security ACL. This can enable an ACL bypass.

    Published: 5 Aug 2022
    4
    Medium

    CVE-2022-29071

    Last Modified: 2 Jun 2026

    This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs. The impact of this vulnerability is that the CVP user login passwords might be leaked to other authenticated users.

    Published: 5 Aug 2022
    4.3
    Medium

    CVE-2022-28880

    Last Modified: 2 Jun 2026

    A Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files it is possible that can crash the scanning engine. The exploit can be triggered remotely by an attacker.

    Published: 5 Aug 2022
    7.1
    High

    CVE-2022-37398

    Last Modified: 2 Jun 2026

    A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validation. An attacker can exploit this vulnerability to run arbitrary code. Affected ADM versions include: 3.5.9.RUE3 and below, 4.0.5.RVI1 and below as well as 4.1.0.RJD1 and below.

    Published: 5 Aug 2022
    —
    Unknown

    CVE-2019-10204

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 5 Aug 2022
    —
    Unknown

    CVE-2018-1076

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 5 Aug 2022
    4
    Medium

    CVE-2021-46678

    Last Modified: 2 Jun 2026

    A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the service name field.

    Published: 5 Aug 2022
    4
    Medium

    CVE-2021-46680

    Last Modified: 2 Jun 2026

    A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the module form name field.

    Published: 5 Aug 2022
    4
    Medium

    CVE-2021-46677

    Last Modified: 2 Jun 2026

    A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the event filter name field.

    Published: 5 Aug 2022
    4
    Medium

    CVE-2021-46676

    Last Modified: 2 Jun 2026

    A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the transactional maps name field.

    Published: 5 Aug 2022
    4
    Medium

    CVE-2021-46679

    Last Modified: 2 Jun 2026

    A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via service elements.

    Published: 5 Aug 2022
    4
    Medium

    CVE-2021-46681

    Last Modified: 2 Jun 2026

    A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via module massive operation name field.

    Published: 5 Aug 2022
    7.6
    High

    CVE-2022-1704

    Last Modified: 16 Apr 2025

    Due to an XML external entity reference, the software parses XML in the backup/restore functionality without XML security flags, which may lead to a XXE attack while restoring the backup.

    Published: 5 Aug 2022
    6.3
    Medium

    CVE-2022-34769

    Last Modified: 21 Nov 2024

    Michlol - rashim web interface Insecure direct object references (IDOR). First of all, the attacker needs to login. After he performs log into the system there are some functionalities that the specific user is not allowed to perform. However all the attacker needs to do in order to achieve his goals is to change the value of the ptMsl parameter and then the attacker can access sensitive data that he not supposed to access because its belong to another user.

    Published: 5 Aug 2022
    6.5
    Medium

    CVE-2022-34768

    Last Modified: 2 Jun 2026

    insert HTML / js code inside input how to get to the vulnerable input : Workers &gt; worker nickname &gt; inject in this input the code.

    Published: 5 Aug 2022
    5.5
    Medium

    CVE-2021-27798

    Last Modified: 15 Feb 2025

    A vulnerability in Brocade Fabric OS versions 7.4.1b and 7.3.1d could allow local users to conduct privileged directory transversal. Brocade Fabric OS versions 7.4.1.x and 7.3.x have reached end of life. Brocade Fabric OS Users should upgrade to supported versions as described in the Product End-of-Life published report.

    Published: 5 Aug 2022
    7.8
    High

    CVE-2022-22299

    Last Modified: 21 Nov 2024

    A format string vulnerability [CWE-134] in the command line interpreter of FortiADC version 6.0.0 through 6.0.4, FortiADC version 6.1.0 through 6.1.5, FortiADC version 6.2.0 through 6.2.1, FortiProxy version 1.0.0 through 1.0.7, FortiProxy version 1.1.0 through 1.1.6, FortiProxy version 1.2.0 through 1.2.13, FortiProxy version 2.0.0 through 2.0.7, FortiProxy version 7.0.0 through 7.0.1, FortiOS version 6.0.0 through 6.0.14, FortiOS version 6.2.0 through 6.2.10, FortiOS version 6.4.0 through 6.4.8, FortiOS version 7.0.0 through 7.0.2, FortiMail version 6.4.0 through 6.4.5, FortiMail version 7.0.0 through 7.0.2 may allow an authenticated user to execute unauthorized code or commands via specially crafted command arguments.

    Published: 5 Aug 2022
    5.4
    Medium

    CVE-2016-3098

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code.

    Published: 5 Aug 2022
    4.3
    Medium

    CVE-2020-1754

    Last Modified: 23 Jun 2026

    In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

    Published: 5 Aug 2022
    5.4
    Medium

    CVE-2020-1691

    Last Modified: 21 Nov 2024

    In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting.

