CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2022-32012

    Last Modified: 21 Nov 2024

    Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/employee/index.php?view=edit&id=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32013

    Last Modified: 21 Nov 2024

    Complete Online Job Search System v1.0 is vulnerable to SQL Injection via eris/admin/category/index.php?view=edit&id=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32014

    Last Modified: 21 Nov 2024

    Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=byfunction.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32015

    Last Modified: 21 Nov 2024

    Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=category&search=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32016

    Last Modified: 21 Nov 2024

    Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=bycompany.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32017

    Last Modified: 21 Nov 2024

    Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=bytitle.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32018

    Last Modified: 21 Nov 2024

    Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=hiring&search=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-31985

    Last Modified: 21 Nov 2024

    Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=reports/daily_sales_report&date=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-31986

    Last Modified: 21 Nov 2024

    Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=reports/daily_court_rental_report&date=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-31988

    Last Modified: 21 Nov 2024

    Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/?page=reports/daily_services_report&date=.

    Published: 2 Jun 2022
    9.8
    Critical

    CVE-2022-31989

    Last Modified: 21 Nov 2024

    Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=user/manage_user&id=.

    Published: 2 Jun 2022
    9.8
    Critical

    CVE-2022-31990

    Last Modified: 21 Nov 2024

    Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/classes/Master.php?f=delete_product.

    Published: 2 Jun 2022
    9.8
    Critical

    CVE-2022-31991

    Last Modified: 21 Nov 2024

    Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/classes/Master.php?f=delete_court.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-31992

    Last Modified: 21 Nov 2024

    Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=court_rentals/view_court_rental&id=.

    Published: 2 Jun 2022
    9.8
    Critical

    CVE-2022-31993

    Last Modified: 21 Nov 2024

    Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_service.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-31994

    Last Modified: 21 Nov 2024

    Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=sales/view_details&id.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-31996

    Last Modified: 21 Nov 2024

    Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/?page=sales/manage_sale&id=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-31998

    Last Modified: 21 Nov 2024

    Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=service_transactions/view_details&id=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32000

    Last Modified: 21 Nov 2024

    Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=service_transactions/manage_service_transaction&id=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32001

    Last Modified: 21 Nov 2024

    Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/products/view_product.php?id=.

    Published: 2 Jun 2022
    9.8
    Critical

    CVE-2022-32002

    Last Modified: 21 Nov 2024

    Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/courts/manage_court.php?id=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32003

    Last Modified: 21 Nov 2024

    Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/courts/view_court.php?id=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32004

    Last Modified: 21 Nov 2024

    Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/products/manage_product.php?id=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32005

    Last Modified: 21 Nov 2024

    Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/services/manage_service.php?id=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32006

    Last Modified: 21 Nov 2024

    Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/services/view_service.php?id=.

    Published: 2 Jun 2022
    6.5
    Medium

    CVE-2022-29788

    Last Modified: 21 Nov 2024

    libmobi before v0.10 contains a NULL pointer dereference via the component mobi_buffer_getpointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mobi file.

    Published: 2 Jun 2022
    9.8
    Critical

    CVE-2019-12350

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_download.php via an id parameter value with a trailing comma.

    Published: 2 Jun 2022
    9.8
    Critical

    CVE-2019-12349

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id parameter.

    Published: 2 Jun 2022
    7.5
    High

    CVE-2021-33615

    Last Modified: 21 Nov 2024

    RSA Archer 6.8.00500.1003 P5 allows Unrestricted Upload of a File with a Dangerous Type.

    Published: 2 Jun 2022
    9.8
    Critical

    CVE-2019-12351

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_print.php via an id parameter value with a trailing comma.

    Published: 2 Jun 2022
    3.1
    Low

    CVE-2022-30629

    Last Modified: 6 Mar 2026

    Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

    Published: 2 Jun 2022
    —
    Unknown

    CVE-2022-1966

    Last Modified: 13 Feb 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-32250. Reason: This candidate is a duplicate of CVE-2022-32250. Notes: All CVE users should reference CVE-2022-32250 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 2 Jun 2022
    7.8
    High

    CVE-2022-1968

    Last Modified: 21 Nov 2024

    Use After Free in GitHub repository vim/vim prior to 8.2.

    Published: 2 Jun 2022
    5.3
    Medium

    CVE-2022-1972

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-2078. Reason: This candidate is a reservation duplicate of CVE-2022-2078. Notes: All CVE users should reference CVE-2022-2078 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 2 Jun 2022
    6.1
    Medium

    CVE-2022-29718

    Last Modified: 21 Nov 2024

    Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.

    Published: 2 Jun 2022
    5.5
    Medium

    CVE-2022-3077

    Last Modified: 27 Jun 2025

    A buffer overflow vulnerability was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way it handled the I2C_SMBUS_BLOCK_PROC_CALL case (via the ioctl I2C_SMBUS) with malicious input data. This flaw could allow a local user to crash the system.

    Published: 2 Jun 2022
    5.4
    Medium

    CVE-2022-26497

    Last Modified: 21 Nov 2024

    BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username containing a JavaScript payload. The payload gets executed in the browser of the victim in the "Share room access" dialog if the victim has shared access to the particular room with the attacker previously.

