CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2022-23101

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message.

    Published: 27 Jul 2022
    8.1
    High

    CVE-2022-35291

    Last Modified: 21 Nov 2024

    Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to perform activities with admin privileges over the network. These APIs were consumed in the SF Mobile application for Time Off, Time Sheet, EC Workflow, and Benefits. On successful exploitation, the attacker can read/write attachments. Thus, compromising the confidentiality and integrity of the application

    Published: 27 Jul 2022
    7.2
    High

    CVE-2022-33970

    Last Modified: 20 Feb 2025

    Authenticated WordPress Options Change vulnerability in Biplob018 Shortcode Addons plugin <= 3.1.2 at WordPress.

    Published: 27 Jul 2022
    5.4
    Medium

    CVE-2022-23099

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.6 allows XSS by forcing block-wise read.

    Published: 27 Jul 2022
    9.8
    Critical

    CVE-2022-23100

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).

    Published: 27 Jul 2022
    6.5
    Medium

    CVE-2022-34551

    Last Modified: 21 Nov 2024

    Sims v1.0 was discovered to allow path traversal when downloading attachments.

    Published: 27 Jul 2022
    5.4
    Medium

    CVE-2022-34550

    Last Modified: 21 Nov 2024

    Sims v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /addNotifyServlet. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the notifyInfo parameter.

    Published: 27 Jul 2022
    8.8
    High

    CVE-2022-34549

    Last Modified: 21 Nov 2024

    Sims v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /uploadServlet. This vulnerability allows attackers to escalate privileges and execute arbitrary commands via a crafted file.

    Published: 27 Jul 2022
    5.5
    Medium

    CVE-2022-34529

    Last Modified: 21 Nov 2024

    WASM3 v0.5.0 was discovered to contain a segmentation fault via the component Compile_Memory_CopyFill.

    Published: 27 Jul 2022
    8.2
    High

    CVE-2022-2313

    Last Modified: 21 Nov 2024

    A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL into the folder from where the Smart installer is being executed.

    Published: 27 Jul 2022
    10
    Critical

    CVE-2022-2310

    Last Modified: 21 Nov 2024

    An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x prior to 8.2.28, and controlled release 11.x prior to 11.2.1 allows a remote attacker to bypass authentication into the administration User Interface. This is possible because of SWG incorrectly whitelisting authentication bypass methods and using a weak crypto password. This can lead to the attacker logging into the SWG admin interface, without valid credentials, as the super user with complete control over the SWG.

    Published: 27 Jul 2022
    6.5
    Medium

    CVE-2022-27610

    Last Modified: 21 Nov 2024

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25423 allows remote authenticated users to delete arbitrary files via unspecified vectors.

    Published: 27 Jul 2022
    6.1
    Medium

    CVE-2022-36880

    Last Modified: 21 Nov 2024

    The Read Mail module in Webmin 1.995 and Usermin through 1.850 allows XSS via a crafted HTML e-mail message.

    Published: 27 Jul 2022
    4.8
    Medium

    CVE-2022-34594

    Last Modified: 21 Nov 2024

    Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component ip/school/moudel/update_subject.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit Subject text field.

    Published: 27 Jul 2022
    5.4
    Medium

    CVE-2022-34611

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in /index.php/?p=report of Online Fire Reporting System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "Contac #" text field.

    Published: 27 Jul 2022
    8.8
    High

    CVE-2022-34971

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 27 Jul 2022
    5.4
    Medium

    CVE-2022-32746

    Last Modified: 21 Nov 2024

    A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database module, resulting in a use-after-free issue. This issue is only possible when modifying certain privileged attributes, such as userAccountControl.

    Published: 27 Jul 2022
    8.1
    High

    CVE-2022-32745

    Last Modified: 21 Nov 2024

    A flaw was found in Samba. Samba AD users can cause the server to access uninitialized data with an LDAP add or modify the request, usually resulting in a segmentation fault.

