CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-2210

    Last Modified: 21 Nov 2024

    Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.

    Published: 27 Jun 2022
    7.8
    High

    CVE-2022-2207

    Last Modified: 21 Nov 2024

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

    Published: 27 Jun 2022
    5.5
    Medium

    CVE-2022-2208

    Last Modified: 21 Nov 2024

    NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.5163.

    Published: 27 Jun 2022
    7.7
    High

    CVE-2022-31090

    Last Modified: 23 Apr 2025

    Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handler, it is possible to use the `CURLOPT_HTTPAUTH` option to specify an `Authorization` header. On making a request which responds with a redirect to a URI with a different origin (change in host, scheme or port), if we choose to follow it, we should remove the `CURLOPT_HTTPAUTH` option before continuing, stopping curl from appending the `Authorization` header to the new request. Affected Guzzle 7 users should upgrade to Guzzle 7.4.5 as soon as possible. Affected users using any earlier series of Guzzle should upgrade to Guzzle 6.5.8 or 7.4.5. Note that a partial fix was implemented in Guzzle 7.4.2, where a change in host would trigger removal of the curl-added Authorization header, however this earlier fix did not cover change in scheme or change in port. If you do not require or expect redirects to be followed, one should simply disable redirects all together. Alternatively, one can specify to use the Guzzle steam handler backend, rather than curl.

    Published: 27 Jun 2022
    7.7
    High

    CVE-2022-31091

    Last Modified: 23 Apr 2025

    Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. In affected versions on making a request which responds with a redirect to a URI with a different port, if we choose to follow it, we should remove the `Authorization` and `Cookie` headers from the request, before containing. Previously, we would only consider a change in host or scheme. Affected Guzzle 7 users should upgrade to Guzzle 7.4.5 as soon as possible. Affected users using any earlier series of Guzzle should upgrade to Guzzle 6.5.8 or 7.4.5. Note that a partial fix was implemented in Guzzle 7.4.2, where a change in host would trigger removal of the curl-added Authorization header, however this earlier fix did not cover change in scheme or change in port. An alternative approach would be to use your own redirect middleware, rather than ours, if you are unable to upgrade. If you do not require or expect redirects to be followed, one should simply disable redirects all together.

    Published: 27 Jun 2022
    4.3
    Medium

    CVE-2022-32205

    Last Modified: 5 May 2025

    A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the cookies match, create requests that become larger than the threshold that curl uses internally to avoid sending crazy large requests (1048576 bytes) and instead returns an error.This denial state might remain for as long as the same cookies are kept, match and haven't expired. Due to cookie matching rules, a server on `foo.example.com` can set cookies that also would match for `bar.example.com`, making it it possible for a "sister server" to effectively cause a denial of service for a sibling site on the same second level domain using this method.

    Published: 27 Jun 2022
    6.5
    Medium

    CVE-2022-32206

    Last Modified: 5 May 2025

    curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a "malloc bomb", makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.

    Published: 27 Jun 2022
    9.8
    Critical

    CVE-2022-32207

    Last Modified: 23 Apr 2025

    When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.

    Published: 27 Jun 2022
    6.1
    Medium

    CVE-2022-2217

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Generic in GitHub repository ionicabizau/parse-url prior to 7.0.0.

    Published: 27 Jun 2022
    7.3
    High

    CVE-2022-31081

    Last Modified: 22 Apr 2025

    HTTP::Daemon is a simple http server class written in perl. Versions prior to 6.15 are subject to a vulnerability which could potentially be exploited to gain privileged access to APIs or poison intermediate caches. It is uncertain how large the risks are, most Perl based applications are served on top of Nginx or Apache, not on the `HTTP::Daemon`. This library is commonly used for local development and tests. Users are advised to update to resolve this issue. Users unable to upgrade may add additional request handling logic as a mitigation. After calling `my $rqst = $conn->get_request()` one could inspect the returned `HTTP::Request` object. Querying the 'Content-Length' (`my $cl = $rqst->header('Content-Length')`) will show any abnormalities that should be dealt with by a `400` response. Expected strings of 'Content-Length' SHOULD consist of either a single non-negative integer, or, a comma separated repetition of that number. (that is `42` or `42, 42, 42`). Anything else MUST be rejected.

