7.5
    High

    CVE-2022-24992

    Last Modified: 21 Nov 2024

    A vulnerability in the component process.php of QR Code Generator v5.2.7 allows attackers to perform directory traversal.

    Published:25 Jul 2022
    9.8
    Critical

    CVE-2022-24990

    Last Modified: 7 Nov 2025

    TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.

    Published:7 Feb 2023
    9.8
    Critical

    CVE-2022-24934

    Last Modified: 21 Nov 2024

    wpsupdater.exe in Kingsoft WPS Office through 11.2.0.10382 allows remote code execution by modifying HKEY_CURRENT_USER in the registry.

    Published:23 Mar 2022
    2.2
    Low

    CVE-2022-24924

    Last Modified: 21 Nov 2024

    An improper access control in LiveWallpaperService prior to versions 3.0.9.0 allows to create a specific named system directory without a proper permission.

    Published:11 Feb 2022
    8.1
    High

    CVE-2022-24903

    Last Modified: 23 Apr 2025

    Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overflow when octet-counted framing is used. This can result in a segfault or some other malfunction. As of our understanding, this vulnerability can not be used for remote code execution. But there may still be a slight chance for experts to do that. The bug occurs when the octet count is read. While there is a check for the maximum number of octets, digits are written to a heap buffer even when the octet count is over the maximum, This can be used to overrun the memory buffer. However, once the sequence of digits stop, no additional characters can be added to the buffer. In our opinion, this makes remote exploits impossible or at least highly complex. Octet-counted framing is one of two potential framing modes. It is relatively uncommon, but enabled by default on receivers. Modules `imtcp`, `imptcp`, `imgssapi`, and `imhttp` are used for regular syslog message reception. It is best practice not to directly expose them to the public. When this practice is followed, the risk is considerably lower. Module `imdiag` is a diagnostics module primarily intended for testbench runs. We do not expect it to be present on any production installation. Octet-counted framing is not very common. Usually, it needs to be specifically enabled at senders. If users do not need it, they can turn it off for the most important modules. This will mitigate the vulnerability.

    Published:5 May 2022
    7.5
    High

    CVE-2022-24897

    Last Modified: 22 Apr 2025

    APIs to evaluate content with Velocity is a package for APIs to evaluate content with Velocity. Starting with version 2.3 and prior to 12.6.7, 12.10.3, and 13.0, the velocity scripts are not properly sandboxed against using the Java File API to perform read or write operations on the filesystem. Writing an attacking script in Velocity requires the Script rights in XWiki so not all users can use it, and it also requires finding an XWiki API which returns a File. The problem has been patched in versions 12.6.7, 12.10.3, and 13.0. There is no easy workaround for fixing this vulnerability other than upgrading and being careful when giving Script rights.

    Published:2 May 2022
    5.9
    Medium

    CVE-2022-24894

    Last Modified: 10 Apr 2025

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse proxy: It caches entire responses (including headers) and returns them to the clients. In a recent change in the `AbstractSessionListener`, the response might contain a `Set-Cookie` header. If the Symfony HTTP cache system is enabled, this response might bill stored and return to the next clients. An attacker can use this vulnerability to retrieve the victim's session. This issue has been patched and is available for branch 4.4.

    Published:3 Feb 2023
    5.4
    Medium

    CVE-2022-24891

    Last Modified: 3 Nov 2025

    ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, there is a potential for a cross-site scripting vulnerability in ESAPI caused by a incorrect regular expression for "onsiteURL" in the **antisamy-esapi.xml** configuration file that can cause "javascript:" URLs to fail to be correctly sanitized. This issue is patched in ESAPI 2.3.0.0. As a workaround, manually edit the **antisamy-esapi.xml** configuration files to change the "onsiteURL" regular expression. More information about remediation of the vulnerability, including the workaround, is available in the maintainers' release notes and security bulletin.

    Published:27 Apr 2022
    5.9
    Medium

    CVE-2022-24853

    Last Modified: 22 Apr 2025

    Metabase is an open source business intelligence and analytics application. Metabase has a proxy to load arbitrary URLs for JSON maps as part of our GeoJSON support. While we do validation to not return contents of arbitrary URLs, there is a case where a particularly crafted request could result in file access on windows, which allows enabling an `NTLM relay attack`, potentially allowing an attacker to receive the system password hash. If you use Windows and are on this version of Metabase, please upgrade immediately. The following patches (or greater versions) are available: 0.42.4 and 1.42.4, 0.41.7 and 1.41.7, 0.40.8 and 1.40.8.

    Published:14 Apr 2022
    7
    High

    CVE-2022-24834

    Last Modified: 13 Feb 2025

    Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson library, and result with heap corruption and potentially remote code execution. The problem exists in all versions of Redis with Lua scripting support, starting from 2.6, and affects only authenticated and authorized users. The problem is fixed in versions 7.0.12, 6.2.13, and 6.0.20.

