9.8
    Critical

    CVE-2022-31296

    Last Modified: 21 Nov 2024

    Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php.

    Published:17 Jun 2022
    7.5
    High

    CVE-2022-31295

    Last Modified: 22 Apr 2025

    An issue in the delete_post() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily delete posts.

    Published:16 Jun 2022
    6.5
    Medium

    CVE-2022-31294

    Last Modified: 22 Apr 2025

    An issue in the save_users() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily create or update user accounts.

    Published:16 Jun 2022
    8.2
    High

    CVE-2022-31269

    Last Modified: 21 Nov 2024

    Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)

    Published:25 Aug 2022
    7.8
    High

    CVE-2022-31262

    Last Modified: 21 Nov 2024

    An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder structure and change the GalaxyCommunication service executable to a malicious file, resulting in code execution as SYSTEM.

    Published:17 Aug 2022
    8.8
    High

    CVE-2022-31245

    Last Modified: 21 Nov 2024

    mailcow before 2022-05d allows a remote authenticated user to inject OS commands and escalate privileges to domain admin via the --debug option in conjunction with the ---PIPEMESS option in Sync Jobs.

    Published:20 May 2022
    9.8
    Critical

    CVE-2022-31199

    Last Modified: 3 Nov 2025

    Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors.

    Published:8 Nov 2022
    7.2
    High

    CVE-2022-31195

    Last Modified: 23 Apr 2025

    DSpace open source software is a repository application which provides durable access to digital resources. In affected versions the ItemImportServiceImpl is vulnerable to a path traversal vulnerability. This means a malicious SAF (simple archive format) package could cause a file/directory to be created anywhere the Tomcat/DSpace user can write to on the server. However, this path traversal vulnerability is only possible by a user with special privileges (either Administrators or someone with command-line access to the server). This vulnerability impacts the XMLUI, JSPUI and command-line. Users are advised to upgrade. As a basic workaround, users may block all access to the following URL paths: If you are using the XMLUI, block all access to /admin/batchimport path (this is the URL of the Admin Batch Import tool). Keep in mind, if your site uses the path "/xmlui", then you'd need to block access to /xmlui/admin/batchimport. If you are using the JSPUI, block all access to /dspace-admin/batchimport path (this is the URL of the Admin Batch Import tool). Keep in mind, if your site uses the path "/jspui", then you'd need to block access to /jspui/dspace-admin/batchimport. Keep in mind, only an Administrative user or a user with command-line access to the server is able to import/upload SAF packages. Therefore, assuming those users do not blindly upload untrusted SAF packages, then it is unlikely your site could be impacted by this vulnerability.

    Published:1 Aug 2022
    8.2
    High

    CVE-2022-31194

    Last Modified: 23 Apr 2025

    DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI resumable upload implementations in SubmissionController and FileUploadRequest are vulnerable to multiple path traversal attacks, allowing an attacker to create files/directories anywhere on the server writable by the Tomcat/DSpace user, by modifying some request parameters during submission. This path traversal can only be executed by a user with special privileges (submitter rights). This vulnerability only impacts the JSPUI. Users are advised to upgrade. There are no known workarounds. However, this vulnerability cannot be exploited by an anonymous user or a basic user. The user must first have submitter privileges to at least one Collection and be able to determine how to modify the request parameters to exploit the vulnerability.

    Published:1 Aug 2022
    7.1
    High

    CVE-2022-31192

    Last Modified: 23 Apr 2025

    DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI "Request a Copy" feature does not properly escape values submitted and stored from the "Request a Copy" form. This means that item requests could be vulnerable to XSS attacks. This vulnerability only impacts the JSPUI. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published:1 Aug 2022
    8.6
    High

    CVE-2022-31188

    Last Modified: 18 Nov 2022

    CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vulnerability. Validation has been added to urls used in the affected code path in version 2.0.0. Users are advised to upgrade. There are no known workarounds for this issue.

