CVE-2022-23733
Last Modified: 21 Nov 2024A stored XSS vulnerability was identified in GitHub Enterprise Server that allowed the injection of arbitrary attributes. This injection was blocked by Github's Content Security Policy (CSP). This vulnerability affected all versions of GitHub Enterprise Server prior to 3.6 and was fixed in versions 3.3.11, 3.4.6 and 3.5.3. This vulnerability was reported via the GitHub Bug Bounty program.
CVE-2022-1293
Last Modified: 21 Nov 2024The embedded neutralization of Script-Related HTML Tag, was by-passed in the case of some extra conditions.
CVE-2022-35223
Last Modified: 21 Nov 2024EasyUse MailHunter Ultimate’s cookie deserialization function has an inadequate validation vulnerability. Deserializing a cookie containing malicious payload will trigger this insecure deserialization vulnerability, allowing an unauthenticated remote attacker to execute arbitrary code, manipulate system command or interrupt service.
CVE-2022-35222
Last Modified: 21 Nov 2024HiCOS Citizen verification component has a stack-based buffer overflow vulnerability due to insufficient parameter length validation. An unauthenticated physical attacker can exploit this vulnerability to execute arbitrary code, manipulate system command or disrupt service.
CVE-2022-35221
Last Modified: 21 Nov 2024Teamplus Pro community discussion has an ‘allocation of resource without limits or throttling’ vulnerability on thread subject field. A remote attacker with general user privilege posting a thread subject with large content can cause the server to allocate too much memory, leading to missing partial post content and disrupt partial service.
CVE-2022-35220
Last Modified: 21 Nov 2024Teamplus Pro community discussion function has an ‘allocation of resource without limits or throttling’ vulnerability. A remote attacker with general user privilege posting a thread with large content can cause the receiving client device to allocate too much memory, leading to abnormal termination of this client’s Teamplus Pro application.
CVE-2022-35219
Last Modified: 21 Nov 2024The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet key parameter. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service.
CVE-2022-35218
Last Modified: 21 Nov 2024The NHI card’s web service component has a heap-based buffer overflow vulnerability due to insufficient validation for packet origin parameter length. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service.
CVE-2022-34625
Last Modified: 21 Nov 2024Mealie1.0.0beta3 was discovered to contain a Server-Side Template Injection vulnerability, which allows attackers to execute arbitrary code via a crafted Jinja2 template.
CVE-2022-34613
Last Modified: 21 Nov 2024Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file.
CVE-2022-34618
Last Modified: 21 Nov 2024A stored cross-site scripting (XSS) vulnerability in Mealie 1.0.0beta3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the recipe description text field.
CVE-2022-25867
Last Modified: 21 Nov 2024The package io.socket:socket.io-client before 2.0.1 are vulnerable to NULL Pointer Dereference when parsing a packet with with invalid payload format.
CVE-2020-28423
Last Modified: 21 Nov 2024This affects all versions of package monorepo-build.
CVE-2020-28424
Last Modified: 21 Nov 2024This affects all versions of package s3-kilatstorage.
CVE-2020-28425
Last Modified: 21 Nov 2024This affects all versions of package curljs.
CVE-2020-28433
Last Modified: 21 Nov 2024This affects all versions of package node-latex-pdf.
CVE-2020-7795
Last Modified: 21 Nov 2024The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js.
CVE-2020-28434
Last Modified: 21 Nov 2024This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.
CVE-2020-28437
Last Modified: 21 Nov 2024This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.
CVE-2020-28451
Last Modified: 21 Nov 2024This affects the package image-tiler before 2.0.2.
CVE-2020-28453
Last Modified: 21 Nov 2024This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.
CVE-2021-23385
Last Modified: 21 Nov 2024This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect functions, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \\\evil.com/path. This vulnerability is only exploitable if an alternative WSGI server other than Werkzeug is used, or the default behaviour of Werkzeug is modified using 'autocorrect_location_header=False. **Note:** Flask-Security is not maintained anymore.
CVE-2022-36426
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-36353
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-33940
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-36281
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-36291
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-35217
Last Modified: 21 Nov 2024The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A local area network attacker with general user privilege can exploit this vulnerability to execute arbitrary code, manipulate system command or disrupt service.
