9.8
    Critical

    CVE-2022-45477

    Last Modified: 24 Apr 2025

    Telepad allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

    Published:5 Dec 2022
    5.4
    Medium

    CVE-2022-45472

    Last Modified: 25 Apr 2025

    CAE LearningSpace Enterprise (with Intuity License) image 267r patch 639 allows DOM XSS, related to ontouchmove and onpointerup.

    Published:23 Nov 2022
    9.8
    Critical

    CVE-2022-45460

    Last Modified: 19 Feb 2025

    Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow an unauthenticated and remote user to exploit a stack-based buffer overflow and crash the web server, resulting in a system reboot. An unauthenticated and remote attacker can execute arbitrary code by sending a crafted HTTP request that triggers the overflow condition via a long URI passed to a sprintf call. NOTE: this is different than CVE-2018-10088, but this may overlap CVE-2017-16725.

    Published:28 Mar 2023
    7.8
    High

    CVE-2022-45451

    Last Modified: 21 Nov 2024

    Local privilege escalation due to insecure driver communication port permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40173, Acronis Agent (Windows) before build 30600, Acronis Cyber Protect 15 (Windows) before build 30984.

    Published:31 Aug 2023
    6.1
    Medium

    CVE-2022-45436

    Last Modified: 18 Mar 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Artica PFMS Pandora FMS v765 on all platforms, allows Cross-Site Scripting (XSS). As a manager privilege user , create a network map containing name as xss payload. Once created, admin user must click on the edit network maps and XSS payload will be executed, which could be used for stealing admin users cookie value.

    Published:15 Feb 2023
    5.3
    Medium

    CVE-2022-45354

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.

    Published:8 Jan 2024
    9.8
    Critical

    CVE-2022-45299

    Last Modified: 7 Apr 2025

    An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL.

    Published:13 Jan 2023
    9.8
    Critical

    CVE-2022-45297

    Last Modified: 31 Mar 2023

    EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter.

    Source:TLF
    Published:31 Jan 2023
    Unknown

    CVE-2022-45265

    https://github.com/maikroservice/CVE-2022-45265

    5.4
    Medium

    CVE-2022-45217

    Last Modified: 23 Apr 2025

    A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Level parameter under the Add New System User module.

    Published:7 Dec 2022
    7.5
    High

    CVE-2022-45059

    Last Modified: 1 May 2025

    An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache servers by requesting that certain headers are made hop-by-hop, preventing the Varnish Cache servers from forwarding critical headers to the backend.

    Published:8 Nov 2022
    9.8
    Critical

    CVE-2022-45047

    Last Modified: 1 May 2026

    Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apache MINA SSHD can choose for loading the host keys of an SSH server.

    Published:16 Nov 2022
    8.8
    High

    CVE-2022-45030

    Last Modified: 31 Mar 2023

    A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may interact with secure-file-priv).

    Source:azhen
    Published:15 Apr 2023
    9.8
    Critical

    CVE-2022-45025

    Last Modified: 23 Apr 2025

    Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerability via the PDF file import function.

    Published:7 Dec 2022
    6.1
    Medium

    CVE-2022-45004

    Last Modified: 26 Feb 2025

    Gophish through 0.12.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted landing page.

    Published:22 Mar 2023
    7.5
    High

    CVE-2022-45003

    Last Modified: 25 Feb 2025

    Gophish through 0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted payload involving autofocus.

    Published:22 Mar 2023
    9.1
    Critical

    CVE-2022-44900

    Last Modified: 23 Apr 2025

    A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z file.

    Published:6 Dec 2022
    9.8
    Critical

    CVE-2022-44877

    Last Modified: 1 Apr 2023

    login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.

    Source:numan türle
    Published:5 Jan 2023
    5.4
    Medium

    CVE-2022-44875

    Last Modified: 6 Mar 2025

    KioWare through 8.33 on Windows sets KioScriptingUrlACL.AclActions.AllowHigh for the about:blank origin, which allows attackers to obtain SYSTEM access via KioUtils.Execute in JavaScript code.

    Published:6 Mar 2023
    6.1
    Medium

    CVE-2022-44870

    Last Modified: 9 Apr 2025

    A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management module.

    Published:6 Jan 2023
    7.8
    High

    CVE-2022-44830

    Last Modified: 29 Apr 2025

    Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.

    Published:21 Nov 2022
    8.8
    High

    CVE-2022-44789

    Last Modified: 25 Apr 2025

    A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.

    Published:23 Nov 2022
    Low

    CVE-2022-44721

    Last Modified: 13 Feb 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-2841. Reason: This issue was MERGED into CVE-2022-2841 in accordance with CVE content decisions, because it is the same type of vulnerability and affects the same versions. Notes: All CVE users should reference CVE-2022-2841 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published:4 Dec 2022
    7.8
    High

    CVE-2022-44666

    Last Modified: 27 Aug 2025

    Windows Contacts Remote Code Execution Vulnerability

    Published:13 Dec 2022
    7.8
    High

    CVE-2022-44569

    Last Modified: 21 Nov 2024

    A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.

    Published:3 Nov 2023
    5.5
    Medium

    CVE-2022-44318

    Last Modified: 1 May 2025

    PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StringStrcat function in cstdlib/string.c when called from ExpressionParseFunctionCall.

    Published:8 Nov 2022
    5.5
    Medium

    CVE-2022-44312

    Last Modified: 1 May 2025

    PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceInteger function in expression.c when called from ExpressionInfixOperator.