    Source:Emir Polat
    Published:1 Aug 2022
    9.8
    Critical

    CVE-2022-31181

    Last Modified: 23 Apr 2025

    PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerability which can be chained to call PHP's Eval function on attacker input. The problem is fixed in version 1.7.8.7. Users are advised to upgrade. Users unable to upgrade may delete the MySQL Smarty cache feature.

    Published:1 Aug 2022
    10
    Critical

    CVE-2022-31161

    Last Modified: 3 Apr 2023

    Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Version 6.1.1.0 contains a patch for this issue.

    Source:Nuri Çilengir
    Published:15 Jul 2022
    6.1
    Medium

    CVE-2022-31160

    Last Modified: 22 Apr 2025

    jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. Calling `.checkboxradio( "refresh" )` on such a widget and the initial HTML contained encoded HTML entities will make them erroneously get decoded. This can lead to potentially executing JavaScript code. The bug has been patched in jQuery UI 1.13.2. To remediate the issue, someone who can change the initial HTML can wrap all the non-input contents of the `label` in a `span`.

    Published:20 Jul 2022
    7.9
    High

    CVE-2022-31159

    Last Modified: 22 Apr 2025

    The AWS SDK for Java enables Java developers to work with Amazon Web Services. A partial-path traversal issue exists within the `downloadDirectory` method in the AWS S3 TransferManager component of the AWS SDK for Java v1 prior to version 1.12.261. Applications using the SDK control the `destinationDirectory` argument, but S3 object keys are determined by the application that uploaded the objects. The `downloadDirectory` method allows the caller to pass a filesystem object in the object key but contained an issue in the validation logic for the key name. A knowledgeable actor could bypass the validation logic by including a UNIX double-dot in the bucket key. Under certain conditions, this could permit them to retrieve a directory from their S3 bucket that is one level up in the filesystem from their working directory. This issue’s scope is limited to directories whose name prefix matches the destinationDirectory. E.g. for destination directory`/tmp/foo`, the actor can cause a download to `/tmp/foo-bar`, but not `/tmp/bar`. If `com.amazonaws.services.s3.transfer.TransferManager::downloadDirectory` is used to download an untrusted buckets contents, the contents of that bucket can be written outside of the intended destination directory. Version 1.12.261 contains a patch for this issue. As a workaround, when calling `com.amazonaws.services.s3.transfer.TransferManager::downloadDirectory`, pass a `KeyFilter` that forbids `S3ObjectSummary` objects that `getKey` method return a string containing the substring `..` .

    Published:15 Jul 2022
    7.5
    High

    CVE-2022-31147

    Last Modified: 23 Apr 2025

    The jQuery Validation Plugin (jquery-validation) provides drop-in validation for forms. Versions of jquery-validation prior to 1.19.5 are vulnerable to regular expression denial of service (ReDoS) when an attacker is able to supply arbitrary input to the url2 method. This is due to an incomplete fix for CVE-2021-43306. Users should upgrade to version 1.19.5 to receive a patch.

    Published:14 Jul 2022
    7
    High

    CVE-2022-31144

    Last Modified: 23 Apr 2025

    Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch prior to 7.0.4. The patch is released in version 7.0.4.

    Published:19 Jul 2022
    8.8
    High

    CVE-2022-31138

    Last Modified: 22 Apr 2025

    mailcow is a mailserver suite. Prior to mailcow-dockerized version 2022-06a, an extended privilege vulnerability can be exploited by manipulating the custom parameters regexmess, skipmess, regexflag, delete2foldersonly, delete2foldersbutnot, regextrans2, pipemess, or maxlinelengthcmd to execute arbitrary code. Users should update their mailcow instances with the `update.sh` script in the mailcow root directory to 2022-06a or newer to receive a patch for this issue. As a temporary workaround, the Syncjob ACL can be removed from all mailbox users, preventing changes to those settings.

