8.8
    High

    CVE-2023-0455

    Last Modified: 31 May 2023

    Unrestricted Upload of File with Dangerous Type in GitHub repository unilogies/bumsys prior to v1.0.3-beta.

    Source:AFFAN AHMED
    Published:26 Jan 2023
    Unknown

    CVE-2023-422

    https://github.com/HusenjanDev/CVE-2023-422-Chamilo-LMS-RCE

    5.9
    Medium

    CVE-2023-0400

    Last Modified: 26 Mar 2025

    The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when uploading sensitive data from a mapped drive into a web email client. Loading from a local driver was correctly prevented. Versions prior to 11.9 correctly detected and blocked the attempted upload of sensitive data.

    Published:1 Feb 2023
    7.8
    High

    CVE-2023-0386

    Last Modified: 4 Nov 2025

    A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.

    Published:24 Jan 2023
    8.8
    High

    CVE-2023-0315

    Last Modified: 5 Apr 2023

    Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.

    Source:Askar
    Published:16 Jan 2023
    9.8
    Critical

    CVE-2023-0297

    Last Modified: 20 Jun 2023

    Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31.

    Source:Gabriel Lima
    Published:14 Jan 2023
    7.9
    High

    CVE-2023-0266

    Last Modified: 24 Oct 2025

    A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e

    Published:13 Jan 2023
    5
    Medium

    CVE-2023-0264

    Last Modified: 21 Nov 2024

    A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availability.

    Published:28 Feb 2023
    6.1
    Medium

    CVE-2023-0214

    Last Modified: 5 Apr 2023

    A cross-site scripting vulnerability in Skyhigh SWG in main releases 11.x prior to 11.2.6, 10.x prior to 10.2.17, and controlled release 12.x prior to 12.0.1 allows a remote attacker to craft SWG-specific internal requests with URL paths to any third-party website, causing arbitrary content to be injected into the response when accessed through SWG.

    Source:RedTeam Pentesting GmbH
    Published:18 Jan 2023
    7.8
    High

    CVE-2023-0179

    Last Modified: 19 Feb 2025

    A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution.

    Published:13 Jan 2023
    7.5
    High

    CVE-2023-0159

    Last Modified: 19 Mar 2025

    The Extensive VC Addons for WPBakery page builder WordPress plugin before 1.9.1 does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated attacker to override the template path to read arbitrary files from the hosts file system. This may be escalated to RCE using PHP filter chains.

    Source:Ravina
    Published:13 Feb 2023
    4.8
    Medium

    CVE-2023-0157

    Last Modified: 11 Feb 2025

    The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not escape the content of log files before outputting it to the plugin admin page, allowing an authorized user (admin+) to plant bogus log files containing malicious JavaScript code that will be executed in the context of any administrator visiting this page.

    Published:10 Apr 2023
    4.9
    Medium

    CVE-2023-0156

    Last Modified: 11 Feb 2025

    The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not limit what log files to display in it's settings pages, allowing an authorized user (admin+) to view the contents of arbitrary files and list directories anywhere on the server (to which the web server has access). The plugin only displays the last 50 lines of the file.

    Published:10 Apr 2023
    6.1
    Medium

    CVE-2023-0099

    Last Modified: 13 Feb 2025

    The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published:13 Feb 2023
    9.8
    Critical

    CVE-2023-0090

    Last Modified: 28 Feb 2025

    The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'. Exploitation requires network access to the webservices API, but such access is a non-standard configuration. This affects all versions 8.20.0 and below.

    Published:8 Mar 2023
    8.8
    High

    CVE-2023-0089

    Last Modified: 28 Feb 2025

    The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to execute remote code through 'eval injection'. This affects all versions 8.20.0 and below.

    Published:8 Mar 2023
    7.2
    High

    CVE-2023-0084

    Last Modified: 3 Apr 2023

    The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text areas on forms in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, which is the submissions page.

    Source:Mohammed Chemouri
    Published:2 Mar 2023
    4.7
    Medium

    CVE-2023-0045

    Last Modified: 13 Feb 2025

    The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall. The ib_prctl_set  function updates the Thread Information Flags (TIFs) for the task and updates the SPEC_CTRL MSR on the function __speculation_ctrl_update, but the IBPB is only issued on the next schedule, when the TIF bits are checked. This leaves the victim vulnerable to values already injected on the BTB, prior to the prctl syscall.  The patch that added the support for the conditional mitigation via prctl (ib_prctl_set) dates back to the kernel 4.9.176. We recommend upgrading past commit a664ec9158eeddd75121d39c9a0758016097fa96

    Published:3 Feb 2023
    Unknown

    CVE-2023-08

    https://github.com/amirzargham/CVE-2023-08-21-exploit

    Unknown

    CVE-2022-218882

    https://github.com/Sausageinforest/CVE-2022-218882

    7.8
    High

    CVE-2022-49186

    Last Modified: 1 Oct 2025

    In the Linux kernel, the following vulnerability has been resolved: clk: visconti: prevent array overflow in visconti_clk_register_gates() This code was using -1 to represent that there was no reset function. Unfortunately, the -1 was stored in u8 so the if (clks[i].rs_id >= 0) condition was always true. This lead to an out of bounds access in visconti_clk_register_gates().

