8.8
    High

    CVE-2022-47132

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users.

    Published:3 Feb 2023
    4.8
    Medium

    CVE-2022-47131

    Last Modified: 26 Mar 2025

    A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows an attacker to arbitrarily create a page.

    Published:3 Feb 2023
    4.3
    Medium

    CVE-2022-47130

    Last Modified: 26 Mar 2025

    A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with administrative privileges interacts on the CSRF page.

    Published:3 Feb 2023
    5.4
    Medium

    CVE-2022-47102

    Last Modified: 8 Apr 2025

    A cross-site scripting (XSS) vulnerability in Student Study Center Management System V 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.

    Published:12 Jan 2023
    7.5
    High

    CVE-2022-47076

    Last Modified: 22 Jun 2023

    An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via DisplayParallelLogData.aspx.

    Source:Tejas Pingulkar
    Published:28 Feb 2023
    7.5
    High

    CVE-2022-47075

    Last Modified: 22 Jun 2023

    An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.

    Source:Tejas Pingulkar
    Published:28 Feb 2023
    6.1
    Medium

    CVE-2022-47052

    Last Modified: 1 Apr 2025

    The web interface of the 'Nighthawk R6220 AC1200 Smart Wi-Fi Router' is vulnerable to a CRLF Injection attack that can be leveraged to perform Reflected XSS and HTML Injection. A malicious unauthenticated attacker can exploit this vulnerability using a specially crafted URL. This affects firmware versions: V1.1.0.112_1.0.1, V1.1.0.114_1.0.1.

    Published:25 Jan 2023
    9.1
    Critical

    CVE-2022-46945

    Last Modified: 16 Apr 2025

    Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagVisHoverUrl.php.

    Source:xerosec
    Published:26 May 2023
    6.1
    Medium

    CVE-2022-46907

    Last Modified: 13 Feb 2025

    A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.0 or later.

    Published:25 May 2023
    9.1
    Critical

    CVE-2022-46836

    Last Modified: 21 Nov 2024

    PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP code which will be executed upon request of the vulnerable component.

    Published:20 Feb 2023
    7.5
    High

    CVE-2022-46770

    Last Modified: 31 Mar 2023

    qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumption and loss of forwarding) via a crafted multicast UDP packet (IP address range of 224.0.0.0 through 239.255.255.255).

    Source:Krzysztof Burghardt
    Published:7 Dec 2022
    5.5
    Medium

    CVE-2022-46718

    Last Modified: 5 Dec 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, macOS Monterey 12.6.2. An app may be able to read sensitive location information

    Published:23 Jun 2023
    7
    High

    CVE-2022-46689

    Last Modified: 21 Apr 2025

    A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.

    Published:15 Dec 2022
    8.8
    High

    CVE-2022-46649

    Last Modified: 24 Mar 2025

    Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.

    Published:10 Feb 2023
    Unknown

    CVE-2022-46638

    https://github.com/naonymous101/CVE-2022-46638

    7.8
    High

    CVE-2022-46623

    Last Modified: 8 Apr 2025

    Judging Management System v1.0.0 was discovered to contain a SQL injection vulnerability via the username parameter.

    Published:12 Jan 2023
    6.1
    Medium

    CVE-2022-46622

    Last Modified: 8 Apr 2025

    A cross-site scripting (XSS) vulnerability in Judging Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter.

    Published:12 Jan 2023
    8.8
    High

    CVE-2022-46604

    Last Modified: 18 May 2023

    An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP file, leading to arbitrary code execution.

    Source:Galoget Latorre
    Published:2 Feb 2023
    8.8
    High

    CVE-2022-46552

    Last Modified: 5 Apr 2023

    D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.

    Source:Françoa Taffarel
    Published:2 Feb 2023
    7.5
    High

    CVE-2022-46505

    Last Modified: 4 Apr 2025

    An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an all-zero MasterSecret that can decrypt secret data.

    Published:18 Jan 2023
    7.5
    High

    CVE-2022-46485

    Last Modified: 21 Nov 2024

    Data Illusion Survey Software Solutions ngSurvey version 2.4.28 and below is vulnerable to Denial of Service if a survey contains a "Text Field", "Comment Field" or "Contact Details".

    Published:2 Aug 2023
    7.5
    High

    CVE-2022-46484

    Last Modified: 21 Nov 2024

    Information disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to view the password to access and arbitrarily submit surveys.

    Published:2 Aug 2023
    7.5
    High

    CVE-2022-46463

    Last Modified: 8 Apr 2025

    An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."

    Published:12 Jan 2023
    8.8
    High

    CVE-2022-46395

    Last Modified: 27 Nov 2024

    An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Midgard r0p0 through r32p0, Bifrost r0p0 through r41p0 before r42p0, Valhall r19p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0.

    Published:6 Mar 2023
    6.1
    Medium

    CVE-2022-46381

    Last Modified: 22 Apr 2025

    Certain Linear eMerge E3-Series devices are vulnerable to XSS via the type parameter (e.g., to the badging/badge_template_v0.php component). This affects 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e.

