CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2022-2578

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, has been found in SourceCodester Garage Management System 1.0. This issue affects some unknown processing of the file /php_action/createUser.php. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jul 2022
    6.3
    Medium

    CVE-2022-2577

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical was found in SourceCodester Garage Management System 1.0. This vulnerability affects unknown code of the file /edituser.php. The manipulation of the argument id with the input -2'%20UNION%20select%2011,user(),333,444--+ leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jul 2022
    —
    Unknown

    CVE-2016-4981

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-4982. Reason: This candidate is a duplicate of CVE-2016-4982. Notes: All CVE users should reference CVE-2016-4982 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 29 Jul 2022
    7.8
    High

    CVE-2022-33881

    Last Modified: 21 Nov 2024

    Parsing a maliciously crafted PRT file can force Autodesk AutoCAD 2023 to read beyond allocated boundaries. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 29 Jul 2022
    7.8
    High

    CVE-2022-27873

    Last Modified: 21 Nov 2024

    An attacker can force the victim’s device to perform arbitrary HTTP requests in WAN through a malicious SVG file being parsed by Autodesk Fusion 360’s document parser. The vulnerability exists in the application’s ‘Insert SVG’ procedure. An attacker can also leverage this vulnerability to obtain victim’s public IP and possibly other sensitive information.

    Published: 29 Jul 2022
    9.1
    Critical

    CVE-2022-35643

    Last Modified: 21 Nov 2024

    IBM PowerVM VIOS 3.1 could allow a remote attacker to tamper with system configuration or cause a denial of service. IBM X-Force ID: 230956.

    Published: 29 Jul 2022
    7.5
    High

    CVE-2022-2576

    Last Modified: 21 Nov 2024

    In Eclipse Californium version 2.0.0 to 2.7.2 and 3.0.0-3.5.0 a DTLS resumption handshake falls back to a DTLS full handshake on a parameter mismatch without using a HelloVerifyRequest. Especially, if used with certificate based cipher suites, that results in message amplification (DDoS other peers) and high CPU load (DoS own peer). The misbehavior occurs only with DTLS_VERIFY_PEERS_ON_RESUMPTION_THRESHOLD values larger than 0.

    Published: 29 Jul 2022
    9.4
    Critical

    CVE-2022-1277

    Last Modified: 20 May 2026

    Inavitas Solar Log product has an unauthenticated SQL Injection vulnerability.

    Published: 29 Jul 2022
    7.5
    High

    CVE-2022-24912

    Last Modified: 21 Nov 2024

    The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 are vulnerable to Timing Attack in the webhook event validator code, which does not use a constant-time comparison function to validate the webhook secret. It can allow an attacker to recover this secret as an attacker and then forge webhook events.

    Published: 29 Jul 2022
    5.7
    Medium

    CVE-2022-1799

    Last Modified: 21 Apr 2025

    Incorrect signature trust exists within Google Play services SDK play-services-basement. A debug version of Google Play services is trusted by the SDK for devices that are non-GMS. We recommend upgrading the SDK past the 2022-05-03 release.

    Published: 29 Jul 2022
    5.5
    Medium

    CVE-2022-2873

    Last Modified: 21 Nov 2024

    An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way a user triggers the I2C_SMBUS_BLOCK_DATA (with the ioctl I2C_SMBUS) with malicious input data. This flaw allows a local user to crash the system.

    Published: 29 Jul 2022
    7.8
    High

    CVE-2022-36123

    Last Modified: 21 Nov 2024

    The Linux kernel before 5.18.13 lacks a certain clear operation for the block starting symbol (.bss). This allows Xen PV guest OS users to cause a denial of service or gain privileges.

    Published: 29 Jul 2022
    7.5
    High

    CVE-2022-2509

    Last Modified: 2 Dec 2025

    A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function.

    Published: 29 Jul 2022
    6.5
    Medium

    CVE-2022-34526

    Last Modified: 21 Nov 2024

    A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted TIFF file parsed by the "tiffsplit" or "tiffcrop" utilities.

