CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2022-35867

    Last Modified: 21 Nov 2024

    This vulnerability allows local attackers to escalate privileges on affected installations of xhyve. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the e1000 virtual device. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-15056.

    Published: 3 Aug 2022
    9.8
    Critical

    CVE-2022-35865

    Last Modified: 2 Jun 2026

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication is not required to exploit this vulnerability. The specific flaw exists within the authorization of HTTP requests. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-16709.

    Published: 3 Aug 2022
    6.5
    Medium

    CVE-2022-35864

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! 20.21.02.109. Authentication is required to exploit this vulnerability. The specific flaw exists within the GetPopupSubQueryDetails endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-16690.

    Published: 3 Aug 2022
    6.5
    Medium

    CVE-2022-34872

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of Virtual Metrics. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-16336.

    Published: 3 Aug 2022
    7.2
    High

    CVE-2022-34871

    Last Modified: 2 Jun 2026

    This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the configuration of poller resources. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-16335.

    Published: 3 Aug 2022
    9.8
    Critical

    CVE-2022-2272

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to bypass authentication on affected installations of Sante PACS Server 3.0.4. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of calls to the login endpoint. When parsing the username element, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-17331.

    Published: 3 Aug 2022
    8.8
    High

    CVE-2022-28684

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of DevExpress. Authentication is required to exploit this vulnerability. The specific flaw exists within the SafeBinaryFormatter library. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-16710.

    Published: 3 Aug 2022
    7.8
    High

    CVE-2022-28668

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro 11.9.2. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of J2K files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16679.

    Published: 3 Aug 2022
    7.5
    High

    CVE-2022-34973

    Last Modified: 3 Nov 2025

    D-Link DIR820LA1_FW106B02 was discovered to contain a buffer overflow via the nextPage parameter at ping.ccp.

    Published: 3 Aug 2022
    9.8
    Critical

    CVE-2022-35620

    Last Modified: 21 Nov 2024

    D-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the function binary.soapcgi_main.

    Published: 3 Aug 2022
    9.8
    Critical

    CVE-2022-35619

    Last Modified: 21 Nov 2024

    D-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the function ssdpcgi_main.

    Published: 3 Aug 2022
    9.8
    Critical

    CVE-2022-34974

    Last Modified: 3 Nov 2025

    D-Link DIR810LA1_FW102B22 was discovered to contain a command injection vulnerability via the Ping_addr function.

    Published: 3 Aug 2022
    4.3
    Medium

    CVE-2022-23442

    Last Modified: 21 Nov 2024

    An improper access control vulnerability [CWE-284] in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8 and 7.0.0 through 7.0.5 may allow an authenticated attacker with a restricted user profile to gather the checksum information about the other VDOMs via CLI commands.

    Published: 3 Aug 2022
    5.4
    Medium

    CVE-2022-27484

    Last Modified: 21 Nov 2024

    A unverified password change in Fortinet FortiADC version 6.2.0 through 6.2.3, 6.1.x, 6.0.x, 5.x.x allows an authenticated attacker to bypass the Old Password check in the password change form via a crafted HTTP request.

    Published: 3 Aug 2022
    5.5
    Medium

    CVE-2022-27621

    Last Modified: 14 Jan 2025

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology USB Copy before 2.2.0-1086 allows remote authenticated users to read or write arbitrary files via unspecified vectors.

    Published: 3 Aug 2022
    6.8
    Medium

    CVE-2022-27620

    Last Modified: 14 Jan 2025

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology SSO Server before 2.2.3-0331 allows remote authenticated users to read arbitrary files via unspecified vectors.

    Published: 3 Aug 2022
    6.8
    Medium

    CVE-2022-27619

    Last Modified: 21 Nov 2024

    Cleartext transmission of sensitive information vulnerability in authentication management in Synology Note Station Client before 2.2.2-609 allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.

    Published: 3 Aug 2022
    4.3
    Medium

    CVE-2022-36800

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The affected versions are before version 4.22.2.

    Published: 3 Aug 2022
    6.8
    Medium

    CVE-2022-27618

    Last Modified: 14 Jan 2025

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Storage Analyzer before 2.1.0-0390 allows remote authenticated users to delete arbitrary files via unspecified vectors.

    Published: 3 Aug 2022
    5
    Medium

    CVE-2022-27617

    Last Modified: 14 Jan 2025

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to download arbitrary files via unspecified vectors.

