CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2022-34539

    Last Modified: 21 Nov 2024

    Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/curltest.cgi. This vulnerability is exploitable via a crafted POST request.

    Published: 19 Jul 2022
    8.8
    High

    CVE-2022-34540

    Last Modified: 21 Nov 2024

    Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/license/license_tok.cgi. This vulnerability is exploitable via a crafted POST request.

    Published: 19 Jul 2022
    8.8
    High

    CVE-2022-34538

    Last Modified: 21 Nov 2024

    Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/bia/addacph.cgi. This vulnerability is exploitable via a crafted POST request.

    Published: 19 Jul 2022
    5.4
    Medium

    CVE-2022-34537

    Last Modified: 21 Nov 2024

    Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a cross-site scripting (XSS) vulnerability via the component bia_oneshot.cgi.

    Published: 19 Jul 2022
    7.5
    High

    CVE-2022-34536

    Last Modified: 21 Nov 2024

    Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows attackers to access the core log file and perform session hijacking via a crafted session token.

    Published: 19 Jul 2022
    7.5
    High

    CVE-2022-34535

    Last Modified: 21 Nov 2024

    Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows unauthenticated attackers to view internal paths and scripts via web files.

    Published: 19 Jul 2022
    7.5
    High

    CVE-2022-34534

    Last Modified: 21 Nov 2024

    Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.

    Published: 19 Jul 2022
    6.1
    Medium

    CVE-2022-36305

    Last Modified: 21 Nov 2024

    Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1/upload/UploadHandler.php.

    Published: 19 Jul 2022
    6.1
    Medium

    CVE-2022-36304

    Last Modified: 21 Nov 2024

    Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function at /web/api/v1/upload/UploadHandler.php.

    Published: 19 Jul 2022
    6.1
    Medium

    CVE-2022-36303

    Last Modified: 21 Nov 2024

    Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function at /web/api/v1/upload/UploadHandler.php.

    Published: 19 Jul 2022
    6.1
    Medium

    CVE-2022-34025

    Last Modified: 21 Nov 2024

    Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the post function at /web/api/v1/upload/UploadHandler.php.

    Published: 19 Jul 2022
    6.5
    Medium

    CVE-2022-30570

    Last Modified: 21 Nov 2024

    The Column Based Security component of TIBCO Software Inc.'s TIBCO Data Virtualization and TIBCO Data Virtualization for AWS Marketplace contains an easily exploitable vulnerability that allows a low privileged attacker with network access to obtain read access to application information on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Data Virtualization: versions 8.5.2 and below and TIBCO Data Virtualization for AWS Marketplace: versions 8.5.2 and below.

    Published: 19 Jul 2022
    4.1
    Medium

    CVE-2022-2394

    Last Modified: 21 Nov 2024

    Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, such as via Puppet Enterprise.

    Published: 19 Jul 2022
    8.8
    High

    CVE-2022-27373

    Last Modified: 21 Nov 2024

    Shanghai Feixun Data Communication Technology Co., Ltd router fir302b A2 was discovered to contain a remote command execution (RCE) vulnerability via the Ping function.

    Published: 19 Jul 2022
    7.2
    High

    CVE-2022-34024

    Last Modified: 21 Nov 2024

    Barangay Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the resident module editing function at /bmis/pages/resident/resident.php.

    Published: 19 Jul 2022
    9.8
    Critical

    CVE-2022-34023

    Last Modified: 21 Nov 2024

    Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /officials/officials.php.

    Published: 19 Jul 2022
    5.4
    Medium

    CVE-2022-22417

    Last Modified: 21 Nov 2024

    IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 223127.

    Published: 19 Jul 2022
    5.4
    Medium

    CVE-2022-22416

    Last Modified: 21 Nov 2024

    IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 223126.

    Published: 19 Jul 2022
    8.8
    High

    CVE-2022-22360

    Last Modified: 21 Nov 2024

    IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 220782.

    Published: 19 Jul 2022
    6.5
    Medium

    CVE-2022-22359

    Last Modified: 21 Nov 2024

    IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 220652.

