CVE Feed

    Dashboard / CVE

    5.7
    Medium

    CVE-2022-30625

    Last Modified: 21 Nov 2024

    Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. A directory listing provides an attacker with the complete index of all the resources located inside of the directory. The specific risks and consequences vary depending on which files are listed and accessible.

    Published: 18 Jul 2022
    6.3
    Medium

    CVE-2022-30626

    Last Modified: 21 Nov 2024

    Browsing the path: http://ip/wifi_ap_pata_get.cmd, will show in the name of the existing access point on the component, and a password in clear text.

    Published: 18 Jul 2022
    6.8
    Medium

    CVE-2022-30624

    Last Modified: 21 Nov 2024

    Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password.

    Published: 18 Jul 2022
    5.7
    Medium

    CVE-2022-30627

    Last Modified: 21 Nov 2024

    This vulnerability affects all of the company's products that also include the FW versions: update_i90_cv2.021_b20210104, update_i50_v1.0.55_b20200509, update_x6_v2.1.2_b202001127, update_b5_v2.0.9_b20200706. This vulnerability makes it possible to extract from the FW the existing user passwords on their operating systems and passwords.

    Published: 18 Jul 2022
    7.6
    High

    CVE-2022-30621

    Last Modified: 21 Nov 2024

    Allows a remote user to read files on the camera's OS "GetFileContent.cgi". Reading arbitrary files on the camera's OS as root user.

    Published: 18 Jul 2022
    8.2
    High

    CVE-2022-30620

    Last Modified: 21 Nov 2024

    On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" privileges by changing the following cookie values from "is_admin", "showConfig". Administrative Privileges which allows changing various configuration in the camera.

    Published: 18 Jul 2022
    5.4
    Medium

    CVE-2022-24692

    Last Modified: 21 Nov 2024

    An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The new menu option within the general Parameters page is vulnerable to stored XSS. The attacker can create a menu option, make it visible to every application user, and conduct session hijacking, account takeover, or malicious code delivery, with the final goal of achieving client-side code execution.

    Published: 18 Jul 2022
    7.1
    High

    CVE-2022-24691

    Last Modified: 21 Nov 2024

    An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A SQL Injection vulnerability allows authenticated users to taint database data and extract sensitive information via crafted HTTP requests. The type of SQL Injection is blind boolean based.

    Published: 18 Jul 2022
    8.2
    High

    CVE-2022-24690

    Last Modified: 21 Nov 2024

    An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A PresAbs.php SQL Injection vulnerability allows unauthenticated users to taint database data and extract sensitive information via crafted HTTP requests. The type of SQL Injection is blind boolean based. (An unauthenticated attacker can discover the endpoint by abusing a Broken Access Control issue with further SQL injection attacks to gather all user's badge numbers and PIN codes.)

    Published: 18 Jul 2022
    5.3
    Medium

    CVE-2022-24689

    Last Modified: 21 Nov 2024

    An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. It mishandles access control. This allows a remote attacker to access account information pages (including personal data) without being authenticated. The collected information includes the badge numbers that operate as user login names. They have a PIN code. The PIN code is 4 digits and thus can be guessed in 10000 brute force attempts.

    Published: 18 Jul 2022
    8.8
    High

    CVE-2022-24688

    Last Modified: 21 Nov 2024

    An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The Touch settings allow unrestricted file upload (and consequently Remote Code Execution) via PDF upload with PHP content and a .php extension. The attacker must hijack or obtain privileged user access to the Parameters page in order to exploit this issue. (That can be easily achieved by exploiting the Broken Access Control with further Brute-force attack or SQL Injection.) The uploaded file is stored within the database and copied to the sync web folder if the attacker visits a certain .php?action= page.

    Published: 18 Jul 2022
    8.2
    High

    CVE-2022-35404

    Last Modified: 21 Nov 2024

    ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a server machine.

    Published: 18 Jul 2022
    7.1
    High

    CVE-2022-32450

    Last Modified: 21 Nov 2024

    AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM when writing chat-room data there.

    Published: 18 Jul 2022
    7.5
    High

    CVE-2022-36127

    Last Modified: 10 Dec 2025

    A vulnerability in Apache SkyWalking NodeJS Agent prior to 0.5.1. The vulnerability will cause NodeJS services that has this agent installed to be unavailable if the OAP is unhealthy and NodeJS agent can't establish the connection.

