| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-46405 | Hig | 0.49 | 7.5 | 0.01 | Dec 4, 2022 | Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attacker-controlled accounts on certain other servers associated with a wildcard DNS A record, such that there is uncontrolled recursion of… | ||
| CVE-2022-3491 | Hig | 0.00 | 7.8 | 0.01 | Dec 3, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742. | ||
| CVE-2022-4273 | Hig | 0.48 | 7.3 | 0.01 | Dec 3, 2022 | A vulnerability, which was classified as critical, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the file /hrm/controller/employee.php of the component Content-Type Handler. The manipulation of the argument… | ||
| CVE-2022-23465 | Hig | 0.39 | 7.1 | 0.00 | Dec 2, 2022 | SwiftTerm is a Xterm/VT100 Terminal emulator. Prior to commit a94e6b24d24ce9680ad79884992e1dff8e150a31, an attacker could modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views… | ||
| CVE-2022-4262 | Hig | 0.70 | 8.8 | 0.15 | KEV | Dec 2, 2022 | Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2022-3086 | Hig | 0.46 | 7.1 | 0.00 | Dec 2, 2022 | Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable to shell escape, which enables local attackers with non-superuser credentials to gain full, unrestrictive shell access which may allow an attacker to execute arbitrary code. | ||
| CVE-2022-2642 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Horner Automation’s RCC 972 firmware version 15.40 contains global variables. This could allow an attacker to read out sensitive values and variable keys from the device. | ||
| CVE-2022-2640 | Hig | 0.49 | 7.5 | 0.00 | Dec 2, 2022 | The Config-files of Horner Automation’s RCC 972 with firmware version 15.40 are encrypted with weak XOR encryption vulnerable to reverse engineering. This could allow an attacker to obtain credentials to run services such as File Transfer Protocol (FTP) and Hypertext Transfer… | ||
| CVE-2022-46167 | Hig | 0.50 | 8.8 | 0.01 | Dec 2, 2022 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to version 0.1.3, a ServiceAccount deployed in a Tenant Namespace, when granted with `PATCH` capabilities on its own Namespace, is able to edit it and remove the Owner Reference, breaking the… | ||
| CVE-2022-46145 | Hig | 0.53 | 8.1 | 0.01 | Dec 2, 2022 | authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential account takeover. With the default flows, unauthenticated users can create new accounts in authentik. If a flow exists that allows… | ||
| CVE-2022-45672 | Hig | 0.49 | 7.5 | 0.09 | Dec 2, 2022 | Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the formWx3AuthorizeSet function. | ||
| CVE-2022-45671 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the appData parameter in the formSetAppFilterRule function. | ||
| CVE-2022-45670 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the ping1 parameter in the formSetAutoPing function. | ||
| CVE-2022-45669 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterGet function. | ||
| CVE-2022-45664 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDget function. | ||
| CVE-2022-45663 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet function. | ||
| CVE-2022-45661 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the time parameter in the setSmartPowerManagement function. | ||
| CVE-2022-45660 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the schedStartTime parameter in the setSchedWifi function. | ||
| CVE-2022-45659 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the wpapsk_crypto parameter in the fromSetWirelessRepeat function. | ||
| CVE-2022-45658 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the schedEndTime parameter in the setSchedWifi function. | ||
| CVE-2022-45657 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function. | ||
| CVE-2022-45656 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the time parameter in the fromSetSysTime function. | ||
| CVE-2022-45655 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the timeZone parameter in the form_fast_setting_wifi_set function. | ||
| CVE-2022-45654 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the ssid parameter in the form_fast_setting_wifi_set function. | ||
| CVE-2022-45653 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the page parameter in the fromNatStaticSetting function. | ||
| CVE-2022-45652 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the startIp parameter in the formSetPPTPServer function. | ||
| CVE-2022-45651 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the list parameter in the formSetVirtualSer function. | ||
| CVE-2022-45650 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the firewallEn parameter in the formSetFirewallCfg function. | ||
