CVE Feed

    Dashboard / CVE

    6.6
    Medium

    CVE-2022-22023

    Last Modified: 8 Jul 2025

    Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability

    Published: 12 Jul 2022
    7.1
    High

    CVE-2022-22022

    Last Modified: 8 Jul 2025

    Windows Print Spooler Elevation of Privilege Vulnerability

    Published: 12 Jul 2022
    4.7
    Medium

    CVE-2022-21845

    Last Modified: 8 Jul 2025

    Windows Kernel Information Disclosure Vulnerability

    Published: 12 Jul 2022
    2.6
    Low

    CVE-2022-31102

    Last Modified: 23 Apr 2025

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with 2.3.0 and prior to 2.3.6 and 2.4.5 is vulnerable to a cross-site scripting (XSS) bug which could allow an attacker to inject arbitrary JavaScript in the `/auth/callback` page in a victim's browser. This vulnerability only affects Argo CD instances which have single sign on (SSO) enabled. The exploit also assumes the attacker has 1) access to the API server's encryption key, 2) a method to add a cookie to the victim's browser, and 3) the ability to convince the victim to visit a malicious `/auth/callback` link. The vulnerability is classified as low severity because access to the API server's encryption key already grants a high level of access. Exploiting the XSS would allow the attacker to impersonate the victim, but would not grant any privileges which the attacker could not otherwise gain using the encryption key. A patch for this vulnerability has been released in the following Argo CD versions 2.4.5 and 2.3.6. There is currently no known workaround.

    Published: 12 Jul 2022
    8.3
    High

    CVE-2022-31105

    Last Modified: 23 Apr 2025

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.4.0 and prior to 2.2.11, 2.3.6, and 2.4.5 is vulnerable to an improper certificate validation bug which could cause Argo CD to trust a malicious (or otherwise untrustworthy) OpenID Connect (OIDC) provider. A patch for this vulnerability has been released in Argo CD versions 2.4.5, 2.3.6, and 2.2.11. There are no complete workarounds, but a partial workaround is available. Those who use an external OIDC provider (not the bundled Dex instance), can mitigate the issue by setting the `oidc.config.rootCA` field in the `argocd-cm` ConfigMap. This mitigation only forces certificate validation when the API server handles login flows. It does not force certificate verification when verifying tokens on API calls.

    Published: 12 Jul 2022
    9.8
    Critical

    CVE-2022-35628

    Last Modified: 21 Nov 2024

    A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3.

    Published: 12 Jul 2022
    5.4
    Medium

    CVE-2022-33155

    Last Modified: 21 Nov 2024

    The ameos_tarteaucitron (aka AMEOS - TarteAuCitron GDPR cookie banner and tracking management / French RGPD compatible) extension before 1.2.23 for TYPO3 allows XSS.

    Published: 12 Jul 2022
    7.5
    High

    CVE-2022-35403

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenticated local file disclosure vulnerability via ticket-creation email. (This also affects Asset Explorer before 6977 with authentication.)

    Published: 12 Jul 2022
    5.4
    Medium

    CVE-2022-33154

    Last Modified: 21 Nov 2024

    The schema (aka Embedding schema.org vocabulary) extension before 1.13.1 and 2.x before 2.5.1 for TYPO3 allows XSS.

    Published: 12 Jul 2022
    9.8
    Critical

    CVE-2022-29600

    Last Modified: 21 Nov 2024

    The oelib (aka One is Enough Library) extension through 4.1.5 for TYPO3 allows SQL Injection.

    Published: 12 Jul 2022
    9.8
    Critical

    CVE-2022-29601

    Last Modified: 21 Nov 2024

    The seminars (aka Seminar Manager) extension through 4.1.3 for TYPO3 allows SQL Injection.

    Published: 12 Jul 2022
    5.4
    Medium

    CVE-2022-31655

    Last Modified: 21 Nov 2024

    VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in alerts.

    Published: 12 Jul 2022
    5.4
    Medium

    CVE-2022-31654

    Last Modified: 21 Nov 2024

    VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in configurations.

    Published: 12 Jul 2022
    9.8
    Critical

    CVE-2022-1737

    Last Modified: 16 Apr 2025

    Pyramid Solutions' affected products, the Developer and DLL kits for EtherNet/IP Adapter and EtherNet/IP Scanner, are vulnerable to an out-of-bounds write, which may allow an unauthorized attacker to send a specially crafted packet that may result in a denial-of-service condition.

    Published: 12 Jul 2022
    5.5
    Medium

    CVE-2011-4916

    Last Modified: 21 Nov 2024

    Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /dev/pts/ and /dev/tty*.

    Published: 12 Jul 2022
    8.2
    High

    CVE-2022-31012

    Last Modified: 23 Apr 2025

    Git for Windows is a fork of Git that contains Windows-specific patches. This vulnerability in versions prior to 2.37.1 lets Git for Windows' installer execute a binary into `C:\mingw64\bin\git.exe` by mistake. This only happens upon a fresh install, not when upgrading Git for Windows. A patch is included in version 2.37.1. Two workarounds are available. Create the `C:\mingw64` folder and remove read/write access from this folder, or disallow arbitrary authenticated users to create folders in `C:\`.

