| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-46157 | Hig | 0.50 | 8.8 | 0.01 | Dec 9, 2022 | Akeneo PIM is an open source Product Information Management (PIM). Akeneo PIM Community Edition versions before v5.0.119 and v6.0.53 allows remote authenticated users to execute arbitrary PHP code on the server by uploading a crafted image. Akeneo PIM Community Edition after the… | ||
| CVE-2022-44790 | Hig | 0.49 | 7.5 | 0.01 | Dec 9, 2022 | Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could successfully perform an attack to extract potentially sensitive information from the database if the survey id exists. | ||
| CVE-2022-2993 | Hig | 0.56 | 8.6 | 0.01 | Dec 9, 2022 | There is an error in the condition of the last if-statement in the function smp_check_keys. It was rejecting current keys if all requirements were unmet. | ||
| CVE-2022-3259 | Hig | 0.48 | 7.4 | 0.01 | Dec 9, 2022 | Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks. | ||
| CVE-2022-23484 | Hig | 0.53 | 8.2 | 0.01 | Dec 9, 2022 | xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Integer Overflow in xrdp_mm_process_rail_update_window_text() function. There are no known workarounds for this issue. Users… | ||
| CVE-2022-23483 | Hig | 0.49 | 7.5 | 0.01 | Dec 9, 2022 | xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in libxrdp_send_to_channel() function. There are no known workarounds for this issue. Users are advised to… | ||
| CVE-2022-44838 | Hig | 0.47 | 7.2 | 0.01 | Dec 9, 2022 | Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /services/view_service.php. | ||
| CVE-2022-46153 | Hig | 0.46 | 8.1 | 0.00 | Dec 8, 2022 | Traefik is an open source HTTP reverse proxy and load balancer. In affected versions there is a potential vulnerability in Traefik managing TLS connections. A router configured with a not well-formatted TLSOption is exposed with an empty TLSOption. For instance, a route secured… | ||
| CVE-2022-23496 | Hig | 0.42 | 7.5 | 0.01 | Dec 8, 2022 | Yet Another UserAgent Analyzer (Yauaa) is a java library that tries to parse and analyze the useragent string and extract as many relevant attributes as possible. Applications using the Client Hints analysis feature introduced with 7.0.0 can crash because the Yauaa library… | ||
| CVE-2022-23495 | Hig | 0.00 | 7.5 | 0.01 | Dec 8, 2022 | go-merkledag implements the 'DAGService' interface and adds two ipld node types, Protobuf and Raw for the ipfs project. A `ProtoNode` may be modified in such a way as to cause various encode errors which will trigger a panic on common method calls that don't allow for error… | ||
| CVE-2022-4366 | Hig | 0.00 | 7.5 | 0.01 | Dec 8, 2022 | Missing Authorization in GitHub repository lirantal/daloradius prior to master branch. | ||
| CVE-2022-46829 | Hig | 0.46 | 7.1 | 0.00 | Dec 8, 2022 | In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented. | ||
| CVE-2022-45877 | Hig | 0.54 | 8.3 | 0.00 | Dec 8, 2022 | OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks. | ||
| CVE-2022-45525 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the downaction parameter at /goform/CertListInfo. | ||
| CVE-2022-45524 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the opttype parameter at /goform/IPSECsave. | ||
| CVE-2022-45523 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/L7Im. | ||
| CVE-2022-45522 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeClientFilter. | ||
| CVE-2022-45521 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeUrlFilter. | ||
| CVE-2022-45520 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/qossetting. | ||
| CVE-2022-45519 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the Go parameter at /goform/SafeMacFilter. | ||
| CVE-2022-45518 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SetIpBind. | ||
| CVE-2022-45517 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/VirtualSer. | ||
| CVE-2022-45516 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/NatStaticSetting. | ||
| CVE-2022-45515 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the entries parameter at /goform/addressNat. | ||
| CVE-2022-45514 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/webExcptypemanFilter. | ||
| CVE-2022-45513 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/P2pListFilter. | ||
| CVE-2022-45512 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeEmailFilter. | ||
| CVE-2022-45511 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the PPPOEPassword parameter at /goform/QuickIndex. | ||
| CVE-2022-45510 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the mit_ssid_index parameter at /goform/AdvSetWrlsafeset. | ||
| CVE-2022-45509 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the account parameter at /goform/addUserName. | ||
| CVE-2022-45508 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the new_account parameter at /goform/editUserName. | ||