    Published: 27 Jun 2022
    5.9
    Medium

    CVE-2022-32208

    Last Modified: 5 May 2025

    When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.

    Published: 27 Jun 2022
    —
    Unknown

    CVE-2022-30932

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 26 Jun 2022
    5.4
    Medium

    CVE-2020-27509

    Last Modified: 4 Jul 2026

    Persistent XSS in Galaxkey Secure Mail Client in Galaxkey up to 5.6.11.5 allows an attacker to perform an account takeover by intercepting the HTTP Post request when sending an email and injecting a specially crafted XSS payload in the 'subject' field. The payload executes when the recipient logs into their mailbox.

    Published: 26 Jun 2022
    7.8
    High

    CVE-2022-2206

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

    Published: 26 Jun 2022
    5.5
    Medium

    CVE-2022-34495

    Last Modified: 21 Nov 2024

    rpmsg_probe in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free.

    Published: 26 Jun 2022
    —
    Unknown

    CVE-2022-34623

    Last Modified: 7 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-32425. Reason: This candidate is a duplicate of CVE-2022-32425. Notes: All CVE users should reference CVE-2022-32425 instead of this candidate.

    Published: 26 Jun 2022
    5.5
    Medium

    CVE-2022-35205

    Last Modified: 21 Nov 2024

    An issue was discovered in Binutils readelf 2.38.50, reachable assertion failure in function display_debug_names allows attackers to cause a denial of service.

    Published: 26 Jun 2022
    5.5
    Medium

    CVE-2022-35206

    Last Modified: 21 Nov 2024

    Null pointer dereference vulnerability in Binutils readelf 2.38.50 via function read_and_display_attr_value in file dwarf.c.

    Published: 26 Jun 2022
    —
    Unknown

    CVE-2022-34491

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-29969. Reason: This candidate is a duplicate of CVE-2022-29969. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2022-29969 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 25 Jun 2022
    6.1
    Medium

    CVE-2022-29931

    Last Modified: 30 May 2025

    The administration interface of the Raytion Custom Security Manager (Raytion CSM) in Version 7.2.0 allows reflected Cross-site Scripting (XSS).

    Published: 25 Jun 2022
    2
    Low

    CVE-2022-31017

    Last Modified: 23 Apr 2025

    Zulip is an open-source team collaboration tool. Versions 2.1.0 through and including 5.2 are vulnerable to a logic error. A stream configured as private with protected history, where new subscribers should not be allowed to see messages sent before they were subscribed, when edited causes the server to incorrectly send an API event that includes the edited message to all of the stream’s current subscribers. This API event is ignored by official clients, but can be observed by using a modified client or the browser’s developer tools. This bug will be fixed in Zulip Server 5.3. There are no known workarounds.

    Published: 25 Jun 2022
    9.6
    Critical

    CVE-2022-29168

    Last Modified: 23 Apr 2025

    Wire is a secure messaging application. Wire is vulnerable to arbitrary HTML and Javascript execution via insufficient escaping when rendering `@mentions` in the wire-webapp. If a user receives and views a malicious message, arbitrary code is injected and executed in the context of the victim allowing the attacker to fully control the user account. Wire-desktop clients that are connected to a vulnerable wire-webapp version are also vulnerable to this attack. The issue has been fixed in wire-webapp 2022-05-04-production.0 and is already deployed on all Wire managed services. On-premise instances of wire-webapp need to be updated to docker tag 2022-05-04-production.0-v0.29.7-0-a6f2ded or wire-server 2022-05-04 (chart/4.11.0) or later. No known workarounds exist.

    Published: 25 Jun 2022
    7.5
    High

    CVE-2022-24893

    Last Modified: 23 Apr 2025

    ESP-IDF is the official development framework for Espressif SoCs. In Espressif’s Bluetooth Mesh SDK (`ESP-BLE-MESH`), a memory corruption vulnerability can be triggered during provisioning, because there is no check for the `SegN` field of the Transaction Start PDU. This can result in memory corruption related attacks and potentially attacker gaining control of the entire system. Patch commits are available on the 4.1, 4.2, 4.3 and 4.4 branches and users are recommended to upgrade. The upgrade is applicable for all applications and users of `ESP-BLE-MESH` component from `ESP-IDF`. As it is implemented in the Bluetooth Mesh stack, there is no workaround for the user to fix the application layer without upgrading the underlying firmware.