    Published:11 Jul 2022
    10
    Critical

    CVE-2022-31126

    Last Modified: 4 Jun 2023

    Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file. This affects Roxy-wi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.

    Source:Nuri Çilengir
    Published:6 Jul 2022
    10
    Critical

    CVE-2022-31125

    Last Modified: 24 May 2023

    Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to bypass authentication and access admin functionality by sending a specially crafted HTTP request. This affects Roxywi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.

    Source:Nuri Çilengir
    Published:6 Jul 2022
    8.1
    High

    CVE-2022-31101

    Last Modified: 9 Aug 2022

    prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated customer can perform SQL injection. This issue is fixed in version 2.1.1. Users are advised to upgrade. There are no known workarounds for this issue.

    Source:Karthik UJ
    Published:27 Jun 2022
    5.3
    Medium

    CVE-2022-31062

    Last Modified: 3 Apr 2023

    ### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds `b/deploy/index.php` file can be deleted if deploy feature is not used.

    Source:Nuri Çilengir
    Published:20 Jun 2022
    9.8
    Critical

    CVE-2022-31061

    Last Modified: 23 Apr 2025

    GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions there is a SQL injection vulnerability which is possible on login page. No user credentials are required to exploit this vulnerability. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

    Published:28 Jun 2022
    9.8
    Critical

    CVE-2022-31056

    Last Modified: 3 Apr 2023

    GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all assistance forms (Ticket/Change/Problem) permit sql injection on the actor fields. This issue has been resolved in version 10.0.2 and all affected users are advised to upgrade.

    Source:Nuri Çilengir
    Published:28 Jun 2022
    4.9
    Medium

    CVE-2022-31007

    Last Modified: 23 Apr 2025

    eLabFTW is an electronic lab notebook manager for research teams. Prior to version 4.3.0, a vulnerability allows an authenticated user with an administrator role in a team to assign itself system administrator privileges within the application, or create a new system administrator account. The issue has been corrected in eLabFTW version 4.3.0. In the context of eLabFTW, an administrator is a user account with certain privileges to manage users and content in their assigned team/teams. A system administrator account can manage all accounts, teams and edit system-wide settings within the application. The impact is not deemed as high, as it requires the attacker to have access to an administrator account. Regular user accounts cannot exploit this to gain admin rights. A workaround for one if the issues is removing the ability of administrators to create accounts.

    Published:31 May 2022
    8.8
    High

    CVE-2022-30929

    Last Modified: 21 Nov 2024

    Mini-Tmall v1.0 is vulnerable to Insecure Permissions via tomcat-embed-jasper.

    Published:6 Jul 2022
    9.8
    Critical

    CVE-2022-30887

    Last Modified: 21 Nov 2024

    Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.

    Published:20 May 2022
    7.5
    High

    CVE-2022-30781

    Last Modified: 2 Aug 2023

    Gitea before 1.16.7 does not escape git fetch remote.

    Source:samguy
    Published:16 May 2022
    7.5
    High

    CVE-2022-30780

    Last Modified: 21 Nov 2024

    Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read_header_more in connections.c has a typo that disrupts use of multiple read operations on large headers.

    Published:11 Jun 2022
    Low

    CVE-2022-30778

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published:16 May 2022
    9.8
    Critical

    CVE-2022-30600

    Last Modified: 21 Nov 2024

    A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

    Published:18 May 2022
    7.8
    High

    CVE-2022-30594

    Last Modified: 21 Nov 2024

    The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag.

    Published:12 May 2022
    9.8
    Critical

    CVE-2022-30592

    Last Modified: 21 Nov 2024

    liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY.