| CVE-2022-45507 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the editNameMit parameter at /goform/editFileName. | ||
| CVE-2022-45505 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the cmdinput parameter at /goform/exeCommand. | ||
| CVE-2022-45504 | Hig | 0.50 | 7.5 | 0.18 | Dec 8, 2022 | An issue in the component tpi_systool_handle(0) (/goform/SysToolRestoreSet) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to arbitrarily reboot the device. | ||
| CVE-2022-45503 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the linkEn parameter at /goform/setAutoPing. | ||
| CVE-2022-45501 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/wifiSSIDset. | ||
| CVE-2022-45499 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/WifiMacFilterGet. | ||
| CVE-2022-45498 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | An issue in the component tpi_systool_handle(0) (/goform/SysToolReboot) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to arbitrarily reboot the device. | ||
| CVE-2022-44932 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | An access control issue in Tenda A18 v15.13.07.09 allows unauthenticated attackers to access the Telnet service. | ||
| CVE-2022-44931 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda A18 v15.13.07.09 was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet. | ||
| CVE-2022-3262 | Hig | 0.53 | 8.1 | 0.01 | Dec 8, 2022 | A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability. | ||
| CVE-2022-39909 | Hig | 0.46 | 7.1 | 0.00 | Dec 8, 2022 | Insufficient verification of data authenticity vulnerability in Samsung Gear IconX PC Manager prior to version 2.1.221019.51 allows local attackers to create arbitrary file using symbolic link. | ||
| CVE-2022-38754 | Hig | 0.52 | 8.0 | 0.01 | Dec 8, 2022 | A potential vulnerability has been identified in Micro Focus Operations Bridge - Containerized. The vulnerability could be exploited by a malicious authenticated OBM (Operations Bridge Manager) user to run Java Scripts in the browser context of another OBM user. Please note: The… | ||
| CVE-2022-37918 | Hig | 0.53 | 8.1 | 0.01 | Dec 8, 2022 | Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change… | ||
| CVE-2022-37917 | Hig | 0.53 | 8.1 | 0.01 | Dec 8, 2022 | Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change… | ||
| CVE-2022-37916 | Hig | 0.53 | 8.1 | 0.01 | Dec 8, 2022 | Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change… | ||
| CVE-2022-4364 | Hig | 0.48 | 7.3 | 0.04 | Dec 8, 2022 | A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality of the file palette.php of the component Web Service Handler. The manipulation of the argument palette leads to command injection. The attack is possible to be… | ||
| CVE-2022-46792 | Hig | 0.57 | 8.8 | 0.01 | Dec 8, 2022 | Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The fixed versions are 2.10.2, 2.11.3, 2.12.1, 2.13.2, 2.14.1, and 2.15.2. (Versions before 2.10.0 are unaffected.) | ||
| CVE-2022-23476 | Hig | 0.42 | 7.5 | 0.02 | Dec 8, 2022 | Nokogiri is an open source XML and HTML library for the Ruby programming language. Nokogiri `1.13.8` and `1.13.9` fail to check the return value from `xmlTextReaderExpand` in the method `Nokogiri::XML::Reader#attribute_hash`. This can lead to a null pointer exception when… | ||
| CVE-2022-23492 | Hig | 0.42 | 7.5 | 0.01 | Dec 8, 2022 | go-libp2p is the offical libp2p implementation in the Go programming language. Version `0.18.0` and older of go-libp2p are vulnerable to targeted resource exhaustion attacks. These attacks target libp2p’s connection, stream, peer, and memory management. An attacker can cause… |
- risk 0.50cvss 8.8epss 0.01
Akeneo PIM is an open source Product Information Management (PIM). Akeneo PIM Community Edition versions before v5.0.119 and v6.0.53 allows remote authenticated users to execute arbitrary PHP code on the server by uploading a crafted image. Akeneo PIM Community Edition after the…
- risk 0.49cvss 7.5epss 0.01
Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could successfully perform an attack to extract potentially sensitive information from the database if the survey id exists.
- risk 0.56cvss 8.6epss 0.01
There is an error in the condition of the last if-statement in the function smp_check_keys. It was rejecting current keys if all requirements were unmet.
- risk 0.48cvss 7.4epss 0.01
Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks.
- risk 0.53cvss 8.2epss 0.01
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Integer Overflow in xrdp_mm_process_rail_update_window_text() function. There are no known workarounds for this issue. Users…
- risk 0.49cvss 7.5epss 0.01
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in libxrdp_send_to_channel() function. There are no known workarounds for this issue. Users are advised to…
- risk 0.47cvss 7.2epss 0.01
Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /services/view_service.php.
