9.8
    Critical

    CVE-2022-37042

    Last Modified: 4 Nov 2025

    Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.

    Published:11 Aug 2022
    9.1
    Critical

    CVE-2022-37032

    Last Modified: 21 Nov 2024

    An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.

    Published:19 Sept 2022
    7.5
    High

    CVE-2022-37017

    Last Modified: 24 Apr 2025

    Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing security controls. This CVE applies narrowly to the Client User Interface Password protection and Policy Import/Export Password protection, if it has been enabled.

    Published:1 Dec 2022
    7.5
    High

    CVE-2022-36946

    Last Modified: 5 May 2025

    nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service (panic) because, in the case of an nf_queue verdict with a one-byte nfta_payload attribute, an skb_pull can encounter a negative skb->len.

    Published:26 Jul 2022
    9.8
    Critical

    CVE-2022-36944

    Last Modified: 27 May 2025

    Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0 functions) via a gadget chain.

    Published:23 Sept 2022
    9.8
    Critical

    CVE-2022-36934

    Last Modified: 24 Sept 2025

    An integer overflow in WhatsApp could result in remote code execution in an established video call.

    Published:22 Sept 2022
    7.5
    High

    CVE-2022-36883

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.

    Published:27 Jul 2022
    8.8
    High

    CVE-2022-36804

    Last Modified: 23 Mar 2023

    Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.

    Source:khal4n1
    Published:25 Aug 2022
    6.5
    Medium

    CVE-2022-36779

    Last Modified: 21 Nov 2024

    PROSCEND - PROSCEND / ADVICE .Ltd - G/5G Industrial Cellular Router (with GPS)4 Unauthenticated OS Command Injection Proscend M330-w / M33-W5 / M350-5G / M350-W5G / M350-6 / M350-W6 / M301-G / M301-GW ADVICE ICR 111WG / https://www.proscend.com/en/category/industrial-Cellular-Router/industrial-Cellular-Router.html https://cdn.shopify.com/s/files/1/0036/9413/3297/files/ADVICE_Industrial_4G_LTE_Cellular_Router_ICR111WG.pdf?v=1620814301

    Published:13 Sept 2022
    5.5
    Medium

    CVE-2022-36752

    Last Modified: 21 Nov 2024

    png2webp v1.0.4 was discovered to contain an out-of-bounds write via the function w2p. This vulnerability is exploitable via a crafted png file.

    Published:28 Jul 2022
    6.1
    Medium

    CVE-2022-36664

    Last Modified: 25 Mar 2023

    Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter.

    Source:VP4TR10T
    Published:26 Dec 2022
    9.8
    Critical

    CVE-2022-36663

    Last Modified: 21 Nov 2024

    Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.

    Published:6 Sept 2022
    8.8
    High

    CVE-2022-36633

    Last Modified: 23 Sept 2022

    Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with carriage return line feed. This url encoded payload can be used in place of a token and sent to a user in a social engineering attack. This is fully unauthenticated attack utilizing the trusted teleport server to deliver the payload.

    Source:Brandon Roach
    Published:24 Aug 2022
    9.8
    Critical

    CVE-2022-36553

    Last Modified: 21 Nov 2024

    Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi.

    Published:29 Aug 2022
    6.5
    Medium

    CVE-2022-36551

    Last Modified: 28 Mar 2023

    A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authenticated user to access arbitrary files on the system. Furthermore, self-registration is enabled by default in these versions of Label Studio enabling a remote attacker to create a new account and then exploit the SSRF.

    Source:Ryan Smith
    Published:3 Oct 2022
    7.5
    High

    CVE-2022-36539

    Last Modified: 21 Nov 2024

    WeDayCare B.V Ouderapp before v1.1.22 allows attackers to alter the ID value within intercepted calls to gain access to data of other parents and children.

    Published:7 Sept 2022
    7.5
    High

    CVE-2022-36537

    Last Modified: 3 Nov 2025

    ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.

    Published:26 Aug 2022
    8.8
    High

    CVE-2022-36532

    Last Modified: 21 Nov 2024

    Bolt CMS contains a vulnerability in version 5.1.12 and below that allows an authenticated user with the ROLE_EDITOR privileges to upload and rename a malicious file to achieve remote code execution.

    Published:16 Sept 2022
    9.8
    Critical

    CVE-2022-36446

    Last Modified: 1 Aug 2022

    software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.