CVE-2022-35421
Last Modified: 21 Nov 2024Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the pname parameter at /admin/operations/packages.php.
CVE-2022-34956
Last Modified: 21 Nov 2024Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_groups.php.
CVE-2022-34953
Last Modified: 21 Nov 2024Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getOrderReport.php.
CVE-2022-35422
Last Modified: 21 Nov 2024Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the qid parameter at update.php.
CVE-2022-34954
Last Modified: 21 Nov 2024Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at invoiceprint.php.
CVE-2022-34955
Last Modified: 21 Nov 2024Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_topusers.php.
CVE-2022-34952
Last Modified: 21 Nov 2024Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edituser.php.
CVE-2022-34951
Last Modified: 21 Nov 2024Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getsalereport.php.
CVE-2022-34950
Last Modified: 21 Nov 2024Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editproduct.php.
CVE-2022-34949
Last Modified: 21 Nov 2024Pharmacy Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the email or password parameter at login.php.
CVE-2022-34948
Last Modified: 21 Nov 2024Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editbrand.php.
CVE-2022-34947
Last Modified: 21 Nov 2024Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editcategory.php.
CVE-2022-34946
Last Modified: 21 Nov 2024Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getexpproduct.php.
CVE-2022-34945
Last Modified: 21 Nov 2024Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getproductreport.php.
CVE-2022-37035
Last Modified: 4 Nov 2025An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution or Information Disclosure by sending crafted BGP packets. User interaction is not needed for exploitation.
CVE-2022-29154
Last Modified: 21 Nov 2024An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. However, the rsync client performs insufficient validation of file names. A malicious rsync server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the rsync client target directory and subdirectories (for example, overwrite the .ssh/authorized_keys file).
CVE-2022-37315
Last Modified: 25 Aug 2026graphql-go (aka GraphQL for Go) through 0.8.0 has infinite recursion in the type definition parser.
CVE-2022-35921
Last Modified: 23 Apr 2025fof/byobu is a private discussions extension for Flarum forum. Affected versions were found to not respect private discussion disablement by users. Users of Byobu should update the extension to version 1.1.7, where this has been patched. Users of Byobu with Flarum 1.0 or 1.1 should upgrade to Flarum 1.2 or later, or evaluate the impact this issue has on your forum's users and choose to disable the extension if needed. There are no workarounds for this issue.
CVE-2022-35920
Last Modified: 22 Apr 2025Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when using `app.static` if using encoded `%2F` URLs. Parent directory traversal is not impacted. Users are advised to upgrade. There is no known workaround for this issue.
CVE-2022-35922
Last Modified: 23 Apr 2025Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connections can cause an out-of-memory (OOM) process abort in a client or a server. The root cause of the issue is during dataframe parsing. Affected versions would allocate a buffer based on the declared dataframe size, which may come from an untrusted source. When `Vec::with_capacity` fails to allocate, the default Rust allocator will abort the current process, killing all threads. This affects only sync (non-Tokio) implementation. Async version also does not limit memory, but does not use `with_capacity`, so DoS can happen only when bytes for oversized dataframe or message actually got delivered by the attacker. The crashes are fixed in version 0.26.5 by imposing default dataframe size limits. Affected users are advised to update to this version. Users unable to upgrade are advised to filter websocket traffic externally or to only accept trusted traffic.
CVE-2022-35918
Last Modified: 23 Apr 2025Streamlit is a data oriented application development framework for python. Users hosting Streamlit app(s) that use custom components are vulnerable to a directory traversal attack that could leak data from their web server file-system such as: server logs, world readable files, and potentially other sensitive information. An attacker can craft a malicious URL with file paths and the streamlit server would process that URL and return the contents of that file. This issue has been resolved in version 1.11.1. Users are advised to upgrade. There are no known workarounds for this issue.
CVE-2022-35917
Last Modified: 23 Apr 2025Solana Pay is a protocol and set of reference implementations that enable developers to incorporate decentralized payments into their apps and services. When a Solana Pay transaction is located using a reference key, it may be checked to represent a transfer of the desired amount to the recipient, using the supplied `validateTransfer` function. An edge case regarding this mechanism could cause the validation logic to validate multiple transfers. This issue has been patched as of version `0.2.1`. Users of the Solana Pay SDK should upgrade to it. There are no known workarounds for this issue.