- risk 0.46cvss 8.1epss 0.00
Traefik is an open source HTTP reverse proxy and load balancer. In affected versions there is a potential vulnerability in Traefik managing TLS connections. A router configured with a not well-formatted TLSOption is exposed with an empty TLSOption. For instance, a route secured…
- risk 0.42cvss 7.5epss 0.01
Yet Another UserAgent Analyzer (Yauaa) is a java library that tries to parse and analyze the useragent string and extract as many relevant attributes as possible. Applications using the Client Hints analysis feature introduced with 7.0.0 can crash because the Yauaa library…
- risk 0.00cvss 7.5epss 0.01
go-merkledag implements the 'DAGService' interface and adds two ipld node types, Protobuf and Raw for the ipfs project. A `ProtoNode` may be modified in such a way as to cause various encode errors which will trigger a panic on common method calls that don't allow for error…
- risk 0.00cvss 7.5epss 0.01
Missing Authorization in GitHub repository lirantal/daloradius prior to master branch.
- risk 0.46cvss 7.1epss 0.00
In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.
- risk 0.54cvss 8.3epss 0.00
OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the downaction parameter at /goform/CertListInfo.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the opttype parameter at /goform/IPSECsave.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/L7Im.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeClientFilter.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeUrlFilter.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/qossetting.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the Go parameter at /goform/SafeMacFilter.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SetIpBind.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/VirtualSer.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/NatStaticSetting.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the entries parameter at /goform/addressNat.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/webExcptypemanFilter.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/P2pListFilter.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeEmailFilter.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the PPPOEPassword parameter at /goform/QuickIndex.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the mit_ssid_index parameter at /goform/AdvSetWrlsafeset.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the account parameter at /goform/addUserName.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the new_account parameter at /goform/editUserName.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the editNameMit parameter at /goform/editFileName.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the cmdinput parameter at /goform/exeCommand.
- risk 0.50cvss 7.5epss 0.18
An issue in the component tpi_systool_handle(0) (/goform/SysToolRestoreSet) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to arbitrarily reboot the device.
- risk 0.49cvss 7.5epss 0.01
Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the linkEn parameter at /goform/setAutoPing.
- risk 0.49cvss 7.5epss 0.01
Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/wifiSSIDset.
- risk 0.49cvss 7.5epss 0.01
Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/WifiMacFilterGet.
- risk 0.49cvss 7.5epss 0.01
An issue in the component tpi_systool_handle(0) (/goform/SysToolReboot) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to arbitrarily reboot the device.
- risk 0.49cvss 7.5epss 0.01
An access control issue in Tenda A18 v15.13.07.09 allows unauthenticated attackers to access the Telnet service.
- risk 0.49cvss 7.5epss 0.01
Tenda A18 v15.13.07.09 was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.
- risk 0.53cvss 8.1epss 0.01
A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.
- risk 0.46cvss 7.1epss 0.00
Insufficient verification of data authenticity vulnerability in Samsung Gear IconX PC Manager prior to version 2.1.221019.51 allows local attackers to create arbitrary file using symbolic link.
- risk 0.52cvss 8.0epss 0.01
A potential vulnerability has been identified in Micro Focus Operations Bridge - Containerized. The vulnerability could be exploited by a malicious authenticated OBM (Operations Bridge Manager) user to run Java Scripts in the browser context of another OBM user. Please note: The…
- risk 0.53cvss 8.1epss 0.01
Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change…
- risk 0.53cvss 8.1epss 0.01
Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change…
- risk 0.53cvss 8.1epss 0.01
Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change…
- risk 0.48cvss 7.3epss 0.04
A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality of the file palette.php of the component Web Service Handler. The manipulation of the argument palette leads to command injection. The attack is possible to be…
- risk 0.57cvss 8.8epss 0.01
Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The fixed versions are 2.10.2, 2.11.3, 2.12.1, 2.13.2, 2.14.1, and 2.15.2. (Versions before 2.10.0 are unaffected.)
- risk 0.42cvss 7.5epss 0.02
Nokogiri is an open source XML and HTML library for the Ruby programming language. Nokogiri `1.13.8` and `1.13.9` fail to check the return value from `xmlTextReaderExpand` in the method `Nokogiri::XML::Reader#attribute_hash`. This can lead to a null pointer exception when…
- risk 0.42cvss 7.5epss 0.01
go-libp2p is the offical libp2p implementation in the Go programming language. Version `0.18.0` and older of go-libp2p are vulnerable to targeted resource exhaustion attacks. These attacks target libp2p’s connection, stream, peer, and memory management. An attacker can cause…