CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2022-27803

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in Space of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Space.

    Published: 4 Jul 2022
    4.3
    Medium

    CVE-2022-27661

    Last Modified: 21 Nov 2024

    Operation restriction bypass vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Workflow.

    Published: 4 Jul 2022
    6.1
    Medium

    CVE-2022-27627

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Organization's Information of Cybozu Garoon 4.10.2 to 5.5.1 allows a remote attacker to execute an arbitrary script on the logged-in user's web browser.

    Published: 4 Jul 2022
    5.4
    Medium

    CVE-2022-26368

    Last Modified: 21 Nov 2024

    Browse restriction bypass and operation restriction bypass vulnerability in Cabinet of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter and/or obtain the data of Cabinet.

    Published: 4 Jul 2022
    4.3
    Medium

    CVE-2022-26054

    Last Modified: 21 Nov 2024

    Operation restriction bypass vulnerability in Link of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Link.

    Published: 4 Jul 2022
    4.3
    Medium

    CVE-2022-26051

    Last Modified: 21 Nov 2024

    Operation restriction bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Portal.

    Published: 4 Jul 2022
    8.1
    High

    CVE-2022-34151

    Last Modified: 2 Jun 2026

    Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, Automation software 'Sysmac Studio' all models V1.49 and earlier, and Programmable Terminal (PT) NA series NA5-15W/NA5-12W/NA5-9W/NA5-7W models Runtime V1.15 and earlier, which may allow a remote attacker who successfully obtained the user credentials by analyzing the affected product to access the controller.

    Published: 4 Jul 2022
    7.5
    High

    CVE-2022-33971

    Last Modified: 2 Jun 2026

    Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine automation controller NJ series all models V 1.48 and earlier, which may allow an adjacent attacker who can analyze the communication between the controller and the specific software used by OMRON internally to cause a denial-of-service (DoS) condition or execute a malicious program.

    Published: 4 Jul 2022
    8.8
    High

    CVE-2022-33948

    Last Modified: 21 Nov 2024

    HOME SPOT CUBE2 V102 contains an OS command injection vulnerability due to improper processing of data received from DHCP server. An adjacent attacker may execute an arbitrary OS command on the product if a malicious DHCP server is placed on the WAN side of the product.

    Published: 4 Jul 2022
    8.1
    High

    CVE-2022-33208

    Last Modified: 21 Nov 2024

    Authentication bypass by capture-replay vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, Automation software 'Sysmac Studio' all models V1.49 and earlier, and Programmable Terminal (PT) NA series NA5-15W/NA5-12W/NA5-9W/NA5-7W models Runtime V1.15 and earlier, which may allow a remote attacker who can analyze the communication between the affected controller and automation software 'Sysmac Studio' and/or a Programmable Terminal (PT) to access the controller.

    Published: 4 Jul 2022
    7.5
    High

    CVE-2022-32284

    Last Modified: 21 Nov 2024

    Use of insufficiently random values vulnerability exists in Vnet/IP communication module VI461 of YOKOGAWA Wide Area Communication Router (WAC Router) AW810D, which may allow a remote attacker to cause denial-of-service (DoS) condition by sending a specially crafted packet.

    Published: 4 Jul 2022
    8.8
    High

    CVE-2022-32792

    Last Modified: 22 May 2025

    An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 4 Jul 2022
    6.5
    Medium

    CVE-2022-32816

    Last Modified: 22 May 2025

    The issue was addressed with improved UI handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. Visiting a website that frames malicious content may lead to UI spoofing.

    Published: 4 Jul 2022
    9.8
    Critical

    CVE-2022-34265

    Last Modified: 13 Feb 2025

    An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected.

    Published: 4 Jul 2022
    6.1
    Medium

    CVE-2022-2290

    Last Modified: 23 Feb 2026

    Cross-site Scripting (XSS) - Reflected in GitHub repository zadam/trilium prior to 0.52.4, 0.53.1-beta.

    Published: 3 Jul 2022
    7.8
    High

    CVE-2022-2288

    Last Modified: 21 Nov 2024

    Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.

    Published: 3 Jul 2022
    7.8
    High

    CVE-2022-2289

    Last Modified: 21 Nov 2024

    Use After Free in GitHub repository vim/vim prior to 9.0.

    Published: 3 Jul 2022
    9.8
    Critical

    CVE-2022-34913

    Last Modified: 21 Nov 2024

    md2roff 1.7 has a stack-based buffer overflow via a Markdown file containing a large number of consecutive characters to be processed. NOTE: the vendor's position is that the product is not intended for untrusted input

    Published: 2 Jul 2022
    7.8
    High

    CVE-2022-34918

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but must start with an unprivileged user namespace to obtain CAP_NET_ADMIN access.) This can be fixed in nft_setelem_parse_data in net/netfilter/nf_tables_api.c.

    Published: 2 Jul 2022
    —
    Unknown

    CVE-2022-33016

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 2 Jul 2022
    —
    Unknown

    CVE-2022-33014

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 2 Jul 2022
    —
    Unknown

    CVE-2022-33015

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 2 Jul 2022
    —
    Unknown

    CVE-2022-34863

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 2 Jul 2022
    —
    Unknown

    CVE-2022-34856

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 2 Jul 2022
    —
    Unknown

    CVE-2022-33197

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 2 Jul 2022
    —
    Unknown

    CVE-2022-32581

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 2 Jul 2022
    8.2
    High

    CVE-2022-28200

    Last Modified: 21 Nov 2024

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the BiosCfgTool, where a local user with elevated privileges can read and write beyond intended bounds in SMRAM, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.

    Published: 2 Jul 2022
    7.8
    High

    CVE-2022-2284

    Last Modified: 21 Nov 2024

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.

