9.8
    Critical

    CVE-2022-26133

    Last Modified: 21 Nov 2024

    SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.

    Published:20 Apr 2022
    5.3
    Medium

    CVE-2022-26049

    Last Modified: 21 Nov 2024

    This affects the package com.diffplug.gradle:goomph before 3.37.2. It allows a malicious zip file to potentially break out of the expected destination directory, writing contents into arbitrary locations on the file system. Overwriting certain files/directories could allow an attacker to achieve remote code execution on a target system by exploiting this vulnerability. **Note:** This could have allowed a malicious zip file to extract itself into an arbitrary directory. The only file that Goomph extracts is the p2 bootstrapper and eclipse metadata files hosted at eclipse.org, which are not malicious, so the only way this vulnerability could have affected you is if you had set a custom bootstrap zip, and that zip was malicious.

    Published:11 Sept 2022
    7.8
    High

    CVE-2022-25949

    Last Modified: 21 Nov 2024

    The kernel mode driver kwatch3 of KINGSOFT Internet Security 9 Plus Version 2010.06.23.247 fails to properly handle crafted inputs, leading to stack-based buffer overflow.

    Published:17 Mar 2022
    7.8
    High

    CVE-2022-25943

    Last Modified: 21 Nov 2024

    The installer of WPS Office for Windows versions prior to v11.2.0.10258 fails to configure properly the ACL for the directory where the service program is installed.

    Published:9 Mar 2022
    5.3
    Medium

    CVE-2022-25927

    Last Modified: 1 Apr 2025

    Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.

    Published:22 Jan 2023
    4.2
    Medium

    CVE-2022-25869

    Last Modified: 20 Nov 2025

    All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of <textarea> elements.

    Published:15 Jul 2022
    8.1
    High

    CVE-2022-25845

    Last Modified: 21 Nov 2024

    The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).

    Published:10 Jun 2022
    6.9
    Medium

    CVE-2022-25842

    Last Modified: 21 Nov 2024

    All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a specially crafted archive that holds directory traversal filenames (e.g. ../../evil.exe). The attacker can overwrite executable files and either invoke them remotely or wait for the system or user to call them, thus achieving remote command execution on the victim’s machine.

    Published:1 May 2022
    7.5
    High

    CVE-2022-25813

    Last Modified: 21 Nov 2024

    In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a party manager needs to list the communications in the party component to activate the SSTI. A RCE is then possible.

    Published:2 Sept 2022
    7.3
    High

    CVE-2022-25765

    Last Modified: 21 Nov 2024

    The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized.

    Published:9 Sept 2022
    7.5
    High

    CVE-2022-25640

    Last Modified: 21 Nov 2024

    In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_verify message from the handshake, and never present a certificate.

    Published:24 Feb 2022
    7.8
    High

    CVE-2022-25636

    Last Modified: 21 Nov 2024

    net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. This is related to nf_tables_offload.

    Published:22 Feb 2022
    5.4
    Medium

    CVE-2022-25630

    Last Modified: 8 Apr 2023

    An authenticated user can embed malicious content with XSS into the admin group policy page.

    Source:omurugur
    Published:9 Dec 2022
    7.5
    High

    CVE-2022-25584

    Last Modified: 21 Nov 2024

    Seyeon Tech Co., Ltd FlexWATCH FW3170-PS-E Network Video System 4.23-3000_GY allows attackers to access sensitive information.

    Published:5 Apr 2022
    7.8
    High

    CVE-2022-25581

    Last Modified: 21 Nov 2024

    Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to execute code injection via a crafted .txt file.

    Published:18 Mar 2022
    6.1
    Medium

    CVE-2022-25479

    Last Modified: 21 Nov 2024

    Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows for the leakage of kernel memory from both the stack and the heap.

    Published:2 Jul 2024
    5.5
    Medium

    CVE-2022-25477

    Last Modified: 21 Nov 2024

    Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 leaks driver logs that contain addresses of kernel mode objects, weakening KASLR.

    Published:2 Jul 2024
    Unknown

    CVE-2022-25476

    https://github.com/HORKimhab/CVE-2022-25476

    5.5
    Medium

    CVE-2022-25375

    Last Modified: 21 Nov 2024

    An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation of the size of the RNDIS_MSG_SET command. Attackers can obtain sensitive information from kernel memory.

    Published:11 Feb 2022
    7.8
    High

    CVE-2022-25365

    Last Modified: 21 Nov 2024

    Docker Desktop before 4.5.1 on Windows allows attackers to move arbitrary files. NOTE: this issue exists because of an incomplete fix for CVE-2022-23774.

    Published:19 Feb 2022
    9.1
    Critical

    CVE-2022-25359

    Last Modified: 23 Feb 2022

    On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.

    Source:LiquidWorm
    Published:26 Feb 2022
    9.8
    Critical

    CVE-2022-25315

    Last Modified: 5 May 2025

    In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.