    Published: 27 Jul 2022
    5.5
    Medium

    CVE-2022-1615

    Last Modified: 22 Aug 2025

    In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values.

    Published: 27 Jul 2022
    5.5
    Medium

    CVE-2022-34612

    Last Modified: 21 Nov 2024

    Rizin v0.4.0 and below was discovered to contain an integer overflow via the function get_long_object(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted binary.

    Published: 27 Jul 2022
    7.5
    High

    CVE-2022-36883

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.

    Published: 27 Jul 2022
    5.3
    Medium

    CVE-2022-36884

    Last Modified: 21 Nov 2024

    The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to use an attacker-specified Git repository.

    Published: 27 Jul 2022
    5.3
    Medium

    CVE-2022-36885

    Last Modified: 21 Nov 2024

    Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided and computed webhook signatures are equal, allowing attackers to use statistical methods to obtain a valid webhook signature.

    Published: 27 Jul 2022
    8.8
    High

    CVE-2022-2031

    Last Modified: 21 Nov 2024

    A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them to decrypt each other's tickets. A user who has been requested to change their password, can exploit this flaw to obtain and use tickets to other services.

    Published: 27 Jul 2022
    6.5
    Medium

    CVE-2022-37050

    Last Modified: 3 Nov 2025

    In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulnerability is caused by the incomplete patch of CVE-2018-20662.

    Published: 27 Jul 2022
    4.3
    Medium

    CVE-2022-32742

    Last Modified: 21 Nov 2024

    A flaw was found in Samba. Some SMB1 write requests were not correctly range-checked to ensure the client had sent enough data to fulfill the write, allowing server memory contents to be written into the file (or printer) instead of client-supplied data. The client cannot control the area of the server memory written to the file (or printer).

    Published: 27 Jul 2022
    8.8
    High

    CVE-2022-32744

    Last Modified: 21 Nov 2024

    A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.

    Published: 27 Jul 2022
    7.5
    High

    CVE-2021-33057

    Last Modified: 21 Nov 2024

    The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) for determining the device's physical location. An attacker can use qq.createMapContext to create a MapContext object, use MapContext.moveToLocation to move the center of the map to the device's location, and use MapContext.getCenterLocation to get the latitude and longitude of the current map center.

    Published: 26 Jul 2022
    7.5
    High

    CVE-2021-40180

    Last Modified: 21 Nov 2024

    In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContacts.

    Published: 26 Jul 2022
    9.1
    Critical

    CVE-2022-36129

    Last Modified: 21 Nov 2024

    HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cluster, introducing potential for future data loss or catastrophic failure. Fixed in Vault Enterprise 1.9.8, 1.10.5, and 1.11.1.

    Published: 26 Jul 2022
    7.5
    High

    CVE-2022-30276

    Last Modified: 21 Nov 2024

    The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for interfacing between Motorola Data Link Communication (MDLC) networks (potentially over a variety of serial, RF and/or Ethernet links) and TCP/IP networks. Communication with RTUs behind the gateway is done by means of the proprietary IPGW protocol (5001/TCP). This protocol does not have any authentication features, allowing any attacker capable of communicating with the port in question to invoke (a subset of) desired functionality.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-30269

    Last Modified: 21 Nov 2024

    Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation via either STS software, the C toolkit, or the ACE1000 Easy Configurator. In the case of the Easy Configurator, application images (as PLX/DAT/APP/CRC files) are uploaded via the Web UI. In case of the C toolkit, they are transferred and installed using SFTP/SSH. In each case, application images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.

    Published: 26 Jul 2022
    9.8
    Critical

    CVE-2022-30270

    Last Modified: 21 Nov 2024

    The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This interface is used for remote maintenance and for SFTP file-transfer operations that are part of engineering software functionality. Access to this interface is controlled by 5 preconfigured accounts (root, abuilder, acelogin, cappl, ace), all of which come with default credentials. Although the ACE1000 documentation mentions the root, abuilder and acelogin accounts and instructs users to change the default credentials, the cappl and ace accounts remain undocumented and thus are unlikely to have their credentials changed.

