CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2022-31014

    Last Modified: 22 Apr 2025

    Nextcloud server is an open source personal cloud server. Affected versions were found to be vulnerable to SMTP command injection. The impact varies based on which commands are supported by the backend SMTP server. However, the main risk here is that the attacker can then hijack an already-authenticated SMTP session and run arbitrary SMTP commands as the email user, such as sending emails to other users, changing the FROM user, and so on. As before, this depends on the configuration of the server itself, but newlines should be sanitized to mitigate such arbitrary SMTP command injection. It is recommended that the Nextcloud Server is upgraded to 22.2.8 , 23.0.5 or 24.0.1. There are no known workarounds for this issue.

    Published: 5 Jul 2022
    7.2
    High

    CVE-2021-44915

    Last Modified: 21 Nov 2024

    Taocms 3.0.2 was discovered to contain a blind SQL injection vulnerability via the function Edit category.

    Published: 5 Jul 2022
    4.9
    Medium

    CVE-2022-31770

    Last Modified: 21 Nov 2024

    IBM App Connect Enterprise Certified Container 4.2 could allow a user from the administration console to cause a denial of service by creating a specially crafted request. IBM X-Force ID: 228221.

    Published: 5 Jul 2022
    6.5
    Medium

    CVE-2022-34879

    Last Modified: 21 Nov 2024

    Reflected Cross Site Scripting (XSS) vulnerabilities in AST Agent Time Sheet interface (/vicidial/AST_agent_time_sheet.php) of VICIdial via agent, and search_archived_data parameters. This issue affects: VICIdial 2.14b0.5 versions prior to 3555.

    Published: 5 Jul 2022
    5.5
    Medium

    CVE-2022-34878

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in User Stats interface (/vicidial/user_stats.php) of VICIdial via the file_download parameter allows attacker to spoof identity, tamper with existing data, allow the complete disclosure of all data on the system, destroy the data or make it otherwise unavailable, and become administrators of the database server.

    Published: 5 Jul 2022
    6.4
    Medium

    CVE-2022-34877

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in AST Agent Time Sheet interface ((/vicidial/AST_agent_time_sheet.php) of VICIdial via the agent parameter allows attacker to spoof identity, tamper with existing data, allow the complete disclosure of all data on the system, destroy the data or make it otherwise unavailable, and become administrators of the database server. This issue affects: VICIdial 2.14b0.5 versions prior to 3555.

    Published: 5 Jul 2022
    5.5
    Medium

    CVE-2022-34876

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in admin interface (/vicidial/admin.php) of VICIdial via modify_email_accounts, access_recordings, and agentcall_email parameters allows attacker to spoof identity, tamper with existing data, allow the complete disclosure of all data on the system, destroy the data or make it otherwise unavailable, and become administrators of the database server. This issue affects: VICIdial 2.14b0.5 versions prior to 3555.

    Published: 5 Jul 2022
    7.1
    High

    CVE-2022-33742

    Last Modified: 21 Nov 2024

    Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742).

    Published: 5 Jul 2022
    7.1
    High

    CVE-2022-33741

    Last Modified: 21 Nov 2024

    Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742).

    Published: 5 Jul 2022
    7.1
    High

    CVE-2022-33740

    Last Modified: 21 Nov 2024

    Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742).

    Published: 5 Jul 2022
    7.1
    High

    CVE-2022-26365

    Last Modified: 21 Nov 2024

    Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742).

    Published: 5 Jul 2022
    4.7
    Medium

    CVE-2022-33744

    Last Modified: 21 Nov 2024

    Arm guests can cause Dom0 DoS via PV devices When mapping pages of guests on Arm, dom0 is using an rbtree to keep track of the foreign mappings. Updating of that rbtree is not always done completely with the related lock held, resulting in a small race window, which can be used by unprivileged guests via PV devices to cause inconsistencies of the rbtree. These inconsistencies can lead to Denial of Service (DoS) of dom0, e.g. by causing crashes or the inability to perform further mappings of other guests' memory pages.

    Published: 5 Jul 2022
    7.5
    High

    CVE-2022-30290

    Last Modified: 21 Nov 2024

    In OpenCTI through 5.2.4, a broken access control vulnerability has been identified in the profile endpoint. An attacker can abuse the identified vulnerability in order to arbitrarily change their registered e-mail address as well as their API key, even though such action is not possible through the interface, legitimately.