    Published: 18 Jul 2022
    6.3
    Medium

    CVE-2016-15003

    Last Modified: 15 Apr 2025

    A vulnerability has been found in FileZilla Client 3.17.0.0 and classified as problematic. This vulnerability affects unknown code of the file C:\Program Files\FileZilla FTP Client\uninstall.exe of the component Installer. The manipulation leads to unquoted search path. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 18 Jul 2022
    7.2
    High

    CVE-2022-1565

    Last Modified: 8 Apr 2026

    The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. This makes it possible for authenticated attackers, with administrator level permissions and above, to upload arbitrary files on the affected sites server which may make remote code execution possible.

    Published: 18 Jul 2022
    7.5
    High

    CVE-2022-2255

    Last Modified: 21 Nov 2024

    A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.

    Published: 18 Jul 2022
    5.3
    Medium

    CVE-2022-2400

    Last Modified: 21 Nov 2024

    External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0.

    Published: 18 Jul 2022
    3.8
    Low

    CVE-2022-2469

    Last Modified: 21 Nov 2024

    GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client

    Published: 18 Jul 2022
    8.2
    High

    CVE-2022-2458

    Last Modified: 21 Nov 2024

    XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with an application's processing of XML data. This attack occurs when XML input containing a reference to an external entity is processed by a weakly configured XML parser. The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. Here, XML external entity injection lead to External Service interaction & Internal file read in Business Central and also Kie-Server APIs.

    Published: 18 Jul 2022
    8.8
    High

    CVE-2022-33891

    Last Modified: 23 Oct 2025

    The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A malicious user might then be able to reach a permission check function that will ultimately build a Unix shell command based on their input, and execute it. This will result in arbitrary shell command execution as the user Spark is currently running as. This affects Apache Spark versions 3.0.3 and earlier, versions 3.1.1 to 3.1.2, and versions 3.2.0 to 3.2.1.

    Published: 18 Jul 2022
    8.8
    High

    CVE-2022-26117

    Last Modified: 21 Nov 2024

    An empty password in configuration file vulnerability [CWE-258] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.3 and below may allow an authenticated attacker to access the MySQL databases via the CLI.

    Published: 18 Jul 2022
    9.8
    Critical

    CVE-2022-2457

    Last Modified: 24 Sept 2025

    A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as the application does not limit the number of unsuccessful login attempts.

    Published: 18 Jul 2022
    9.8
    Critical

    CVE-2022-27434

    Last Modified: 21 Nov 2024

    UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in the errorReporting page.

    Published: 17 Jul 2022
    7.8
    High

    CVE-2021-44954

    Last Modified: 21 Nov 2024

    In QVIS NVR DVR before 2021-12-13, an attacker can escalate privileges from a qvisdvr user to the root user by abusing a Sudo misconfiguration.

    Published: 17 Jul 2022
    7.3
    High

    CVE-2021-42923

    Last Modified: 21 Nov 2024

    ShowMyPC 3606 on Windows suffers from a DLL hijack vulnerability. If an attacker overwrites the file %temp%\ShowMyPC\-ShowMyPC3606\wodVPN.dll, it will run any malicious code contained in that file. The code will run with normal user privileges unless the user specifically runs ShowMyPC as administrator.

    Published: 17 Jul 2022
    9.8
    Critical

    CVE-2021-41419

    Last Modified: 21 Nov 2024

    QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.

    Published: 17 Jul 2022
    9.8
    Critical

    CVE-2021-40874

    Last Modified: 21 Nov 2024

    An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with the Combination authentication plug-in, any password will be recognized as valid for an existing user.

    Published: 17 Jul 2022
    5.5
    Medium

    CVE-2020-23563

    Last Modified: 21 Nov 2024

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000002cba.

    Published: 17 Jul 2022
    5.5
    Medium

    CVE-2020-23562

    Last Modified: 21 Nov 2024

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000000aefe.

    Published: 17 Jul 2022
    5.5
    Medium

    CVE-2020-23561

    Last Modified: 21 Nov 2024

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000005722.