    Published: 12 Jul 2022
    4.9
    Medium

    CVE-2022-31134

    Last Modified: 23 Apr 2025

    Zulip is an open-source team collaboration tool. Zulip Server versions 2.1.0 above have a user interface tool, accessible only to server owners and server administrators, which provides a way to download a "public data" export. While this export is only accessible to administrators, in many configurations server administrators are not expected to have access to private messages and private streams. However, the "public data" export which administrators could generate contained the attachment contents for all attachments, even those from private messages and streams. Zulip Server version 5.4 contains a patch for this issue.

    Published: 12 Jul 2022
    7.5
    High

    CVE-2022-32249

    Last Modified: 21 Nov 2024

    Under special integration scenario of SAP Business one and SAP HANA - version 10.0, an attacker can exploit HANA cockpit�s data volume to gain access to highly sensitive information (e.g., high privileged account credentials)

    Published: 12 Jul 2022
    6.1
    Medium

    CVE-2022-35224

    Last Modified: 21 Nov 2024

    SAP Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This attack can be used to non-permanently deface or modify portal content. The execution of script content by a victim registered on the portal could compromise the confidentiality and integrity of victim�s web browser session.

    Published: 12 Jul 2022
    8.8
    High

    CVE-2022-35228

    Last Modified: 21 Nov 2024

    SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This can be achieved only when a legitimate user accesses the application and a local compromise occurs, like sniffing or social engineering. On successful exploitation, the attacker can completely compromise the application.

    Published: 12 Jul 2022
    6.1
    Medium

    CVE-2022-35225

    Last Modified: 21 Nov 2024

    SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. This leads to limited impact on confidentiality and integrity of data.

    Published: 12 Jul 2022
    6.1
    Medium

    CVE-2022-35227

    Last Modified: 21 Nov 2024

    A vulnerability in SAP NW EP (WPC) - versions 7.30, 7.31, 7.40, 7.50, which does not sufficiently validate user-controlled input, allows a remote attacker to conduct a Cross-Site (XSS) scripting attack. A successful exploit could allow the attacker to execute arbitrary script code which could lead to stealing or modifying of authentication information of the user, such as data relating to his or her current session.

    Published: 12 Jul 2022
    6.1
    Medium

    CVE-2022-35172

    Last Modified: 21 Nov 2024

    SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.

    Published: 12 Jul 2022
    5.5
    Medium

    CVE-2022-35171

    Last Modified: 21 Nov 2024

    When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below

    Published: 12 Jul 2022
    6
    Medium

    CVE-2022-35169

    Last Modified: 21 Nov 2024

    SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege to read and decrypt LCMBIAR file's password under certain conditions, enabling the attacker to modify the password or import the file into another system causing high impact on confidentiality but a limited impact on the availability and integrity of the application.

    Published: 12 Jul 2022
    6.1
    Medium

    CVE-2022-35170

    Last Modified: 21 Nov 2024

    SAP NetWeaver Enterprise Portal does - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. This leads to limited impact on confidentiality and integrity of data.

    Published: 12 Jul 2022
    7.5
    High

    CVE-2022-35168

    Last Modified: 21 Nov 2024

    Due to improper input sanitization of XML input in SAP Business One - version 10.0, an attacker can perform a denial-of-service attack rendering the system temporarily inoperative.

    Published: 12 Jul 2022
    6.1
    Medium

    CVE-2022-32247

    Last Modified: 21 Nov 2024

    SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the User inputs while interacting on the Network. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

    Published: 12 Jul 2022
    5.3
    Medium

    CVE-2022-32248

    Last Modified: 21 Nov 2024

    Due to missing input validation in the Manage Checkbooks component of SAP S/4HANA - version 101, 102, 103, 104, 105, 106, an attacker could insert or edit the value of an existing field in the database. This leads to an impact on the integrity of the data.

    Published: 12 Jul 2022
    8.8
    High

    CVE-2022-31593

    Last Modified: 21 Nov 2024

    SAP Business One client - version 10.0 allows an attacker with low privileges, to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

    Published: 12 Jul 2022
    7.8
    High

    CVE-2022-31591

    Last Modified: 21 Nov 2024

    SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A local attacker can gain elevated privileges by inserting an executable file in the path of the affected service

    Published: 12 Jul 2022
    5.4
    Medium

    CVE-2022-31597

    Last Modified: 21 Nov 2024

    Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does not perform necessary authorization checks for a low privileged authenticated user over the network, resulting in escalation of privileges leading to low impact on confidentiality and integrity of the data.

    Published: 12 Jul 2022
    7.5
    High

    CVE-2022-28771

    Last Modified: 25 Feb 2026

    Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http requests over the network. On successful exploitation, an attacker can break the whole application making it inaccessible.

    Published: 12 Jul 2022
    6.5
    Medium

    CVE-2022-29619

    Last Modified: 21 Nov 2024

    Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.x - versions 420,430 allows user Administrator to view, edit or modify rights of objects it doesn't own and which would otherwise be restricted.

