CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-34226

    Last Modified: 23 Apr 2025

    Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jul 2022
    7.8
    High

    CVE-2022-34225

    Last Modified: 23 Apr 2025

    Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jul 2022
    7.8
    High

    CVE-2022-34222

    Last Modified: 23 Apr 2025

    Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jul 2022
    7.8
    High

    CVE-2022-34223

    Last Modified: 23 Apr 2025

    Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jul 2022
    7.8
    High

    CVE-2022-34219

    Last Modified: 27 May 2026

    Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jul 2022
    7.8
    High

    CVE-2022-34217

    Last Modified: 23 Apr 2025

    Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by an Out-Of-Bounds Write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jul 2022
    7.8
    High

    CVE-2022-34220

    Last Modified: 27 May 2026

    Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jul 2022
    7.8
    High

    CVE-2022-34221

    Last Modified: 27 May 2026

    Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jul 2022
    7.8
    High

    CVE-2022-34215

    Last Modified: 23 Apr 2025

    Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jul 2022
    7.8
    High

    CVE-2022-34216

    Last Modified: 27 May 2026

    Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jul 2022
    7.5
    High

    CVE-2022-23141

    Last Modified: 21 Nov 2024

    ZXMP M721 has an information leak vulnerability. Since the serial port authentication on the ZBOOT interface is not effective although it is enabled, an attacker could use this vulnerability to log in to the device to obtain sensitive information.

    Published: 15 Jul 2022
    —
    Unknown

    CVE-2022-2445

    Last Modified: 7 Nov 2023

    Incorrectly assigned CVE. Not a valid issue.

    Published: 15 Jul 2022
    6.1
    Medium

    CVE-2020-35305

    Last Modified: 21 Nov 2024

    Cross site scripting (XSS) in gollum 5.0 to 5.1.2 via the filename parameter to the 'New Page' dialog.

    Published: 15 Jul 2022
    6.5
    Medium

    CVE-2022-30245

    Last Modified: 21 Nov 2024

    Honeywell Alerton Compass Software 1.6.5 allows unauthenticated configuration changes from remote users. This enables configuration data to be stored on the controller and then implemented. A user with malicious intent can send a crafted packet to change the controller configuration without the knowledge of other users, altering the controller's function capabilities. The changed configuration is not updated in the User Interface, which creates an inconsistency between the configuration display and the actual configuration on the controller. After the configuration change, remediation requires reverting to the correct configuration, requiring either physical or remote access depending on the configuration that was altered.

    Published: 15 Jul 2022
    8
    High

    CVE-2022-30244

    Last Modified: 21 Nov 2024

    Honeywell Alerton Ascent Control Module (ACM) through 2022-05-04 allows unauthenticated programming writes from remote users. This enables code to be store on the controller and then run without verification. A user with malicious intent can send a crafted packet to change and/or stop the program without the knowledge of other users, altering the controller's function. After the programming change, the program needs to be overwritten in order for the controller to restore its original operational function.

    Published: 15 Jul 2022
    8.8
    High

    CVE-2022-30243

    Last Modified: 21 Nov 2024

    Honeywell Alerton Visual Logic through 2022-05-04 allows unauthenticated programming writes from remote users. This enables code to be stored on the controller and then run without verification. A user with malicious intent can send a crafted packet to change and/or stop the program without the knowledge of other users, altering the controller's function. After the programming change, the program needs to be overwritten in order for the controller to restore its original operational function.

    Published: 15 Jul 2022
    6.8
    Medium

    CVE-2022-30242

    Last Modified: 21 Nov 2024

    Honeywell Alerton Ascent Control Module (ACM) through 2022-05-04 allows unauthenticated configuration changes from remote users. This enables configuration data to be stored on the controller and then implemented. A user with malicious intent can send a crafted packet to change the controller configuration without the knowledge of other users, altering the controller's function capabilities. The changed configuration is not updated in the User Interface, which creates an inconsistency between the configuration display and the actual configuration on the controller. After the configuration change, remediation requires reverting to the correct configuration, requiring either physical or remote access depending on the configuration that was altered.