    Published:11 May 2022
    7.5
    High

    CVE-2022-30591

    Last Modified: 21 Nov 2024

    quic-go through 0.27.0 allows remote attackers to cause a denial of service (CPU consumption) via a Slowloris variant in which incomplete QUIC or HTTP/3 requests are sent. This occurs because mtu_discoverer.go misparses the MTU Discovery service and consequently overflows the probe timer. NOTE: the vendor's position is that this behavior should not be listed as a vulnerability on the CVE List

    Published:6 Jul 2022
    7.8
    High

    CVE-2022-30526

    Last Modified: 21 Nov 2024

    A privilege escalation vulnerability was identified in the CLI command of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware versions 4.50 through 5.30, USG FLEX 700 firmware versions 4.50 through 5.30, USG FLEX 50(W) firmware versions 4.16 through 5.30, USG20(W)-VPN firmware versions 4.16 through 5.30, ATP series firmware versions 4.32 through 5.30, VPN series firmware versions 4.30 through 5.30, USG/ZyWALL series firmware versions 4.09 through 4.72, which could allow a local attacker to execute some OS commands with root privileges in some directories on a vulnerable device.

    Published:19 Jul 2022
    9.8
    Critical

    CVE-2022-30525

    Last Modified: 3 Jun 2022

    A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versions 4.60 through 5.21 Patch 1, which could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.

    Source:Valentin Lobstein
    Published:12 May 2022
    7.8
    High

    CVE-2022-30524

    Last Modified: 21 Nov 2024

    There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters at large y coordinates. It can be triggered by (for example) sending a crafted pdf file to the pdftotext binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.

    Published:9 May 2022
    6.1
    Medium

    CVE-2022-30519

    Last Modified: 1 Apr 2023

    XSS in signing form in Reprise Software RLM License Administration v14.2BL4 allows remote attacker to inject arbitrary code via password field.

    Source:Mohammed A.Siledar
    Published:29 Dec 2022
    6.1
    Medium

    CVE-2022-30514

    Last Modified: 21 Nov 2024

    School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.php:126.

    Published:27 May 2022
    6.1
    Medium

    CVE-2022-30513

    Last Modified: 21 Nov 2024

    School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.php:125

    Published:27 May 2022
    9.8
    Critical

    CVE-2022-30512

    Last Modified: 21 Nov 2024

    School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31.

    Published:27 May 2022
    9.8
    Critical

    CVE-2022-30511

    Last Modified: 21 Nov 2024

    School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/view_details.php:4.

    Published:27 May 2022
    9.8
    Critical

    CVE-2022-30510

    Last Modified: 21 Nov 2024

    School Dormitory Management System 1.0 is vulnerable to SQL Injection via reports/daily_collection_report.php:59.

    Published:27 May 2022
    Unknown

    CVE-2022-30507

    https://github.com/yosef0x01/CVE-2022-30507-PoC

    6.1
    Medium

    CVE-2022-30489

    Last Modified: 21 Nov 2024

    WAVLINK WN535 G3 was discovered to contain a cross-site scripting (XSS) vulnerability via the hostname parameter at /cgi-bin/login.cgi.

    Published:13 May 2022
    7.5
    High

    CVE-2022-30333

    Last Modified: 3 Nov 2025

    RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.

    Published:9 May 2022
    10
    Critical

    CVE-2022-30292

    Last Modified: 21 Nov 2024

    Heap-based buffer overflow in sqbaselib.cpp in SQUIRREL 3.2 due to lack of a certain sq_reservestack call.

    Published:4 May 2022
    7.5
    High

    CVE-2022-30286

    Last Modified: 11 May 2022

    pyscriptjs (aka PyScript Demonstrator) in PyScript through 2022-05-04 allows a remote user to read Python source code.

    Source:Momen Eldawakhly
    Published:9 May 2022
    8.8
    High

    CVE-2022-30216

    Last Modified: 8 Jul 2025

    Windows Server Service Tampering Vulnerability

    Published:12 Jul 2022
    7.8
    High

    CVE-2022-30206

    Last Modified: 25 Feb 2026

    Windows Print Spooler Elevation of Privilege Vulnerability

    Published:12 Jul 2022