9.9
    Critical

    CVE-2022-41272

    Last Modified: 21 Apr 2025

    An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and data across the entire system. This allows the attacker to have full read access to user data, make limited modifications to user data, and degrade the performance of the system, leading to a high impact on confidentiality and a limited impact on the availability and integrity of the application.

    Published:13 Dec 2022
    9.8
    Critical

    CVE-2022-41220

    Last Modified: 9 Apr 2025

    md2roff 1.9 has a stack-based buffer overflow via a Markdown file, a different vulnerability than CVE-2022-34913. NOTE: the vendor's position is that the product is not intended for untrusted input

    Published:21 Sept 2022
    5.5
    Medium

    CVE-2022-41218

    Last Modified: 28 May 2025

    In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting dvb_demux_open and dvb_dmxdev_release.

    Published:21 Sept 2022
    7
    High

    CVE-2022-41114

    Last Modified: 2 Jan 2025

    Windows Bind Filter Driver Elevation of Privilege Vulnerability

    Published:9 Nov 2022
    4.6
    Medium

    CVE-2022-41099

    Last Modified: 2 Jan 2025

    BitLocker Security Feature Bypass Vulnerability

    Published:9 Nov 2022
    8
    High

    CVE-2022-41082

    Last Modified: 30 Oct 2025

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Published:3 Oct 2022
    8.8
    High

    CVE-2022-41080

    Last Modified: 30 Oct 2025

    Microsoft Exchange Server Elevation of Privilege Vulnerability

    Published:9 Nov 2022
    8.8
    High

    CVE-2022-41040

    Last Modified: 30 Oct 2025

    Microsoft Exchange Server Elevation of Privilege Vulnerability

    Published:3 Oct 2022
    7.8
    High

    CVE-2022-41034

    Last Modified: 2 Jan 2025

    Visual Studio Code Remote Code Execution Vulnerability

    Published:11 Oct 2022
    7.8
    High

    CVE-2022-41032

    Last Modified: 28 Feb 2025

    NuGet Client Elevation of Privilege Vulnerability

    Published:11 Oct 2022
    7.5
    High

    CVE-2022-40946

    Last Modified: 25 Mar 2023

    On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via the sys_token parameter in a cgi-bin/webproc?getpage=html/index.html request.

    Source:whokilleddb
    Published:16 Apr 2023
    9.8
    Critical

    CVE-2022-40916

    Last Modified: 31 Dec 2025

    Tiny File Manager v2.4.7 and below is vulnerable to session fixation.

    Published:6 Feb 2025
    9.8
    Critical

    CVE-2022-40881

    Last Modified: 29 Apr 2025

    SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php

    Published:17 Nov 2022
    8.8
    High

    CVE-2022-40799

    Last Modified: 3 Nov 2025

    Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device.

    Published:29 Nov 2022
    7.5
    High

    CVE-2022-40769

    Last Modified: 21 Nov 2024

    profanity through 1.60 has only four billion possible RNG initializations. Thus, attackers can recover private keys from Ethereum vanity addresses and steal cryptocurrency, as exploited in the wild in June 2022.

    Published:18 Sept 2022
    9.8
    Critical

    CVE-2022-40684

    Last Modified: 27 Mar 2023

    An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

    Source:Felipe Alcantara
    Published:18 Oct 2022
    6.4
    Medium

    CVE-2022-40635

    Last Modified: 21 Nov 2024

    Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass.

    Published:13 Sept 2022
    6.4
    Medium

    CVE-2022-40634

    Last Modified: 21 Nov 2024

    Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker SSTI.

    Published:13 Sept 2022
    9.8
    Critical

    CVE-2022-40624

    Last Modified: 17 Apr 2025

    pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814.

    Published:20 Dec 2022
    4.8
    Medium

    CVE-2022-40490

    Last Modified: 31 Dec 2025

    Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the name of an uploaded or already existing file.

    Published:6 Feb 2025
    9.8
    Critical

    CVE-2022-40471

    Last Modified: 6 May 2025

    Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functionality in users.php

    Published:31 Oct 2022
    4.8
    Medium

    CVE-2022-40470

    Last Modified: 29 Apr 2025

    Phpgurukul Blood Donor Management System 1.0 allows Cross Site Scripting via Add Blood Group Name Feature.

    Published:21 Nov 2022
    5.5
    Medium

    CVE-2022-40363

    Last Modified: 21 May 2025

    A buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 allows attackers to cause a Denial of Service (DoS) via a crafted NFC file.

    Published:29 Sept 2022
    5.4
    Medium

    CVE-2022-40348

    Last Modified: 17 Mar 2025

    Cross Site Scripting (XSS) vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'name' and 'email' parameters, allows attackers to execute arbitrary code.