    Source:Emir Polat
    Published:25 Jul 2022
    6.1
    Medium

    CVE-2022-36433

    Last Modified: 25 Apr 2025

    The blog-post creation functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 allows injection of JavaScript code in the short_content and full_content fields, leading to XSS attacks against admin panel users via posts/preview or posts/save.

    Published:29 Nov 2022
    5.4
    Medium

    CVE-2022-36432

    Last Modified: 30 Apr 2025

    The Preview functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 uses eval unsafely. This allows attackers to perform Cross-site Scripting attacks on admin panel users by manipulating the generated preview application response.

    Published:17 Nov 2022
    7.8
    High

    CVE-2022-36271

    Last Modified: 29 Jul 2026

    Outbyte PC Repair Installation File 1.7.112.7856 is vulnerable to Dll Hijacking. iertutil.dll is missing so an attacker can use a malicious dll with same name and can get admin privileges.

    Published:7 Sept 2022
    9.8
    Critical

    CVE-2022-36267

    Last Modified: 20 Sept 2022

    In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can be called without user authentication when crafting a malicious http request by injecting code in one of the parameters allowing for remote code execution. This vulnerability is exploited via the binary file /home/www/cgi-bin/diagnostics.cgi that accepts unauthenticated requests and unsanitized data. As a result, a malicious actor can craft a specific request and interact remotely with the device.

    Source:Samy Younsi
    Published:8 Aug 2022
    7.5
    High

    CVE-2022-36234

    Last Modified: 21 Nov 2024

    SimpleNetwork TCP Server commit 29bc615f0d9910eb2f59aa8dff1f54f0e3af4496 was discovered to contain a double free vulnerability which is exploited via crafted TCP packets.

    Published:28 Jul 2022
    9.8
    Critical

    CVE-2022-36231

    Last Modified: 13 Mar 2025

    pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.

    Published:23 Feb 2023
    7.5
    High

    CVE-2022-36200

    Last Modified: 21 Nov 2024

    In FiberHome VDSL2 Modem HG150-Ub_V3.0, Credentials of Admin are submitted in URL, which can be logged/sniffed.

    Published:29 Aug 2022
    9.8
    Critical

    CVE-2022-36193

    Last Modified: 25 Apr 2025

    SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.

    Published:28 Nov 2022
    Unknown

    CVE-2022-36163

    https://github.com/MaherAzzouzi/CVE-2022-36163

    Unknown

    CVE-2022-36162

    https://github.com/MaherAzzouzi/CVE-2022-36162

    10
    Critical

    CVE-2022-36067

    Last Modified: 22 Apr 2025

    vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.11 of vm2. There are no known workarounds.

    Published:6 Sept 2022
    5.5
    Medium

    CVE-2022-36021

    Last Modified: 7 Mar 2025

    Redis is an in-memory database that persists on disk. Authenticated users can use string matching commands (like `SCAN` or `KEYS`) with a specially crafted pattern to trigger a denial-of-service attack on Redis, causing it to hang and consume 100% CPU time. The problem is fixed in Redis versions 6.0.18, 6.2.11, 7.0.9.

    Published:28 Feb 2023
    6.1
    Medium

    CVE-2022-36007

    Last Modified: 22 Apr 2025

    Venice is a Clojure inspired sandboxed Lisp dialect with excellent Java interoperability. A partial path traversal issue exists within the functions `load-file` and `load-resource`. These functions can be limited to load files from a list of load paths. Assuming Venice has been configured with the load paths: `[ "/Users/foo/resources" ]` When passing **relative** paths to these two vulnerable functions everything is fine: `(load-resource "test.png")` => loads the file "/Users/foo/resources/test.png" `(load-resource "../resources-alt/test.png")` => rejected, outside the load path When passing **absolute** paths to these two vulnerable functions Venice may return files outside the configured load paths: `(load-resource "/Users/foo/resources/test.png")` => loads the file "/Users/foo/resources/test.png" `(load-resource "/Users/foo/resources-alt/test.png")` => loads the file "/Users/foo/resources-alt/test.png" !!! The latter call suffers from the _Partial Path Traversal_ vulnerability. This issue’s scope is limited to absolute paths whose name prefix matches a load path. E.g. for a load-path `"/Users/foo/resources"`, the actor can cause loading a resource also from `"/Users/foo/resources-alt"`, but not from `"/Users/foo/images"`. Versions of Venice before and including v1.10.17 are affected by this issue. Upgrade to Venice >= 1.10.18, if you are on a version < 1.10.18. There are currently no known workarounds.