| CVE-2022-45649 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the endIp parameter in the formSetPPTPServer function. | ||
| CVE-2022-45648 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the devName parameter in the formSetDeviceName function. | ||
| CVE-2022-45647 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the limitSpeed parameter in the formSetClientState function. | ||
| CVE-2022-45646 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the limitSpeedUp parameter in the formSetClientState function. | ||
| CVE-2022-45645 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the deviceMac parameter in the addWifiMacFilter function. | ||
| CVE-2022-45644 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the deviceId parameter in the formSetClientState function. | ||
| CVE-2022-45643 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the deviceId parameter in the addWifiMacFilter function. | ||
| CVE-2022-45641 | Hig | 0.49 | 7.5 | 0.01 | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 is vulnerable to Buffer Overflow via formSetMacFilterCfg. | ||
| CVE-2022-44348 | Hig | 0.47 | 7.2 | 0.01 | Dec 2, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/update_status.php?id=. | ||
| CVE-2022-44347 | Hig | 0.47 | 7.2 | 0.01 | Dec 2, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=inquiries/view_inquiry&id=. | ||
| CVE-2022-44345 | Hig | 0.47 | 7.2 | 0.01 | Dec 2, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=quotes/view_quote&id=. | ||
| CVE-2022-44277 | Hig | 0.47 | 7.2 | 0.01 | Dec 2, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/classes/Master.php?f=delete_product. | ||
| CVE-2022-3591 | Hig | 0.00 | 7.8 | 0.00 | Dec 2, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0789. | ||
| CVE-2022-43272 | Hig | 0.49 | 7.5 | 0.02 | Dec 2, 2022 | DCMTK v3.6.7 was discovered to contain a memory leak via the T_ASC_Association object. | ||
| CVE-2022-2808 | Hig | 0.57 | 8.8 | 0.01 | Dec 2, 2022 | Authorization Bypass Through User-Controlled Key vulnerability in Algan Software Prens Student Information System allows Object Relational Mapping Injection. This issue affects Prens Student Information System: before 2.1.11. | ||
| CVE-2022-45562 | Hig | 0.57 | 8.8 | 0.01 | Dec 2, 2022 | Insecure permissions in Telos Alliance Omnia MPX Node v1.0.0 to v1.4.9 allow attackers to manipulate and access system settings with backdoor account low privilege, this can lead to change hardware settings and execute arbitrary commands in vulnerable system functions that is… | ||
| CVE-2022-44211 | Hig | 0.48 | 7.4 | 0.01 | Dec 1, 2022 | In GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings. | ||
| CVE-2022-35120 | Hig | 0.57 | 8.8 | 0.00 | Dec 1, 2022 | IXPdata EasyInstall 6.6.14725 contains an access control issue. | ||
| CVE-2022-42718 | Hig | 0.51 | 7.8 | 0.00 | Dec 1, 2022 | Incorrect default permissions in the installation folder for NI LabVIEW Command Line Interface (CLI) may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2022-3713 | Hig | 0.57 | 8.8 | 0.01 | Dec 1, 2022 | A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 GA. | ||
| CVE-2022-3696 | Hig | 0.47 | 7.2 | 0.01 | Dec 1, 2022 | A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA. | ||
| CVE-2022-3226 | Hig | 0.47 | 7.2 | 0.02 | Dec 1, 2022 | An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version 19.5 GA. |
- risk 0.49cvss 7.5epss 0.01
Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attacker-controlled accounts on certain other servers associated with a wildcard DNS A record, such that there is uncontrolled recursion of…
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742.
- risk 0.48cvss 7.3epss 0.01
A vulnerability, which was classified as critical, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the file /hrm/controller/employee.php of the component Content-Type Handler. The manipulation of the argument…
- risk 0.39cvss 7.1epss 0.00
SwiftTerm is a Xterm/VT100 Terminal emulator. Prior to commit a94e6b24d24ce9680ad79884992e1dff8e150a31, an attacker could modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views…
- risk 0.70cvss 8.8epss 0.15
Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.46cvss 7.1epss 0.00
Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable to shell escape, which enables local attackers with non-superuser credentials to gain full, unrestrictive shell access which may allow an attacker to execute arbitrary code.
- risk 0.49cvss 7.5epss 0.01
Horner Automation’s RCC 972 firmware version 15.40 contains global variables. This could allow an attacker to read out sensitive values and variable keys from the device.