    Published:13 Dec 2022
    9.8
    Critical

    CVE-2022-46364

    Last Modified: 22 Apr 2025

    A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. 

    Published:13 Dec 2022
    Low

    CVE-2022-46196

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published:28 Nov 2022
    7.1
    High

    CVE-2022-46175

    Last Modified: 21 Nov 2024

    JSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for config files). The `parse` method of the JSON5 library before and including versions 1.0.1 and 2.2.1 does not restrict parsing of keys named `__proto__`, allowing specially crafted strings to pollute the prototype of the resulting object. This vulnerability pollutes the prototype of the object returned by `JSON5.parse` and not the global Object prototype, which is the commonly understood definition of Prototype Pollution. However, polluting the prototype of a single object can have significant security impact for an application if the object is later used in trusted operations. This vulnerability could allow an attacker to set arbitrary and unexpected keys on the object returned from `JSON5.parse`. The actual impact will depend on how applications utilize the returned object and how they filter unwanted keys, but could include denial of service, cross-site scripting, elevation of privilege, and in extreme cases, remote code execution. `JSON5.parse` should restrict parsing of `__proto__` keys when parsing JSON strings to objects. As a point of reference, the `JSON.parse` method included in JavaScript ignores `__proto__` keys. Simply changing `JSON5.parse` to `JSON.parse` in the examples above mitigates this vulnerability. This vulnerability is patched in json5 versions 1.0.2, 2.2.2, and later.

    Published:24 Dec 2022
    9.8
    Critical

    CVE-2022-46169

    Last Modified: 31 Mar 2023

    Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti, if a specific data source was selected for any monitored device. The vulnerability resides in the `remote_agent.php` file. This file can be accessed without authentication. This function retrieves the IP address of the client via `get_client_addr` and resolves this IP address to the corresponding hostname via `gethostbyaddr`. After this, it is verified that an entry within the `poller` table exists, where the hostname corresponds to the resolved hostname. If such an entry was found, the function returns `true` and the client is authorized. This authorization can be bypassed due to the implementation of the `get_client_addr` function. The function is defined in the file `lib/functions.php` and checks serval `$_SERVER` variables to determine the IP address of the client. The variables beginning with `HTTP_` can be arbitrarily set by an attacker. Since there is a default entry in the `poller` table with the hostname of the server running Cacti, an attacker can bypass the authentication e.g. by providing the header `Forwarded-For: <TARGETIP>`. This way the function `get_client_addr` returns the IP address of the server running Cacti. The following call to `gethostbyaddr` will resolve this IP address to the hostname of the server, which will pass the `poller` hostname check because of the default entry. After the authorization of the `remote_agent.php` file is bypassed, an attacker can trigger different actions. One of these actions is called `polldata`. The called function `poll_for_data` retrieves a few request parameters and loads the corresponding `poller_item` entries from the database. If the `action` of a `poller_item` equals `POLLER_ACTION_SCRIPT_PHP`, the function `proc_open` is used to execute a PHP script. The attacker-controlled parameter `$poller_id` is retrieved via the function `get_nfilter_request_var`, which allows arbitrary strings. This variable is later inserted into the string passed to `proc_open`, which leads to a command injection vulnerability. By e.g. providing the `poller_id=;id` the `id` command is executed. In order to reach the vulnerable call, the attacker must provide a `host_id` and `local_data_id`, where the `action` of the corresponding `poller_item` is set to `POLLER_ACTION_SCRIPT_PHP`. Both of these ids (`host_id` and `local_data_id`) can easily be bruteforced. The only requirement is that a `poller_item` with an `POLLER_ACTION_SCRIPT_PHP` action exists. This is very likely on a productive instance because this action is added by some predefined templates like `Device - Uptime` or `Device - Polling Time`. This command injection vulnerability allows an unauthenticated user to execute arbitrary commands if a `poller_item` with the `action` type `POLLER_ACTION_SCRIPT_PHP` (`2`) is configured. The authorization bypass should be prevented by not allowing an attacker to make `get_client_addr` (file `lib/functions.php`) return an arbitrary IP address. This could be done by not honoring the `HTTP_...` `$_SERVER` variables. If these should be kept for compatibility reasons it should at least be prevented to fake the IP address of the server running Cacti. This vulnerability has been addressed in both the 1.2.x and 1.3.x release branches with `1.2.23` being the first release containing the patch.

    Source:Riadh Bouchahoua
    Published:5 Dec 2022
    8.1
    High

    CVE-2022-46166

    Last Modified: 23 Apr 2025

    Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are affected. Users are advised to upgrade to the most recent releases of Spring Boot Admin 2.6.10 and 2.7.8 to resolve this issue. Users unable to upgrade may disable any notifier or disable write access (POST request) on `/env` actuator endpoint.