    Published:26 Feb 2025
    9.8
    Critical

    CVE-2022-48565

    Last Modified: 21 Nov 2024

    An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.

    Published:22 Aug 2023
    8.2
    High

    CVE-2022-48474

    Last Modified: 21 Nov 2024

    Control de Ciber, in its 1.650 version, is affected by a Denial of Service condition through the version function. Sending a malicious request could cause the server to check if an unrecognized component is up to date, causing a memory failure error that shuts down the process.

    Published:12 Sept 2023
    4.6
    Medium

    CVE-2022-48429

    Last Modified: 19 Feb 2025

    In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible

    Published:27 Mar 2023
    9
    Critical

    CVE-2022-48311

    Last Modified: 26 Mar 2025

    **UNSUPPORTED WHEN ASSIGNED** Cross Site Scripting (XSS) in HP Deskjet 2540 series printer Firmware Version CEP1FN1418BR and Product Model Number A9U23B allows authenticated attacker to inject their own script into the page via HTTP configuration page. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published:6 Feb 2023
    6.1
    Medium

    CVE-2022-48197

    Last Modified: 7 Jun 2023

    Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, TreeView component and the YUI Javascript library overall are not affected. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Source:SITE Team
    Published:2 Jan 2023
    8.8
    High

    CVE-2022-48194

    Last Modified: 1 Apr 2023

    TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploading a crafted firmware update because the signature check is inadequate.

    Source:Tobias Müller
    Published:30 Dec 2022
    5.4
    Medium

    CVE-2022-48178

    Last Modified: 8 Apr 2023

    X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action function, aka an index.php/actions/update URI.

    Source:Betul Denizler
    Published:15 Apr 2023
    5.4
    Medium

    CVE-2022-48177

    Last Modified: 8 Apr 2023

    X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importModels Import Records Model field (model parameter). This vulnerability allows attackers to create malicious JavaScript that will be executed by the victim user's browser.

    Source:Betul Denizler
    Published:15 Apr 2023
    6.1
    Medium

    CVE-2022-48150

    Last Modified: 5 Feb 2025

    Shopware v5.5.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the recovery/install/ URI.

    Published:21 Apr 2023
    6.1
    Medium

    CVE-2022-48110

    Last Modified: 5 Apr 2023

    CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget. NOTE: the vendor's position is that this is not a vulnerability. The CKEditor 5 documentation discusses that it is the responsibility of an integrator (who is adding CKEditor 5 functionality to a website) to choose the correct security settings for their use case. Also, safe default values are established (e.g., config.htmlEmbed.showPreviews is false).

    Source:Manish Pathak
    Published:13 Feb 2023
    9.8
    Critical

    CVE-2022-47986

    Last Modified: 7 Apr 2023

    IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.

    Source:Maurice Lambert
    Published:17 Feb 2023
    9.8
    Critical

    CVE-2022-47966

    Last Modified: 31 Oct 2025

    Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus before 10.1.2220.18, Endpoint Central before 10.1.2228.11, Endpoint Central MSP before 10.1.2228.11, Endpoint DLP before 10.1.2137.6, Key Manager Plus before 6401, OS Deployer before 1.1.2243.1, PAM 360 before 5713, Password Manager Pro before 12124, Patch Manager Plus before 10.1.2220.18, Remote Access Plus before 10.1.2228.11, Remote Monitoring and Management (RMM) before 10.1.41. ServiceDesk Plus before 14004, ServiceDesk Plus MSP before 13001, SupportCenter Plus before 11026, and Vulnerability Manager Plus before 10.1.2220.18. Exploitation is only possible if SAML SSO has ever been configured for a product (for some products, exploitation requires that SAML SSO is currently active).

    Published:18 Jan 2023
    3.3
    Low

    CVE-2022-47952

    Last Modified: 10 Apr 2025

    lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "does not refer to a network namespace path" often indicates that a file exists. NOTE: this is different from CVE-2018-6556 because the CVE-2018-6556 fix design was based on the premise that "we will report back to the user that the open() failed but the user has no way of knowing why it failed"; however, in many realistic cases, there are no plausible reasons for failing except that the file does not exist.

