CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2022-20862

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains directory traversal character sequences to an affected system. A successful exploit could allow the attacker to access sensitive files on the operating system.

    Published: 6 Jul 2022
    6.5
    Medium

    CVE-2022-20859

    Last Modified: 21 Nov 2024

    A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an authenticated, remote attacker to perform certain administrative actions they should not be able to. This vulnerability is due to insufficient access control checks on the affected device. An attacker with read-only privileges could exploit this vulnerability by executing a specific vulnerable command on an affected device. A successful exploit could allow the attacker to perform a set of administrative actions they should not be able to.

    Published: 6 Jul 2022
    6.1
    Medium

    CVE-2022-20815

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.

    Published: 6 Jul 2022
    9
    Critical

    CVE-2022-20813

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected device. Note: Cisco Expressway Series refers to the Expressway Control (Expressway-C) device and the Expressway Edge (Expressway-E) device. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 6 Jul 2022
    9
    Critical

    CVE-2022-20812

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected device. Note: Cisco Expressway Series refers to the Expressway Control (Expressway-C) device and the Expressway Edge (Expressway-E) device. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 6 Jul 2022
    7.7
    High

    CVE-2022-20808

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incorrect handling of multiple simultaneous device registrations on Cisco SSM On-Prem. An attacker could exploit this vulnerability by sending multiple device registration requests to Cisco SSM On-Prem. A successful exploit could allow the attacker to cause a DoS condition on an affected device.

    Published: 6 Jul 2022
    6.1
    Medium

    CVE-2022-20800

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.

    Published: 6 Jul 2022
    6.5
    Medium

    CVE-2022-20791

    Last Modified: 21 Nov 2024

    A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device. This vulnerability is due to insufficient file permission restrictions. An attacker could exploit this vulnerability by sending a crafted command from the API to the application. A successful exploit could allow the attacker to read arbitrary files on the underlying operating system of the affected device. The attacker would need valid user credentials to exploit this vulnerability.

    Published: 6 Jul 2022
    4.9
    Medium

    CVE-2022-20768

    Last Modified: 21 Nov 2024

    A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to access confidential information, some of which may contain personally identifiable information (PII). Note: To access the logs that are stored in the RoomOS Cloud, an attacker would need valid Administrator-level credentials.

    Published: 6 Jul 2022
    5.3
    Medium

    CVE-2022-20752

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to perform a timing attack. This vulnerability is due to insufficient protection of a system password. An attacker could exploit this vulnerability by observing the time it takes the system to respond to various queries. A successful exploit could allow the attacker to determine a sensitive system password.

    Published: 6 Jul 2022
    4
    Medium

    CVE-2022-27549

    Last Modified: 21 Nov 2024

    HCL Launch may store certain data for recurring activities in a plain text format.

    Published: 6 Jul 2022
    4.9
    Medium

    CVE-2022-27548

    Last Modified: 21 Nov 2024

    HCL Launch stores user credentials in plain clear text which can be read by a local user.

    Published: 6 Jul 2022
    7.5
    High

    CVE-2021-4234

    Last Modified: 21 Nov 2024

    OpenVPN Access Server 2.10 and prior versions are susceptible to resending multiple packets in a response to a reset packet sent from the client which the client again does not respond to, resulting in a limited amplification attack.

    Published: 6 Jul 2022
    7.2
    High

    CVE-2015-3173

    Last Modified: 21 Nov 2024

    custom-content-type-manager Wordpress plugin can be used by an administrator to achieve arbitrary PHP remote code execution.

    Published: 6 Jul 2022
    5.4
    Medium

    CVE-2015-3172

    Last Modified: 21 Nov 2024

    EidoGo is susceptible to Cross-Site Scripting (XSS) attacks via maliciously crafted SGF input.

    Published: 6 Jul 2022
    5.4
    Medium

    CVE-2022-2316

    Last Modified: 21 Nov 2024

    HTML injection vulnerability in secure messages of Devolutions Server before 2022.2 allows attackers to alter the rendering of the page or redirect a user to another site.

    Published: 6 Jul 2022
    9.8
    Critical

    CVE-2022-33047

    Last Modified: 21 Nov 2024

    OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c.

    Published: 6 Jul 2022
    7.1
    High

    CVE-2022-31127

    Last Modified: 22 Apr 2025

    NextAuth.js is a complete open source authentication solution for Next.js applications. An attacker can pass a compromised input to the e-mail [signin endpoint](https://next-auth.js.org/getting-started/rest-api#post-apiauthsigninprovider) that contains some malicious HTML, tricking the e-mail server to send it to the user, so they can perform a phishing attack. Eg.: `[email protected], <a href="http://attacker.com">Before signing in, claim your money!</a>`. This was previously sent to `[email protected]`, and the content of the email containing a link to the attacker's site was rendered in the HTML. This has been remedied in the following releases, by simply not rendering that e-mail in the HTML, since it should be obvious to the receiver what e-mail they used: next-auth v3 users before version 3.29.8 are impacted. (We recommend upgrading to v4, as v3 is considered unmaintained. next-auth v4 users before version 4.9.0 are impacted. If for some reason you cannot upgrade, the workaround requires you to sanitize the `email` parameter that is passed to `sendVerificationRequest` and rendered in the HTML. If you haven't created a custom `sendVerificationRequest`, you only need to upgrade. Otherwise, make sure to either exclude `email` from the HTML body or efficiently sanitize it.