    Published: 15 Jul 2022
    8.8
    High

    CVE-2021-36461

    Last Modified: 21 Nov 2024

    An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini.

    Published: 15 Jul 2022
    5.9
    Medium

    CVE-2022-34826

    Last Modified: 21 Nov 2024

    In Couchbase Server 7.1.x before 7.1.1, an encrypted Private Key passphrase may be leaked in the logs.

    Published: 15 Jul 2022
    5.4
    Medium

    CVE-2020-35261

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Restaurant Name field to /dashboard/profile.php.

    Published: 15 Jul 2022
    5.4
    Medium

    CVE-2020-36550

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Table Name field to /dashboard/table-list.php.

    Published: 15 Jul 2022
    5.4
    Medium

    CVE-2020-36551

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Item Name field to /dashboard/menu-list.php.

    Published: 15 Jul 2022
    5.4
    Medium

    CVE-2020-36552

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Made field to /dashboard/menu-list.php.

    Published: 15 Jul 2022
    5.4
    Medium

    CVE-2020-36553

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Area(food_type) field to /dashboard/menu-list.php.

    Published: 15 Jul 2022
    6.1
    Medium

    CVE-2022-32118

    Last Modified: 21 Nov 2024

    Arox School ERP Pro v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the dispatchcategory parameter in backoffice.inc.php.

    Published: 15 Jul 2022
    8.8
    High

    CVE-2022-32119

    Last Modified: 21 Nov 2024

    Arox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo function at photogalleries.inc.php and the import staff excel function at 1finance_master.inc.php.

    Published: 15 Jul 2022
    6.1
    Medium

    CVE-2022-29890

    Last Modified: 21 Nov 2024

    In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link.

    Published: 15 Jul 2022
    5.3
    Medium

    CVE-2022-1881

    Last Modified: 21 Nov 2024

    In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for a user to download Project Exports from a Project they do not have permissions to access. This vulnerability only impacts projects within the same Space.

    Published: 15 Jul 2022
    8
    High

    CVE-2022-2420

    Last Modified: 15 Apr 2025

    A vulnerability was found in URVE Web Manager. It has been rated as critical. This issue affects some unknown processing of the file _internal/uploader.php. The manipulation leads to unrestricted upload. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be used.

    Published: 15 Jul 2022
    8
    High

    CVE-2022-2419

    Last Modified: 15 Apr 2025

    A vulnerability was found in URVE Web Manager. It has been declared as critical. This vulnerability affects unknown code of the file _internal/collector/upload.php. The manipulation leads to unrestricted upload. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the public and may be used.

    Published: 15 Jul 2022
    8
    High

    CVE-2022-2418

    Last Modified: 15 Apr 2025

    A vulnerability was found in URVE Web Manager. It has been classified as critical. This affects an unknown part of the file kreator.html5/img_upload.php. The manipulation leads to unrestricted upload. Access to the local network is required for this attack. The exploit has been disclosed to the public and may be used.

    Published: 15 Jul 2022
    9.1
    Critical

    CVE-2022-35409

    Last Modified: 5 Jun 2026

    An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-read of up to 255 bytes. This can cause a server crash or possibly information disclosure based on error responses. Affected configurations have MBEDTLS_SSL_DTLS_CLIENT_PORT_REUSE enabled and MBEDTLS_SSL_IN_CONTENT_LEN less than a threshold that depends on the configuration: 258 bytes if using mbedtls_ssl_cookie_check, and possibly up to 571 bytes with a custom cookie check function.

    Published: 15 Jul 2022
    9.8
    Critical

    CVE-2022-2466

    Last Modified: 21 Nov 2024

    It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior.