    Published: 17 Jul 2022
    5.4
    Medium

    CVE-2022-31201

    Last Modified: 21 Nov 2024

    SoftGuard Web (SGW) before 5.1.5 allows HTML injection.

    Published: 17 Jul 2022
    7.5
    High

    CVE-2021-40150

    Last Modified: 21 Nov 2024

    The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. In this way an attacker can download the entire NGINX/FastCGI configurations by querying the /conf/nginx.conf or /conf/fastcgi.conf URI.

    Published: 17 Jul 2022
    9.8
    Critical

    CVE-2022-32985

    Last Modified: 21 Nov 2024

    libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on port 50200 or 50201.

    Published: 17 Jul 2022
    9.8
    Critical

    CVE-2022-31211

    Last Modified: 21 Nov 2024

    An issue was discovered in Infiray IRAY-A8Z3 1.0.957. There is a blank root password for TELNET by default.

    Published: 17 Jul 2022
    9.8
    Critical

    CVE-2022-31210

    Last Modified: 21 Nov 2024

    An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The binary file /usr/local/sbin/webproject/set_param.cgi contains hardcoded credentials to the web application. Because these accounts cannot be deactivated or have their passwords changed, they are considered to be backdoor accounts.

    Published: 17 Jul 2022
    9.8
    Critical

    CVE-2022-31209

    Last Modified: 21 Nov 2024

    An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The firmware contains a potential buffer overflow by calling strcpy() without checking the string length beforehand.

    Published: 17 Jul 2022
    8.8
    High

    CVE-2022-31208

    Last Modified: 21 Nov 2024

    An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The webserver contains an endpoint that can execute arbitrary commands by manipulating the cmd_string URL parameter.

    Published: 17 Jul 2022
    6.5
    Medium

    CVE-2022-31202

    Last Modified: 21 Nov 2024

    The export function in SoftGuard Web (SGW) before 5.1.5 allows directory traversal to read an arbitrary local file via export or man.tcl.

    Published: 17 Jul 2022
    5.4
    Medium

    CVE-2022-30982

    Last Modified: 21 Nov 2024

    An issue was discovered in Gentics CMS before 5.43.1. There is stored XSS in the profile description and in the username.

    Published: 17 Jul 2022
    8.8
    High

    CVE-2022-30981

    Last Modified: 21 Nov 2024

    An issue was discovered in Gentics CMS before 5.43.1. By uploading a malicious ZIP file, an attacker is able to deserialize arbitrary data and hence can potentially achieve Java code execution.

    Published: 17 Jul 2022
    7.8
    High

    CVE-2022-28809

    Last Modified: 21 Nov 2024

    An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading a DWG file with an invalid vertex number in a recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 17 Jul 2022
    7.8
    High

    CVE-2022-28808

    Last Modified: 21 Nov 2024

    An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading DWG files in a recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 17 Jul 2022
    7.8
    High

    CVE-2022-28807

    Last Modified: 21 Nov 2024

    An issue was discovered in Open Design Alliance Drawings SDK before 2023.2. An Out-of-Bounds Read vulnerability exists when rendering a .dwg file after it's opened in the recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 17 Jul 2022
    8.8
    High

    CVE-2022-26481

    Last Modified: 21 Nov 2024

    An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) action.

    Published: 17 Jul 2022
    7.2
    High

    CVE-2022-26482

    Last Modified: 21 Nov 2024

    An issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an admin.

    Published: 17 Jul 2022
    9.8
    Critical

    CVE-2022-26479

    Last Modified: 21 Nov 2024

    An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created via an rsync backdoor) causes all API calls to execute as admin without authentication.

    Published: 17 Jul 2022
    9.8
    Critical

    CVE-2022-26352

    Last Modified: 3 Nov 2025

    An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage location. If anonymous content creation is enabled, this allows an unauthenticated attacker to upload an executable file, such as a .jsp file, that can lead to remote code execution.

    Published: 17 Jul 2022
    5.9
    Medium

    CVE-2021-40149

    Last Modified: 21 Nov 2024

    The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the /self.key URI.

    Published: 17 Jul 2022
    7.5
    High

    CVE-2022-32263

    Last Modified: 21 Nov 2024

    Pexip Infinity before 28.1 allows remote attackers to trigger a software abort via G.719.

    Published: 17 Jul 2022