8.1
    High

    CVE-2022-1903

    Last Modified: 21 Nov 2024

    The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username

    Published:27 Jun 2022
    8.8
    High

    CVE-2022-1802

    Last Modified: 16 Apr 2025

    If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox for Android < 100.3.0, and Thunderbird < 91.9.1.

    Published:20 May 2022
    7.8
    High

    CVE-2022-1679

    Last Modified: 21 Nov 2024

    A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privileges on the system.

    Published:7 Feb 2022
    8.8
    High

    CVE-2022-1631

    Last Modified: 3 Jun 2022

    Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account in the application using the Victim’s Email. This allows an attacker to gain pre-authentication to the victim’s account. Further, due to the lack of proper validation of email coming from Social Login and failing to check if an account already exists, the victim will not identify if an account is already existing. Hence, the attacker’s persistence will remain. An attacker would be able to see all the activities performed by the victim user impacting the confidentiality and attempt to modify/corrupt the data impacting the integrity and availability factor. This attack becomes more interesting when an attacker can register an account from an employee’s email address. Assuming the organization uses G-Suite, it is much more impactful to hijack into an employee’s account.

    Source:Manojkumar J
    Published:9 May 2022
    9.8
    Critical

    CVE-2022-1609

    Last Modified: 2 Jun 2025

    The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenticated attacker to execute arbitrary PHP code on the site.

    Published:16 Jan 2024
    5.3
    Medium

    CVE-2022-1598

    Last Modified: 21 Nov 2024

    The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unauthenticated users to discover private questions sent between users on the site.

    Published:6 Jun 2022
    6.1
    Medium

    CVE-2022-1597

    Last Modified: 21 Nov 2024

    The WPQA Builder WordPress plugin before 5.4, used as a companion for the Discy and Himer , does not sanitise and escape a parameter on its reset password form which makes it possible to perform Reflected Cross-Site Scripting attacks

    Published:6 Jun 2022
    8.2
    High

    CVE-2022-1592

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery in scout in GitHub repository clinical-genomics/scout prior to v4.42. An attacker could make the application perform arbitrary requests to fishing steal cookie, request to private area, or lead to xss...

    Published:5 May 2022
    Low

    CVE-2022-1588

    Last Modified: 3 Jun 2022

    DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Chetanya Sharma
    Published:5 May 2022
    7.2
    High

    CVE-2022-1565

    Last Modified: 9 Jun 2023

    The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. This makes it possible for authenticated attackers, with administrator level permissions and above, to upload arbitrary files on the affected sites server which may make remote code execution possible.

    Source:AkuCyberSec
    Published:18 Jul 2022
    8.3
    High

    CVE-2022-1471

    Last Modified: 18 Jun 2025

    SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.

    Published:13 Oct 2022
    7.5
    High

    CVE-2022-1442

    Last Modified: 8 Apr 2026

    The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file which can be exploited by an unauthenticated attacker to view all API keys and secrets of integrated third-party APIs like that of PayPal, Stripe, Mailchimp, Hubspot, HelpScout, reCAPTCHA and many more, in versions up to and including 2.1.3.

    Published:10 May 2022
    4.3
    Medium

    CVE-2022-1421

    Last Modified: 21 Nov 2024

    The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack

    Published:6 Jun 2022
    9.8
    Critical

    CVE-2022-1388

    Last Modified: 12 May 2022

    On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Source:Yesith Alvarez
    Published:5 May 2022
    9.8
    Critical

    CVE-2022-1386

    Last Modified: 21 Nov 2024

    The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local network bypassing firewalls and access control measures.

    Published:16 May 2022
    8.8
    High

    CVE-2022-1364

    Last Modified: 24 Oct 2025

    Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published:26 Jul 2022
    8.8
    High

    CVE-2022-1329

    Last Modified: 7 Feb 2025

    The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.

    Published:19 Apr 2022
    9.8
    Critical

    CVE-2022-1292

    Last Modified: 30 Dec 2025

    The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd).

    Published:3 May 2022
    5.4
    Medium

    CVE-2022-1274

    Last Modified: 21 Nov 2024

    A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.

    Published:28 Feb 2023
    6.1
    Medium

    CVE-2022-1257

    Last Modified: 26 Jun 2025

    Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through storage in ma.db. The sensitive information has been moved to encrypted database files.

    Source:Keenan Scott
    Published:14 Apr 2022
    8.8
    High

    CVE-2022-1227

    Last Modified: 21 Nov 2024

    A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.

    Published:15 Jul 2021
    4.3
    Medium

    CVE-2022-1203

    Last Modified: 21 Nov 2024

    The Content Mask WordPress plugin before 1.8.4.1 does not have authorisation and CSRF checks in various AJAX actions, as well as does not validate the option to be updated to ensure it belongs to the plugin. As a result, any authenticated user, such as subscriber could modify arbitrary blog options

    Published:30 May 2022
    8.7
    High

    CVE-2022-1175

    Last Modified: 11 May 2022

    Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.

    Source:Greenwolf
    Published:4 Apr 2022
    4.8
    Medium

    CVE-2022-1163

    Last Modified: 7 Apr 2022

    Cross-site Scripting (XSS) - Stored in GitHub repository mineweb/minewebcms prior to next.

