7.8
    High

    CVE-2022-20138

    Last Modified: 21 Nov 2024

    In ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService.java, there is a possible way for unprivileged app to send MANAGED_PROFILE_PROVISIONED intent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-210469972

    Published:15 Jun 2022
    9.8
    Critical

    CVE-2022-20130

    Last Modified: 21 Nov 2024

    In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-224314979

    Published:15 Jun 2022
    Low

    CVE-2022-20128

    Last Modified: 17 Jan 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published:14 Oct 2021
    7.3
    High

    CVE-2022-20126

    Last Modified: 21 Nov 2024

    In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interaction due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-203431023

    Published:15 Jun 2022
    9.8
    Critical

    CVE-2022-20120

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-203213034References: N/A

    Published:10 May 2022
    6.8
    Medium

    CVE-2022-20009

    Last Modified: 21 Nov 2024

    In various functions of the USB gadget subsystem, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-213172319References: Upstream kernel

    Published:10 May 2022
    7
    High

    CVE-2022-20007

    Last Modified: 21 Nov 2024

    In startActivityForAttachedApplicationIfNeeded of RootWindowContainer.java, there is a possible way to overlay an app that believes it's still in the foreground, when it is not, due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-211481342

    Published:10 May 2022
    7.8
    High

    CVE-2022-20005

    Last Modified: 21 Nov 2024

    In validateApkInstallLocked of PackageInstallerSession.java, there is a way to force a mismatch between running code and a parsed APK . This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-219044664

    Published:10 May 2022
    7.8
    High

    CVE-2022-20004

    Last Modified: 21 Nov 2024

    In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-179699767

    Published:10 May 2022
    Unknown

    CVE-2022-14733

    https://github.com/hkzck/CVE-2022-14733

    Unknown

    CVE-2022-10270

    https://github.com/baimaobg/sunflower_exp

    Unknown

    CVE-2022-8475

    https://github.com/Kvi74/CVE-2022-8475

    Unknown

    CVE-2022-5561

    https://github.com/Kvi74/CVE-2022-5561

    6.1
    Medium

    CVE-2022-4953

    Last Modified: 8 Sept 2023

    The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs.

    Source:Miguel Santareno
    Published:14 Aug 2023
    4.3
    Medium

    CVE-2022-4944

    Last Modified: 25 Apr 2023

    A vulnerability, which was classified as problematic, has been found in kalcaddle KodExplorer up to 4.49. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.50 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-227000.

    Source:Mr Empy
    Published:22 Apr 2023
    9.8
    Critical

    CVE-2022-4939

    Last Modified: 8 Apr 2026

    THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, due to a missing capability check on the wp_ajax_nopriv_wcfm_ajax_controller AJAX action that controls membership settings. This makes it possible for unauthenticated attackers to modify the membership registration form in a way that allows them to set the role for registration to that of any user including administrators. Once configured, the attacker can then register as an administrator.

    Published:5 Apr 2023
    8.2
    High

    CVE-2022-4896

    Last Modified: 21 Nov 2024

    Cyber Control, in its 1.650 version, is affected by a vulnerability in the generation on the server of pop-up windows with the messages "PNTMEDIDAS", "PEDIR", "HAYDISCOA" or "SPOOLER". A complete denial of service can be achieved by sending multiple requests simultaneously on a core.

    Published:12 Sept 2023
    5.4
    Medium

    CVE-2022-4782

    Last Modified: 21 Nov 2024

    The ClickFunnels WordPress plugin through 3.1.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

    Published:16 Aug 2023
    9.8
    Critical

    CVE-2022-4681

    Last Modified: 10 Mar 2024

    The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

    Source:Xenofon Vassilakopoulos
    Published:6 Feb 2023
    7.2
    High

    CVE-2022-4616

    Last Modified: 16 Jan 2025

    The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to command injection through the network diagnosis page. This vulnerability could allow a remote unauthenticated user to add files, delete files, and change file permissions.

