CVE-2022-22953
Last Modified: 21 Nov 2024VMware HCX update addresses an information disclosure vulnerability. A malicious actor with network user access to the VMware HCX appliance may be able to gain access to sensitive information.
CVE-2022-27532
Last Modified: 21 Nov 2024A maliciously crafted TIF file in Autodesk 3ds Max 2022 and 2021 can be used to write beyond the allocated buffer while parsing TIF files. This vulnerability in conjunction with other vulnerabilities could lead to arbitrary code execution.
CVE-2022-27531
Last Modified: 21 Nov 2024A maliciously crafted TIF file can be forced to read beyond allocated boundaries in Autodesk 3ds Max 2022, and 2021 when parsing the TIF files. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
CVE-2022-31914
Last Modified: 21 Nov 2024Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via zms/admin/public_html/save_animal?an_id=24.
CVE-2022-31913
Last Modified: 22 Apr 2025Online Discussion Forum Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /odfs/classes/Master.php?f=save_category, name.
CVE-2022-31912
Last Modified: 21 Nov 2024Online Tutor Portal Site v1.0 is vulnerable to SQL Injection via /otps/classes/Master.php?f=delete_team.
CVE-2022-31911
Last Modified: 22 Apr 2025Online Discussion Forum Site v1.0 is vulnerable to SQL Injection via /odfs/classes/Master.php?f=delete_team.
CVE-2022-31910
Last Modified: 21 Nov 2024Online Tutor Portal Site v1.0 is vulnerable to Cross Site Scripting (XSS). via /otps/classes/Master.php.
CVE-2022-31849
Last Modified: 21 Nov 2024MERCURY MIPC451-4 1.0.22 Build 220105 Rel.55642n was discovered to contain a remote code execution (RCE) vulnerability which is exploitable via a crafted POST request.
CVE-2022-31277
Last Modified: 21 Nov 2024Xiaomi Lamp 1 v2.0.4_0066 was discovered to be vulnerable to replay attacks. This allows attackers to to bypass the expected access restrictions and gain control of the switch and other functions via a crafted POST request.
CVE-2022-31908
Last Modified: 21 Nov 2024Student Registration and Fee Payment System v1.0 is vulnerable to SQL Injection via /scms/student.php.
CVE-2022-31906
Last Modified: 21 Nov 2024Online Fire Reporting System v1.0 is vulnerable to Cross Site Scripting (XSS) via /ofrs/classes/Master.php.
CVE-2022-30023
Last Modified: 21 Nov 2024Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.
CVE-2022-31300
Last Modified: 21 Nov 2024A cross-site scripting vulnerability in the DM Section component of Haraj v3.7 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.
CVE-2022-31372
Last Modified: 21 Nov 2024Wiris Mathtype v7.28.0 was discovered to contain a path traversal vulnerability in the resourceFile parameter. This vulnerability is exploited via a crafted request to the resource handler.
CVE-2017-20056
Last Modified: 15 Apr 2025A vulnerability was found in weblizar User Login Log Plugin 2.2.1. It has been classified as problematic. Affected is an unknown function. The manipulation leads to basic cross site scripting (Stored). It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2017-20055
Last Modified: 15 Apr 2025A vulnerability classified as problematic has been found in BestWebSoft Contact Form Plugin 4.0.0. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.0.2 is able to address this issue. It is recommended to upgrade the affected component.
CVE-2017-20054
Last Modified: 15 Apr 2025A vulnerability was found in XYZScripts Contact Form Manager Plugin. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2017-20053
Last Modified: 15 Apr 2025A vulnerability was found in XYZScripts Contact Form Manager Plugin. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2021-41654
Last Modified: 21 Nov 2024SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php
CVE-2022-2098
Last Modified: 21 Nov 2024Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1.
CVE-2021-41402
Last Modified: 21 Nov 2024flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP code.
CVE-2021-41458
Last Modified: 21 Nov 2024In GPAC MP4Box v1.1.0, there is a stack buffer overflow at src/utils/error.c:1769 which leads to a denial of service vulnerability.
CVE-2017-20052
Last Modified: 15 Apr 2025A vulnerability classified as problematic was found in Python 2.7.13. This vulnerability affects unknown code of the component pgAdmin4. The manipulation leads to uncontrolled search path. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2017-20051
Last Modified: 30 Sept 2026** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The sole source documents PE-format conformance defects in innosetup-5.5.9.exe with no exploit, attack path, or untrusted search path condition (CWE-426/427), and the author states Windows loads these files normally; the record's remote/exploited claims are unsupported, as is the product maintainer's contention.