    Published:18 Feb 2022
    7.5
    High

    CVE-2022-25314

    Last Modified: 5 May 2025

    In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.

    Published:18 Feb 2022
    6.5
    Medium

    CVE-2022-25313

    Last Modified: 30 May 2025

    In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.

    Published:18 Feb 2022
    7.8
    High

    CVE-2022-25265

    Last Modified: 21 Nov 2024

    In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execution of bytes located in supposedly non-executable regions of a file.

    Published:16 Feb 2022
    9.8
    Critical

    CVE-2022-25262

    Last Modified: 21 Nov 2024

    In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.

    Published:25 Feb 2022
    9.1
    Critical

    CVE-2022-25260

    Last Modified: 21 Nov 2024

    JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).

    Published:25 Feb 2022
    4.6
    Medium

    CVE-2022-25258

    Last Modified: 21 Nov 2024

    An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.

    Published:16 Feb 2022
    Unknown

    CVE-2022-25257

    https://github.com/polling-repo-continua/CVE-2022-25257

    6.1
    Medium

    CVE-2022-25256

    Last Modified: 21 Nov 2024

    SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_backurl_list. The first one affects the content of the button placed in the top left. The second affects the page to which the user is directed after pressing the button, e.g., a malicious web page. In addition, the second parameter executes JavaScript, which means XSS is possible by adding a javascript: URL.

    Published:19 Feb 2022
    8.8
    High

    CVE-2022-25241

    Last Modified: 21 Feb 2022

    In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF).

    Source:Masashi Fujiwara
    Published:16 Feb 2022
    9.8
    Critical

    CVE-2022-25236

    Last Modified: 5 May 2025

    xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.

    Published:16 Feb 2022
    9.8
    Critical

    CVE-2022-25235

    Last Modified: 5 May 2025

    xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.

    Published:16 Feb 2022
    10
    Critical

    CVE-2022-25226

    Last Modified: 21 Nov 2024

    ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?cmd=connect' by obtaining a valid SID without any kind of authentication. It is possible to achieve code execution on the server by sending keyboard or mouse events to the server.

    Published:18 Apr 2022
    8.8
    High

    CVE-2022-25175

    Last Modified: 21 Nov 2024

    Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs for the readTrusted step, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.

    Published:15 Feb 2022
    8.8
    High

    CVE-2022-25174

    Last Modified: 21 Nov 2024

    Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libraries, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.

    Published:15 Feb 2022
    8.8
    High

    CVE-2022-25173

    Last Modified: 21 Nov 2024

    Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the script file (typically Jenkinsfile) for Pipelines, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.

    Published:15 Feb 2022
    9.8
    Critical

    CVE-2022-25148

    Last Modified: 4 Sept 2023

    The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.

    Source:psychoSherlock
    Published:24 Feb 2022
    8.1
    High

    CVE-2022-25090

    Last Modified: 9 Mar 2022

    Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure permissions, leading to privilege escalation because of a race condition.

    Source:Logan Latvala
    Published:9 Mar 2022
    9.8
    Critical

    CVE-2022-25089

    Last Modified: 2 Mar 2022

    Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.PersistentRegistryData.

    Source:Logan Latvala
    Published:2 Mar 2022
    9.8
    Critical

    CVE-2022-25064

    Last Modified: 21 Nov 2024

    TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.

    Published:25 Feb 2022
    Unknown

    CVE-2022-25063

    https://github.com/exploitwritter/CVE-2022-25063

    7.5
    High

    CVE-2022-25062

    Last Modified: 21 Nov 2024

    TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain an integer overflow via the function dm_checkString. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

    Published:25 Feb 2022
    9.8
    Critical

    CVE-2022-25061

    Last Modified: 21 Nov 2024

    TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.

    Published:25 Feb 2022
    9.8
    Critical

    CVE-2022-25060

    Last Modified: 21 Nov 2024

    TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.

    Published:25 Feb 2022
    5.4
    Medium

    CVE-2022-25022

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in the content field of a blog post.

    Published:1 Mar 2022
    5.4
    Medium

    CVE-2022-25020

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the thumbnail path of a blog post.

    Published:1 Mar 2022
    8.8
    High

    CVE-2022-25018

    Last Modified: 21 Nov 2024

    Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.

    Published:1 Mar 2022
    5.5
    Medium

    CVE-2022-25012

    Last Modified: 21 Nov 2024

    Argus Surveillance DVR v4.0 employs weak password encryption.

    Published:1 Mar 2022
    7.5
    High

    CVE-2022-24999

    Last Modified: 29 Apr 2025

    qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[__proto__]=b&a[__proto__]&a[length]=100000000. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4 (and therefore Express 4.17.3, which has "deps: [email protected]" in its release description, is not vulnerable).

    Published:26 Nov 2022