CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2022-31501

    Last Modified: 21 Nov 2024

    The ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

    Published: 11 Jul 2022
    4.3
    Medium

    CVE-2022-31472

    Last Modified: 21 Nov 2024

    Browse restriction bypass vulnerability in Cabinet of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to obtain the data of Cabinet.

    Published: 11 Jul 2022
    4.3
    Medium

    CVE-2022-30943

    Last Modified: 21 Nov 2024

    Browsing restriction bypass vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated attacker to obtain the data of Bulletin.

    Published: 11 Jul 2022
    8.1
    High

    CVE-2022-30602

    Last Modified: 21 Nov 2024

    Operation restriction bypass in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated attacker to alter the file information and/or delete the files.

    Published: 11 Jul 2022
    6.5
    Medium

    CVE-2022-29512

    Last Modified: 21 Nov 2024

    Exposure of sensitive information to an unauthorized actor issue in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated attacker to obtain the data without the viewing privilege.

    Published: 11 Jul 2022
    6.1
    Medium

    CVE-2022-27168

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in LiteCart versions prior to 2.4.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.

    Published: 11 Jul 2022
    8.1
    High

    CVE-2022-2385

    Last Modified: 21 Nov 2024

    A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.

    Published: 11 Jul 2022
    9.8
    Critical

    CVE-2022-32294

    Last Modified: 21 Nov 2024

    Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ca" command). It is visible in cleartext on port UDP 514 (aka the syslog port). NOTE: a third party reports that this cannot be reproduced.

    Published: 11 Jul 2022
    8.8
    High

    CVE-2022-35414

    Last Modified: 21 Nov 2024

    softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex crash. NOTE: a third party states that the Non-virtualization Use Case in the qemu.org reference applies here, i.e., "Bugs affecting the non-virtualization use case are not considered security bugs at this time.

    Published: 11 Jul 2022
    —
    Unknown

    CVE-2022-35604

    Last Modified: 6 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-35601. Reason: This candidate is a duplicate of CVE-2022-35601. Notes: All CVE users should reference CVE-2022-35601 instead of this candidate.

    Published: 11 Jul 2022
    5.5
    Medium

    CVE-2022-4128

    Last Modified: 25 Jun 2025

    A NULL pointer dereference issue was discovered in the Linux kernel in the MPTCP protocol when traversing the subflow list at disconnect time. A local user could use this flaw to potentially crash the system causing a denial of service.

    Published: 11 Jul 2022
    6.7
    Medium

    CVE-2022-2991

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow was found in the Linux kernel's LightNVM subsystem. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. This vulnerability allows a local attacker to escalate privileges and execute arbitrary code in the context of the kernel. The attacker must first obtain the ability to execute high-privileged code on the target system to exploit this vulnerability.

    Published: 11 Jul 2022
    9.8
    Critical

    CVE-2022-36227

    Last Modified: 3 Nov 2025

    In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."

    Published: 11 Jul 2022
    5.4
    Medium

    CVE-2022-2365

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.53.3.

    Published: 10 Jul 2022
    6.1
    Medium

    CVE-2022-27910

    Last Modified: 25 Feb 2026

    In Joomla component 'Joomlatools - DOCman 3.5.13 (and likely most versions below)' are affected to an reflected Cross-Site Scripting (XSS) in an image upload function

    Published: 10 Jul 2022
    6.1
    Medium

    CVE-2022-2353

    Last Modified: 21 Nov 2024

    Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch contents from same-site and redirect a user.

    Published: 9 Jul 2022
    5.5
    Medium

    CVE-2022-4127

    Last Modified: 25 Jun 2025

    A NULL pointer dereference issue was discovered in the Linux kernel in io_files_update_with_index_alloc. A local user could use this flaw to potentially crash the system causing a denial of service.

    Published: 9 Jul 2022
    5.1
    Medium

    CVE-2022-35412

    Last Modified: 21 Nov 2024

    Digital Guardian Agent 7.7.4.0042 allows an administrator (who ordinarily does not have a supported way to uninstall the product) to disable some of the agent functionality and then exfiltrate files to an external USB device.

    Published: 8 Jul 2022
    9.8
    Critical

    CVE-2022-34914

    Last Modified: 21 Nov 2024

    Webswing before 22.1.3 allows X-Forwarded-For header injection. The client IP address is associated with a variable in the configuration page. The {clientIp} variable can be used as an application startup argument. The X-Forwarded-For header can be manipulated by a client to store an arbitrary value that is used to replace the clientIp variable (without sanitization). A client can thus inject multiple arguments into the session startup. Systems that do not use the clientIP variable in the configuration are not vulnerable. The vulnerability is fixed in these versions: 20.1.16, 20.2.19, 21.1.8, 21.2.12, and 22.1.3.

    Published: 8 Jul 2022
    9.8
    Critical

    CVE-2022-35411

    Last Modified: 21 Nov 2024

    rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated client can cause the data to be processed with unpickle.

    Published: 8 Jul 2022
    8.8
    High

    CVE-2022-22476

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to identity spoofing by an authenticated user using a specially crafted request. IBM X-Force ID: 225604.

    Published: 8 Jul 2022
    7.8
    High

    CVE-2022-22465

    Last Modified: 21 Nov 2024

    IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 could allow a local user to obtain elevated privileges due to improper access permissions. IBM X-Force ID: 225082.

    Published: 8 Jul 2022
    7.5
    High

    CVE-2022-22464

    Last Modified: 21 Nov 2024

    IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225081.

    Published: 8 Jul 2022
    6.5
    Medium

    CVE-2022-22463

    Last Modified: 21 Nov 2024

    IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 225079.

    Published: 8 Jul 2022
    5.4
    Medium

    CVE-2022-22370

    Last Modified: 21 Nov 2024

    IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 221194.

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-8819

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-7800

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-5598

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-5597

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-5596

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-5328

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-4332

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-4169

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-4102

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-4101

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-3377

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-3266

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-3265

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-3264

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-3263

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-3262

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-3261

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-3260

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-2671

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-2236

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-1871

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-1837

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-0281

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-0280

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2015-0256

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none

    Published: 8 Jul 2022