    Published: 2 Jun 2022
    5.5
    Medium

    CVE-2022-36879

    Last Modified: 5 May 2025

    An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice.

    Published: 2 Jun 2022
    5.3
    Medium

    CVE-2022-29235

    Last Modified: 21 Nov 2024

    BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker who is able to obtain the meeting identifier for a meeting on a server can find information related to an external video being shared, like the current timestamp and play/pause. The problem has been patched in versions 2.3.18 and 2.4-rc-6 by modifying the stream to send the data only for users in the meeting. There are currently no known workarounds.

    Published: 1 Jun 2022
    4.3
    Medium

    CVE-2022-29236

    Last Modified: 21 Nov 2024

    BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently skipped on the server, due to a previously introduced grace period. The attacker must be a meeting participant. The problem has been patched in versions 2.3.18 and 2.4-rc-6. There are currently no known workarounds.

    Published: 1 Jun 2022
    4.3
    Medium

    CVE-2022-29234

    Last Modified: 23 Apr 2025

    BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4.1, an attacker could send messages to a locked chat within a grace period of 5s any lock setting in the meeting was changed. The attacker needs to be a participant in the meeting. Versions 2.3.18 and 2.4.1 contain a patch for this issue. There are currently no known workarounds.

    Published: 1 Jun 2022
    4.3
    Medium

    CVE-2022-29233

    Last Modified: 23 Apr 2025

    BigBlueButton is an open source web conferencing system. In BigBlueButton starting with 2.2 but before 2.3.18 and 2.4-rc-1, an attacker can circumvent access controls to gain access to all breakout rooms of the meeting they are in. The permission checks rely on knowledge of internal ids rather than on verification of the role of the user. Versions 2.3.18 and 2.4-rc-1 contain a patch for this issue. There are currently no known workarounds.

    Published: 1 Jun 2022
    6.5
    Medium

    CVE-2022-29232

    Last Modified: 23 Apr 2025

    BigBlueButton is an open source web conferencing system. Starting with version 2.2 and prior to versions 2.3.9 and 2.4-beta-1, an attacker can circumvent access controls to obtain the content of public chat messages from different meetings on the server. The attacker must be a participant in a meeting on the server. BigBlueButton versions 2.3.9 and 2.4-beta-1 contain a patch for this issue. There are currently no known workarounds.

    Published: 1 Jun 2022
    7.5
    High

    CVE-2022-29169

    Last Modified: 23 Apr 2025

    BigBlueButton is an open source web conferencing system. Versions starting with 2.2 and prior to 2.3.19, 2.4.7, and 2.5.0-beta.2 are vulnerable to regular expression denial of service (ReDoS) attacks. By using specific a RegularExpression, an attacker can cause denial of service for the bbb-html5 service. The useragent library performs checking of device by parsing the input of User-Agent header and lets it go through lookupUserAgent() (alias of useragent.lookup() ). This function handles input by regexing and attackers can abuse that by providing some ReDos payload using `SmartWatch`. The maintainers removed `htmlclient/useragent` from versions 2.3.19, 2.4.7, and 2.5.0-beta.2. As a workaround, disable NginX forwarding the requests to the handler according to the directions in the GitHub Security Advisory.

    Published: 1 Jun 2022
    7.8
    High

    CVE-2022-30190

    Last Modified: 5 Aug 2026

    A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.

    Published: 1 Jun 2022
    8.3
    High

    CVE-2022-30128

    Last Modified: 2 Jan 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 1 Jun 2022
    8.3
    High

    CVE-2022-30127

    Last Modified: 2 Jan 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 1 Jun 2022
    4.3
    Medium

    CVE-2022-26905

    Last Modified: 2 Jan 2025

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

    Published: 1 Jun 2022
    6.2
    Medium

    CVE-2022-31022

    Last Modified: 27 May 2025

    Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sample application. These HTTP methods pave way for exploitation of a node’s filesystem where the bleve index resides, if the user has used bleve’s own HTTP (bleve/http) handlers for exposing the access to the indexes. For instance, the CreateIndexHandler (`http/index_create.go`) and DeleteIndexHandler (`http/index_delete.go`) enable an attacker to create a bleve index (directory structure) anywhere where the user running the server has the write permissions and to delete recursively any directory owned by the same user account. Users who have used the bleve/http package for exposing access to bleve index without the explicit handling for the Role Based Access Controls(RBAC) of the index assets would be impacted by this issue. Version 2.5.0 relocated the `http/` dir used _only_ by bleve-explorer to `blevesearch/bleve-explorer`, thereby addressing the issue. However, the http package is purely intended to be used for demonstration purposes. Bleve was never designed handle the RBACs, nor it was ever advertised to be used in that way. The collaborators of this project have decided to stay away from adding any authentication or authorization to bleve project at the moment. The bleve/http package is mainly for demonstration purposes and it lacks exhaustive validation of the user inputs as well as any authentication and authorization measures. It is recommended to not use bleve/http in production use cases.

    Published: 1 Jun 2022
    6.5
    Medium

    CVE-2022-31973

    Last Modified: 21 Nov 2024

    Online Fire Reporting System v1.0 is vulnerable to Delete any file via /ofrs/classes/Master.php?f=delete_img.

    Published: 1 Jun 2022