    Published: 3 Aug 2022
    7.2
    High

    CVE-2022-27616

    Last Modified: 14 Jan 2025

    Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 7.0.1-42218-3 allows remote authenticated users to execute arbitrary commands via unspecified vectors.

    Published: 3 Aug 2022
    7.5
    High

    CVE-2022-34968

    Last Modified: 21 Nov 2024

    An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL query.

    Published: 3 Aug 2022
    7.5
    High

    CVE-2022-34969

    Last Modified: 21 Nov 2024

    PingCAP TiDB v6.1.0 was discovered to contain a NULL pointer dereference.

    Published: 3 Aug 2022
    7.5
    High

    CVE-2022-34967

    Last Modified: 21 Nov 2024

    The assertion `stmt->Dbc->FirstStmt' failed in MonetDB Database Server v11.43.13.

    Published: 3 Aug 2022
    —
    Unknown

    CVE-2022-34943

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 3 Aug 2022
    8.8
    High

    CVE-2022-34937

    Last Modified: 21 Nov 2024

    Yuba u5cms v8.3.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component savepage.php. This vulnerability allows attackers to execute arbitrary code.

    Published: 3 Aug 2022
    8.8
    High

    CVE-2022-34928

    Last Modified: 21 Nov 2024

    JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user.

    Published: 3 Aug 2022
    7.8
    High

    CVE-2022-34927

    Last Modified: 21 Nov 2024

    MilkyTracker v1.03.00 was discovered to contain a stack overflow via the component LoaderXM::load. This vulnerability is triggered when the program is supplied a crafted XM module file.

    Published: 3 Aug 2022
    5.4
    Medium

    CVE-2022-36197

    Last Modified: 21 Nov 2024

    BigTree CMS 4.4.16 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PDF file.

    Published: 3 Aug 2022
    7.4
    High

    CVE-2022-4055

    Last Modified: 29 Apr 2025

    When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

    Published: 3 Aug 2022
    3.3
    Low

    CVE-2022-37394

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail to restart, resulting in a possible denial of service. Only Nova deployments configured with SR-IOV are affected.

    Published: 3 Aug 2022
    8.1
    High

    CVE-2022-32293

    Last Modified: 21 Nov 2024

    In ConnMan through 1.41, a man-in-the-middle attack against a WISPR HTTP query could be used to trigger a use-after-free in WISPR handling, leading to crashes or code execution.

    Published: 3 Aug 2022
    8.8
    High

    CVE-2022-36359

    Last Modified: 13 Feb 2025

    An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a FileResponse when the filename is derived from user-supplied input.

    Published: 3 Aug 2022
    7.1
    High

    CVE-2022-31197

    Last Modified: 3 Nov 2025

    PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. The PGJDBC implementation of the `java.sql.ResultRow.refreshRow()` method is not performing escaping of column names so a malicious column name that contains a statement terminator, e.g. `;`, could lead to SQL injection. This could lead to executing additional SQL commands as the application's JDBC user. User applications that do not invoke the `ResultSet.refreshRow()` method are not impacted. User application that do invoke that method are impacted if the underlying database that they are querying via their JDBC application may be under the control of an attacker. The attack requires the attacker to trick the user into executing SQL against a table name who's column names would contain the malicious SQL and subsequently invoke the `refreshRow()` method on the ResultSet. Note that the application's JDBC user and the schema owner need not be the same. A JDBC application that executes as a privileged user querying database schemas owned by potentially malicious less-privileged users would be vulnerable. In that situation it may be possible for the malicious user to craft a schema that causes the application to execute commands as the privileged user. Patched versions will be released as `42.2.26` and `42.4.1`. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 3 Aug 2022
    9.8
    Critical

    CVE-2022-32292

    Last Modified: 21 Nov 2024

    In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow in received_data to execute code.

    Published: 3 Aug 2022
    9.8
    Critical

    CVE-2022-35866

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the MySQL server. The server uses a hard-coded password for the administrator user. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-17139.

    Published: 3 Aug 2022
    5.5
    Medium

    CVE-2022-33917

    Last Modified: 21 Nov 2024

    An issue was discovered in the Arm Mali GPU Kernel Driver (Valhall r29p0 through r38p0). A non-privileged user can make improper GPU processing operations to gain access to already freed memory.

    Published: 2 Aug 2022
    4.3
    Medium

    CVE-2022-36968

    Last Modified: 21 Nov 2024

    In Progress WS_FTP Server prior to version 8.7.3, forms within the administrative interface did not include a nonce to mitigate the risk of cross-site request forgery (CSRF) attacks.