    Published: 5 Aug 2022
    2.4
    Low

    CVE-2022-33720

    Last Modified: 21 Nov 2024

    Improper authentication vulnerability in AppLock prior to SMR Aug-2022 Release 1 allows physical attacker to access Chrome locked by AppLock via new tap shortcut.

    Published: 5 Aug 2022
    6.8
    Medium

    CVE-2022-33730

    Last Modified: 21 Nov 2024

    Heap-based buffer overflow vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows arbitrary code execution by physical attackers.

    Published: 5 Aug 2022
    8.6
    High

    CVE-2022-33719

    Last Modified: 21 Nov 2024

    Improper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap overflow.

    Published: 5 Aug 2022
    3.3
    Low

    CVE-2022-33724

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information in Samsung Dialer application?prior to SMR Aug-2022 Release 1 allows local attackers to access ICCID via log.

    Published: 5 Aug 2022
    7.3
    High

    CVE-2022-36833

    Last Modified: 21 Nov 2024

    Improper Privilege Management vulnerability in Game Optimizing Service prior to versions 3.3.04.0 in Android 10, and 3.5.04.8 in Android 11 and above allows local attacker to execute hidden function for developer by changing package name.

    Published: 5 Aug 2022
    3.3
    Low

    CVE-2022-33726

    Last Modified: 21 Nov 2024

    Unprotected dynamic receiver in Samsung Galaxy Friends prior to SMR Aug-2022 Release 1 allows attacker to launch activity.

    Published: 5 Aug 2022
    4
    Medium

    CVE-2022-33722

    Last Modified: 21 Nov 2024

    Implicit Intent hijacking vulnerability in Smart View prior to SMR Aug-2022 Release 1 allows attacker to access connected device MAC address.

    Published: 5 Aug 2022
    5.9
    Medium

    CVE-2022-36839

    Last Modified: 21 Nov 2024

    SQL injection vulnerability via IAPService in Samsung Checkout prior to version 5.0.53.1 allows attackers to access IAP information.

    Published: 5 Aug 2022
    4.4
    Medium

    CVE-2022-33721

    Last Modified: 21 Nov 2024

    A vulnerability using PendingIntent in DeX for PC prior to SMR Aug-2022 Release 1 allows attackers to access files with system privilege.

    Published: 5 Aug 2022
    6.2
    Medium

    CVE-2022-33732

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unprotected binder call.

    Published: 5 Aug 2022
    4
    Medium

    CVE-2022-36832

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in WebApp in Cameralyzer prior to versions 3.2.22, 3.3.22, 3.4.22 and 3.5.51 allows attackers to access external storage as Cameralyzer privilege.

    Published: 5 Aug 2022
    5.1
    Medium

    CVE-2022-33731

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in DesktopSystemUI prior to SMR Aug-2022 Release 1 allows attackers to enable and disable arbitrary components.

    Published: 5 Aug 2022
    4.5
    Medium

    CVE-2022-36840

    Last Modified: 21 Nov 2024

    DLL hijacking vulnerability in Samsung Update Setup prior to version 2.2.9.50 allows attackers to execute arbitrary code.

    Published: 5 Aug 2022
    3.3
    Low

    CVE-2022-36834

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information vulnerability in Game Launcher prior to version 6.0.07 allows local attacker to access app data with user interaction.

    Published: 5 Aug 2022
    6.2
    Medium

    CVE-2022-33714

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in SemWifiApBroadcastReceiver prior to SMR Aug-2022 Release 1 allows attacker to reset a setting value related to mobile hotspot.

    Published: 5 Aug 2022
    6.2
    Medium

    CVE-2022-33718

    Last Modified: 21 Nov 2024

    An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the list of apps that can use mobile data.

    Published: 5 Aug 2022
    5.3
    Medium

    CVE-2022-33715

    Last Modified: 21 Nov 2024

    Improper access control and path traversal vulnerability in LauncherProvider prior to SMR Aug-2022 Release 1 allow local attacker to access files of One UI.

    Published: 5 Aug 2022
    6.2
    Medium

    CVE-2022-36836

    Last Modified: 21 Nov 2024

    Unprotected provider vulnerability in Charm by Samsung prior to version 1.2.3 allows attackers to read connection state without permission.

    Published: 5 Aug 2022
    6.2
    Medium

    CVE-2022-36830

    Last Modified: 21 Nov 2024

    PendingIntent hijacking vulnerability in cancelAlarmManager in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.

    Published: 5 Aug 2022