    Published: 19 Jul 2022
    7.1
    High

    CVE-2022-22358

    Last Modified: 21 Nov 2024

    IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 220651.

    Published: 19 Jul 2022
    6.5
    Medium

    CVE-2022-34001

    Last Modified: 21 Nov 2024

    Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously.

    Published: 19 Jul 2022
    9.8
    Critical

    CVE-2022-35912

    Last Modified: 21 Nov 2024

    In grails-databinding in Grails before 3.3.15, 4.x before 4.1.1, 5.x before 5.1.9, and 5.2.x before 5.2.1 (at least when certain Java 8 configurations are used), data binding allows a remote attacker to execute code by gaining access to the class loader.

    Published: 19 Jul 2022
    7.8
    High

    CVE-2022-27580

    Last Modified: 21 Nov 2024

    A deserialization vulnerability in a .NET framework class used and not properly checked by Safety Designer all versions up to and including 1.11.0 allows an attacker to craft malicious project files. Opening/importing such a malicious project file would execute arbitrary code with the privileges of the current user when opened or imported by the Safety Designer. This compromises confidentiality integrity and availability. For the attack to succeed a user must manually open a malicious project file.

    Published: 19 Jul 2022
    7.8
    High

    CVE-2022-27579

    Last Modified: 21 Nov 2024

    A deserialization vulnerability in a .NET framework class used and not properly checked by Flexi Soft Designer in all versions up to and including 1.9.4 SP1 allows an attacker to craft malicious project files. Opening/importing such a malicious project file would execute arbitrary code with the privileges of the current user when opened or imported by the Flexi Soft Designer. This compromises confidentiality integrity and availability. For the attack to succeed a user must manually open a malicious project file.

    Published: 19 Jul 2022
    4.6
    Medium

    CVE-2022-27545

    Last Modified: 21 Nov 2024

    BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.

    Published: 19 Jul 2022
    5
    Medium

    CVE-2022-27544

    Last Modified: 21 Nov 2024

    BigFix Web Reports authorized users may see SMTP credentials in clear text.

    Published: 19 Jul 2022
    9.8
    Critical

    CVE-2022-35405

    Last Modified: 31 Oct 2025

    Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)

    Published: 19 Jul 2022
    5.3
    Medium

    CVE-2021-32504

    Last Modified: 21 Nov 2024

    Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only. A malicious attacker could use this sensitive information’s to launch further attacks on the system.

    Published: 19 Jul 2022
    7.5
    High

    CVE-2022-2193

    Last Modified: 21 Nov 2024

    Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 authenticator to arbitrary accounts via parameter tampering in the Device Manager page. This issue affects: HYPR Server versions prior to 6.14.1.

    Published: 19 Jul 2022
    4.5
    Medium

    CVE-2022-1984

    Last Modified: 21 Nov 2024

    This issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before version 7.2 may allow local authenticated attackers to elevate privileges via a malicious serialized payload.

    Published: 19 Jul 2022
    7.5
    High

    CVE-2022-2192

    Last Modified: 21 Nov 2024

    Forced Browsing vulnerability in HYPR Server version 6.10 to 6.15.1 allows remote attackers with a valid one-time recovery token to elevate privileges via path tampering in the Magic Link page. This issue affects: HYPR Server versions later than 6.10; version 6.15.1 and prior versions.

    Published: 19 Jul 2022
    7.8
    High

    CVE-2022-2453

    Last Modified: 21 Nov 2024

    Use After Free in GitHub repository gpac/gpac prior to 2.1-DEV.

    Published: 19 Jul 2022
    6.3
    Medium

    CVE-2022-2468

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Garage Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /editbrand.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 19 Jul 2022
    7.3
    High

    CVE-2022-2467

    Last Modified: 14 Apr 2025

    A vulnerability has been found in SourceCodester Garage Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument username with the input [email protected]' AND (SELECT 6427 FROM (SELECT(SLEEP(5)))LwLu) AND 'hsvT'='hsvT leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 19 Jul 2022
    5.3
    Medium

    CVE-2022-30532

    Last Modified: 21 Nov 2024

    In affected versions of Octopus Deploy, there is no logging of changes to artifacts within Octopus Deploy.