    Published: 5 Jul 2022
    5.4
    Medium

    CVE-2022-30289

    Last Modified: 21 Nov 2024

    A stored Cross-site Scripting (XSS) vulnerability was identified in the Data Import functionality of OpenCTI through 5.2.4. An attacker can abuse the vulnerability to upload a malicious file that will then be executed by a victim when they open the file location.

    Published: 5 Jul 2022
    9
    Critical

    CVE-2021-43702

    Last Modified: 21 Nov 2024

    ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.

    Published: 5 Jul 2022
    7.5
    High

    CVE-2022-2306

    Last Modified: 21 Nov 2024

    Old session tokens can be used to authenticate to the application and send authenticated requests.

    Published: 5 Jul 2022
    7.5
    High

    CVE-2022-2309

    Last Modified: 4 Nov 2025

    NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused by the iterwalk function (also used by the canonicalize function). Such code shouldn't be in wide-spread use, given that parsing + iterwalk would usually be replaced with the more efficient iterparse function. However, an XML converter that serialises to C14N would also be vulnerable, for example, and there are legitimate use cases for this code sequence. If untrusted input is received (also remotely) and processed via iterwalk function, a crash can be triggered.

    Published: 5 Jul 2022
    7.8
    High

    CVE-2022-2304

    Last Modified: 3 Nov 2025

    Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.

    Published: 5 Jul 2022
    8.8
    High

    CVE-2021-43116

    Last Modified: 21 Nov 2024

    An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.

    Published: 5 Jul 2022
    9.8
    Critical

    CVE-2022-31836

    Last Modified: 21 Nov 2024

    The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to cross directory risk.

    Published: 5 Jul 2022
    5.3
    Medium

    CVE-2022-2097

    Last Modified: 21 Nov 2024

    AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p).

    Published: 5 Jul 2022
    4.3
    Medium

    CVE-2022-22677

    Last Modified: 6 May 2025

    A logic issue in the handling of concurrent media was addressed with improved state handling. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. Video self-preview in a webRTC call may be interrupted if the user answers a phone call.

    Published: 5 Jul 2022
    7.8
    High

    CVE-2022-2345

    Last Modified: 21 Nov 2024

    Use After Free in GitHub repository vim/vim prior to 9.0.0046.

    Published: 5 Jul 2022
    8.8
    High

    CVE-2022-26710

    Last Modified: 6 May 2025

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, tvOS 15.5, watchOS 8.6. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 5 Jul 2022
    7.5
    High

    CVE-2022-34829

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload to the Mobile App Deployment API.

    Published: 4 Jul 2022
    6.4
    Medium

    CVE-2022-31603

    Last Modified: 21 Nov 2024

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with high privileges and preconditioned IpSecDxe global data can exploit improper validation of an array index to cause code execution, which may lead to denial of service, data integrity impact, and information disclosure.

    Published: 4 Jul 2022
    6.4
    Medium

    CVE-2022-31602

    Last Modified: 21 Nov 2024

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with elevated privileges and a preconditioned heap can exploit an out-of-bounds write vulnerability, which may lead to code execution, denial of service, data integrity impact, and information disclosure.

    Published: 4 Jul 2022
    6.7
    Medium

    CVE-2022-31601

    Last Modified: 21 Nov 2024

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmbiosPei, which may allow a highly privileged local attacker to cause an out-of-bounds write, which may lead to code execution, denial of service, compromised integrity, and information disclosure.

    Published: 4 Jul 2022
    7.5
    High

    CVE-2022-31600

    Last Modified: 21 Nov 2024

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmmCore, where a user with high privileges can chain another vulnerability to this vulnerability, causing an integer overflow, possibly leading to code execution, escalation of privileges, denial of service, compromised integrity, and information disclosure. The scope of impact can extend to other components.

    Published: 4 Jul 2022
    8.2
    High

    CVE-2022-31599

    Last Modified: 21 Nov 2024

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the Ofbd, where a local user with elevated privileges can cause access to an uninitialized pointer, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.