CVE-2022-30549
Last Modified: 21 Nov 2024Out-of-bounds read vulnerability exists in V-Server v4.0.11.0 and earlier and V-Server Lite v4.0.13.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.
CVE-2022-30546
Last Modified: 21 Nov 2024Out-of-bounds read vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.
CVE-2022-30538
Last Modified: 21 Nov 2024Out-of-bounds write vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.
CVE-2022-30533
Last Modified: 21 Nov 2024Cross-site scripting vulnerability in Modern Events Calendar Lite versions prior to 6.3.0 allows remote an authenticated attacker to inject an arbitrary script via unspecified vectors.
CVE-2022-47007
Last Modified: 21 Nov 2024An issue was discovered function stab_demangle_v3_arg in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
CVE-2022-47008
Last Modified: 21 Nov 2024An issue was discovered function make_tempdir, and make_tempname in bucomm.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
CVE-2022-31291
Last Modified: 21 Nov 2024An issue in dlt_config_file_parser.c of dlt-daemon v2.18.8 allows attackers to cause a double free via crafted TCP packets.
CVE-2022-3479
Last Modified: 21 Nov 2024A vulnerability found in nss. By this security vulnerability, nss client auth crash without a user certificate in the database and this can lead us to a segmentation fault or crash.
CVE-2022-31071
Last Modified: 23 Apr 2025Octopoller is a micro gem for polling and retrying. Version 0.2.0 of the octopoller gem was published containing world-writeable files. Specifically, the gem was packed with files having their permissions set to `-rw-rw-rw-` (i.e. 0666) instead of `rw-r--r--` (i.e. 0644). This means everyone who is not the owner (Group and Public) with access to the instance where this release had been installed could modify the world-writable files from this gem. This issue is patched in Octopoller 0.3.0. Two workarounds are available. Users can use the previous version of the gem, v0.1.0. Alternatively, users can modify the file permissions manually until they are able to upgrade to the latest version.
CVE-2022-31072
Last Modified: 23 Apr 2025Octokit is a Ruby toolkit for the GitHub API. Versions 4.23.0 and 4.24.0 of the octokit gem were published containing world-writeable files. Specifically, the gem was packed with files having their permissions set to `-rw-rw-rw-` (i.e. 0666) instead of `rw-r--r--` (i.e. 0644). This means everyone who is not the owner (Group and Public) with access to the instance where this release had been installed could modify the world-writable files from this gem. This issue is patched in Octokit 4.25.0. Two workarounds are available. Users can use the previous version of the gem, v4.22.0. Alternatively, users can modify the file permissions manually until they are able to upgrade to the latest version.
CVE-2022-30193
Last Modified: 2 Jan 2025AV1 Video Extension Remote Code Execution Vulnerability
CVE-2022-30189
Last Modified: 2 Jan 2025Windows Autopilot Device Management and Enrollment Client Spoofing Vulnerability
CVE-2022-30188
Last Modified: 2 Jan 2025HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2022-30180
Last Modified: 2 Jan 2025Azure RTOS GUIX Studio Information Disclosure Vulnerability
CVE-2022-30179
Last Modified: 2 Jan 2025Azure RTOS GUIX Studio Remote Code Execution Vulnerability
CVE-2022-30178
Last Modified: 2 Jan 2025Azure RTOS GUIX Studio Remote Code Execution Vulnerability
CVE-2022-30177
Last Modified: 2 Jan 2025Azure RTOS GUIX Studio Remote Code Execution Vulnerability
CVE-2022-30174
Last Modified: 2 Jan 2025Microsoft Office Remote Code Execution Vulnerability
CVE-2022-30173
Last Modified: 2 Jan 2025Microsoft Excel Remote Code Execution Vulnerability
CVE-2022-30172
Last Modified: 2 Jan 2025Microsoft Office Information Disclosure Vulnerability
CVE-2022-30171
Last Modified: 2 Jan 2025Microsoft Office Information Disclosure Vulnerability
CVE-2022-30168
Last Modified: 2 Jan 2025Microsoft Photos App Remote Code Execution Vulnerability
CVE-2022-30167
Last Modified: 2 Jan 2025AV1 Video Extension Remote Code Execution Vulnerability
CVE-2022-30166
Last Modified: 2 Jan 2025Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
CVE-2022-30165
Last Modified: 16 Dec 2025Windows Kerberos Elevation of Privilege Vulnerability
