10
    Critical

    CVE-2022-32548

    Last Modified: 21 Nov 2024

    An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or password to the aa or ab field.

    Published:29 Aug 2022
    9.8
    Critical

    CVE-2022-32532

    Last Modified: 21 Nov 2024

    Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

    Published:28 Jun 2022
    9.8
    Critical

    CVE-2022-32429

    Last Modified: 18 Nov 2022

    An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, leading to remote code execution.

    Source:Eli Fulkerson
    Published:9 Aug 2022
    7.5
    High

    CVE-2022-32287

    Last Modified: 2 May 2025

    A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows an attacker to create files outside the designated target directory using carefully crafted ZIP entry names. This issue affects Apache UIMA Apache UIMA version 3.3.0 and prior versions. Note that PEAR files should never be installed into an UIMA installation from untrusted sources because PEAR archives are executable plugins that will be able to perform any actions with the same privileges as the host Java Virtual Machine.

    Published:3 Nov 2022
    9.8
    Critical

    CVE-2022-32272

    Last Modified: 28 Mar 2023

    OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access control, resulting in privilege escalation.

    Source:Ulascan Yildirim
    Published:9 Jun 2022
    7.8
    High

    CVE-2022-32250

    Last Modified: 21 Nov 2024

    net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.

    Published:31 May 2022
    9.8
    Critical

    CVE-2022-32224

    Last Modified: 11 May 2026

    A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (via means like SQL injection), the ability to escalate to an RCE.

    Published:12 Jul 2022
    7.3
    High

    CVE-2022-32223

    Last Modified: 30 Apr 2025

    Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploited if the victim has the following dependencies on a Windows machine:* OpenSSL has been installed and “C:\Program Files\Common Files\SSL\openssl.cnf” exists.Whenever the above conditions are present, `node.exe` will search for `providers.dll` in the current user directory.After that, `node.exe` will try to search for `providers.dll` by the DLL Search Order in Windows.It is possible for an attacker to place the malicious file `providers.dll` under a variety of paths and exploit this vulnerability.

    Published:14 Jul 2022
    6.5
    Medium

    CVE-2022-32199

    Last Modified: 19 Feb 2025

    db_convert.php in ScriptCase through 9.9.008 is vulnerable to Arbitrary File Deletion by an admin via a directory traversal sequence in the file parameter.

    Published:27 Mar 2023
    Unknown

    CVE-2022-32132

    https://github.com/reewardius/CVE-2022-32132

    8.8
    High

    CVE-2022-32119

    Last Modified: 21 Nov 2024

    Arox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo function at photogalleries.inc.php and the import staff excel function at 1finance_master.inc.php.

    Published:15 Jul 2022
    6.1
    Medium

    CVE-2022-32118

    Last Modified: 21 Nov 2024

    Arox School ERP Pro v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the dispatchcategory parameter in backoffice.inc.php.

    Published:15 Jul 2022
    8.8
    High

    CVE-2022-32114

    Last Modified: 13 Feb 2025

    An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file. NOTE: the project documentation suggests that a user with the Media Library "Create (upload)" permission is supposed to be able to upload PDF files containing JavaScript, and that all files in a public assets folder are accessible to the outside world (unless the filename begins with a dot character). The administrator can choose to allow only image, video, and audio files (i.e., not PDF) if desired.

    Published:13 Jul 2022
    5.4
    Medium

    CVE-2022-32074

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889fd5533d13deb3c6a7789768795ae allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file.

    Published:13 Jul 2022
    9.8
    Critical

    CVE-2022-32073

    Last Modified: 21 Nov 2024

    WolfSSH v1.4.7 was discovered to contain an integer overflow via the function wolfSSH_SFTP_RecvRMDIR.

    Published:13 Jul 2022
    4.8
    Medium

    CVE-2022-32060

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.

    Published:7 Jul 2022
    7.2
    High

    CVE-2022-32013

    Last Modified: 21 Nov 2024

    Complete Online Job Search System v1.0 is vulnerable to SQL Injection via eris/admin/category/index.php?view=edit&id=.

    Published:2 Jun 2022
    7.2
    High

    CVE-2022-31983

    Last Modified: 21 Nov 2024

    Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=requests/manage_request&id=.

    Published:1 Jun 2022
    5.5
    Medium

    CVE-2022-31902

    Last Modified: 27 Mar 2025

    Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().

    Published:1 Feb 2023
    6.5
    Medium

    CVE-2022-31901

    Last Modified: 4 Apr 2025

    Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two crafted files.

    Published:19 Jan 2023
    6.8
    Medium

    CVE-2022-31898

    Last Modified: 7 May 2025

    gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered to contain multiple command injection vulnerabilities via the ping_addr and trace_addr function parameters.

    Published:27 Oct 2022
    6.1
    Medium

    CVE-2022-31897

    Last Modified: 21 Nov 2024

    SourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via public_html/register_visitor?msg=.

    Published:29 Jun 2022
    9.8
    Critical

    CVE-2022-31890

    Last Modified: 13 Feb 2025

    SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae via the order parameter to the getOrder function.

    Published:5 Apr 2023
    6.1
    Medium

    CVE-2022-31889

    Last Modified: 13 Feb 2025

    Cross Site Scripting (XSS) vulnerability in audit/templates/auditlogs.tmpl.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae.

    Published:5 Apr 2023
    6.5
    Medium

    CVE-2022-31886

    Last Modified: 11 Jul 2022

    Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a malicious form.

    Source:Momen Eldawakhly
    Published:28 Jun 2022
    9.8
    Critical

    CVE-2022-31885

    Last Modified: 11 Jul 2022

    Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.