    Published:9 Dec 2022
    9.4
    Critical

    CVE-2022-46164

    Last Modified: 23 Apr 2025

    NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts. This vulnerability has been patched in version 2.6.1. Users are advised to upgrade. Users unable to upgrade may cherry-pick commit `48d143921753914da45926cca6370a92ed0c46b8` into their codebase to patch the exploit.

    Published:5 Dec 2022
    8.2
    High

    CVE-2022-46152

    Last Modified: 5 Jun 2026

    OP-TEE Trusted OS is the secure side implementation of OP-TEE project, a Trusted Execution Environment. Versions prior to 3.19.0, contain an Improper Validation of Array Index vulnerability. The function `cleanup_shm_refs()` is called by both `entry_invoke_command()` and `entry_open_session()`. The commands `OPTEE_MSG_CMD_OPEN_SESSION` and `OPTEE_MSG_CMD_INVOKE_COMMAND` can be executed from the normal world via an OP-TEE SMC. This function is not validating the `num_params` argument, which is only limited to `OPTEE_MSG_MAX_NUM_PARAMS` (127) in the function `get_cmd_buffer()`. Therefore, an attacker in the normal world can craft an SMC call that will cause out-of-bounds reading in `cleanup_shm_refs` and potentially freeing of fake-objects in the function `mobj_put()`. A normal-world attacker with permission to execute SMC instructions may exploit this flaw. Maintainers believe this problem permits local privilege escalation from the normal world to the secure world. Version 3.19.0 contains a fix for this issue. There are no known workarounds.

    Published:29 Nov 2022
    Unknown

    CVE-2022-46104

    https://github.com/NurSec747/CVE-2022-46104---POC

    5.4
    Medium

    CVE-2022-46087

    Last Modified: 28 Mar 2025

    CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notification received by the admin user.

    Published:30 Jan 2023
    9.8
    Critical

    CVE-2022-46080

    Last Modified: 21 Nov 2024

    Nexxt Nebula 1200-AC 15.03.06.60 allows authentication bypass and command execution by using the HTTPD service to enable TELNET.

    Published:6 Jul 2023
    7.8
    High

    CVE-2022-45988

    Last Modified: 7 Mar 2025

    starsoftcomm CooCare 5.304 allows local attackers to escalate privileges and execute arbitrary commands via a crafted file upload.

    Published:3 Mar 2023
    7.8
    High

    CVE-2022-45934

    Last Modified: 29 Apr 2025

    An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets.

    Published:21 Nov 2022
    9.9
    Critical

    CVE-2022-45808

    Last Modified: 8 Jan 2025

    SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.

    Published:24 Jan 2023
    8.8
    High

    CVE-2022-45782

    Last Modified: 27 Mar 2025

    An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure random generation algorithm for password-reset token generation leads to account takeover.

    Published:1 Feb 2023
    8.8
    High

    CVE-2022-45771

    Last Modified: 24 Apr 2025

    An issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary code via uploading a crafted audit file.

    Published:5 Dec 2022
    7.8
    High

    CVE-2022-45770

    Last Modified: 31 Mar 2025

    Improper input validation in adgnetworkwfpdrv.sys in Adguard For Windows x86 through 7.11 allows local privilege escalation.

    Published:26 Jan 2023
    6.1
    Medium

    CVE-2022-45729

    Last Modified: 8 Apr 2025

    A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Employee ID parameter.

    Published:12 Jan 2023
    6.1
    Medium

    CVE-2022-45728

    Last Modified: 8 Apr 2025

    Doctor Appointment Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability.

    Published:12 Jan 2023
    8.8
    High

    CVE-2022-45701

    Last Modified: 6 Apr 2023

    Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.

    Source:Yerodin Richards
    Published:17 Feb 2023
    7.5
    High

    CVE-2022-45688

    Last Modified: 19 Sept 2025

    A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.

    Published:13 Dec 2022
    7.8
    High

    CVE-2022-45639

    Last Modified: 3 Apr 2023

    OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.

    Source:Dino Barlattani
    Published:24 Jan 2023
    8.8
    High

    CVE-2022-45600

    Last Modified: 17 Mar 2025

    Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal login.

    Published:22 Feb 2023
    9.8
    Critical

    CVE-2022-45599

    Last Modified: 17 Mar 2025

    Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, allows attackers to gain escalated privileges only when specific conditions regarding a given accounts hashed password.

    Published:22 Feb 2023
    8.8
    High

    CVE-2022-45544

    Last Modified: 21 Nov 2024

    Insecure Permission vulnerability in Schlix Web Inc SCHLIX CMS 2.2.7-2 allows attacker to upload arbitrary files and execute arbitrary code via the tristao parameter. NOTE: this is disputed by the vendor because an admin is intentionally allowed to upload new executable PHP code, such as a theme that was obtained from a trusted source or was developed for their own website. Only an admin can upload such code, not someone else in an "attacker" role.

    Published:7 Feb 2023
    7.5
    High

    CVE-2022-45511

    Last Modified: 23 Apr 2025

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the PPPOEPassword parameter at /goform/QuickIndex.

    Published:8 Dec 2022