    Published:10 Jul 2023
    8.2
    High

    CVE-2022-24818

    Last Modified: 23 Apr 2025

    GeoTools is an open source Java library that provides tools for geospatial data. The GeoTools library has a number of data sources that can perform unchecked JNDI lookups, which in turn can be used to perform class deserialization and result in arbitrary code execution. Similar to the Log4J case, the vulnerability can be triggered if the JNDI names are user-provided, but requires admin-level login to be triggered. The lookups are now restricted in GeoTools 26.4, GeoTools 25.6, and GeoTools 24.6. Users unable to upgrade should ensure that any downstream application should not allow usage of remotely provided JNDI strings.

    Published:13 Apr 2022
    10
    Critical

    CVE-2022-24816

    Last Modified: 24 Oct 2025

    JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. In particular, this affects the downstream GeoServer project. Version 1.2.22 will contain a patch that disables the ability to inject malicious code into the resulting script. Users unable to upgrade may negate the ability to compile Jiffle scripts from the final application, by removing janino-x.y.z.jar from the classpath.

    Published:13 Apr 2022
    7.5
    High

    CVE-2022-24785

    Last Modified: 3 Nov 2025

    Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.

    Published:4 Apr 2022
    8.8
    High

    CVE-2022-24780

    Last Modified: 22 Apr 2025

    Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds.

    Published:5 Apr 2022
    10
    Critical

    CVE-2022-24760

    Last Modified: 22 Apr 2025

    Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server. This vulnerability affects Parse Server in the default configuration with MongoDB. The main weakness that leads to RCE is the Prototype Pollution vulnerable code in the file `DatabaseController.js`, so it is likely to affect Postgres and any other database backend as well. This vulnerability has been confirmed on Linux (Ubuntu) and Windows. Users are advised to upgrade as soon as possible. The only known workaround is to manually patch your installation with code referenced at the source GHSA-p6h4-93qp-jhcm.

    Published:11 Mar 2022
    7.2
    High

    CVE-2022-24734

    Last Modified: 11 May 2022

    MyBB is a free and open source forum software. In affected versions the Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type `php` with PHP code, executed on on _Change Settings_ pages. This results in a Remote Code Execution (RCE) vulnerability. The vulnerable module requires Admin CP access with the `Can manage settings?` permission. MyBB's Settings module, which allows administrators to add, edit, and delete non-default settings, stores setting data in an options code string ($options_code; mybb_settings.optionscode database column) that identifies the setting type and its options, separated by a new line character (\n). In MyBB 1.2.0, support for setting type php was added, for which the remaining part of the options code is PHP code executed on Change Settings pages (reserved for plugins and internal use). MyBB 1.8.30 resolves this issue. There are no known workarounds.

    Source:Altelus
    Published:9 Mar 2022
    7.5
    High

    CVE-2022-24716

    Last Modified: 8 Apr 2023

    Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2. Database credentials should be rotated.

    Source:Jacob Ebben
    Published:8 Mar 2022
    8.5
    High

    CVE-2022-24715

    Last Modified: 15 Jul 2023

    Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code. This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2. Users unable to upgrade should limit access to the Icinga Web 2 configuration.

    Source:Dante Corona
    Published:8 Mar 2022
    7.5
    High

    CVE-2022-24713

    Last Modified: 23 Apr 2025

    regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API. Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. All versions of the regex crate before or equal to 1.5.4 are affected by this issue. The fix is include starting from regex 1.5.5. All users accepting user-controlled regexes are recommended to upgrade immediately to the latest version of the regex crate. Unfortunately there is no fixed set of problematic regexes, as there are practically infinite regexes that could be crafted to exploit this vulnerability. Because of this, it us not recommend to deny known problematic regexes.

    Published:8 Mar 2022
    7.4
    High

    CVE-2022-24707

    Last Modified: 11 May 2022

    Anuko Time Tracker is an open source, web-based time tracking application written in PHP. UNION SQL injection and time-based blind injection vulnerabilities existed in Time Tracker Puncher plugin in versions of anuko timetracker prior to 1.20.0.5642. This was happening because the Puncher plugin was reusing code from other places and was relying on an unsanitized date parameter in POST requests. Because the parameter was not checked, it was possible to craft POST requests with malicious SQL for Time Tracker database. This issue has been resolved in in version 1.20.0.5642. Users unable to upgrade are advised to add their own checks to input.

    Source:Altelus
    Published:23 Feb 2022
    9.8
    Critical

    CVE-2022-24706

    Last Modified: 11 May 2022

    In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

    Source:Konstantin Burov
    Published:26 Apr 2022
    9.8
    Critical

    CVE-2022-24702

    Last Modified: 21 Nov 2024

    An issue was discovered in WinAPRS 2.9.0. A buffer overflow in the VHF KISS TNC component allows a remote attacker to achieve remote code execution via malicious AX.25 packets over the air. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published:31 May 2022
    9.8
    Critical

    CVE-2022-24693

    Last Modified: 21 Nov 2024

    Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.)

    Published:30 Mar 2022
    7.5
    High

    CVE-2022-24675

    Last Modified: 21 Nov 2024

    encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.