    Published: 26 Jul 2022
    9.8
    Critical

    CVE-2022-30271

    Last Modified: 21 Nov 2024

    The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to be used by default.

    Published: 26 Jul 2022
    7.2
    High

    CVE-2022-30272

    Last Modified: 21 Nov 2024

    The Motorola ACE1000 RTU through 2022-05-02 mishandles firmware integrity. It utilizes either the STS software suite or ACE1000 Easy Configurator for performing firmware updates. In case of the Easy Configurator, firmware updates are performed through access to the Web UI where file system, kernel, package, bundle, or application images can be installed. Firmware updates for the Front End Processor (FEP) module are performed via access to the SSH interface (22/TCP), where a .hex file image is transferred and a bootloader script invoked. File system, kernel, package, and bundle updates are supplied as RPM (RPM Package Manager) files while FEP updates are supplied as S-rec files. In all cases, firmware images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.

    Published: 26 Jul 2022
    9.8
    Critical

    CVE-2022-30274

    Last Modified: 21 Nov 2024

    The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio gateway by means of an embedded client. Credentials for accessing this gateway are stored after being encrypted with the Tiny Encryption Algorithm (TEA) in ECB mode using a hardcoded key. Similarly, the ACE1000 RTU can route MDLC traffic over Extended Command and Management Protocol (XCMP) and Network Layer (XNL) networks via the MDLC driver. Authentication to the XNL port is protected by TEA in ECB mode using a hardcoded key.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-1641

    Last Modified: 21 Nov 2024

    Use after free in Web UI Diagnostics in Google Chrome on Chrome OS prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interaction.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-1640

    Last Modified: 21 Nov 2024

    Use after free in Sharing in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-1639

    Last Modified: 21 Nov 2024

    Use after free in ANGLE in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-1638

    Last Modified: 21 Nov 2024

    Heap buffer overflow in V8 Internationalization in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Jul 2022
    4.3
    Medium

    CVE-2022-1637

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Web Contents in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-1636

    Last Modified: 21 Nov 2024

    Use after free in Performance APIs in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-1635

    Last Modified: 21 Nov 2024

    Use after free in Permission Prompts in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interactions.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-1634

    Last Modified: 21 Nov 2024

    Use after free in Browser UI in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who had convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific user interactions.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-1633

    Last Modified: 21 Nov 2024

    Use after free in Sharesheet in Google Chrome on Chrome OS prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interactions.

    Published: 26 Jul 2022
    9.8
    Critical

    CVE-2022-29953

    Last Modified: 21 Nov 2024

    The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, hardcoded credentials. An attacker capable of connecting to this interface can thus trivially take over its functionality.

    Published: 26 Jul 2022
    9.1
    Critical

    CVE-2022-29952

    Last Modified: 21 Nov 2024

    Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command and data protocols (60005/TCP, 60007/TCP) for communications between the monitoring controller and System 1 and/or Bently Nevada Monitor Configuration (BNMC) software. These protocols provide configuration management and historical data related functionality. Neither protocol has any authentication features, allowing any attacker capable of communicating with the ports in question to invoke (a subset of) desired functionality.

    Published: 26 Jul 2022
    6.5
    Medium

    CVE-2022-1501

    Last Modified: 21 Nov 2024

    Inappropriate implementation in iframe in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 26 Jul 2022
    6.5
    Medium

    CVE-2022-1500

    Last Modified: 21 Nov 2024

    Insufficient data validation in Dev Tools in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass content security policy via a crafted HTML page.

    Published: 26 Jul 2022
    6.3
    Medium

    CVE-2022-1499

    Last Modified: 21 Nov 2024

    Inappropriate implementation in WebAuthentication in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

    Published: 26 Jul 2022