    Source:Momen Eldawakhly
    Published:28 Jun 2022
    7.2
    High

    CVE-2022-31854

    Last Modified: 21 Jul 2022

    Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.

    Source:Krish Pandey
    Published:7 Jul 2022
    9.8
    Critical

    CVE-2022-31814

    Last Modified: 20 Feb 2023

    pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.

    Source:IHTeam
    Published:5 Sept 2022
    9.8
    Critical

    CVE-2022-31813

    Last Modified: 1 May 2025

    Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.

    Published:8 Jun 2022
    6.1
    Medium

    CVE-2022-31798

    Last Modified: 21 Nov 2024

    Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin account or a user account.

    Published:25 Aug 2022
    7.5
    High

    CVE-2022-31793

    Last Modified: 21 Nov 2024

    do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. This occurs because the code skips over the first character when serving files. Arris NVG443, NVG599, NVG589, and NVG510 devices and Arris-derived BGW210 and BGW320 devices are affected.

    Published:4 Aug 2022
    6.5
    Medium

    CVE-2022-31749

    Last Modified: 15 Apr 2026

    An argument injection vulnerability in the diagnose and import pac commands in WatchGuard Fireware OS before 12.8.1, 12.1.4, and 12.5.10 allows an authenticated remote attacker with unprivileged credentials to upload or read files to limited, arbitrary locations on WatchGuard Firebox and XTM appliances

    Published:27 Jan 2025
    8.2
    High

    CVE-2022-31705

    Last Modified: 18 Apr 2025

    VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.

    Published:14 Dec 2022
    9.8
    Critical

    CVE-2022-31692

    Last Modified: 6 May 2025

    Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the following are true: The application expects that Spring Security applies security to forward and include dispatcher types. The application uses the AuthorizationFilter either manually or via the authorizeHttpRequests() method. The application configures the FilterChainProxy to apply to forward and/or include requests (e.g. spring.security.filter.dispatcher-types = request, error, async, forward, include). The application may forward or include the request to a higher privilege-secured endpoint.The application configures Spring Security to apply to every dispatcher type via authorizeHttpRequests().shouldFilterAllDispatcherTypes(true)

    Published:31 Oct 2022
    9.8
    Critical

    CVE-2022-31691

    Last Modified: 2 May 2025

    Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39.0 and below all use Snakeyaml library for YAML editing support. This library allows for some special syntax in the YAML that under certain circumstances allows for potentially harmful remote code execution by the attacker.

    Published:4 Nov 2022
    6.5
    Medium

    CVE-2022-31630

    Last Modified: 21 Nov 2024

    In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information. 

    Published:27 Oct 2022
    6.5
    Medium

    CVE-2022-31629

    Last Modified: 4 Nov 2025

    In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.

    Published:28 Sept 2022
    7.5
    High

    CVE-2022-31626

    Last Modified: 21 Nov 2024

    In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.

    Published:16 May 2022
    9.8
    Critical

    CVE-2022-31499

    Last Modified: 21 Nov 2024

    Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.

    Published:25 Aug 2022
    10
    Critical

    CVE-2022-31491

    Last Modified: 15 Apr 2026

    Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote attacker to run arbitrary code via an unspecified web interface related to detection of a managed UPS shutting down. An unauthenticated attacker can use this to run arbitrary code immediately regardless of any managed UPS state or presence.

    Published:22 Aug 2025
    9.6
    Critical

    CVE-2022-31479

    Last Modified: 21 Nov 2024

    An unauthenticated attacker can update the hostname with a specially crafted name that will allow for shell commands to be executed during the core collection process. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.302 for the LP series and 1.296 for the EP series. An attacker with this level of access on the device can monitor all communications sent to and from this device, modify onboard relays, change configuration files, or cause the device to become unstable. The injected commands only get executed during start up or when unsafe calls regarding the hostname are used. This allows the attacker to gain remote access to the device and can make their persistence permanent by modifying the filesystem.

    Published:6 Jun 2022
    6.1
    Medium

    CVE-2022-31470

    Last Modified: 8 Sept 2023

    An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 allows attackers to run arbitrary Javascript code that, using an active end-user session (for a logged-in user), can access and retrieve mailbox content.

    Source:AmirZargham
    Published:7 Jun 2022
    6.1
    Medium

    CVE-2022-31403

    Last Modified: 21 Nov 2024

    ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/pages/ajax.render.php.

    Published:14 Jun 2022
    6.1
    Medium

    CVE-2022-31402

    Last Modified: 21 Nov 2024

    ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php.

    Published:10 Jun 2022
    7.2
    High

    CVE-2022-31325

    Last Modified: 14 Jun 2022

    There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php.

    Source:nu11secur1ty
    Published:8 Jun 2022
    5.4
    Medium

    CVE-2022-31301

    Last Modified: 21 Nov 2024

    Haraj v3.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Post Ads component.

    Published:16 Jun 2022
    5.4
    Medium

    CVE-2022-31300

    Last Modified: 21 Nov 2024

    A cross-site scripting vulnerability in the DM Section component of Haraj v3.7 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.

    Published:16 Jun 2022
    6.1
    Medium

    CVE-2022-31299

    Last Modified: 21 Nov 2024

    Haraj v3.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the User Upgrade Form.

    Published:16 Jun 2022
    5.4
    Medium

    CVE-2022-31298

    Last Modified: 21 Nov 2024

    A cross-site scripting vulnerability in the ads comment section of Haraj v3.7 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.

    Published:16 Jun 2022
    Unknown

    CVE-2022-31297

    https://github.com/bigzooooz/CVE-2022-31297