CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2022-30974

    Last Modified: 21 Nov 2024

    compile in regexp.c in Artifex MuJS through 1.2.0 results in stack consumption because of unlimited recursion, a different issue than CVE-2019-11413.

    Published: 18 May 2022
    5.5
    Medium

    CVE-2022-30975

    Last Modified: 21 Nov 2024

    In Artifex MuJS through 1.2.0, jsP_dumpsyntax in jsdump.c has a NULL pointer dereference, as demonstrated by mujs-pp.

    Published: 18 May 2022
    —
    Unknown

    CVE-2022-30996

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 18 May 2022
    7.8
    High

    CVE-2021-42704

    Last Modified: 16 Apr 2025

    Inkscape version 0.91 is vulnerable to an out-of-bounds write, which may allow an attacker to arbitrary execute code.

    Published: 18 May 2022
    7.5
    High

    CVE-2022-1183

    Last Modified: 21 Nov 2024

    On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and DNS over HTTPS (DoH), but configurations using DoT alone are unaffected. Affects BIND 9.18.0 -> 9.18.2 and version 9.19.0 of the BIND 9.19 development branch.

    Published: 18 May 2022
    4.3
    Medium

    CVE-2022-24904

    Last Modified: 23 Apr 2025

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.7.0 and prior to versions 2.1.15m 2.2.9, and 2.3.4 is vulnerable to a symlink following bug allowing a malicious user with repository write access to leak sensitive files from Argo CD's repo-server. A malicious Argo CD user with write access for a repository which is (or may be) used in a directory-type Application may commit a symlink which points to an out-of-bounds file. Sensitive files which could be leaked include manifest files from other Applications' source repositories (potentially decrypted files, if you are using a decryption plugin) or any JSON-formatted secrets which have been mounted as files on the repo-server. A patch for this vulnerability has been released in Argo CD versions 2.3.4, 2.2.9, and 2.1.15. Users of versions 2.3.0 or above who do not have any Jsonnet/directory-type Applications may disable the Jsonnet/directory config management tool as a workaround.

    Published: 18 May 2022
    10
    Critical

    CVE-2022-29165

    Last Modified: 23 Apr 2025

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been discovered in Argo CD starting with version 1.4.0 and prior to versions 2.1.15, 2.2.9, and 2.3.4 which would allow unauthenticated users to impersonate as any Argo CD user or role, including the `admin` user, by sending a specifically crafted JSON Web Token (JWT) along with the request. In order for this vulnerability to be exploited, anonymous access to the Argo CD instance must have been enabled. In a default Argo CD installation, anonymous access is disabled. The vulnerability can be exploited to impersonate as any user or role, including the built-in `admin` account regardless of whether it is enabled or disabled. Also, the attacker does not need an account on the Argo CD instance in order to exploit this. If anonymous access to the instance is enabled, an attacker can escalate their privileges, effectively allowing them to gain the same privileges on the cluster as the Argo CD instance, which is cluster admin in a default installation. This will allow the attacker to create, manipulate and delete any resource on the cluster. They may also exfiltrate data by deploying malicious workloads with elevated privileges, thus bypassing any redaction of sensitive data otherwise enforced by the Argo CD API. A patch for this vulnerability has been released in Argo CD versions 2.3.4, 2.2.9, and 2.1.15. As a workaround, one may disable anonymous access, but upgrading to a patched version is preferable.

    Published: 18 May 2022
    8.1
    High

    CVE-2022-29174

    Last Modified: 23 Apr 2025

    countly-server is the server-side part of Countly, a product analytics solution. Prior to versions 22.03.7 and 21.11.4, a malicious actor who knows an account email address/username and full name specified in the database is capable of guessing the password reset token. The actor may use this information to reset the password and take over the account. The problem has been patched in Countly Server version 22.03.7 for servers using the new user interface and in 21.11.4 for servers using the old user interface.

    Published: 17 May 2022
    5
    Medium

    CVE-2022-1362

    Last Modified: 16 Apr 2025

    The affected On-Premise cnMaestro is vulnerable inside a specific route where a user can upload a crafted package to the system. An attacker could abuse this user-controlled data to execute arbitrary commands on the server.

    Published: 17 May 2022
    7.4
    High

    CVE-2022-1361

    Last Modified: 16 Apr 2025

    The affected On-Premise cnMaestro is vulnerable to a pre-auth data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate data about other user’s accounts and devices.

    Published: 17 May 2022
    8.2
    High

    CVE-2022-1360

    Last Modified: 16 Apr 2025

    The affected On-Premise cnMaestro is vulnerable to execution of code on the cnMaestro hosting server. This could allow a remote attacker to change server configuration settings.