    Published: 2 Jul 2022
    7.1
    High

    CVE-2022-2287

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

    Published: 2 Jul 2022
    5.9
    Medium

    CVE-2022-31117

    Last Modified: 23 Apr 2025

    UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. In versions prior to 5.4.0 an error occurring while reallocating a buffer for string decoding can cause the buffer to get freed twice. Due to how UltraJSON uses the internal decoder, this double free is impossible to trigger from Python. This issue has been resolved in version 5.4.0 and all users should upgrade to UltraJSON 5.4.0. There are no known workarounds for this issue.

    Published: 2 Jul 2022
    6.1
    Medium

    CVE-2022-34911

    Last Modified: 21 Nov 2024

    An issue was discovered in MediaWiki before 1.35.7, 1.36.x and 1.37.x before 1.37.3, and 1.38.x before 1.38.1. XSS can occur in configurations that allow a JavaScript payload in a username. After account creation, when it sets the page title to "Welcome" followed by the username, the username is not escaped: SpecialCreateAccount::successfulAction() calls ::showSuccessPage() with a message as second parameter, and OutputPage::setPageTitle() uses text().

    Published: 2 Jul 2022
    6.1
    Medium

    CVE-2022-34912

    Last Modified: 21 Nov 2024

    An issue was discovered in MediaWiki before 1.37.3 and 1.38.x before 1.38.1. The contributions-title, used on Special:Contributions, is used as page title without escaping. Hence, in a non-default configuration where a username contains HTML entities, it won't be escaped.

    Published: 2 Jul 2022
    7.8
    High

    CVE-2022-2285

    Last Modified: 21 Nov 2024

    Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.

    Published: 2 Jul 2022
    7.8
    High

    CVE-2022-2286

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

    Published: 2 Jul 2022
    7.5
    High

    CVE-2022-31116

    Last Modified: 22 Apr 2025

    UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Affected versions were found to improperly decode certain characters. JSON strings that contain escaped surrogate characters not part of a proper surrogate pair were decoded incorrectly. Besides corrupting strings, this allowed for potential key confusion and value overwriting in dictionaries. All users parsing JSON from untrusted sources are vulnerable. From version 5.4.0, UltraJSON decodes lone surrogates in the same way as the standard library's `json` module does, preserving them in the parsed output. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 2 Jul 2022
    7.5
    High

    CVE-2022-32551

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ServiceDesk Plus MSP before 10604 allows path traversal (to WEBINF/web.xml from sample/WEB-INF/web.xml or sample/META-INF/web.xml).

    Published: 1 Jul 2022
    7.2
    High

    CVE-2022-32412

    Last Modified: 21 Nov 2024

    An issue in the /template/edit component of HongCMS v3.0 allows attackers to getshell.

    Published: 1 Jul 2022
    7.2
    High

    CVE-2022-32411

    Last Modified: 21 Nov 2024

    An issue in the languages config file of HongCMS v3.0 allows attackers to getshell.

    Published: 1 Jul 2022
    9.8
    Critical

    CVE-2022-32324

    Last Modified: 21 Nov 2024

    PDFAlto v0.4 was discovered to contain a heap buffer overflow via the component /pdfalto/src/pdfalto.cc.

    Published: 1 Jul 2022
    9.8
    Critical

    CVE-2022-32095

    Last Modified: 21 Nov 2024

    Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at orders.php.

    Published: 1 Jul 2022
    9.8
    Critical

    CVE-2022-32094

    Last Modified: 21 Nov 2024

    Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doctorlogin.php.

    Published: 1 Jul 2022
    9.8
    Critical

    CVE-2022-32093

    Last Modified: 21 Nov 2024

    Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at adminlogin.php.

    Published: 1 Jul 2022
    8.8
    High

    CVE-2022-32420

    Last Modified: 21 Nov 2024

    College Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /College/admin/teacher.php. This vulnerability is exploited via a crafted PHP file.

    Published: 1 Jul 2022
    8.8
    High

    CVE-2022-32384

    Last Modified: 21 Nov 2024

    Tenda AC23 v16.03.07.44 was discovered to contain a stack overflow via the security_5g parameter in the function formWifiBasicSet.

    Published: 1 Jul 2022
    9.8
    Critical

    CVE-2022-31943

    Last Modified: 21 Nov 2024

    MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.

    Published: 1 Jul 2022
    4.8
    Medium

    CVE-2022-25896

    Last Modified: 21 Nov 2024

    This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.

    Published: 1 Jul 2022
    8.1
    High

    CVE-2022-25900

    Last Modified: 21 Nov 2024

    All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git.

    Published: 1 Jul 2022
    7.7
    High

    CVE-2022-25898

    Last Modified: 21 Nov 2024

    The package jsrsasign before 10.5.25 are vulnerable to Improper Verification of Cryptographic Signature when JWS or JWT signature with non Base64URL encoding special characters or number escaped characters may be validated as valid by mistake. Workaround: Validate JWS or JWT signature if it has Base64URL and dot safe string before executing JWS.verify() or JWS.verifyJWT() method.

    Published: 1 Jul 2022
    6.2
    Medium

    CVE-2022-25876

    Last Modified: 21 Nov 2024

    The package link-preview-js before 2.1.16 are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to send arbitrary requests to the local network and read the response. This is due to flawed DNS rebinding protection.

    Published: 1 Jul 2022
    5.4
    Medium

    CVE-2022-22373

    Last Modified: 21 Nov 2024

    An improper validation vulnerability in IBM InfoSphere Information Server 11.7 Pack for SAP Apps and BW Packs may lead to creation of directories and files on the server file system that may contain non-sensitive debugging information like stack traces. IBM X-Force ID: 221323.

    Published: 1 Jul 2022