    Published: 4 Jul 2022
    9.8
    Critical

    CVE-2022-33171

    Last Modified: 21 Nov 2024

    The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input to the function is a user-controlled parsed JSON object, supplying a crafted FindOneOptions instead of an id string leads to SQL injection. NOTE: the vendor's position is that the user's application is responsible for input validation

    Published: 4 Jul 2022
    7.2
    High

    CVE-2022-2268

    Last Modified: 21 Nov 2024

    The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE

    Published: 4 Jul 2022
    6.5
    Medium

    CVE-2022-1967

    Last Modified: 21 Nov 2024

    The WP Championship WordPress plugin before 9.3 is lacking CSRF checks in various places, allowing attackers to make a logged in admin perform unwanted actions, such as create and delete arbitrary teams as well as update the plugin's settings. Due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

    Published: 4 Jul 2022
    6.1
    Medium

    CVE-2022-1946

    Last Modified: 21 Nov 2024

    The Gallery WordPress plugin before 2.0.0 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue

    Published: 4 Jul 2022
    4.8
    Medium

    CVE-2022-1301

    Last Modified: 21 Nov 2024

    The WP Contact Slider WordPress plugin before 2.4.7 does not sanitize and escape the Text to Display settings of sliders, which could allow high privileged users such as editor and above to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

    Published: 4 Jul 2022
    6.1
    Medium

    CVE-2022-0250

    Last Modified: 21 Nov 2024

    The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it in an attribute, leading to a Reflected Cross-Site Scripting

    Published: 4 Jul 2022
    4.8
    Medium

    CVE-2021-25066

    Last Modified: 21 Nov 2024

    The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 4 Jul 2022
    4.8
    Medium

    CVE-2021-25056

    Last Modified: 21 Nov 2024

    The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitise and escape field labels, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 4 Jul 2022
    5.4
    Medium

    CVE-2022-2300

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.

    Published: 4 Jul 2022
    5.5
    Medium

    CVE-2022-2301

    Last Modified: 21 Nov 2024

    Buffer Over-read in GitHub repository hpjansson/chafa prior to 1.10.3.

    Published: 4 Jul 2022
    7.8
    High

    CVE-2022-33743

    Last Modified: 21 Nov 2024

    network backend may cause Linux netfront to use freed SKBs While adding logic to support XDP (eXpress Data Path), a code label was moved in a way allowing for SKBs having references (pointers) retained for further processing to nevertheless be freed.

    Published: 4 Jul 2022
    6.5
    Medium

    CVE-2022-29892

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in Space of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to repeatedly display errors in certain functions and cause a denial-of-service (DoS).

    Published: 4 Jul 2022
    4.8
    Medium

    CVE-2022-29513

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote authenticated attacker with an administrative privilege to execute an arbitrary script.

    Published: 4 Jul 2022
    8.1
    High

    CVE-2022-29484

    Last Modified: 21 Nov 2024

    Operation restriction bypass vulnerability in Space of Cybozu Garoon 4.0.0 to 5.9.0 allows a remote authenticated attacker to delete the data of Space.

    Published: 4 Jul 2022
    4.3
    Medium

    CVE-2022-29471

    Last Modified: 21 Nov 2024

    Browse restriction bypass vulnerability in Bulletin of Cybozu Garoon allows a remote authenticated attacker to obtain the data of Bulletin.

    Published: 4 Jul 2022
    4.3
    Medium

    CVE-2022-29467

    Last Modified: 21 Nov 2024

    Address information disclosure vulnerability in Cybozu Garoon 4.2.0 to 5.5.1 allows a remote authenticated attacker to obtain some data of Address.

    Published: 4 Jul 2022
    4.3
    Medium

    CVE-2022-28718

    Last Modified: 21 Nov 2024

    Operation restriction bypass vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.5.1 allow a remote authenticated attacker to alter the data of Bulletin.

    Published: 4 Jul 2022
    5.3
    Medium

    CVE-2022-28713

    Last Modified: 21 Nov 2024

    Improper authentication vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote attacker to obtain some data of Facility Information without logging in to the product.

    Published: 4 Jul 2022
    4.3
    Medium

    CVE-2022-28692

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in Scheduler of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Scheduler.

    Published: 4 Jul 2022
    4.3
    Medium

    CVE-2022-27807

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in Link of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to disable to add Categories.

    Published: 4 Jul 2022