    Source:Chetanya Sharma
    Published:30 Mar 2022
    9.1
    Critical

    CVE-2022-1162

    Last Modified: 11 May 2022

    A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

    Source:Greenwolf
    Published:4 Apr 2022
    7.5
    High

    CVE-2022-1119

    Last Modified: 8 Apr 2026

    The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php file due to missing controls which makes it possible unauthenticated attackers to supply a path to a file that will subsequently be downloaded, in versions up to and including 3.2.7.

    Published:19 Apr 2022
    4.8
    Medium

    CVE-2022-1104

    Last Modified: 10 Jun 2022

    The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Source:Roel van Beurden
    Published:9 May 2022
    8.8
    High

    CVE-2022-1103

    Last Modified: 11 May 2022

    The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE

    Source:Roel van Beurden
    Published:16 May 2022
    8.8
    High

    CVE-2022-1096

    Last Modified: 24 Oct 2025

    Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published:22 Jul 2022
    5.3
    Medium

    CVE-2022-1077

    Last Modified: 15 Apr 2025

    A vulnerability was found in TEM FLEX-1080 and FLEX-1085 1.6.0. It has been declared as problematic. This vulnerability log.cgi of the component Log Handler. A direct request leads to information disclosure of hardware information. The attack can be initiated remotely and does not require any form of authentication.

    Published:29 Mar 2022
    5.5
    Medium

    CVE-2022-1068

    Last Modified: 16 Apr 2025

    Modbus Tools Modbus Slave (versions 7.4.2 and prior) is vulnerable to a stack-based buffer overflow in the registration field. This may cause the program to crash when a long character string is used.

    Published:1 Apr 2022
    5.4
    Medium

    CVE-2022-1051

    Last Modified: 21 Nov 2024

    The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanitise and escape the city, phone or profile credentials fields when outputting it in the profile page, allowing any authenticated user to perform Cross-Site Scripting attacks.

    Published:16 May 2022
    9.8
    Critical

    CVE-2022-1040

    Last Modified: 2 Sept 2022

    An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.

    Source:Aryan Chehreghani
    Published:25 Mar 2022
    8.6
    High

    CVE-2022-1026

    Last Modified: 21 Nov 2024

    Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information, including usernames and passwords, through an insufficiently protected address book export function.

    Published:4 Apr 2022
    6.6
    Medium

    CVE-2022-1015

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel in linux/net/netfilter/nf_tables_api.c of the netfilter subsystem. This flaw allows a local user to cause an out-of-bounds write issue.

    Published:28 Mar 2022
    8.2
    High

    CVE-2022-1012

    Last Modified: 21 Nov 2024

    A memory leak problem was found in the TCP source port generation algorithm in net/ipv4/tcp.c due to the small table perturb size. This flaw may allow an attacker to information leak and may cause a denial of service problem.

    Published:2 May 2022
    7.8
    High

    CVE-2022-1011

    Last Modified: 26 Aug 2026

    A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation.

    Published:7 Mar 2022
    3.9
    Low

    CVE-2022-0997

    Last Modified: 21 Nov 2024

    Improper file permissions in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected script files, which could result in arbitrary commands being run as root upon subsequent logon by a root user. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.

    Published:17 May 2022
    7.8
    High

    CVE-2022-0995

    Last Modified: 26 Aug 2026

    An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.

    Published:11 Mar 2022
    5.4
    Medium

    CVE-2022-0967

    Last Modified: 24 May 2022

    Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.10.4.

    Source:Akshay Ravi
    Published:15 Mar 2022
    8.8
    High

    CVE-2022-0952

    Last Modified: 21 Nov 2024

    The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog.

    Published:2 May 2022
    7.2
    High

    CVE-2022-0944

    Last Modified: 21 Nov 2024

    Template injection in connection test endpoint leads to RCE in GitHub repository sqlpad/sqlpad prior to 6.10.1.

    Published:15 Mar 2022
    7.5
    High

    CVE-2022-0918

    Last Modified: 3 Nov 2025

    A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crashing.

    Published:16 Mar 2022
    7.5
    High

    CVE-2022-0853

    Last Modified: 21 Nov 2024

    A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.

    Published:4 Mar 2022
    9.8
    Critical

    CVE-2022-0848

    Last Modified: 7 Mar 2022

    OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11.

    Source:Chetanya Sharma
    Published:4 Mar 2022
    7.8
    High

    CVE-2022-0847

    Last Modified: 8 Mar 2022

    A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.

    Source:Lance Biggerstaff
    Published:7 Mar 2022
    8.8
    High

    CVE-2022-0824

    Last Modified: 9 Mar 2022

    Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.

    Source:faisalfs10x
    Published:2 Mar 2022
    8.8
    High

    CVE-2022-0811

    Last Modified: 21 Nov 2024

    A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.

    Published:15 Mar 2022
    7.5
    High

    CVE-2022-0778

    Last Modified: 22 May 2026

    The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the infinite loop. In particular the attacker can use a self-signed certificate to trigger the loop during verification of the certificate signature. This issue affects OpenSSL versions 1.0.2, 1.1.1 and 3.0. It was addressed in the releases of 1.1.1n and 3.0.2 on the 15th March 2022. Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1). Fixed in OpenSSL 1.1.1n (Affected 1.1.1-1.1.1m). Fixed in OpenSSL 1.0.2zd (Affected 1.0.2-1.0.2zc).

    Published:15 Mar 2022
    9.8
    Critical

    CVE-2022-0739

    Last Modified: 21 Nov 2024

    The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in a dynamically constructed SQL query via the bookingpress_front_get_category_services AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection

    Published:21 Mar 2022