CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2022-34839

    Last Modified: 28 Apr 2026

    Authentication Bypass vulnerability in CodexShaper's WP OAuth2 Server plugin <= 1.0.1 at WordPress.

    Published: 22 Jul 2022
    6.3
    Medium

    CVE-2022-27235

    Last Modified: 20 Feb 2025

    Multiple Broken Access Control vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.

    Published: 22 Jul 2022
    8.5
    High

    CVE-2022-33960

    Last Modified: 20 Feb 2025

    Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.

    Published: 22 Jul 2022
    5.4
    Medium

    CVE-2022-29495

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacker to update plugin settings.

    Published: 22 Jul 2022
    4.3
    Medium

    CVE-2017-20140

    Last Modified: 15 Apr 2025

    A vulnerability was found in Itech Movie Portal Script 7.36. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /movie.php. The manipulation of the argument f with the input <img src=i onerror=prompt(1)> leads to basic cross site scripting (Reflected). The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 22 Jul 2022
    6.3
    Medium

    CVE-2017-20139

    Last Modified: 15 Apr 2025

    A vulnerability was found in Itech Movie Portal Script 7.36. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /show_news.php. The manipulation of the argument id with the input AND (SELECT 1222 FROM(SELECT COUNT(*),CONCAT(0x71786b7a71,(SELECT (ELT(1222=1222,1))),0x717a627871,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a) leads to sql injection (Error). The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 22 Jul 2022
    4.3
    Medium

    CVE-2022-2510

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) vulnerability in "Extension:ExtendedSearch" of Hallo Welt! GmbH BlueSpice allows attacker to inject arbitrary HTML (XSS) on page "Special:SearchCenter", using the search term in the URL.

    Published: 22 Jul 2022
    4.3
    Medium

    CVE-2022-2511

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) vulnerability in the "commonuserinterface" component of BlueSpice allows an attacker to inject arbitrary HTML into a page using the title parameter of the call URL.

    Published: 22 Jul 2022
    7.5
    High

    CVE-2020-14114

    Last Modified: 21 Nov 2024

    information leakage vulnerability exists in the Xiaomi SmartHome APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information.

    Published: 22 Jul 2022
    7.5
    High

    CVE-2020-14126

    Last Modified: 21 Nov 2024

    Information leakage vulnerability exists in the Mi Sound APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information.

    Published: 22 Jul 2022
    4.3
    Medium

    CVE-2022-28878

    Last Modified: 21 Nov 2024

    A Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed APK file it is possible that can crash the scanning engine.

    Published: 22 Jul 2022
    4.3
    Medium

    CVE-2022-28879

    Last Modified: 21 Nov 2024

    A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the scanning the aepack.dll component can crash the scanning engine.

    Published: 22 Jul 2022
    8.1
    High

    CVE-2022-2142

    Last Modified: 16 Apr 2025

    The affected product is vulnerable to a SQL injection with high attack complexity, which may allow an unauthorized attacker to disclose information.

    Published: 22 Jul 2022
    9.8
    Critical

    CVE-2022-2143

    Last Modified: 16 Apr 2025

    The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.

    Published: 22 Jul 2022
    8.8
    High

    CVE-2022-2136

    Last Modified: 16 Apr 2025

    The affected product is vulnerable to multiple SQL injections that require low privileges for exploitation and may allow an unauthorized attacker to disclose information.

    Published: 22 Jul 2022
    7.5
    High

    CVE-2022-2135

    Last Modified: 16 Apr 2025

    The affected product is vulnerable to multiple SQL injections, which may allow an unauthorized attacker to disclose information.

    Published: 22 Jul 2022
    8.2
    High

    CVE-2022-2138

    Last Modified: 16 Apr 2025

    The affected product is vulnerable due to missing authentication, which may allow an attacker to read or modify sensitive data and execute arbitrary code, resulting in a denial-of-service condition.

    Published: 22 Jul 2022
    6.5
    Medium

    CVE-2022-2139

    Last Modified: 16 Apr 2025

    The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary code.

    Published: 22 Jul 2022
    4.9
    Medium

    CVE-2022-2137

    Last Modified: 16 Apr 2025

    The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information

    Published: 22 Jul 2022
    5.3
    Medium

    CVE-2021-36200

    Last Modified: 21 Nov 2024

    Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users.

    Published: 22 Jul 2022
    6.1
    Medium

    CVE-2022-2470

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21.

    Published: 22 Jul 2022
    9.8
    Critical

    CVE-2022-34982

    Last Modified: 21 Nov 2024

    The eziod package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party.

    Published: 22 Jul 2022
    9.8
    Critical

    CVE-2022-34983

    Last Modified: 21 Nov 2024

    The scu-captcha package in PyPI v0.0.1 to v0.0.4 included a code execution backdoor inserted by a third party.

    Published: 22 Jul 2022
    9.8
    Critical

    CVE-2022-34509

    Last Modified: 21 Nov 2024

    The wikifaces package in PyPI v1.0 included a code execution backdoor inserted by a third party.

    Published: 22 Jul 2022
    9.8
    Critical

    CVE-2022-34981

    Last Modified: 21 Nov 2024

    The PyCrowdTangle package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party.