    Published:8 Nov 2022
    8.1
    High

    CVE-2022-44311

    Last Modified: 1 May 2025

    html2xhtml v1.3 was discovered to contain an Out-Of-Bounds read in the function static void elm_close(tree_node_t *nodo) at procesador.c. This vulnerability allows attackers to access sensitive files or cause a Denial of Service (DoS) via a crafted html file.

    Published:8 Nov 2022
    9.8
    Critical

    CVE-2022-44276

    Last Modified: 5 Dec 2024

    In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.

    Published:28 Jun 2023
    6.5
    Medium

    CVE-2022-44268

    Last Modified: 24 Apr 2023

    ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it).

    Source:Cristian Giustini
    Published:6 Feb 2023
    6.5
    Medium

    CVE-2022-44267

    Last Modified: 5 Apr 2023

    ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left waiting for stdin input.

    Source:nu11secur1ty
    Published:6 Feb 2023
    9.8
    Critical

    CVE-2022-44262

    Last Modified: 29 Apr 2025

    ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).

    Published:1 Dec 2022
    6.1
    Medium

    CVE-2022-44215

    Last Modified: 21 Nov 2024

    There is an open redirect vulnerability in Titan FTP server 19.0 and below. Users are redirected to any target URL.

    Published:22 Aug 2023
    9.8
    Critical

    CVE-2022-44183

    Last Modified: 29 Apr 2025

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetWifiGuestBasic.

    Published:21 Nov 2022
    8.8
    High

    CVE-2022-44149

    Last Modified: 1 Apr 2023

    The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field to the ping feature of the goform/sysTools component. Authentication is required

    Source:Yerodin Richards
    Published:6 Jan 2023
    9.8
    Critical

    CVE-2022-44136

    Last Modified: 24 Apr 2025

    Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).

    Published:30 Nov 2022
    9.8
    Critical

    CVE-2022-44118

    Last Modified: 28 Apr 2025

    dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php.

    Published:23 Nov 2022
    5.2
    Medium

    CVE-2022-43980

    Last Modified: 27 Mar 2025

    There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An attacker could modify a network map, including on purpose the name of an XSS payload. Once created, if a user with admin privileges clicks on the edited network maps, the XSS payload will be executed. The exploitation of this vulnerability could allow an atacker to steal the value of the admin user´s cookie.

    Published:27 Jan 2023
    7.2
    High

    CVE-2022-43973

    Last Modified: 9 Apr 2025

    An arbitrary code execution vulnerability exisits in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. The Check_TSSI function within the httpd binary uses unvalidated user input in the construction of a system command. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via a malicious POST request to /apply.cgi to execute arbitrary commands on the underlying Linux operating system as root.

    Published:9 Jan 2023
    4.9
    Medium

    CVE-2022-43959

    Last Modified: 2 Apr 2025

    Insufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remote administrators to discover an AD/LDAP administrative password by reading the source code of /bitrix/admin/ldap_server_edit.php.

    Published:20 Jan 2023
    8.6
    High

    CVE-2022-43939

    Last Modified: 8 Apr 2023

    Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.

    Source:dwbzn
    Published:3 Apr 2023
    8.8
    High

    CVE-2022-43769

    Last Modified: 8 Apr 2023

    Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.

    Source:dwbzn
    Published:3 Apr 2023
    5.9
    Medium

    CVE-2022-43704

    Last Modified: 2 Apr 2025

    The Sinilink XY-WFT1 WiFi Remote Thermostat, running firmware 1.3.6, allows an attacker to bypass the intended requirement to communicate using MQTT. It is possible to replay Sinilink aka SINILINK521 protocol (udp/1024) commands interfacing directly with the target device. This, in turn, allows for an attack to control the onboard relay without requiring authentication via the mobile application. This might result in an unacceptable temperature within the target device's physical environment.

    Published:20 Jan 2023
    7.5
    High

    CVE-2022-43680

    Last Modified: 30 May 2025

    In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.

    Published:24 Oct 2022
    8.8
    High

    CVE-2022-43571

    Last Modified: 2 May 2025

    In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation component.

    Published:3 Nov 2022
    6.1
    Medium

    CVE-2022-43369

    Last Modified: 23 Apr 2025

    AutoTaxi Stand Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component search.php.

    Published:6 Dec 2022
    7.5
    High

    CVE-2022-43343

    Last Modified: 1 May 2025

    N-Prolog v1.91 was discovered to contain a global buffer overflow vulnerability in the function gettoken() at Main.c.

    Published:8 Nov 2022
    6.1
    Medium

    CVE-2022-43332

    Last Modified: 29 Apr 2025

    A cross-site scripting (XSS) vulnerability in Wondercms v3.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Site title field of the Configuration Panel.

    Published:17 Nov 2022
    5.9
    Medium

    CVE-2022-43293

    Last Modified: 11 Feb 2025

    Wacom Driver 6.3.46-1 for Windows was discovered to contain an arbitrary file write vulnerability via the component \Wacom\Wacom_Tablet.exe.

    Published:11 Apr 2023
    5.4
    Medium

    CVE-2022-43271

    Last Modified: 15 Apr 2025

    Inhabit Systems Pty Ltd Move CRM version 4, build 260 was discovered to contain a cross-site scripting (XSS) vulnerability via the User profile component.

    Published:22 Dec 2022