    Published:12 Jan 2023
    4.3
    Medium

    CVE-2022-4611

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This affects an unknown part. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The identifier VDB-216273 was assigned to this vulnerability.

    Published:19 Dec 2022
    3.5
    Low

    CVE-2022-4556

    Last Modified: 15 Apr 2025

    A vulnerability was found in Alinto SOGo up to 5.7.1 and classified as problematic. Affected by this issue is the function _migrateMailIdentities of the file SoObjects/SOGo/SOGoUserDefaults.m of the component Identity Handler. The manipulation of the argument fullName leads to cross site scripting. The attack may be launched remotely. Upgrading to version 5.8.0 is able to address this issue. The name of the patch is efac49ae91a4a325df9931e78e543f707a0f8e5e. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-215960.

    Published:16 Dec 2022
    5.5
    Medium

    CVE-2022-4543

    Last Modified: 8 Apr 2025

    A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems.

    Published:19 Dec 2022
    5.3
    Medium

    CVE-2022-4539

    Last Modified: 8 Apr 2026

    The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with with a different IP Address that will be logged and can be used to bypass settings that may have blocked out an IP address or country from logging in.

    Published:31 Aug 2024
    7.8
    High

    CVE-2022-4510

    Last Modified: 5 Apr 2023

    A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By crafting a malicious PFS filesystem file, an attacker can get binwalk's PFS extractor to extract files at arbitrary locations when binwalk is run in extraction mode (-e option). Remote code execution can be achieved by building a PFS filesystem that, upon extraction, would extract a malicious binwalk module into the folder .config/binwalk/plugins. This vulnerability is associated with program files src/binwalk/plugins/unpfs.py. This issue affects binwalk from 2.1.2b through 2.3.3 included.

    Source:Etienne Lacoche
    Published:25 Jan 2023
    6.1
    Medium

    CVE-2022-4407

    Last Modified: 16 Apr 2025

    Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.9.

    Source:CodeSecLab
    Published:11 Dec 2022
    9.8
    Critical

    CVE-2022-4395

    Last Modified: 2 Apr 2024

    The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.

    Source:Milad karimi
    Published:30 Jan 2023
    10
    Critical

    CVE-2022-4361

    Last Modified: 21 Nov 2024

    Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the redirect_uri.

    Published:27 Jun 2023
    5.9
    Medium

    CVE-2022-4304

    Last Modified: 4 Nov 2025

    A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.

    Published:7 Feb 2023
    9.8
    Critical

    CVE-2022-4297

    Last Modified: 3 Jul 2023

    The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX available to unauthenticated users, leading to an unauthenticated SQL injection

    Source:matitanium
    Published:2 Jan 2023
    8.8
    High

    CVE-2022-4262

    Last Modified: 24 Oct 2025

    Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published:2 Dec 2022
    7.5
    High

    CVE-2022-4244

    Last Modified: 5 May 2025

    A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outside the intended folder. By manipulating files with "dot-dot-slash (../)" sequences and their variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on the file system, including application source code, configuration, and other critical system files.

    Published:1 Dec 2022
    8.8
    High

    CVE-2022-4174

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published:29 Nov 2022
    7.5
    High

    CVE-2022-4140

    Last Modified: 10 Apr 2025

    The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file, which could allow unauthenticated attacker to read arbitrary files on the server

    Published:2 Jan 2023
    8.1
    High

    CVE-2022-4137

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte handling. This issue allows a malicious link to insert an arbitrary URI into a Keycloak error page. This flaw requires a user or administrator to interact with a link in order to be vulnerable. This may compromise user details, allowing it to be changed or collected by an attacker.

    Published:1 Mar 2023
    6.5
    Medium

    CVE-2022-4096

    Last Modified: 14 Apr 2025

    Server-Side Request Forgery (SSRF) in GitHub repository appsmithorg/appsmith prior to 1.8.2.