    Published: 17 May 2022
    5.7
    Medium

    CVE-2022-1359

    Last Modified: 16 Apr 2025

    The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to a restricted directory inside a specific route. If an attacker supplied path traversal charters (../) as part of a filename, the server will save the file where the attacker chooses. This could allow an attacker to write any data to any file in the server.

    Published: 17 May 2022
    5.9
    Medium

    CVE-2022-1358

    Last Modified: 16 Apr 2025

    The affected On-Premise is vulnerable to data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate and dump all data held in the cnMaestro database.

    Published: 17 May 2022
    7.1
    High

    CVE-2022-1356

    Last Modified: 16 Apr 2025

    cnMaestro is vulnerable to a local privilege escalation. By default, a user does not have root privileges. However, a user can run scripts as sudo, which could allow an attacker to gain root privileges when running user scripts outside allowed commands.

    Published: 17 May 2022
    9.8
    Critical

    CVE-2022-1357

    Last Modified: 16 Apr 2025

    The affected On-Premise cnMaestro allows an unauthenticated attacker to access the cnMaestro server and execute arbitrary code in the privileges of the web server. This lack of validation could allow an attacker to append arbitrary data to the logger command.

    Published: 17 May 2022
    9.8
    Critical

    CVE-2022-28616

    Last Modified: 21 Nov 2024

    A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.

    Published: 17 May 2022
    6.1
    Medium

    CVE-2022-23706

    Last Modified: 21 Nov 2024

    A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.

    Published: 17 May 2022
    9.8
    Critical

    CVE-2022-28617

    Last Modified: 21 Nov 2024

    A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.

    Published: 17 May 2022
    5.4
    Medium

    CVE-2022-29435

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress allows an attacker to delete or to turn on/off snippets.

    Published: 17 May 2022
    4.7
    Medium

    CVE-2022-29436

    Last Modified: 20 Feb 2025

    Persistent Cross-Site Scripting (XSS) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery (vulnerable parameters &title, &snippet_code).

    Published: 17 May 2022
    8.6
    High

    CVE-2022-1118

    Last Modified: 16 Apr 2025

    Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and Safety Instrumented System Workstation (v1.2 and prior (for Trusted Controllers)) do not limit the objects that can be deserialized. This allows attackers to craft a malicious serialized object that, if opened by a local user in Connected Components Workbench, may result in arbitrary code execution. This vulnerability requires user interaction to be successfully exploited

    Published: 17 May 2022
    4.3
    Medium

    CVE-2021-35249

    Last Modified: 21 Nov 2024

    This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user data of other domains which they should not have access to. Please note the admin is unable to modify the data (read only operation). This UAC issue leads to a data leak to unauthorized users for a domain, with no log of them accessing the data unless they attempt to modify it. This read-only activity is logged to the original domain and does not specify which domain was accessed.

    Published: 17 May 2022
    9.8
    Critical

    CVE-2022-30054

    Last Modified: 21 Nov 2024

    In Covid 19 Travel Pass Management 1.0, the code parameter is vulnerable to SQL injection attacks.

    Published: 17 May 2022
    9.8
    Critical

    CVE-2022-30053

    Last Modified: 24 Feb 2025

    In Toll Tax Management System 1.0, the id parameter appears to be vulnerable to SQL injection attacks.

    Published: 17 May 2022
    9.8
    Critical

    CVE-2022-30052

    Last Modified: 21 Nov 2024

    In Home Clean Service System 1.0, the password parameter is vulnerable to SQL injection attacks.

    Published: 17 May 2022
    4.4
    Medium

    CVE-2022-0486

    Last Modified: 21 Nov 2024

    Improper file permissions in the CommandPost, Collector, Sensor, and Sandbox components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected files and enable escalation of privileges equivalent to the root user. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.

    Published: 17 May 2022
    3.9
    Low

    CVE-2022-0997

    Last Modified: 21 Nov 2024

    Improper file permissions in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected script files, which could result in arbitrary commands being run as root upon subsequent logon by a root user. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.

    Published: 17 May 2022
    8.8
    High

    CVE-2022-24388

    Last Modified: 21 Nov 2024

    Vulnerability in rconfig “date” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as well as neighboring Fidelis components. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.

    Published: 17 May 2022
    8.8
    High

    CVE-2022-24389

    Last Modified: 21 Nov 2024

    Vulnerability in rconfig “cert_utils” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as well as neighboring Fidelis components. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.

