Latest CVE Feed
-
9.8
CRITICALCVE-2022-46255
An improper limitation of a pathname to a restricted directory vulnerability was identified in GitHub Enterprise Server that enabled remote code execution. A check was added within Pages to ensure the working directory is clean before unpacking new conten... Read more
Affected Products : enterprise_server- Published: Dec. 14, 2022
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2022-43724
A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software transmits the database credentials for the inbuilt SQL server in cleartext. In combination with the by default enabled xp_cmdshell feature unauthenticated remote... Read more
Affected Products : sicam_pas\/pqs- Published: Dec. 13, 2022
- Modified: Apr. 22, 2025
-
7.5
HIGHCVE-2022-43723
A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0), SICAM PAS/PQS (All versions >= 7.0 < V8.06). Affected software does not properly validate the input for a certain parameter in the s7ontcp.dll. This could allow an unauthenticated... Read more
Affected Products : sicam_pas\/pqs- Published: Dec. 13, 2022
- Modified: Apr. 22, 2025
-
7.8
HIGHCVE-2022-43722
A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software does not properly secure a folder containing library files. This could allow an attacker to place a custom malicious DLL in this folder which is then run with SY... Read more
Affected Products : sicam_pas\/pqs- Published: Dec. 13, 2022
- Modified: Apr. 22, 2025
-
7.8
HIGHCVE-2022-42796
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.7 and iPadOS 15.7, macOS Ventura 13. An app may be able to gain elevated privileges.... Read more
- Published: Nov. 01, 2022
- Modified: Apr. 22, 2025
-
8.8
HIGHCVE-2022-42795
A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS 16, iOS 16, macOS Ventura 13, watchOS 9. Processing a maliciously crafted image may lead to arbitrary code execution.... Read more
- Published: Nov. 01, 2022
- Modified: Apr. 22, 2025
-
5.5
MEDIUMCVE-2022-42793
An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, macOS Monterey 12.6. An app may be able to bypass code signing checks.... Read more
- Published: Nov. 01, 2022
- Modified: Apr. 22, 2025
-
5.4
MEDIUMCVE-2022-42141
Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Cross Site Scripting (XSS) via lform/urlfilter.... Read more
- Published: Dec. 14, 2022
- Modified: Apr. 22, 2025
-
7.2
HIGHCVE-2022-42140
Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.... Read more
- Published: Dec. 14, 2022
- Modified: Apr. 22, 2025
-
8.8
HIGHCVE-2022-42139
Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL.... Read more
- Published: Dec. 14, 2022
- Modified: Apr. 22, 2025
-
7.5
HIGHCVE-2022-3912
The User Registration WordPress plugin before 2.2.4.1 does not properly restrict the files to be uploaded via an AJAX action available to both unauthenticated and authenticated users, which could allow unauthenticated users to upload PHP files for example... Read more
- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
6.1
MEDIUMCVE-2022-3908
The Helloprint WordPress plugin before 1.4.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : helloprint- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
6.5
MEDIUMCVE-2022-3883
The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 7.24 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and ... Read more
Affected Products : stopbadbots- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
6.5
MEDIUMCVE-2022-3882
The Memory Usage, Memory Limit, PHP and Server Memory Health Check and Fix Plugin WordPress plugin before 2.46 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and a... Read more
Affected Products : wp-memory- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
8.8
HIGHCVE-2022-3359
The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain... Read more
Affected Products : shortcodes_and_extra_features_for_phlox_theme- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
5.5
MEDIUMCVE-2022-3104
An issue was discovered in the Linux kernel through 5.16-rc6. lkdtm_ARRAY_BOUNDS in drivers/misc/lkdtm/bugs.c lacks check of the return value of kmalloc() and will cause the null pointer dereference.... Read more
Affected Products : linux_kernel- Published: Dec. 14, 2022
- Modified: Apr. 22, 2025
-
6.1
MEDIUMCVE-2022-38628
Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a cross-site scripting (XSS) vulnerability which is chained with a local session fixation. This vulnerability allows attacke... Read more
- Published: Dec. 13, 2022
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2022-38488
logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter.... Read more
Affected Products : logrocket-oauth2-example- Published: Dec. 14, 2022
- Modified: Apr. 22, 2025
-
8.8
HIGHCVE-2022-37155
RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.... Read more
Affected Products : spip- Published: Dec. 14, 2022
- Modified: Apr. 22, 2025
-
7.5
HIGHCVE-2022-33239
Transient DOS due to loop with unreachable exit condition in WLAN firmware while parsing IPV6 extension header. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdra... Read more
Affected Products : aqt1000_firmware qam8295p_firmware qca6390_firmware qca6391_firmware qca6420_firmware qca6426_firmware qca6430_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware +458 more products- Published: Nov. 15, 2022
- Modified: Apr. 22, 2025