CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2022-22953

    Last Modified: 21 Nov 2024

    VMware HCX update addresses an information disclosure vulnerability. A malicious actor with network user access to the VMware HCX appliance may be able to gain access to sensitive information.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-27532

    Last Modified: 21 Nov 2024

    A maliciously crafted TIF file in Autodesk 3ds Max 2022 and 2021 can be used to write beyond the allocated buffer while parsing TIF files. This vulnerability in conjunction with other vulnerabilities could lead to arbitrary code execution.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-27531

    Last Modified: 21 Nov 2024

    A maliciously crafted TIF file can be forced to read beyond allocated boundaries in Autodesk 3ds Max 2022, and 2021 when parsing the TIF files. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 16 Jun 2022
    5.4
    Medium

    CVE-2022-31914

    Last Modified: 21 Nov 2024

    Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via zms/admin/public_html/save_animal?an_id=24.

    Published: 16 Jun 2022
    4.8
    Medium

    CVE-2022-31913

    Last Modified: 22 Apr 2025

    Online Discussion Forum Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /odfs/classes/Master.php?f=save_category, name.

    Published: 16 Jun 2022
    7.2
    High

    CVE-2022-31912

    Last Modified: 21 Nov 2024

    Online Tutor Portal Site v1.0 is vulnerable to SQL Injection via /otps/classes/Master.php?f=delete_team.

    Published: 16 Jun 2022
    7.2
    High

    CVE-2022-31911

    Last Modified: 22 Apr 2025

    Online Discussion Forum Site v1.0 is vulnerable to SQL Injection via /odfs/classes/Master.php?f=delete_team.

    Published: 16 Jun 2022
    4.8
    Medium

    CVE-2022-31910

    Last Modified: 21 Nov 2024

    Online Tutor Portal Site v1.0 is vulnerable to Cross Site Scripting (XSS). via /otps/classes/Master.php.

    Published: 16 Jun 2022
    8.8
    High

    CVE-2022-31849

    Last Modified: 21 Nov 2024

    MERCURY MIPC451-4 1.0.22 Build 220105 Rel.55642n was discovered to contain a remote code execution (RCE) vulnerability which is exploitable via a crafted POST request.

    Published: 16 Jun 2022
    8.8
    High

    CVE-2022-31277

    Last Modified: 21 Nov 2024

    Xiaomi Lamp 1 v2.0.4_0066 was discovered to be vulnerable to replay attacks. This allows attackers to to bypass the expected access restrictions and gain control of the switch and other functions via a crafted POST request.

    Published: 16 Jun 2022
    7.2
    High

    CVE-2022-31908

    Last Modified: 21 Nov 2024

    Student Registration and Fee Payment System v1.0 is vulnerable to SQL Injection via /scms/student.php.

    Published: 16 Jun 2022
    4.8
    Medium

    CVE-2022-31906

    Last Modified: 21 Nov 2024

    Online Fire Reporting System v1.0 is vulnerable to Cross Site Scripting (XSS) via /ofrs/classes/Master.php.

    Published: 16 Jun 2022
    8.8
    High

    CVE-2022-30023

    Last Modified: 21 Nov 2024

    Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.

    Published: 16 Jun 2022
    5.4
    Medium

    CVE-2022-31300

    Last Modified: 21 Nov 2024

    A cross-site scripting vulnerability in the DM Section component of Haraj v3.7 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.

    Published: 16 Jun 2022
    7.5
    High

    CVE-2022-31372

    Last Modified: 21 Nov 2024

    Wiris Mathtype v7.28.0 was discovered to contain a path traversal vulnerability in the resourceFile parameter. This vulnerability is exploited via a crafted request to the resource handler.

    Published: 16 Jun 2022
    3.5
    Low

    CVE-2017-20056

    Last Modified: 15 Apr 2025

    A vulnerability was found in weblizar User Login Log Plugin 2.2.1. It has been classified as problematic. Affected is an unknown function. The manipulation leads to basic cross site scripting (Stored). It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 16 Jun 2022
    3.5
    Low

    CVE-2017-20055

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in BestWebSoft Contact Form Plugin 4.0.0. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.0.2 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 16 Jun 2022
    3.5
    Low

    CVE-2017-20054

    Last Modified: 15 Apr 2025

    A vulnerability was found in XYZScripts Contact Form Manager Plugin. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 16 Jun 2022
    4.3
    Medium

    CVE-2017-20053

    Last Modified: 15 Apr 2025

    A vulnerability was found in XYZScripts Contact Form Manager Plugin. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 16 Jun 2022
    9.8
    Critical

    CVE-2021-41654

    Last Modified: 21 Nov 2024

    SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php

    Published: 16 Jun 2022
    9.8
    Critical

    CVE-2022-2098

    Last Modified: 21 Nov 2024

    Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1.

    Published: 16 Jun 2022
    8.8
    High

    CVE-2021-41402

    Last Modified: 21 Nov 2024

    flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP code.

    Published: 16 Jun 2022
    5.5
    Medium

    CVE-2021-41458

    Last Modified: 21 Nov 2024

    In GPAC MP4Box v1.1.0, there is a stack buffer overflow at src/utils/error.c:1769 which leads to a denial of service vulnerability.