    Published: 19 Jul 2022
    6.5
    Medium

    CVE-2022-2030

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability caused by specific character sequences within an improperly sanitized URL was identified in some CGI programs of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware versions 4.50 through 5.30, USG FLEX 700 firmware versions 4.50 through 5.30, USG FLEX 50(W) firmware versions 4.16 through 5.30, USG20(W)-VPN firmware versions 4.16 through 5.30, ATP series firmware versions 4.32 through 5.30, VPN series firmware versions 4.30 through 5.30, USG/ZyWALL series firmware versions 4.11 through 4.72, that could allow an authenticated attacker to access some restricted files on a vulnerable device.

    Published: 19 Jul 2022
    7.8
    High

    CVE-2022-30526

    Last Modified: 21 Nov 2024

    A privilege escalation vulnerability was identified in the CLI command of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware versions 4.50 through 5.30, USG FLEX 700 firmware versions 4.50 through 5.30, USG FLEX 50(W) firmware versions 4.16 through 5.30, USG20(W)-VPN firmware versions 4.16 through 5.30, ATP series firmware versions 4.32 through 5.30, VPN series firmware versions 4.30 through 5.30, USG/ZyWALL series firmware versions 4.09 through 4.72, which could allow a local attacker to execute some OS commands with root privileges in some directories on a vulnerable device.

    Published: 19 Jul 2022
    7.5
    High

    CVE-2022-34169

    Last Modified: 20 May 2025

    The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.

    Published: 19 Jul 2022
    4.9
    Medium

    CVE-2022-21553

    Last Modified: 21 Nov 2024

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

    Published: 19 Jul 2022
    7
    High

    CVE-2022-31144

    Last Modified: 23 Apr 2025

    Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch prior to 7.0.4. The patch is released in version 7.0.4.

    Published: 19 Jul 2022
    5.3
    Medium

    CVE-2022-31150

    Last Modified: 22 Apr 2025

    undici is an HTTP/1.1 client, written from scratch for Node.js. It is possible to inject CRLF sequences into request headers in undici in versions less than 5.7.1. A fix was released in version 5.8.0. Sanitizing all HTTP headers from untrusted sources to eliminate `\r\n` is a workaround for this issue.

    Published: 19 Jul 2022
    4.9
    Medium

    CVE-2022-21455

    Last Modified: 21 Nov 2024

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PAM Auth Plugin). Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Server accessible data. CVSS 3.1 Base Score 4.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N).

    Published: 19 Jul 2022
    6.7
    Medium

    CVE-2022-21505

    Last Modified: 18 Jun 2025

    In the linux kernel, if IMA appraisal is used with the "ima_appraise=log" boot param, lockdown can be defeated with kexec on any machine when Secure Boot is disabled or unavailable. IMA prevents setting "ima_appraise=log" from the boot param when Secure Boot is enabled, but this does not cover cases where lockdown is used without Secure Boot. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity, Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

    Published: 19 Jul 2022
    4.9
    Medium

    CVE-2022-21515

    Last Modified: 21 Nov 2024

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 5.7.38 and prior and 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

    Published: 19 Jul 2022
    4.9
    Medium

    CVE-2022-21517

    Last Modified: 21 Nov 2024

    Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

    Published: 19 Jul 2022
    4.4
    Medium

    CVE-2022-21522

    Last Modified: 21 Nov 2024

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 8.0.29 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

    Published: 19 Jul 2022
    4.9
    Medium

    CVE-2022-21526

    Last Modified: 21 Nov 2024

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

    Published: 19 Jul 2022
    4.9
    Medium

    CVE-2022-21530

    Last Modified: 21 Nov 2024

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

    Published: 19 Jul 2022
    4.9
    Medium

    CVE-2022-21537

    Last Modified: 21 Nov 2024

    Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

    Published: 19 Jul 2022