    Published: 29 Jul 2022
    9.8
    Critical

    CVE-2022-34555

    Last Modified: 21 Nov 2024

    TP-LINK TL-R473G 2.0.1 Build 220529 Rel.65574n was discovered to contain a remote code execution vulnerability which is exploited via a crafted packet.

    Published: 28 Jul 2022
    7.5
    High

    CVE-2022-36234

    Last Modified: 21 Nov 2024

    SimpleNetwork TCP Server commit 29bc615f0d9910eb2f59aa8dff1f54f0e3af4496 was discovered to contain a double free vulnerability which is exploited via crafted TCP packets.

    Published: 28 Jul 2022
    5.5
    Medium

    CVE-2022-36752

    Last Modified: 21 Nov 2024

    png2webp v1.0.4 was discovered to contain an out-of-bounds write via the function w2p. This vulnerability is exploitable via a crafted png file.

    Published: 28 Jul 2022
    5.5
    Medium

    CVE-2022-34556

    Last Modified: 21 Nov 2024

    PicoC v3.2.2 was discovered to contain a NULL pointer dereference at variable.c.

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-34557

    Last Modified: 21 Nov 2024

    Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /pages/permit/permit.php.

    Published: 28 Jul 2022
    9.8
    Critical

    CVE-2022-34558

    Last Modified: 21 Nov 2024

    WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr 2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows attackers to execute arbitrary code via a crafted dbs-client package.

    Published: 28 Jul 2022
    7.8
    High

    CVE-2021-39088

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3, 7.4, and 7.5 is vulnerable to local privilege escalation if this could be combined with other unknown vulnerabilities then privilege escalation could be performed. IBM X-Force ID: 216111.

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-2399

    Last Modified: 21 Nov 2024

    Use after free in WebGPU in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-29558

    Last Modified: 21 Nov 2024

    Realtek rtl819x-SDK before v3.6.1 allows command injection over the web interface.

    Published: 28 Jul 2022
    4.8
    Medium

    CVE-2022-34580

    Last Modified: 21 Nov 2024

    Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the address parameter at ip/school/index.php.

    Published: 28 Jul 2022
    8
    High

    CVE-2022-30287

    Last Modified: 21 Nov 2024

    Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects.

    Published: 28 Jul 2022
    10
    Critical

    CVE-2021-41556

    Last Modified: 29 May 2026

    sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel script, it is possible for the attacker to break out of the squirrel script sandbox even if all dangerous functionality such as File System functions has been disabled. An attacker might abuse this bug to target (for example) Cloud services that allow customization via SquirrelScripts, or distribute malware through video games that embed a Squirrel Engine.

    Published: 28 Jul 2022
    7.5
    High

    CVE-2022-34593

    Last Modified: 21 Nov 2024

    DPTech VPN v8.1.28.0 was discovered to contain an arbitrary file read vulnerability.

    Published: 28 Jul 2022
    7.2
    High

    CVE-2022-34578

    Last Modified: 21 Nov 2024

    Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2022-2570

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2016-7049

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2016-7029

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2016-6326

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2016-6324

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2016-6315

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2016-6314

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2016-5428

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2016-5415

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2016-5413

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2016-4458

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2016-4452

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2016-3730

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2016-3701

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2016-3700

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2016-3692

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2016-2122

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2016-2101

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2016-0786

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 28 Jul 2022
    7.5
    High

    CVE-2016-0796

    Last Modified: 21 Nov 2024

    WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and security bypass vulnerabilities because it fails to properly verify user-supplied input. An attacker may leverage these issues to hide attacks directed at a target site from behind vulnerable website or to perform otherwise restricted actions and subsequently download files with the extension mp3, mp4a, wav and ogg from anywhere the web server application has read access to the system. WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files version 1.7.6 is vulnerable; prior versions may also be affected.

    Published: 28 Jul 2022
    9.8
    Critical

    CVE-2016-4991

    Last Modified: 21 Nov 2024

    Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not properly encode all special characters, namely, semicolon and curly braces. This can be abused to achieve command execution. This problem affects nodepdf 1.3.0.

    Published: 28 Jul 2022
    7.5
    High

    CVE-2016-4427

    Last Modified: 21 Nov 2024

    In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.

    Published: 28 Jul 2022