    Published: 16 Jun 2022
    5
    Medium

    CVE-2017-20052

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic was found in Python 2.7.13. This vulnerability affects unknown code of the component pgAdmin4. The manipulation leads to uncontrolled search path. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 16 Jun 2022
    —
    Unknown

    CVE-2017-20051

    Last Modified: 30 Sept 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The sole source documents PE-format conformance defects in innosetup-5.5.9.exe with no exploit, attack path, or untrusted search path condition (CWE-426/427), and the author states Windows loads these files normally; the record's remote/exploited claims are unsupported, as is the product maintainer's contention.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-30549

    Last Modified: 21 Nov 2024

    Out-of-bounds read vulnerability exists in V-Server v4.0.11.0 and earlier and V-Server Lite v4.0.13.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-30546

    Last Modified: 21 Nov 2024

    Out-of-bounds read vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-30538

    Last Modified: 21 Nov 2024

    Out-of-bounds write vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.

    Published: 16 Jun 2022
    5.4
    Medium

    CVE-2022-30533

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Modern Events Calendar Lite versions prior to 6.3.0 allows remote an authenticated attacker to inject an arbitrary script via unspecified vectors.

    Published: 16 Jun 2022
    5.5
    Medium

    CVE-2022-47007

    Last Modified: 21 Nov 2024

    An issue was discovered function stab_demangle_v3_arg in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.

    Published: 16 Jun 2022
    5.5
    Medium

    CVE-2022-47008

    Last Modified: 21 Nov 2024

    An issue was discovered function make_tempdir, and make_tempname in bucomm.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.

    Published: 16 Jun 2022
    7.5
    High

    CVE-2022-31291

    Last Modified: 21 Nov 2024

    An issue in dlt_config_file_parser.c of dlt-daemon v2.18.8 allows attackers to cause a double free via crafted TCP packets.

    Published: 16 Jun 2022
    7.5
    High

    CVE-2022-3479

    Last Modified: 21 Nov 2024

    A vulnerability found in nss. By this security vulnerability, nss client auth crash without a user certificate in the database and this can lead us to a segmentation fault or crash.

    Published: 16 Jun 2022
    2.5
    Low

    CVE-2022-31071

    Last Modified: 23 Apr 2025

    Octopoller is a micro gem for polling and retrying. Version 0.2.0 of the octopoller gem was published containing world-writeable files. Specifically, the gem was packed with files having their permissions set to `-rw-rw-rw-` (i.e. 0666) instead of `rw-r--r--` (i.e. 0644). This means everyone who is not the owner (Group and Public) with access to the instance where this release had been installed could modify the world-writable files from this gem. This issue is patched in Octopoller 0.3.0. Two workarounds are available. Users can use the previous version of the gem, v0.1.0. Alternatively, users can modify the file permissions manually until they are able to upgrade to the latest version.

    Published: 15 Jun 2022
    2.5
    Low

    CVE-2022-31072

    Last Modified: 23 Apr 2025

    Octokit is a Ruby toolkit for the GitHub API. Versions 4.23.0 and 4.24.0 of the octokit gem were published containing world-writeable files. Specifically, the gem was packed with files having their permissions set to `-rw-rw-rw-` (i.e. 0666) instead of `rw-r--r--` (i.e. 0644). This means everyone who is not the owner (Group and Public) with access to the instance where this release had been installed could modify the world-writable files from this gem. This issue is patched in Octokit 4.25.0. Two workarounds are available. Users can use the previous version of the gem, v4.22.0. Alternatively, users can modify the file permissions manually until they are able to upgrade to the latest version.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-30193

    Last Modified: 2 Jan 2025

    AV1 Video Extension Remote Code Execution Vulnerability

    Published: 15 Jun 2022
    6.5
    Medium

    CVE-2022-30189

    Last Modified: 2 Jan 2025

    Windows Autopilot Device Management and Enrollment Client Spoofing Vulnerability

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-30188

    Last Modified: 2 Jan 2025

    HEVC Video Extensions Remote Code Execution Vulnerability

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-30180

    Last Modified: 2 Jan 2025

    Azure RTOS GUIX Studio Information Disclosure Vulnerability

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-30179

    Last Modified: 2 Jan 2025

    Azure RTOS GUIX Studio Remote Code Execution Vulnerability

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-30178

    Last Modified: 2 Jan 2025

    Azure RTOS GUIX Studio Remote Code Execution Vulnerability

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-30177

    Last Modified: 2 Jan 2025

    Azure RTOS GUIX Studio Remote Code Execution Vulnerability

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-30174

    Last Modified: 2 Jan 2025

    Microsoft Office Remote Code Execution Vulnerability

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-30173

    Last Modified: 2 Jan 2025

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 15 Jun 2022
    5.5
    Medium

    CVE-2022-30172

    Last Modified: 2 Jan 2025

    Microsoft Office Information Disclosure Vulnerability

    Published: 15 Jun 2022
    5.5
    Medium

    CVE-2022-30171

    Last Modified: 2 Jan 2025

    Microsoft Office Information Disclosure Vulnerability

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-30168

    Last Modified: 2 Jan 2025

    Microsoft Photos App Remote Code Execution Vulnerability

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-30167

    Last Modified: 2 Jan 2025

    AV1 Video Extension Remote Code Execution Vulnerability

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-30166

    Last Modified: 2 Jan 2025

    Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

    Published: 15 Jun 2022
    8.8
    High

    CVE-2022-30165

    Last Modified: 16 Dec 2025

    Windows Kerberos Elevation of Privilege Vulnerability

    Published: 15 Jun 2022