CVE Feed

    Dashboard / CVE

    8
    High

    CVE-2022-34571

    Last Modified: 21 Nov 2024

    An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the system key information and execute arbitrary commands via accessing the page syslog.shtml.

    Published: 25 Jul 2022
    5.7
    Medium

    CVE-2022-34572

    Last Modified: 21 Nov 2024

    An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the telnet password via accessing the page tftp.txt.

    Published: 25 Jul 2022
    7.5
    High

    CVE-2022-34570

    Last Modified: 21 Nov 2024

    WAVLINK WN579 X3 M79X3.V5030.191012/M79X3.V5030.191012 contains an information leak which allows attackers to obtain the key information via accessing the messages.txt page.

    Published: 25 Jul 2022
    9
    Critical

    CVE-2022-35131

    Last Modified: 21 Nov 2024

    Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.

    Published: 25 Jul 2022
    7.5
    High

    CVE-2022-34906

    Last Modified: 21 Nov 2024

    A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decrypt sensitive information saved in FileWave, and even send crafted requests.

    Published: 25 Jul 2022
    9.8
    Critical

    CVE-2022-34907

    Last Modified: 21 Nov 2024

    An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system with the highest authority possible and gain full control over the FileWave platform.

    Published: 25 Jul 2022
    7.2
    High

    CVE-2022-36375

    Last Modified: 28 Apr 2026

    Authenticated (high role user) WordPress Options Change vulnerability in Biplob Adhikari's Tabs plugin <= 3.6.0 at WordPress.

    Published: 25 Jul 2022
    8.2
    High

    CVE-2022-22999

    Last Modified: 21 Nov 2024

    Western Digital My Cloud devices are vulnerable to a cross side scripting vulnerability that can allow a malicious user with elevated privileges access to drives being backed up to construct and inject JavaScript payloads into an authenticated user's browser. As a result, it may be possible to gain control over the authenticated session, steal data, modify settings, or redirect the user to malicious websites. The scope of impact can extend to other components.

    Published: 25 Jul 2022
    7.3
    High

    CVE-2022-23000

    Last Modified: 21 Nov 2024

    The Western Digital My Cloud Web App [https://os5.mycloud.com/] uses a weak SSLContext when attempting to configure port forwarding rules. This was enabled to maintain compatibility with old or outdated home routers. By using an "SSL" context instead of "TLS" or specifying stronger validation, deprecated or insecure protocols are permitted. As a result, a local user with no privileges can exploit this vulnerability and jeopardize the integrity, confidentiality and authenticity of information transmitted. The scope of impact cannot extend to other components and no user input is required to exploit this vulnerability.

    Published: 25 Jul 2022
    7.5
    High

    CVE-2022-34966

    Last Modified: 21 Nov 2024

    OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an HTML injection vulnerability via the location parameter at http://ip_address/:port/ossn/home.

    Published: 25 Jul 2022
    7.8
    High

    CVE-2022-35873

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of ZIP files. Crafted data in a ZIP file can cause the application to execute arbitrary Python scripts. The user interface fails to provide sufficient indication of the hazard. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-16949.

    Published: 25 Jul 2022
    7.8
    High

    CVE-2022-35872

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ZIP files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-17115.

    Published: 25 Jul 2022
    7.8
    High

    CVE-2022-35871

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required to exploit this vulnerability. The specific flaw exists within the authenticateAdSso method. The issue results from the lack of authentication prior to allowing the execution of python code. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-17206.

    Published: 25 Jul 2022
    7.8
    High

    CVE-2022-35870

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within com.inductiveautomation.metro.impl. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-17265.

    Published: 25 Jul 2022
    9.8
    Critical

    CVE-2022-35869

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required to exploit this vulnerability. The specific flaw exists within com.inductiveautomation.ignition.gateway.web.pages. The issue results from the lack of proper authentication prior to access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-17211.

    Published: 25 Jul 2022
    3.5
    Low

    CVE-2022-2059

    Last Modified: 21 Nov 2024

    In Pandora FMS v7.0NG.761 and below, in the agent creation section, the alias parameter is vulnerable to a Stored Cross Site-Scripting. This vulnerability can be exploited by an attacker with administrator privileges logged in the system.

    Published: 25 Jul 2022
    3.5
    Low

    CVE-2022-2032

    Last Modified: 21 Nov 2024

    In Pandora FMS v7.0NG.761 and below, in the file manager section, the dirname parameter is vulnerable to a Stored Cross Site-Scripting. This vulnerability can be exploited by an attacker with administrator privileges logged in the system.

    Published: 25 Jul 2022
    7.2
    High

    CVE-2022-33969

    Last Modified: 20 Feb 2025

    Authenticated WordPress Options Change vulnerability in Biplob Adhikari's Flipbox plugin <= 2.6.0 at WordPress.

    Published: 25 Jul 2022
    7.5
    High

    CVE-2022-24992

    Last Modified: 21 Nov 2024

    A vulnerability in the component process.php of QR Code Generator v5.2.7 allows attackers to perform directory traversal.

    Published: 25 Jul 2022
    6.5
    Medium

    CVE-2022-35288

    Last Modified: 21 Nov 2024

    IBM Security Verify Information Queue 10.0.2 could allow a user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 230818.

    Published: 25 Jul 2022
    7.5
    High

    CVE-2022-35287

    Last Modified: 21 Nov 2024

    IBM Security Verify Information Queue 10.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 230817.

    Published: 25 Jul 2022
    8.8
    High

    CVE-2022-35285

    Last Modified: 21 Nov 2024

    IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230812.

    Published: 25 Jul 2022
    7.5
    High

    CVE-2022-35284

    Last Modified: 21 Nov 2024

    IBM Security Verify Information Queue 10.0.2 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. IBM X-Force ID: 230811.