    Published: 12 Jul 2022
    4.3
    Medium

    CVE-2022-31592

    Last Modified: 21 Nov 2024

    The application SAP Enterprise Extension Defense Forces & Public Security - versions 605, 606, 616,617,618, 802, 803, 804, 805, 806, does not perform necessary authorization checks for an authenticated user over the network, resulting in escalation of privileges leading to a limited impact on confidentiality.

    Published: 12 Jul 2022
    5.4
    Medium

    CVE-2022-31598

    Last Modified: 21 Nov 2024

    Due to insufficient input validation, SAP Business Objects - version 420, allows an authenticated attacker to submit a malicious request through an allowed operation. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

    Published: 12 Jul 2022
    4.6
    Medium

    CVE-2022-32246

    Last Modified: 21 Nov 2024

    SAP Busines Objects Business Intelligence Platform (Visual Difference Application) - versions 420, 430, allows an authenticated attacker who has access to BI admin console to send crafted queries and extract data from the SQL backend. On successful exploitation, the attacker can cause limited impact on confidentiality and integrity of the application

    Published: 12 Jul 2022
    6.8
    Medium

    CVE-2022-22997

    Last Modified: 21 Nov 2024

    Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 bucket that potentially allowed an attacker to execute unsigned code on My Cloud Home devices.

    Published: 12 Jul 2022
    8
    High

    CVE-2022-22998

    Last Modified: 21 Nov 2024

    Implemented protections on AWS credentials that were not properly protected.

    Published: 12 Jul 2022
    8.1
    High

    CVE-2022-24800

    Last Modified: 23 Apr 2025

    October/System is the system module for October CMS, a self-hosted CMS platform based on the Laravel PHP Framework. Prior to versions 1.0.476, 1.1.12, and 2.2.15, when the developer allows the user to specify their own filename in the `fromData` method, an unauthenticated user can perform remote code execution (RCE) by exploiting a race condition in the temporary storage directory. This vulnerability affects plugins that expose the `October\Rain\Database\Attach\File::fromData` as a public interface and does not affect vanilla installations of October CMS since this method is not exposed or used by the system internally or externally. The issue has been patched in Build 476 (v1.0.476), v1.1.12, and v2.2.15. Those who are unable to upgrade may apply with patch to their installation manually as a workaround.

    Published: 12 Jul 2022
    5.3
    Medium

    CVE-2021-39041

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3, 7.4, and 7.5 may be vulnerable to partial denial of service attack, resulting in some protocols not listening to specified ports. IBM X-Force ID: 214028.

    Published: 12 Jul 2022
    7.5
    High

    CVE-2020-4159

    Last Modified: 21 Nov 2024

    IBM QRadar Network Security 5.4.0 and 5.5.0 discloses sensitive information to unauthorized users which could be used to mount further attacks against the system. IBM X-Force ID: 174339.

    Published: 12 Jul 2022
    7.5
    High

    CVE-2020-4157

    Last Modified: 21 Nov 2024

    IBM QRadar Network Security 5.4.0 and 5.5.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174337.

    Published: 12 Jul 2022
    5.7
    Medium

    CVE-2022-2393

    Last Modified: 21 Nov 2024

    A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content.

    Published: 12 Jul 2022
    3.5
    Low

    CVE-2022-2364

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, was found in SourceCodester Simple Parking Management System 1.0. This affects an unknown part of the file /ci_spms/admin/category. The manipulation of the argument vehicle_type with the input "><script>alert("XSS")</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Jul 2022
    3.5
    Low

    CVE-2022-2363

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in SourceCodester Simple Parking Management System 1.0. Affected by this issue is some unknown functionality of the file /ci_spms/admin/search/searching/. The manipulation of the argument search with the input "><script>alert("XSS")</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Jul 2022
    7.3
    High

    CVE-2022-2298

    Last Modified: 14 Apr 2025

    A vulnerability has been found in SourceCodester Clinics Patient Management System 2.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pms/index.php of the component Login Page. The manipulation of the argument user_name with the input admin' or '1'='1 leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Jul 2022
    6.3
    Medium

    CVE-2022-2297

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, was found in SourceCodester Clinics Patient Management System 2.0. Affected is an unknown function of the file /pms/update_user.php?user_id=1. The manipulation of the argument profile_picture with the input <?php phpinfo();?> leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Jul 2022
    5.4
    Medium

    CVE-2022-25875

    Last Modified: 21 Nov 2024

    The package svelte before 3.49.0 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this vulnerability is possible via objects with a custom toString() function.

    Published: 12 Jul 2022
    5.4
    Medium

    CVE-2022-25303

    Last Modified: 21 Nov 2024

    The package whoogle-search before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via the query string parameter q. In the case where it does not contain the http string, it is used to build the error_message that is then rendered in the error.html template, using the [flask.render_template](https://flask.palletsprojects.com/en/2.1.x/api/flask.render_template) function. However, the error_message is rendered using the [| safe filter](https://jinja.palletsprojects.com/en/3.1.x/templates/working-with-automatic-escaping), meaning the user input is not escaped.

    Published: 12 Jul 2022