- risk 0.49cvss 7.5epss 0.00
The Config-files of Horner Automation’s RCC 972 with firmware version 15.40 are encrypted with weak XOR encryption vulnerable to reverse engineering. This could allow an attacker to obtain credentials to run services such as File Transfer Protocol (FTP) and Hypertext Transfer…
- risk 0.50cvss 8.8epss 0.01
Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to version 0.1.3, a ServiceAccount deployed in a Tenant Namespace, when granted with `PATCH` capabilities on its own Namespace, is able to edit it and remove the Owner Reference, breaking the…
- risk 0.53cvss 8.1epss 0.01
authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential account takeover. With the default flows, unauthenticated users can create new accounts in authentik. If a flow exists that allows…
- risk 0.49cvss 7.5epss 0.09
Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the formWx3AuthorizeSet function.
- risk 0.49cvss 7.5epss 0.01
Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the appData parameter in the formSetAppFilterRule function.
- risk 0.49cvss 7.5epss 0.01
Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the ping1 parameter in the formSetAutoPing function.
- risk 0.49cvss 7.5epss 0.01
Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterGet function.
- risk 0.49cvss 7.5epss 0.01
Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDget function.
- risk 0.49cvss 7.5epss 0.01
Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet function.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the time parameter in the setSmartPowerManagement function.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the schedStartTime parameter in the setSchedWifi function.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the wpapsk_crypto parameter in the fromSetWirelessRepeat function.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the schedEndTime parameter in the setSchedWifi function.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the time parameter in the fromSetSysTime function.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the timeZone parameter in the form_fast_setting_wifi_set function.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the ssid parameter in the form_fast_setting_wifi_set function.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the page parameter in the fromNatStaticSetting function.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the startIp parameter in the formSetPPTPServer function.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the list parameter in the formSetVirtualSer function.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the firewallEn parameter in the formSetFirewallCfg function.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the endIp parameter in the formSetPPTPServer function.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the devName parameter in the formSetDeviceName function.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the limitSpeed parameter in the formSetClientState function.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the limitSpeedUp parameter in the formSetClientState function.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the deviceMac parameter in the addWifiMacFilter function.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the deviceId parameter in the formSetClientState function.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the deviceId parameter in the addWifiMacFilter function.
- risk 0.49cvss 7.5epss 0.01
Tenda AC6V1.0 V15.03.05.19 is vulnerable to Buffer Overflow via formSetMacFilterCfg.
- risk 0.47cvss 7.2epss 0.01
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/update_status.php?id=.
- risk 0.47cvss 7.2epss 0.01
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=inquiries/view_inquiry&id=.
- risk 0.47cvss 7.2epss 0.01
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=quotes/view_quote&id=.
- risk 0.47cvss 7.2epss 0.01
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/classes/Master.php?f=delete_product.
- risk 0.00cvss 7.8epss 0.00
Use After Free in GitHub repository vim/vim prior to 9.0.0789.
- risk 0.49cvss 7.5epss 0.02
DCMTK v3.6.7 was discovered to contain a memory leak via the T_ASC_Association object.
- risk 0.57cvss 8.8epss 0.01
Authorization Bypass Through User-Controlled Key vulnerability in Algan Software Prens Student Information System allows Object Relational Mapping Injection. This issue affects Prens Student Information System: before 2.1.11.
- risk 0.57cvss 8.8epss 0.01
Insecure permissions in Telos Alliance Omnia MPX Node v1.0.0 to v1.4.9 allow attackers to manipulate and access system settings with backdoor account low privilege, this can lead to change hardware settings and execute arbitrary commands in vulnerable system functions that is…
- risk 0.48cvss 7.4epss 0.01
In GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings.
- risk 0.57cvss 8.8epss 0.00
IXPdata EasyInstall 6.6.14725 contains an access control issue.
- risk 0.51cvss 7.8epss 0.00
Incorrect default permissions in the installation folder for NI LabVIEW Command Line Interface (CLI) may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.57cvss 8.8epss 0.01
A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 GA.
- risk 0.47cvss 7.2epss 0.01
A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA.
- risk 0.47cvss 7.2epss 0.02
An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version 19.5 GA.