CVE Feed

    Dashboard / CVE

    9.1
    Critical

    CVE-2022-31003

    Last Modified: 22 Apr 2025

    Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, when parsing each line of a sdp message, `rest = record + 2` will access the memory behind `\0` and cause an out-of-bounds write. An attacker can send a message with evil sdp to FreeSWITCH, causing a crash or more serious consequence, such as remote code execution. Version 1.13.8 contains a patch for this issue.

    Published: 31 May 2022
    7.5
    High

    CVE-2022-31001

    Last Modified: 21 Nov 2024

    Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause crash. This type of crash may be caused by `#define MATCH(s, m) (strncmp(s, m, n = sizeof(m) - 1) == 0)`, which will make `n` bigger and trigger out-of-bound access when `IS_NON_WS(s[n])`. Version 1.13.8 contains a patch for this issue.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-31736

    Last Modified: 15 Apr 2025

    A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

    Published: 31 May 2022
    8.8
    High

    CVE-2022-31739

    Last Modified: 16 Apr 2025

    When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

    Published: 31 May 2022
    8.8
    High

    CVE-2022-31740

    Last Modified: 16 Apr 2025

    On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

    Published: 31 May 2022
    8.8
    High

    CVE-2022-31741

    Last Modified: 15 Apr 2025

    A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

    Published: 31 May 2022
    6.5
    Medium

    CVE-2022-1834

    Last Modified: 16 Apr 2025

    When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would have displayed all the spaces. This could have been used by an attacker to send an email message with the attacker's digital signature, that was shown with an arbitrary sender email address chosen by the attacker. If the sender name started with a false email address, followed by many Braille space characters, the attacker's email address was not visible. Because Thunderbird compared the invisible sender address with the signature's email address, if the signing key or certificate was accepted by Thunderbird, the email was shown as having a valid digital signature. This vulnerability affects Thunderbird < 91.10.

    Published: 31 May 2022
    7.5
    High

    CVE-2022-1949

    Last Modified: 13 Dec 2024

    An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database items they do not have access to, including but not limited to potentially userPassword hashes and other sensitive data.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2020-28246

    Last Modified: 21 Nov 2024

    A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during deletion of the default Email template URL. NOTE: the email templating service was removed after 2020. Additionally, the vendor disputes this issue indicating this is sandboxed and only executable by admins.

    Published: 31 May 2022
    6.5
    Medium

    CVE-2022-31738

    Last Modified: 16 Apr 2025

    When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

    Published: 31 May 2022
    6.5
    Medium

    CVE-2022-31742

    Last Modified: 15 Apr 2025

    An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-31747

    Last Modified: 15 Apr 2025

    Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 and Firefox ESR 91.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

    Published: 31 May 2022
    5.5
    Medium

    CVE-2022-30973

    Last Modified: 21 Nov 2024

    We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular expression in the StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.3.

    Published: 31 May 2022
    7.5
    High

    CVE-2022-31002

    Last Modified: 22 Apr 2025

    Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause a crash. This type of crash may be caused by a URL ending with `%`. Version 1.13.8 contains a patch for this issue.

    Published: 31 May 2022
    7.8
    High

    CVE-2022-1942

    Last Modified: 3 Nov 2025

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

    Published: 31 May 2022
    7.8
    High

    CVE-2022-32250

    Last Modified: 21 Nov 2024

    net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.

    Published: 31 May 2022
    8.8
    High

    CVE-2022-28799

    Last Modified: 21 Nov 2024

    The TikTok application before 23.7.3 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force the com.zhiliaoapp.musically WebView to load an arbitrary website. This may allow an attacker to leverage an attached JavaScript interface for the takeover with one click.

    Published: 30 May 2022
    4.8
    Medium

    CVE-2022-1646

    Last Modified: 21 Nov 2024

    The Simple Real Estate Pack WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

    Published: 30 May 2022
    4.8
    Medium

    CVE-2022-1645

    Last Modified: 21 Nov 2024

    The Amazon Link WordPress plugin through 3.2.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

    Published: 30 May 2022
    4.8
    Medium

    CVE-2022-1644

    Last Modified: 21 Nov 2024

    The Call&Book Mobile Bar WordPress plugin through 1.2.2 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

    Published: 30 May 2022
    4.8
    Medium

    CVE-2022-1643

    Last Modified: 21 Nov 2024

    The Birthdays Widget WordPress plugin through 1.7.18 does not sanitise and escape some of its fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

    Published: 30 May 2022
    8.8
    High

    CVE-2022-1611

    Last Modified: 21 Nov 2024

    The Bulk Page Creator WordPress plugin before 1.1.4 does not protect its page creation functionalities with nonce checks, which makes them vulnerable to CSRF.

    Published: 30 May 2022
    7.5
    High

    CVE-2022-1589

    Last Modified: 14 Jan 2026

    The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings. The attacked could also be performed via a CSRF vector

    Published: 30 May 2022
    6.5
    Medium

    CVE-2022-1583

    Last Modified: 21 Nov 2024

    The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" when links to external sites are clicked, which may enable tabnabbing attacks to occur.

    Published: 30 May 2022
    6.1
    Medium

    CVE-2022-1582

    Last Modified: 21 Nov 2024

    The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to onclick event handlers, which makes Stored Cross-Site Scripting attacks possible.