    Published: 6 Jul 2022
    5.4
    Medium

    CVE-2022-31131

    Last Modified: 22 Apr 2025

    Nextcloud mail is a Mail app for the Nextcloud home server product. Versions of Nextcloud mail prior to 1.12.2 were found to be missing user account ownership checks when performing tasks related to mail attachments. Attachments may have been exposed to incorrect system users. It is recommended that the Nextcloud Mail app is upgraded to 1.12.2. There are no known workarounds for this issue. ### Workarounds No workaround available ### References * [Pull request](https://github.com/nextcloud/mail/pull/6600) * [HackerOne](https://hackerone.com/reports/1579820) ### For more information If you have any questions or comments about this advisory: * Create a post in [nextcloud/security-advisories](https://github.com/nextcloud/security-advisories/discussions) * Customers: Open a support ticket at [support.nextcloud.com](https://support.nextcloud.com)

    Published: 6 Jul 2022
    7.7
    High

    CVE-2022-31124

    Last Modified: 22 Apr 2025

    openssh_key_parser is an open source Python package providing utilities to parse and pack OpenSSH private and public key files. In versions prior to 0.0.6 if a field of a key is shorter than it is declared to be, the parser raises an error with a message containing the raw field value. An attacker able to modify the declared length of a key's sensitive field can thus expose the raw value of that field. Users are advised to upgrade to version 0.0.6, which no longer includes the raw field value in the error message. There are no known workarounds for this issue.

    Published: 6 Jul 2022
    10
    Critical

    CVE-2022-31126

    Last Modified: 23 Apr 2025

    Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file. This affects Roxy-wi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 6 Jul 2022
    5.3
    Medium

    CVE-2022-31111

    Last Modified: 23 Apr 2025

    Frontier is Substrate's Ethereum compatibility layer. In affected versions the truncation done when converting between EVM balance type and Substrate balance type was incorrectly implemented. This leads to possible discrepancy between appeared EVM transfer value and actual Substrate value transferred. It is recommended that an emergency upgrade to be planned and EVM execution temporarily paused in the mean time. The issue is patched in Frontier master branch commit fed5e0a9577c10bea021721e8c2c5c378e16bf66 and polkadot-v0.9.22 branch commit e3e427fa2e5d1200a784679f8015d4774cedc934. This vulnerability affects only EVM internal states, but not Substrate balance states or node. You can temporarily pause EVM execution (by setting up a Substrate `CallFilter` that disables `pallet-evm` and `pallet-ethereum` calls before the patch can be applied.

    Published: 6 Jul 2022
    9.8
    Critical

    CVE-2022-34598

    Last Modified: 21 Nov 2024

    The udpserver in H3C Magic R100 V200R004 and V100R005 has the 9034 port opened, allowing attackers to execute arbitrary commands.

    Published: 6 Jul 2022
    9.8
    Critical

    CVE-2022-34597

    Last Modified: 21 Nov 2024

    Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability via the function WanParameterSetting.

    Published: 6 Jul 2022
    9.8
    Critical

    CVE-2022-34596

    Last Modified: 21 Nov 2024

    Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function WanParameterSetting.

    Published: 6 Jul 2022
    9.8
    Critical

    CVE-2022-34595

    Last Modified: 21 Nov 2024

    Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function setipv6status.

    Published: 6 Jul 2022
    4.7
    Medium

    CVE-2022-39188

    Last Modified: 21 Nov 2024

    An issue was discovered in include/asm-generic/tlb.h in the Linux kernel before 5.19. Because of a race condition (unmap_mapping_range versus munmap), a device driver can free a page while it still has stale TLB entries. This only occurs in situations with VM_PFNMAP VMAs.

    Published: 6 Jul 2022
    8.2
    High

    CVE-2022-26348

    Last Modified: 21 Nov 2024

    Command Centre Server is vulnerable to SQL Injection via Windows Registry settings for date fields on the server. The Windows Registry setting allows an attacker using the Visitor Management Kiosk, an application designed for public use, to invoke an arbitrary SQL query that has been preloaded into the registry of the Windows Server to obtain sensitive information. This issue affects: Gallagher Command Centre 8.60 versions prior to 8.60.1652; 8.50 versions prior to 8.50.2245; 8.40 versions prior to 8.40.2216; 8.30 versions prior to 8.30.1470; version 8.20 and prior versions.

    Published: 6 Jul 2022
    7.5
    High

    CVE-2022-26078

    Last Modified: 21 Nov 2024

    Gallagher Controller 6000 is vulnerable to a Denial of Service attack via conflicting ARP packets with a duplicate IP address. This issue affects: Gallagher Gallagher Controller 6000 vCR8.60 versions prior to 220303a; vCR8.50 versions prior to 220303a; vCR8.40 versions prior to 220303a; vCR8.30 versions prior to 220303a.