    Published: 15 Jul 2022
    4.2
    Medium

    CVE-2022-25869

    Last Modified: 20 Nov 2025

    All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of <textarea> elements.

    Published: 15 Jul 2022
    5.3
    Medium

    CVE-2022-25858

    Last Modified: 21 Nov 2024

    The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.

    Published: 15 Jul 2022
    10
    Critical

    CVE-2022-31161

    Last Modified: 23 Apr 2025

    Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Version 6.1.1.0 contains a patch for this issue.

    Published: 15 Jul 2022
    5.3
    Medium

    CVE-2022-32425

    Last Modified: 21 Nov 2024

    The login function of Mealie v1.0.0beta-2 allows attackers to enumerate existing usernames by timing the server's response time.

    Published: 14 Jul 2022
    9.8
    Critical

    CVE-2022-32417

    Last Modified: 21 Nov 2024

    PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.

    Published: 14 Jul 2022
    7.2
    High

    CVE-2022-32416

    Last Modified: 21 Nov 2024

    Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_product.

    Published: 14 Jul 2022
    8.8
    High

    CVE-2022-32415

    Last Modified: 21 Nov 2024

    Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/?p=products/view_product&id=.

    Published: 14 Jul 2022
    6.1
    Medium

    CVE-2022-34094

    Last Modified: 21 Nov 2024

    Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via request_token.php.

    Published: 14 Jul 2022
    6.1
    Medium

    CVE-2022-34093

    Last Modified: 21 Nov 2024

    Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via access_token.php.

    Published: 14 Jul 2022
    6.1
    Medium

    CVE-2022-34092

    Last Modified: 21 Nov 2024

    Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via svg2img.php.

    Published: 14 Jul 2022
    9.8
    Critical

    CVE-2022-32409

    Last Modified: 21 Nov 2024

    A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to execute arbitrary PHP code via a crafted HTTP request.

    Published: 14 Jul 2022
    5.5
    Medium

    CVE-2022-32406

    Last Modified: 21 Nov 2024

    GtkRadiant v1.6.6 was discovered to contain a buffer overflow via the component q3map2. This vulnerability can cause a Denial of Service (DoS) via a crafted MAP file.

    Published: 14 Jul 2022
    7.5
    High

    CVE-2022-32389

    Last Modified: 21 Nov 2024

    Isode SWIFT v4.0.2 was discovered to contain hard-coded credentials in the Registry Editor. This allows attackers to access sensitive information such as user credentials and certificates.

    Published: 14 Jul 2022
    5.4
    Medium

    CVE-2022-32318

    Last Modified: 21 Nov 2024

    Fast Food Ordering System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the component /ffos/classes/Master.php?f=save_category.

    Published: 14 Jul 2022
    7.5
    High

    CVE-2022-31147

    Last Modified: 23 Apr 2025

    The jQuery Validation Plugin (jquery-validation) provides drop-in validation for forms. Versions of jquery-validation prior to 1.19.5 are vulnerable to regular expression denial of service (ReDoS) when an attacker is able to supply arbitrary input to the url2 method. This is due to an incomplete fix for CVE-2021-43306. Users should upgrade to version 1.19.5 to receive a patch.

    Published: 14 Jul 2022
    7.8
    High

    CVE-2021-26384

    Last Modified: 21 Nov 2024

    A malformed SMI (System Management Interface) command may allow an attacker to establish a corrupted SMI Trigger Info data structure, potentially leading to out-of-bounds memory reads and writes when triggering an SMI resulting in a potential loss of resources.

    Published: 14 Jul 2022
    4.4
    Medium

    CVE-2021-26382

    Last Modified: 21 Nov 2024

    An attacker with root account privileges can load any legitimately signed firmware image into the Audio Co-Processor (ACP,) irrespective of the respective signing key being declared as usable for authenticating an ACP firmware image, potentially resulting in a denial of service.

    Published: 14 Jul 2022