    Published: 30 May 2022
    4.8
    Medium

    CVE-2022-1568

    Last Modified: 21 Nov 2024

    The Team Members WordPress plugin before 5.1.1 does not escape some of its Team settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 30 May 2022
    4.8
    Medium

    CVE-2022-1566

    Last Modified: 21 Nov 2024

    The Quotes llama WordPress plugin before 1.0.0 does not sanitise and escape Quotes, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. The attack could also be performed by tricking an admin to import a malicious CSV file

    Published: 30 May 2022
    4.8
    Medium

    CVE-2022-1564

    Last Modified: 21 Nov 2024

    The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which could allow high privilege user such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 30 May 2022
    5.4
    Medium

    CVE-2022-1562

    Last Modified: 21 Nov 2024

    The Enable SVG WordPress plugin before 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads

    Published: 30 May 2022
    9.8
    Critical

    CVE-2022-1556

    Last Modified: 21 Nov 2024

    The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for Staff in the admin dashboard, leading to an SQL Injection

    Published: 30 May 2022
    4.8
    Medium

    CVE-2022-1542

    Last Modified: 21 Nov 2024

    The HPB Dashboard WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

    Published: 30 May 2022
    6.1
    Medium

    CVE-2022-1528

    Last Modified: 21 Nov 2024

    The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.9 does not escape the current URL before putting it back in a JavaScript context, leading to a Reflected Cross-Site Scripting

    Published: 30 May 2022
    6.1
    Medium

    CVE-2022-1527

    Last Modified: 21 Nov 2024

    The WP 2FA WordPress plugin before 2.2.1 does not sanitise and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

    Published: 30 May 2022
    4.8
    Medium

    CVE-2022-1456

    Last Modified: 21 Nov 2024

    The Poll Maker WordPress plugin before 4.0.2 does not sanitise and escape some settings, which could allow high privilege users such as admin to perform Store Cross-Site Scripting attack even when unfiltered_html is disallowed

    Published: 30 May 2022
    4.8
    Medium

    CVE-2022-1395

    Last Modified: 21 Nov 2024

    The Easy FAQ with Expanding Text WordPress plugin through 3.2.8.3.1 does not sanitise and escape its settings, allowing high privilege users to perform Cross-Site Scripting attacks when unfiltered_html is disallowed

    Published: 30 May 2022
    4.8
    Medium

    CVE-2022-1387

    Last Modified: 21 Nov 2024

    The No Future Posts WordPress plugin through 1.4 does not escape its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed

    Published: 30 May 2022
    4.8
    Medium

    CVE-2022-1299

    Last Modified: 21 Nov 2024

    The Slideshow WordPress plugin through 2.3.1 does not sanitize and escape some of its default slideshow settings, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 30 May 2022
    4.8
    Medium

    CVE-2022-1294

    Last Modified: 21 Nov 2024

    The IMDB info box WordPress plugin through 2.0 does not sanitize and escape some of its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 30 May 2022
    4.8
    Medium

    CVE-2022-1275

    Last Modified: 21 Nov 2024

    The BannerMan WordPress plugin through 0.2.4 does not sanitize or escape its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed (such as in multisite)

    Published: 30 May 2022
    6.1
    Medium

    CVE-2022-1009

    Last Modified: 21 Nov 2024

    The Smush WordPress plugin before 3.9.9 does not sanitise and escape a configuration parameter before outputting it back in an admin page when uploading a malicious preset configuration, leading to a Reflected Cross-Site Scripting. For the attack to be successful, an attacker would need an admin to upload a malicious configuration file

    Published: 30 May 2022
    5.4
    Medium

    CVE-2022-0642

    Last Modified: 21 Nov 2024

    The JivoChat Live Chat WordPress plugin before 1.3.5.4 does not properly check CSRF tokens on POST requests to the plugins admin page, and does not sanitise some parameters, leading to a stored Cross-Site Scripting vulnerability where an attacker can trick a logged in administrator to inject arbitrary javascript.

    Published: 30 May 2022
    4.8
    Medium

    CVE-2022-0376

    Last Modified: 21 Nov 2024

    The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name, as well as Shared Field Labels before outputting them in the admin dashboard when editing a form, which could allow high privilege users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 30 May 2022
    7.8
    High

    CVE-2022-39189

    Last Modified: 5 May 2025

    An issue was discovered the x86 KVM subsystem in the Linux kernel before 5.18.17. Unprivileged guest users can compromise the guest kernel because TLB flush operations are mishandled in certain KVM_VCPU_PREEMPTED situations.

    Published: 30 May 2022
    5.3
    Medium

    CVE-2021-3754

    Last Modified: 21 Nov 2024

    A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password.

    Published: 30 May 2022
    4.3
    Medium

    CVE-2022-1203

    Last Modified: 21 Nov 2024

    The Content Mask WordPress plugin before 1.8.4.1 does not have authorisation and CSRF checks in various AJAX actions, as well as does not validate the option to be updated to ensure it belongs to the plugin. As a result, any authenticated user, such as subscriber could modify arbitrary blog options

    Published: 30 May 2022
    9.8
    Critical

    CVE-2022-31799

    Last Modified: 21 Nov 2024

    Bottle before 0.12.20 mishandles errors during early request binding.

    Published: 29 May 2022
    6.5
    Medium

    CVE-2022-24967

    Last Modified: 30 May 2025

    Black Rainbow NIMBUS before 3.7.0 allows stored Cross-site Scripting (XSS).

    Published: 29 May 2022
    6.5
    Medium

    CVE-2022-31796

    Last Modified: 21 Nov 2024

    libjpeg 1.63 has a heap-based buffer over-read in HierarchicalBitmapRequester::FetchRegion in hierarchicalbitmaprequester.cpp because the MCU size can be different between allocation and use.

    Published: 29 May 2022
    5.4
    Medium

    CVE-2022-1928

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9.

    Published: 29 May 2022
    7.8
    High

    CVE-2021-33641

    Last Modified: 3 Apr 2025

    When processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses the released memory (use after free).

    Published: 28 May 2022