    Published:21 Nov 2022
    5.5
    Medium

    CVE-2022-4065

    Last Modified: 21 Nov 2024

    A vulnerability was found in cbeust testng 7.5.0/7.6.0/7.6.1/7.7.0. It has been declared as critical. Affected by this vulnerability is the function testngXmlExistsInJar of the file testng-core/src/main/java/org/testng/JarFileUtils.java of the component XML File Parser. The manipulation leads to path traversal. The attack can be launched remotely. Upgrading to version 7.5.1 and 7.7.1 is able to address this issue. The patch is named 9150736cd2c123a6a3b60e6193630859f9f0422b. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-214027.

    Published:19 Nov 2022
    9.8
    Critical

    CVE-2022-4063

    Last Modified: 17 Apr 2025

    The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.

    Published:19 Dec 2022
    7.5
    High

    CVE-2022-4061

    Last Modified: 17 Apr 2025

    The JobBoardWP WordPress plugin before 1.2.2 does not properly validate file names and types in its file upload functionalities, allowing unauthenticated users to upload arbitrary files such as PHP.

    Published:19 Dec 2022
    9.8
    Critical

    CVE-2022-4060

    Last Modified: 4 Apr 2025

    The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, making it possible to any visitors to run code on sites running it.

    Published:16 Jan 2023
    9.8
    Critical

    CVE-2022-4047

    Last Modified: 14 Apr 2025

    The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE

    Published:26 Dec 2022
    2.4
    Low

    CVE-2022-3992

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic was found in SourceCodester Sanitization Management System. Affected by this vulnerability is an unknown functionality of the file admin/?page=system_info of the component Banner Image Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-213571.

    Published:14 Nov 2022
    3.5
    Low

    CVE-2022-3949

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in Sourcecodester Simple Cashiering System. This issue affects some unknown processing of the component User Account Handler. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-213455.

    Published:11 Nov 2022
    4.3
    Medium

    CVE-2022-3942

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Sanitization Management System and classified as problematic. This issue affects some unknown processing of the file php-sms/?p=request_quote. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-213449 was assigned to this vulnerability.

    Published:11 Nov 2022
    7.8
    High

    CVE-2022-3910

    Last Modified: 21 Apr 2025

    Use After Free vulnerability in Linux Kernel allows Privilege Escalation. An improper Update of Reference Count in io_uring leads to Use-After-Free and Local Privilege Escalation. When io_msg_ring was invoked with a fixed file, it called io_fput_file() which improperly decreased its reference count (leading to Use-After-Free and Local Privilege Escalation). Fixed files are permanently registered to the ring, and should not be put separately. We recommend upgrading past commit https://github.com/torvalds/linux/commit/fc7222c3a9f56271fba02aabbfbae999042f1679 https://github.com/torvalds/linux/commit/fc7222c3a9f56271fba02aabbfbae999042f1679

    Published:15 Sept 2022
    6.1
    Medium

    CVE-2022-3904

    Last Modified: 8 Apr 2025

    The MonsterInsights WordPress plugin before 8.9.1 does not sanitize or escape page titles in the top posts/pages section, allowing an unauthenticated attacker to inject arbitrary web scripts into the titles by spoofing requests to google analytics.

    Published:16 Jan 2023
    7.5
    High

    CVE-2022-3786

    Last Modified: 14 Apr 2026

    A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed a malicious certificate or for an application to continue certificate verification despite failure to construct a path to a trusted issuer. An attacker can craft a malicious email address in a certificate to overflow an arbitrary number of bytes containing the `.' character (decimal 46) on the stack. This buffer overflow could result in a crash (causing a denial of service). In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects.

    Published:1 Nov 2022
    9.1
    Critical

    CVE-2022-3782

    Last Modified: 9 Apr 2025

    keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field.

    Published:12 Dec 2022
    6.1
    Medium

    CVE-2022-3766

    Last Modified: 2 Dec 2025

    Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

    Source:CodeSecLab
    Published:31 Oct 2022
    7.8
    High

    CVE-2022-3699

    Last Modified: 21 Nov 2024

    A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4.45 that could allow a local user to execute code with elevated privileges.

    Published:24 Oct 2023