    Published: 22 Jul 2022
    5.5
    Medium

    CVE-2022-34520

    Last Modified: 21 Nov 2024

    Radare2 v5.7.2 was discovered to contain a NULL pointer dereference via the function r_bin_file_xtr_load_buffer at bin/bfile.c. This vulnerability allows attackers to cause a Denial of Service (DOS) via a crafted binary file.

    Published: 22 Jul 2022
    5.5
    Medium

    CVE-2022-34502

    Last Modified: 21 Nov 2024

    Radare2 v5.7.0 was discovered to contain a heap buffer overflow via the function consume_encoded_name_new at format/wasm/wasm.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted binary file.

    Published: 22 Jul 2022
    9.8
    Critical

    CVE-2022-34500

    Last Modified: 21 Nov 2024

    The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

    Published: 22 Jul 2022
    9.8
    Critical

    CVE-2022-34501

    Last Modified: 21 Nov 2024

    The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

    Published: 22 Jul 2022
    5.4
    Medium

    CVE-2022-31168

    Last Modified: 23 Apr 2025

    Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could craft an API call that grants organization administrator privileges to one of their bots. The vulnerability is fixed in Zulip Server 5.5. Members who don’t own any bots, and lack permission to create them, can’t exploit the vulnerability. As a workaround for the vulnerability, an organization administrator can restrict the `Who can create bots` permission to administrators only, and change the ownership of existing bots.

    Published: 22 Jul 2022
    6.1
    Medium

    CVE-2022-36131

    Last Modified: 21 Nov 2024

    The Better PDF Exporter add-on 10.0.0 for Atlassian Jira is prone to stored XSS via a crafted description to the PDF Templates overview page.

    Published: 22 Jul 2022
    —
    Unknown

    CVE-2022-2209

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 22 Jul 2022
    4.8
    Medium

    CVE-2022-2495

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21.

    Published: 22 Jul 2022
    5.4
    Medium

    CVE-2022-2494

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.

    Published: 22 Jul 2022
    8.1
    High

    CVE-2022-2493

    Last Modified: 21 Nov 2024

    Data Access from Outside Expected Data Manager Component in GitHub repository openemr/openemr prior to 7.0.0.

    Published: 22 Jul 2022
    —
    Unknown

    CVE-2022-34846

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 22 Jul 2022
    —
    Unknown

    CVE-2022-36298

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 22 Jul 2022
    —
    Unknown

    CVE-2022-32232

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 22 Jul 2022
    7.5
    High

    CVE-2022-2327

    Last Modified: 2 Oct 2026

    io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent with the calling process when executing IORING_OP. Some operations are missing some types, which can lead to incorrect reference counts which can then lead to a double free. We recommend upgrading the kernel past commit df3f3bb5059d20ef094d6b2f0256c4bf4127a859

    Published: 22 Jul 2022
    7.5
    High

    CVE-2022-35737

    Last Modified: 13 Feb 2026

    SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.

    Published: 22 Jul 2022
    8.8
    High

    CVE-2022-1134

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 22 Jul 2022
    6.5
    Medium

    CVE-2022-34503

    Last Modified: 21 Nov 2024

    QPDF v8.4.2 was discovered to contain a heap buffer overflow via the function QPDF::processXRefStream. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

    Published: 22 Jul 2022
    8.8
    High

    CVE-2024-23321

    Last Modified: 13 Feb 2025

    For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to an unauthorized actor even if RocketMQ is enabled with authentication and authorization functions. An attacker, possessing regular user privileges or listed in the IP whitelist, could potentially acquire the administrator's account and password through specific interfaces. Such an action would grant them full control over RocketMQ, provided they have access to the broker IP address list. To mitigate these security threats, it is strongly advised that users upgrade to version 5.3.0 or newer. Additionally, we recommend users to use RocketMQ ACL 2.0 instead of the original RocketMQ ACL when upgrading to version Apache RocketMQ 5.3.0.

    Published: 22 Jul 2022
    7.5
    High

    CVE-2022-34037

    Last Modified: 21 Nov 2024

    An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service (DoS) via a crafted URI. Note: This has been disputed as a bug, not a security vulnerability, in the Caddy web server that emerged when an administrator's bad configuration containing a malformed request URI caused the server to return an empty reply instead of a valid HTTP response to the client.

    Published: 22 Jul 2022
    8.8
    High

    CVE-2022-0980

    Last Modified: 21 Nov 2024

    Use after free in New Tab Page in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific user interactions.

    Published: 21 Jul 2022
    8.8
    High

    CVE-2022-0979

    Last Modified: 21 Nov 2024

    Use after free in Safe Browsing in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

    Published: 21 Jul 2022
    8.8
    High

    CVE-2022-0978

    Last Modified: 21 Nov 2024

    Use after free in ANGLE in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 21 Jul 2022
    9.6
    Critical

    CVE-2022-0977

    Last Modified: 21 Nov 2024

    Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

    Published: 21 Jul 2022
    8.8
    High

    CVE-2022-0976

    Last Modified: 21 Nov 2024

    Heap buffer overflow in GPU in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 21 Jul 2022
    8.8
    High

    CVE-2022-0975

    Last Modified: 21 Nov 2024

    Use after free in ANGLE in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 21 Jul 2022