    Published:12 Apr 2022
    5.4
    Medium

    CVE-2022-24654

    Last Modified: 21 Nov 2024

    Authenticated stored cross-site scripting (XSS) vulnerability in "Field Server Address" field in INTELBRAS ATA 200 Firmware 74.19.10.21 allows attackers to inject JavaScript code through a crafted payload.

    Published:15 Aug 2022
    8.8
    High

    CVE-2022-24644

    Last Modified: 21 Nov 2024

    ZZ Inc. KeyMouse Windows 3.08 and prior is affected by a remote code execution vulnerability during an unauthenticated update. To exploit this vulnerability, a user must trigger an update of an affected installation of KeyMouse.

    Published:7 Mar 2022
    Unknown

    CVE-2022-24638

    https://github.com/726232111/CVE-2022-24638

    9.8
    Critical

    CVE-2022-24637

    Last Modified: 18 Nov 2022

    Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '<?php (instead of the intended "<?php sequence) aren't handled by the PHP interpreter.

    Source:Jacob Ebben
    Published:18 Mar 2022
    5.3
    Medium

    CVE-2022-24632

    Last Modified: 30 Mar 2023

    An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during file download via the BrowseFiles.php view parameter.

    Source:Eric Flokstra
    Published:29 May 2023
    7.2
    High

    CVE-2022-24630

    Last Modified: 30 Mar 2023

    An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh POST request with an ssh_command field that is executed.

    Source:Eric Flokstra
    Published:29 May 2023
    9.8
    Critical

    CVE-2022-24629

    Last Modified: 30 Mar 2023

    An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can upload a .php file to WebAdmin/admin/AudioCodes_files/ajax/.

    Source:Eric Flokstra
    Published:29 May 2023
    9.8
    Critical

    CVE-2022-24627

    Last Modified: 30 Mar 2023

    An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the process_login.php login form.

    Source:Eric Flokstra
    Published:29 May 2023
    6.5
    Medium

    CVE-2022-24611

    Last Modified: 21 Nov 2024

    Denial of Service (DoS) in the Z-Wave S0 NonceGet protocol specification in Silicon Labs Z-Wave 500 series allows local attackers to block S0/S2 protected Z-Wave network via crafted S0 NonceGet Z-Wave packages, utilizing included but absent NodeIDs.

    Published:17 May 2022
    9.8
    Critical

    CVE-2022-24562

    Last Modified: 21 Jul 2022

    In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.

    Source:Tomer Peled
    Published:16 Jun 2022
    7.8
    High

    CVE-2022-24521

    Last Modified: 30 Oct 2025

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    Published:15 Apr 2022
    8.8
    High

    CVE-2022-24500

    Last Modified: 2 Jan 2025

    Windows SMB Remote Code Execution Vulnerability

    Published:15 Apr 2022
    9.8
    Critical

    CVE-2022-24497

    Last Modified: 2 Jan 2025

    Windows Network File System Remote Code Execution Vulnerability

    Published:15 Apr 2022
    7.8
    High

    CVE-2022-24494

    Last Modified: 16 Dec 2025

    Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

    Published:15 Apr 2022
    9.8
    Critical

    CVE-2022-24491

    Last Modified: 2 Jan 2025

    Windows Network File System Remote Code Execution Vulnerability

    Published:15 Apr 2022
    5.5
    Medium

    CVE-2022-24483

    Last Modified: 2 Jan 2025

    Windows Kernel Information Disclosure Vulnerability

    Published:15 Apr 2022
    7.8
    High

    CVE-2022-24481

    Last Modified: 2 Jan 2025

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    Published:15 Apr 2022
    9.8
    Critical

    CVE-2022-24449

    Last Modified: 21 Nov 2024

    Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document.

    Published:28 Apr 2022
    9.8
    Critical

    CVE-2022-24442

    Last Modified: 21 Nov 2024

    JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.

    Published:25 Feb 2022
    8.1
    High

    CVE-2022-24439

    Last Modified: 3 Nov 2025

    All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments.

    Published:5 Dec 2022
    7.5
    High

    CVE-2022-24434

    Last Modified: 21 Nov 2024

    This affects all versions of package dicer. A malicious attacker can send a modified form to server, and crash the nodejs service. An attacker could sent the payload again and again so that the service continuously crashes.

    Published:5 Aug 2021
    8.8
    High

    CVE-2022-24355

    Last Modified: 21 Nov 2024

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of file name extensions. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-13910.

    Published:18 Feb 2022
    7.7
    High

    CVE-2022-24348

    Last Modified: 21 Nov 2024

    Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in helmTemplate in repository.go. For example, an attacker may be able to discover credentials stored in a YAML file.

    Published:4 Feb 2022
    8.8
    High

    CVE-2022-24342

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.

    Published:25 Feb 2022
    9.8
    Critical

    CVE-2022-24263

    Last Modified: 8 Feb 2022

    Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.

    Source:nu11secur1ty
    Published:31 Jan 2022
    6.1
    Medium

    CVE-2022-24227

    Last Modified: 5 May 2025

    A cross-site scripting (XSS) vulnerability in BoltWire v7.10 and v 8.00 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the name and lastname parameters.

    Published:15 Feb 2022