    Published: 6 Jul 2022
    7.5
    High

    CVE-2022-33738

    Last Modified: 21 Nov 2024

    OpenVPN Access Server before 2.11 uses a weak random generator used to create user session token for the web portal

    Published: 6 Jul 2022
    7.5
    High

    CVE-2022-33737

    Last Modified: 21 Nov 2024

    The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random generated admin password

    Published: 6 Jul 2022
    8.8
    High

    CVE-2022-30929

    Last Modified: 21 Nov 2024

    Mini-Tmall v1.0 is vulnerable to Insecure Permissions via tomcat-embed-jasper.

    Published: 6 Jul 2022
    7.8
    High

    CVE-2022-23714

    Last Modified: 21 Nov 2024

    A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.

    Published: 6 Jul 2022
    5.9
    Medium

    CVE-2022-30619

    Last Modified: 21 Nov 2024

    Editable SQL Queries behind Base64 encoding sending from the Client-Side to The Server-Side for a particular API used in legacy Work Center module. He attack is available for any authenticated user, in any kind of rule. under the function : /AgilePointServer/Extension/FetchUsingEncodedData in the parameter: EncodedData

    Published: 6 Jul 2022
    5.5
    Medium

    CVE-2022-23173

    Last Modified: 21 Nov 2024

    this vulnerability affect user that even not allowed to access via the web interface. First of all, the attacker needs to access the "Login menu - demo site" then he can see in this menu all the functionality of the application. If the attacker will try to click on one of the links, he will get an answer that he is not authorized because he needs to log in with credentials. after he performed log in to the system there are some functionalities that the specific user is not allowed to perform because he was configured with low privileges however all the attacker need to do in order to achieve his goals is to change the value of the prog step parameter from 0 to 1 or more and then the attacker could access to some of the functionality the web application that he couldn't perform it before the parameter changed.

    Published: 6 Jul 2022
    5.5
    Medium

    CVE-2022-23172

    Last Modified: 21 Nov 2024

    An attacker can access to "Forgot my password" button, as soon as he puts users is valid in the system, the system would issue a message that a password reset email had been sent to user. This way you can verify which users are in the system and which are not.

    Published: 6 Jul 2022
    6.7
    Medium

    CVE-2022-21787

    Last Modified: 21 Nov 2024

    In audio DSP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558844; Issue ID: ALPS06558844.

    Published: 6 Jul 2022
    6.7
    Medium

    CVE-2022-21786

    Last Modified: 21 Nov 2024

    In audio DSP, there is a possible memory corruption due to improper casting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558822; Issue ID: ALPS06558822.

    Published: 6 Jul 2022
    6.7
    Medium

    CVE-2022-21785

    Last Modified: 21 Nov 2024

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06807363; Issue ID: ALPS06807363.

    Published: 6 Jul 2022
    6.7
    Medium

    CVE-2022-21784

    Last Modified: 21 Nov 2024

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Issue ID: ALPS06704462.

    Published: 6 Jul 2022
    6.7
    Medium

    CVE-2022-21783

    Last Modified: 21 Nov 2024

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Issue ID: ALPS06704482.

    Published: 6 Jul 2022
    6.7
    Medium

    CVE-2022-21782

    Last Modified: 21 Nov 2024

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Issue ID: ALPS06704508.

    Published: 6 Jul 2022
    6.7
    Medium

    CVE-2022-21781

    Last Modified: 21 Nov 2024

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Issue ID: ALPS06704433.

    Published: 6 Jul 2022
    6.7
    Medium

    CVE-2022-21780

    Last Modified: 21 Nov 2024

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Issue ID: ALPS06704526.

    Published: 6 Jul 2022
    6.7
    Medium

    CVE-2022-21779

    Last Modified: 21 Nov 2024

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Issue ID: ALPS06704393.

    Published: 6 Jul 2022
    7.8
    High

    CVE-2022-21777

    Last Modified: 21 Nov 2024

    In Autoboot, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06713894; Issue ID: ALPS06713894.

    Published: 6 Jul 2022
    6.4
    Medium

    CVE-2022-21776

    Last Modified: 21 Nov 2024

    In MDP, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06545450; Issue ID: ALPS06545450.

    Published: 6 Jul 2022
    6.7
    Medium

    CVE-2022-21775

    Last Modified: 21 Nov 2024

    In sched driver, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479032; Issue ID: ALPS06479032.

    Published: 6 Jul 2022
    6.7
    Medium

    CVE-2022-21774

    Last Modified: 21 Nov 2024

    In TEEI driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641447; Issue ID: ALPS06641447.

    Published: 6 Jul 2022
    6.7
    Medium

    CVE-2022-21773

    Last Modified: 21 Nov 2024

    In TEEI driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641388; Issue ID: ALPS06641388.

    Published: 6 Jul 2022