    Published:14 Aug 2022
    7.7
    High

    CVE-2022-35978

    Last Modified: 23 Apr 2025

    Minetest is a free open-source voxel game engine with easy modding and game creation. In **single player**, a mod can set a global setting that controls the Lua script loaded to display the main menu. The script is then loaded as soon as the game session is exited. The Lua environment the menu runs in is not sandboxed and can directly interfere with the user's system. There are currently no known workarounds.

    Published:15 Aug 2022
    7.4
    High

    CVE-2022-35919

    Last Modified: 9 Oct 2023

    MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. In affected versions all 'admin' users authorized for `admin:ServerUpdate` can selectively trigger an error that in response, returns the content of the path requested. Any normal OS system would allow access to contents at any arbitrary paths that are readable by MinIO process. Users are advised to upgrade. Users unable to upgrade may disable ServerUpdate API by denying the `admin:ServerUpdate` action for your admin users via IAM policies.

    Source:Jenson Zhao
    Published:1 Aug 2022
    9.8
    Critical

    CVE-2022-35914

    Last Modified: 19 May 2024

    /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.

    Source:Miguel Redondo
    Published:19 Sept 2022
    7.8
    High

    CVE-2022-35899

    Last Modified: 29 Jul 2022

    There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local user to escalate privileges by creating a %PROGRAMFILES(X86)%\ASUS\GameSDK.exe file.

    Source:Angelo Pio Amirante
    Published:21 Jul 2022
    8.8
    High

    CVE-2022-35841

    Last Modified: 11 Mar 2025

    Windows Enterprise App Management Service Remote Code Execution Vulnerability

    Published:13 Sept 2022
    7.5
    High

    CVE-2022-35737

    Last Modified: 13 Feb 2026

    SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.

    Published:22 Jul 2022
    10
    Critical

    CVE-2022-35698

    Last Modified: 23 Apr 2025

    Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.

    Published:14 Oct 2022
    7.5
    High

    CVE-2022-35650

    Last Modified: 21 Nov 2024

    The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.

    Published:25 Jul 2022
    9.8
    Critical

    CVE-2022-35649

    Last Modified: 21 Nov 2024

    The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

    Published:25 Jul 2022
    9.8
    Critical

    CVE-2022-35583

    Last Modified: 23 Mar 2023

    wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.

    Source:Momen Eldawakhly
    Published:22 Aug 2022
    Unknown

    CVE-2022-35543

    https://www.exploit-db.com/exploits/51200

    7.5
    High

    CVE-2022-35513

    Last Modified: 20 Sept 2022

    The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage.

    Source:p1ckzi
    Published:7 Sept 2022
    5.4
    Medium

    CVE-2022-35501

    Last Modified: 28 Apr 2025

    Stored Cross-site Scripting (XSS) exists in the Amasty Blog Pro 2.10.3 and 2.10.4 plugin for Magento 2 because of the duplicate post function.

    Published:23 Nov 2022
    5.4
    Medium

    CVE-2022-35500

    Last Modified: 28 Apr 2025

    Amasty Blog 2.10.3 is vulnerable to Cross Site Scripting (XSS) via leave comment functionality.

    Published:23 Nov 2022
    7.1
    High

    CVE-2022-35499

    Last Modified: 4 Sept 2026

    In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL.

    Published:4 Sept 2026
    Low

    CVE-2022-35497

    Last Modified: 4 Sept 2026

    In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid session cookies via reflected cross-site scripting affecting the external document viewer endpoint.

    Published:4 Sept 2026
    6.1
    Medium

    CVE-2022-35416

    Last Modified: 21 Nov 2024

    H3C SSL VPN through 2022-07-10 allows wnm/login/login.json svpnlang cookie XSS.

    Published:11 Jul 2022
    9.8
    Critical

    CVE-2022-35411

    Last Modified: 29 Jul 2022

    rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated client can cause the data to be processed with unpickle.

    Source:Elias Hohl
    Published:8 Jul 2022