    Published:18 Feb 2023
    9.8
    Critical

    CVE-2022-40347

    Last Modified: 5 May 2023

    SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allows attackers to execute arbitrary code and gain sensitive information.

    Source:Hamdi Sevben
    Published:17 Feb 2023
    7.5
    High

    CVE-2022-40319

    Last Modified: 30 Mar 2023

    The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a wa.exe URL. The impact is unauthorized modification of a victim's LISTSERV account.

    Source:Shaunt Der-Grigorian
    Published:17 Jan 2023
    5.4
    Medium

    CVE-2022-40317

    Last Modified: 21 Nov 2024

    OpenKM 6.3.11 allows stored XSS related to the javascript&colon; substring in an A element.

    Published:9 Sept 2022
    7.8
    High

    CVE-2022-40297

    Last Modified: 21 Nov 2024

    UBports Ubuntu Touch 16.04 allows the screen-unlock passcode to be used for a privileged shell via Sudo. This passcode is only four digits, far below typical length/complexity for a user account's password. NOTE: a third party states "The described attack cannot be executed as demonstrated.

    Published:8 Sept 2022
    7.5
    High

    CVE-2022-40146

    Last Modified: 3 Nov 2025

    Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14.

    Published:22 Sept 2022
    5.5
    Medium

    CVE-2022-40140

    Last Modified: 21 Nov 2024

    An origin validation error vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to cause a denial-of-service on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published:19 Sept 2022
    8.8
    High

    CVE-2022-40127

    Last Modified: 30 Apr 2025

    A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter. This issue affects Apache Airflow Apache Airflow versions prior to 2.4.0.

    Published:14 Nov 2022
    7.8
    High

    CVE-2022-40126

    Last Modified: 21 May 2025

    A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privileges and execute arbitrary commands when Service Mode is activated.

    Published:29 Sept 2022
    9.8
    Critical

    CVE-2022-40032

    Last Modified: 5 May 2023

    SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows attackers to execute arbitrary code and gain sensitive information.

    Source:Hamdi Sevben
    Published:17 Feb 2023
    4.8
    Medium

    CVE-2022-39996

    Last Modified: 30 Aug 2024

    Cross Site Scripting vulnerability in Teldats Router RS123, RS123w allows attacker to execute arbitrary code via the cmdcookie parameter to the upgrade/query.php page.

    Published:27 Aug 2024
    9.8
    Critical

    CVE-2022-39986

    Last Modified: 21 Nov 2024

    A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php.

    Published:1 Aug 2023
    7.8
    High

    CVE-2022-39959

    Last Modified: 21 Nov 2024

    Panini Everest Engine 2.0.4 allows unprivileged users to create a file named Everest.exe in the %PROGRAMDATA%\Panini folder. This leads to privilege escalation because a service, running as SYSTEM, uses the unquoted path of %PROGRAMDATA%\Panini\Everest Engine\EverestEngine.exe and therefore a Trojan horse %PROGRAMDATA%\Panini\Everest.exe may be executed instead of the intended vendor-supplied EverestEngine.exe file.

    Published:7 Oct 2022
    9.8
    Critical

    CVE-2022-39952

    Last Modified: 21 Nov 2024

    A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request.

    Published:16 Feb 2023
    Unknown

    CVE-2022-39841

    https://github.com/stealthcopter/CVE-2022-39841

    8.6
    High

    CVE-2022-39838

    Last Modified: 21 Nov 2024

    Systematic FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via a UNC share pathname, and also allows absolute path traversal to local pathnames.

    Published:5 Sept 2022
    7.5
    High

    CVE-2022-39802

    Last Modified: 21 Nov 2024

    SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The intended file path can be manipulated to allow arbitrary traversal of directories on the remote server. The file content within each directory can be read which may lead to information disclosure.

    Published:11 Oct 2022
    8.1
    High

    CVE-2022-39425

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.40. Difficult to exploit vulnerability allows unauthenticated attacker with network access via VRDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

    Published:18 Oct 2022
    7.4
    High

    CVE-2022-39299

    Last Modified: 23 Apr 2025

    Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. A remote attacker may be able to bypass SAML authentication on a website using passport-saml. A successful attack requires that the attacker is in possession of an arbitrary IDP signed XML element. Depending on the IDP used, fully unauthenticated attacks (e.g without access to a valid user) might also be feasible if generation of a signed message can be triggered. Users should upgrade to passport-saml version 3.2.2 or newer. The issue was also present in the beta releases of `node-saml` before version 4.0.0-beta.5. If you cannot upgrade, disabling SAML authentication may be done as a workaround.