    Published: 25 Jun 2022
    6.3
    Medium

    CVE-2019-25071

    Last Modified: 30 May 2025

    A vulnerability was found in Apple iPhone up to 12.4.1. It has been declared as critical. Affected by this vulnerability is Siri. Playing an audio or video file might be able to initiate Siri on the same device which makes it possible to execute commands remotely. Exploit details have been disclosed to the public. The existence and implications of this vulnerability are doubted by Apple even though multiple public videos demonstrating the attack exist. Upgrading to version 13.0 migt be able to address this issue. It is recommended to upgrade affected devices. NOTE: Apple claims, that after examining the report they do not see any actual security implications.

    Published: 25 Jun 2022
    9.1
    Critical

    CVE-2022-33128

    Last Modified: 21 Nov 2024

    RG-EG series gateway EG350 EG_RGOS 11.1(6) was discovered to contain a SQL injection vulnerability via the function get_alarmAction at /alarm_pi/alarmService.php.

    Published: 25 Jun 2022
    7.5
    High

    CVE-2021-40894

    Last Modified: 21 Nov 2024

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in underscore-99xp v1.7.2 when the deepValueSearch function is called.

    Published: 24 Jun 2022
    4.8
    Medium

    CVE-2022-33122

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in eyoucms v1.5.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL field under the login page.

    Published: 24 Jun 2022
    8.1
    High

    CVE-2022-33121

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-30885

    Last Modified: 21 Nov 2024

    The pyesasky for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2.0-1.4.2.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-34066

    Last Modified: 21 Nov 2024

    The Texercise package in PyPI v0.0.1 to v0.0.12 was discovered to contain a code execution backdoor. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-34065

    Last Modified: 21 Nov 2024

    The Rondolu-YT-Concate package in PyPI v0.1.0 was discovered to contain a code execution backdoor. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-34064

    Last Modified: 21 Nov 2024

    The Zibal package in PyPI v1.0.0 was discovered to contain a code execution backdoor. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-34061

    Last Modified: 21 Nov 2024

    The Catly-Translate package in PyPI v0.0.3 to v0.0.5 was discovered to contain a code execution backdoor. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-34060

    Last Modified: 21 Nov 2024

    The Togglee package in PyPI version v0.0.8 was discovered to contain a code execution backdoor. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-34059

    Last Modified: 21 Nov 2024

    The Sixfab-Tool in PyPI v0.0.2 to v0.0.3 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-34057

    Last Modified: 21 Nov 2024

    The Scoptrial package in PyPI version v0.0.5 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-34056

    Last Modified: 21 Nov 2024

    The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-34054

    Last Modified: 21 Nov 2024

    The Perdido package in PyPI v0.0.1 to v0.0.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-34055

    Last Modified: 21 Nov 2024

    The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-34053

    Last Modified: 21 Nov 2024

    The DR-Web-Engine package in PyPI v0.2.0b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-33004

    Last Modified: 21 Nov 2024

    The Beginner package in PyPI v0.0.2 to v0.0.4 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-33002

    Last Modified: 21 Nov 2024

    The KGExplore package in PyPI v0.1.1 to v0.1.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-33003

    Last Modified: 21 Nov 2024

    The watools package in PyPI v0.0.1 to v0.0.8 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-33000

    Last Modified: 21 Nov 2024

    The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-33001

    Last Modified: 21 Nov 2024

    The AAmiles package in PyPI v0.1.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-32998

    Last Modified: 21 Nov 2024

    The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-32999

    Last Modified: 21 Nov 2024

    The cloudlabeling package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-32997

    Last Modified: 21 Nov 2024

    The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-32996

    Last Modified: 21 Nov 2024

    The django-navbar-client package of v0.9.50 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

    Published: 24 Jun 2022
    7.5
    High

    CVE-2022-21231

    Last Modified: 21 Nov 2024

    All versions of package deep-get-set are vulnerable to Prototype Pollution via the 'deep' function. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7715](https://security.snyk.io/vuln/SNYK-JS-DEEPGETSET-598666)

    Published: 24 Jun 2022