    Published:1 Jan 2023
    6.8
    Medium

    CVE-2022-47909

    Last Modified: 21 Nov 2024

    Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to perform direct queries to the application's core from localhost.

    Published:20 Feb 2023
    6.8
    Medium

    CVE-2022-47880

    Last Modified: 5 May 2023

    An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify database connections to disclose a connections' cleartext password via the 'test connection' function.

    Source:Team Syslifters
    Published:12 May 2023
    7.5
    High

    CVE-2022-47879

    Last Modified: 5 May 2023

    A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP classes from the 'rtn' directory and execute its methods. NOTE: The vendor states that the vulnerability affects installations running version 22.5 or earlier. The issue was resolved with version 23.2 and later versions are not affected.

    Source:Team Syslifters
    Published:12 May 2023
    9.1
    Critical

    CVE-2022-47878

    Last Modified: 5 May 2023

    Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory. Consecutive file uploads can lead to the execution of arbitrary code. NOTE: The vendor states that the vulnerability affects installations running version 22.2 or earlier. The issue was resolved with the version 22.3 and later versions are not affected. Additionally, the vendor states that this vulnerability affects on-premises deployments only and that it does not impact cloud-hosted or SaaS environments.

    Source:Team Syslifters
    Published:2 May 2023
    9.6
    Critical

    CVE-2022-47877

    Last Modified: 5 May 2023

    A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web script or HTML in the Logs page via the log module 'log'.

    Source:Team Syslifters
    Published:2 May 2023
    9.1
    Critical

    CVE-2022-47876

    Last Modified: 5 May 2023

    The integrator in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to create Jobs to execute arbitrary code via Groovy-scripts.

    Source:Team Syslifters
    Published:2 May 2023
    8.8
    High

    CVE-2022-47875

    Last Modified: 5 May 2023

    A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary code.

    Source:Team Syslifters
    Published:2 May 2023
    6.5
    Medium

    CVE-2022-47874

    Last Modified: 5 May 2023

    Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections via class 'com.jedox.etl.mngr.Connections' and method 'getGlobalConnection'.

    Source:Team Syslifters
    Published:2 May 2023
    8.8
    High

    CVE-2022-47872

    Last Modified: 21 Nov 2024

    A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted payload injected into the Name parameter under the Interface address module.

    Published:1 Feb 2023
    6.1
    Medium

    CVE-2022-47870

    Last Modified: 3 Apr 2023

    A Cross Site Scripting (XSS) vulnerability in the web SQL monitor login page in Redgate SQL Monitor 12.1.31.893 allows remote attackers to inject arbitrary web Script or HTML via the returnUrl parameter.

    Source:geeklinuxman
    Published:4 Apr 2023
    7.8
    High

    CVE-2022-47636

    Last Modified: 10 Aug 2023

    A DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739. When a user open a .oml file (OutSystems Modeling Language), the application will load the following DLLs from the same directory av_libGLESv2.dll, libcef.DLL, user32.dll, and d3d10warp.dll. Using a crafted DLL, it is possible to execute arbitrary code in the context of the current logged in user.

    Source:shinnai
    Published:10 Aug 2023
    9.3
    Critical

    CVE-2022-47615

    Last Modified: 8 Jan 2025

    Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.

    Published:24 Jan 2023
    6.7
    Medium

    CVE-2022-47529

    Last Modified: 8 Apr 2023

    Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Windows user accounts to modify the endpoint agent service configuration: to either disable it completely or run user-supplied code or commands, thereby bypassing tamper-protection features via ACL modification.

    Source:hyp3rlinx
    Published:28 Mar 2023
    7.5
    High

    CVE-2022-47522

    Last Modified: 6 Feb 2025

    The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined frames by spoofing a target's MAC address, sending Power Save frames to the access point, and then sending other frames to the access point (such as authentication frames or re-association frames) to remove the target's original security context. This behavior occurs because the specifications do not require an access point to purge its transmit queue before removing a client's pairwise encryption key.

    Published:15 Apr 2023
    4.3
    Medium

    CVE-2022-47447

    Last Modified: 8 Jan 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Mathieu Chartier WordPress WP-Advanced-Search plugin <= 3.3.8 versions.

    Published:24 May 2023
    6.4
    Medium

    CVE-2022-47373

    Last Modified: 4 Apr 2025

    Reflected Cross Site Scripting in Search Functionality of Module Library in Pandora FMS Console v766 and lower. This vulnerability arises on the forget password functionality in which parameter username does not proper input validation/sanitization thus results in executing malicious JavaScript payload.

    Published:15 Feb 2023