    Published:12 Oct 2022
    5.4
    Medium

    CVE-2022-39291

    Last Modified: 19 Jun 2023

    ZoneMinder is a free, open source Closed-circuit television software application. Affected versions of zoneminder are subject to a vulnerability which allows users with "View" system permissions to inject new data into the logs stored by Zoneminder. This was observed through an HTTP POST request containing log information to the "/zm/index.php" endpoint. Submission is not rate controlled and could affect database performance and/or consume all storage resources. Users are advised to upgrade. There are no known workarounds for this issue.

    Source:Trenches of IT
    Published:7 Oct 2022
    8
    High

    CVE-2022-39290

    Last Modified: 19 Jun 2023

    ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated users can bypass CSRF keys by modifying the request supplied to the Zoneminder web application. These modifications include replacing HTTP POST with an HTTP GET and removing the CSRF key from the request. An attacker can take advantage of this by using an HTTP GET request to perform actions with no CSRF protection. This could allow an attacker to cause an authenticated user to perform unexpected actions on the web application. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

    Source:Trenches of IT
    Published:7 Oct 2022
    7.6
    High

    CVE-2022-39285

    Last Modified: 19 Jun 2023

    ZoneMinder is a free, open source Closed-circuit television software application The file parameter is vulnerable to a cross site scripting vulnerability (XSS) by backing out of the current "tr" "td" brackets. This then allows a malicious user to provide code that will execute when a user views the specific log on the "view=log" page. This vulnerability allows an attacker to store code within the logs that will be executed when loaded by a legitimate user. These actions will be performed with the permission of the victim. This could lead to data loss and/or further exploitation including account takeover. This issue has been addressed in versions `1.36.27` and `1.37.24`. Users are advised to upgrade. Users unable to upgrade should disable database logging.

    Source:Trenches of IT
    Published:7 Oct 2022
    5.3
    Medium

    CVE-2022-39275

    Last Modified: 23 Apr 2025

    Saleor is a headless, GraphQL commerce platform. In affected versions some GraphQL mutations were not properly checking the ID type input which allowed to access database objects that the authenticated user may not be allowed to access. This vulnerability can be used to expose the following information: Estimating database row counts from tables with a sequential primary key or Exposing staff user and customer email addresses and full name through the `assignNavigation()` mutation. This issue has been patched in main and backported to multiple releases (3.7.17, 3.6.18, 3.5.23, 3.4.24, 3.3.26, 3.2.14, 3.1.24). Users are advised to upgrade. There are no known workarounds for this issue.

    Published:6 Oct 2022
    5.5
    Medium

    CVE-2022-39253

    Last Modified: 21 Nov 2024

    Git is an open source, scalable, distributed revision control system. Versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4 are subject to exposure of sensitive information to a malicious actor. When performing a local clone (where the source and target of the clone are on the same volume), Git copies the contents of the source's `$GIT_DIR/objects` directory into the destination by either creating hardlinks to the source contents, or copying them (if hardlinks are disabled via `--no-hardlinks`). A malicious actor could convince a victim to clone a repository with a symbolic link pointing at sensitive information on the victim's machine. This can be done either by having the victim clone a malicious repository on the same machine, or having them clone a malicious repository embedded as a bare repository via a submodule from any source, provided they clone with the `--recurse-submodules` option. Git does not create symbolic links in the `$GIT_DIR/objects` directory. The problem has been patched in the versions published on 2022-10-18, and backported to v2.30.x. Potential workarounds: Avoid cloning untrusted repositories using the `--local` optimization when on a shared machine, either by passing the `--no-local` option to `git clone` or cloning from a URL that uses the `file://` scheme. Alternatively, avoid cloning repositories from untrusted sources with `--recurse-submodules` or run `git config --global protocol.file.allow user`.

    Published:18 Oct 2022
    9.1
    Critical

    CVE-2022-39227

    Last Modified: 21 Nov 2024

    python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key. Depending on the application, this may for example enable the attacker to spoof other user's identities, hijack their sessions, or bypass authentication. Users should upgrade to version 3.3.4. There are no known workarounds.

    Published:23 Sept 2022
    6.1
    Medium

    CVE-2022-39197

    Last Modified: 3 Nov 2025

    An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the username field in the payload (or create a new payload with the extracted information and then modify that username field to be malformed).

    Published:22 Sept 2022
    6.5
    Medium

    CVE-2022-39196

    Last Modified: 21 Nov 2024

    Blackboard Learn 1.10.1 allows remote authenticated users to read unintended files by entering student credentials and then directly visiting a certain webapps/bbcms/execute/ URL. Note: The vendor disputes this stating this cannot be reproduced.

    Published:4 Sept 2022