    Published: 17 May 2022
    8.8
    High

    CVE-2022-24390

    Last Modified: 21 Nov 2024

    Vulnerability in rconfig “remote_text_file” enables an attacker with user level access to the CLI to inject user level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as well as neighboring Fidelis components. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.

    Published: 17 May 2022
    8.8
    High

    CVE-2022-24391

    Last Modified: 21 Nov 2024

    Vulnerability in Fidelis Network and Deception CommandPost enables SQL injection through the web interface by an attacker with user level access. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.

    Published: 17 May 2022
    8.8
    High

    CVE-2022-24392

    Last Modified: 21 Nov 2024

    Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “feed_comm_test” value for the “feed” parameter. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and return results in an HTTP response via an authenticated session. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.

    Published: 17 May 2022
    6.5
    Medium

    CVE-2022-30045

    Last Modified: 21 Nov 2024

    An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs incorrect memory handling while parsing crafted XML files, leading to a heap out-of-bounds read.

    Published: 17 May 2022
    8.8
    High

    CVE-2022-24393

    Last Modified: 21 Nov 2024

    Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “check_vertica_upgrade” value for the “cpIp” parameter. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and return results in an HTTP response via an authenticated session. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.

    Published: 17 May 2022
    8.8
    High

    CVE-2022-24394

    Last Modified: 21 Nov 2024

    Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “update_checkfile” value for the “filename” parameter. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and return results in an HTTP response via an authenticated session. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.

    Published: 17 May 2022
    4.1
    Medium

    CVE-2022-28192

    Last Modified: 21 Nov 2024

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where it may lead to a use-after-free, which in turn may cause denial of service. This attack is complex to carry out because the attacker needs to have control over freeing some host side resources out of sequence, which requires elevated privileges.

    Published: 17 May 2022
    5.5
    Medium

    CVE-2022-28191

    Last Modified: 21 Nov 2024

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where uncontrolled resource consumption can be triggered by an unprivileged regular user, which may lead to denial of service.

    Published: 17 May 2022
    5.5
    Medium

    CVE-2022-28190

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where improper input validation can cause denial of service.

    Published: 17 May 2022
    5.5
    Medium

    CVE-2022-28189

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a NULL pointer dereference may lead to a system crash.

    Published: 17 May 2022
    5.5
    Medium

    CVE-2022-28188

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where the product receives input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly, which may lead to denial of service.

    Published: 17 May 2022
    5.5
    Medium

    CVE-2022-28187

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where the memory management software does not release a resource after its effective lifetime has ended, which may lead to denial of service.

    Published: 17 May 2022
    6.1
    Medium

    CVE-2022-28186

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where the product receives input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly, which may lead to denial of service or data tampering.

    Published: 17 May 2022
    8.5
    High

    CVE-2022-28182

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the DirectX11 user mode driver (nvwgf2um/x.dll), where an unauthorized attacker on the network can cause an out-of-bounds write through a specially crafted shader, which may lead to code execution to cause denial of service, escalation of privileges, information disclosure, and data tampering. The scope of the impact may extend to other components.

    Published: 17 May 2022
    2.4
    Low

    CVE-2022-24890

    Last Modified: 22 Apr 2025

    Nextcloud Talk is a video and audio conferencing app for Nextcloud. In versions prior to 13.0.5 and 14.0.0, a call moderator can indirectly enable user webcams by granting permissions, if they were enabled before removing the permissions. A patch is available in versions 13.0.5 and 14.0.0. There are currently no known workarounds.

    Published: 17 May 2022
    7.8
    High

    CVE-2022-30688

    Last Modified: 3 Nov 2025

    needrestart 0.8 through 3.5 before 3.6 is prone to local privilege escalation. Regexes to detect the Perl, Python, and Ruby interpreters are not anchored, allowing a local user to escalate privileges when needrestart tries to detect if interpreters are using old source files.

    Published: 17 May 2022
    8.8
    High

    CVE-2022-29429

    Last Modified: 20 Feb 2025

    Remote Code Execution (RCE) in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery.

    Published: 17 May 2022
    5.4
    Medium

    CVE-2022-23674

    Last Modified: 21 Nov 2024

    A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

    Published: 17 May 2022
    4.8
    Medium

    CVE-2022-23675

    Last Modified: 21 Nov 2024

    A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

    Published: 17 May 2022
    7.2
    High

    CVE-2022-23673

    Last Modified: 21 Nov 2024

    A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

    Published: 17 May 2022
    7.5
    High

    CVE-2022-23671

    Last Modified: 21 Nov 2024

    A remote authenticated information disclosure vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

    Published: 17 May 2022