    Published: 2 Aug 2022
    6.1
    Medium

    CVE-2022-36967

    Last Modified: 21 Nov 2024

    In Progress WS_FTP Server prior to version 8.7.3, multiple reflected cross-site scripting (XSS) vulnerabilities exist in the administrative web interface. It is possible for a remote attacker to inject arbitrary JavaScript into a WS_FTP administrator's web session. This would allow the attacker to execute code within the context of the victim's browser.

    Published: 2 Aug 2022
    5.4
    Medium

    CVE-2022-34619

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in Mealie v0.5.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Shopping Lists item names text field.

    Published: 2 Aug 2022
    9.8
    Critical

    CVE-2022-29807

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow for remote code execution via download_agent_installer.php.

    Published: 2 Aug 2022
    9.8
    Critical

    CVE-2022-30285

    Last Modified: 21 Nov 2024

    In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication. This may allow authentication with invalid credentials.

    Published: 2 Aug 2022
    7.5
    High

    CVE-2022-29808

    Last Modified: 21 Nov 2024

    In Quest KACE Systems Management Appliance (SMA) through 12.0, predictable token generation occurs when appliance linking is enabled.

    Published: 2 Aug 2022
    5.3
    Medium

    CVE-2022-35925

    Last Modified: 22 Apr 2025

    BookWyrm is a social network for tracking reading. Versions prior to 0.4.5 were found to lack rate limiting on authentication views which allows brute-force attacks. This issue has been patched in version 0.4.5. Admins with existing instances will need to update their `nginx.conf` file that was created when the instance was set up. Users are advised advised to upgrade. Users unable to upgrade may update their nginx.conf files with the changes manually.

    Published: 2 Aug 2022
    7.5
    High

    CVE-2022-35923

    Last Modified: 22 Apr 2025

    v8n is a javascript validation library. Versions of v8n prior to 1.5.1 were found to have an inefficient regular expression complexity in the `lowercase()` and `uppercase()` regex which could lead to a denial of service attack. In testing of the `lowercase()` function a payload of 'a' + 'a'.repeat(i) + 'A' with 32 leading characters took 29443 ms to execute. The same issue happens with uppercase(). Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 2 Aug 2022
    7.5
    High

    CVE-2022-34924

    Last Modified: 21 Nov 2024

    Lanling OA Landray Office Automation (OA) internal patch number #133383/#137780 contains an arbitrary file read vulnerability via the component /sys/ui/extend/varkind/custom.jsp.

    Published: 2 Aug 2022
    9.1
    Critical

    CVE-2022-35924

    Last Modified: 23 Apr 2025

    NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using the `EmailProvider` either in versions before `4.10.3` or `3.29.10` are affected. If an attacker could forge a request that sent a comma-separated list of emails (eg.: `[email protected],[email protected]`) to the sign-in endpoint, NextAuth.js would send emails to both the attacker and the victim's e-mail addresses. The attacker could then login as a newly created user with the email being `[email protected],[email protected]`. This means that basic authorization like `email.endsWith("@victim.com")` in the `signIn` callback would fail to communicate a threat to the developer and would let the attacker bypass authorization, even with an `@attacker.com` address. This vulnerability has been patched in `v4.10.3` and `v3.29.10` by normalizing the email value that is sent to the sign-in endpoint before accessing it anywhere else. We also added a `normalizeIdentifier` callback on the `EmailProvider` configuration, where you can further tweak your requirements for what your system considers a valid e-mail address. (E.g.: strict RFC2821 compliance). Users are advised to upgrade. There are no known workarounds for this vulnerability. If for some reason you cannot upgrade, you can normalize the incoming request using Advanced Initialization.

    Published: 2 Aug 2022
    6.5
    Medium

    CVE-2022-30572

    Last Modified: 21 Nov 2024

    The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains an easily exploitable Directory Traversal vulnerability that allows a low privileged attacker with network access to read arbitrary resources on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO iWay Service Manager: versions 8.0.6 and below.

    Published: 2 Aug 2022
    8.1
    High

    CVE-2022-30571

    Last Modified: 21 Nov 2024

    The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected system or the victim's local system. Affected releases are TIBCO Software Inc.'s TIBCO iWay Service Manager: versions 8.0.6 and below.

    Published: 2 Aug 2022
    8.8
    High

    CVE-2022-2631

    Last Modified: 21 Nov 2024

    Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.

    Published: 2 Aug 2022