    Published: 25 Jul 2022
    5.4
    Medium

    CVE-2022-34962

    Last Modified: 21 Nov 2024

    OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Group Timeline module.

    Published: 25 Jul 2022
    9.8
    Critical

    CVE-2022-24083

    Last Modified: 21 Nov 2024

    Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.

    Published: 25 Jul 2022
    6.1
    Medium

    CVE-2022-35653

    Last Modified: 21 Nov 2024

    A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users.

    Published: 25 Jul 2022
    6.1
    Medium

    CVE-2022-35652

    Last Modified: 21 Nov 2024

    An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can create a link that leads to a trusted website, however, when clicked, it redirects the victims to arbitrary URL/domain. Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.

    Published: 25 Jul 2022
    6.1
    Medium

    CVE-2022-35651

    Last Modified: 21 Nov 2024

    A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks.

    Published: 25 Jul 2022
    7.5
    High

    CVE-2022-35650

    Last Modified: 21 Nov 2024

    The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.

    Published: 25 Jul 2022
    9.8
    Critical

    CVE-2022-35649

    Last Modified: 21 Nov 2024

    The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

    Published: 25 Jul 2022
    4.8
    Medium

    CVE-2022-34964

    Last Modified: 21 Nov 2024

    OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the SitePages module.

    Published: 25 Jul 2022
    5.4
    Medium

    CVE-2022-34961

    Last Modified: 21 Nov 2024

    OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Users Timeline module.

    Published: 25 Jul 2022
    5
    Medium

    CVE-2021-40336

    Last Modified: 21 Nov 2024

    A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This causes a possible HTTP response splitting, which if exploited could lead an attacker to channel down harmful code into the user’s web browser, such as to steal the session cookies. Thus, an attacker who successfully makes an MSM user who has already established a session to MSM web interface clicks a forged link to the MSM web interface, e.g., the link is sent per E-Mail, could trick the user into downloading malicious software onto his computer. This issue affects: Hitachi Energy MSM V2.2 and prior versions.

    Published: 25 Jul 2022
    5
    Medium

    CVE-2021-40335

    Last Modified: 21 Nov 2024

    A vulnerability exists in the HTTP web interface where the web interface does not sufficiently verify if a well-formed, valid, consistent request was intentionally provided by the user who submitted the request. This cause a Cross Site Request Forgery (CSRF), which if exploited could lead an attacker to gain unauthorized access to the web application and perform an unwanted operation on it without the knowledge of the legitimate user. An attacker, who successfully makes an MSM user who has already established a session to MSM web interface clicks a forged link to the MSM web interface, e.g., link is sent per E-Mail, could perform harmful command on MSM through its web server interface. This issue affects: Hitachi Energy MSM V2.2 and prior versions.

    Published: 25 Jul 2022
    5.4
    Medium

    CVE-2022-34963

    Last Modified: 21 Nov 2024

    OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the News Feed module.

    Published: 25 Jul 2022
    8.5
    High

    CVE-2022-2131

    Last Modified: 21 Nov 2024

    OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file without the required security flags, allowing an attacker to perform a XML external entity injection attack.

    Published: 25 Jul 2022
    9.8
    Critical

    CVE-2020-28447

    Last Modified: 21 Nov 2024

    This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath)

    Published: 25 Jul 2022
    6.5
    Medium

    CVE-2021-23451

    Last Modified: 21 Nov 2024

    The package otp-generator before 3.0.0 are vulnerable to Insecure Randomness due to insecure generation of random one-time passwords, which may allow a brute-force attack.

    Published: 25 Jul 2022
    7.5
    High

    CVE-2021-23373

    Last Modified: 21 Nov 2024

    All versions of package set-deep-prop are vulnerable to Prototype Pollution via the main functionality.

    Published: 25 Jul 2022
    7.3
    High

    CVE-2020-28455

    Last Modified: 21 Nov 2024

    This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.

    Published: 25 Jul 2022
    9.4
    Critical

    CVE-2020-28435

    Last Modified: 21 Nov 2024

    This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.

    Published: 25 Jul 2022
    9.8
    Critical

    CVE-2020-28445

    Last Modified: 21 Nov 2024

    This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.latestVersion() function.

    Published: 25 Jul 2022
    7.3
    High

    CVE-2020-28436

    Last Modified: 21 Nov 2024

    This affects all versions of package google-cloudstorage-commands.

    Published: 25 Jul 2022
    7.3
    High

    CVE-2020-28471

    Last Modified: 21 Nov 2024

    This affects the package properties-reader before 2.2.0.

    Published: 25 Jul 2022
    8.6
    High

    CVE-2020-7678

    Last Modified: 21 Nov 2024

    This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located in line 79 in the index file "index.js".

    Published: 25 Jul 2022
    5.6
    Medium

    CVE-2021-23397

    Last Modified: 21 Nov 2024

    All versions of package @ianwalter/merge are vulnerable to Prototype Pollution via the main (merge) function. Maintainer suggests using @generates/merger instead.

    Published: 25 Jul 2022
    4.9
    Medium

    CVE-2020-7649

    Last Modified: 21 Nov 2024

    This affects the package snyk-broker before 4.73.0. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal.

    Published: 25 Jul 2022
    7.3
    High

    CVE-2020-28462

    Last Modified: 21 Nov 2024

    This affects all versions of package ion-parser. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further depending on the context.

    Published: 25 Jul 2022
    7.3
    High

    CVE-2020-28461

    Last Modified: 21 Nov 2024

    This affects the package js-ini before 1.3.0. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further depending on the context.

    Published: 25 Jul 2022
    7.3
    High

    CVE-2020-28441

    Last Modified: 21 Nov 2024

    This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This can be exploited further depending on the context.

    Published: 25 Jul 2022