Weekly Vulnerabilities Reports > December 26, 2022 to January 1, 2023
Overview
396 new vulnerabilities reported during this period, including 88 critical vulnerabilities and 111 high severity vulnerabilities. This weekly summary report vulnerabilities in 316 products from 140 vendors including Nvidia, Trendnet, Tenda, Dahuasecurity, and Usememos. Vulnerabilities are notably categorized as "Cross-site Scripting", "Out-of-bounds Write", "SQL Injection", "Path Traversal", and "Improper Authentication".
- 346 reported vulnerabilities are remotely exploitables.
- 186 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
- 260 reported vulnerabilities are exploitable by an anonymous user.
- Nvidia has the most reported vulnerabilities, with 25 reported vulnerabilities.
- Trendnet has the most reported critical vulnerabilities, with 20 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
88 Critical Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2023-01-01 | CVE-2021-4297 | Jobe Project | Unspecified vulnerability in Jobe Project Jobe A vulnerability has been found in trampgeek jobe up to 1.6.4 and classified as problematic. | 9.8 |
2023-01-01 | CVE-2014-125030 | Empress Project | Use of Hard-coded Credentials vulnerability in Empress Project Empress A vulnerability, which was classified as critical, has been found in taoeffect Empress. | 9.8 |
2023-01-01 | CVE-2022-48198 | Ntpd Driver Project | Code Injection vulnerability in Ntpd Driver Project Ntpd Driver The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in the same ROS application, to change a robot's behavior. | 9.8 |
2022-12-31 | CVE-2017-20160 | Flitto | Improper Handling of Extra Parameters vulnerability in Flitto Express-Param A vulnerability was found in flitto express-param up to 0.x. | 9.8 |
2022-12-31 | CVE-2017-20156 | Printer Project | Command Injection vulnerability in Printer Project Printer A vulnerability was found in Exciting Printer and classified as critical. | 9.8 |
2022-12-31 | CVE-2017-20157 | Ariadne CMS | Server-Side Request Forgery (SSRF) vulnerability in Ariadne-Cms Ariadne Component Library A vulnerability was found in Ariadne Component Library up to 2.x. | 9.8 |
2022-12-31 | CVE-2022-48195 | Mellium | Improper Authentication vulnerability in Mellium Sasl 0.3.0 An issue was discovered in Mellium mellium.im/sasl before 0.3.1. | 9.8 |
2022-12-30 | CVE-2022-46580 | Trendnet | Out-of-bounds Write vulnerability in Trendnet Tew-755Ap Firmware 1.13B01 TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the user_edit_page parameter in the wifi_captive_portal function. | 9.8 |
2022-12-30 | CVE-2022-46581 | Trendnet | Out-of-bounds Write vulnerability in Trendnet Tew-755Ap Firmware 1.13B01 TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.nslookup_target parameter in the tools_nslookup function. | 9.8 |
2022-12-30 | CVE-2022-46582 | Trendnet | Out-of-bounds Write vulnerability in Trendnet Tew-755Ap Firmware 1.13B01 TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the login_name parameter in the do_graph_auth (sub_4061E0) function. | 9.8 |
2022-12-30 | CVE-2022-46583 | Trendnet | Out-of-bounds Write vulnerability in Trendnet Tew-755Ap Firmware 1.13B01 TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reboot_type parameter in the wizard_ipv6 (sub_41C380) function. | 9.8 |
2022-12-30 | CVE-2022-46584 | Trendnet | Out-of-bounds Write vulnerability in Trendnet Tew-755Ap Firmware 1.13B01 TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the qcawifi.wifi%d_vap%d.maclist parameter in the kick_ban_wifi_mac_deny (sub_415D7C) function. | 9.8 |
2022-12-30 | CVE-2022-46585 | Trendnet | Out-of-bounds Write vulnerability in Trendnet Tew-755Ap Firmware 1.13B01 TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the REMOTE_USER parameter in the get_access (sub_45AC2C) function. | 9.8 |
2022-12-30 | CVE-2022-46586 | Trendnet | Out-of-bounds Write vulnerability in Trendnet Tew-755Ap Firmware 1.13B01 TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the qcawifi.wifi%d_vap%d.maclist parameter in the kick_ban_wifi_mac_allow (sub_415B00) function. | 9.8 |
2022-12-30 | CVE-2022-46588 | Trendnet | Out-of-bounds Write vulnerability in Trendnet Tew-755Ap Firmware 1.13B01 TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the sys_service parameter in the setup_wizard_mydlink (sub_4104B8) function. | 9.8 |
2022-12-30 | CVE-2022-46589 | Trendnet | Out-of-bounds Write vulnerability in Trendnet Tew-755Ap Firmware 1.13B01 TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstat_option parameter in the tools_netstat (sub_41E730) function. | 9.8 |
2022-12-30 | CVE-2022-46590 | Trendnet | Out-of-bounds Write vulnerability in Trendnet Tew-755Ap Firmware 1.13B01 TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstat_rsname parameter in the tools_netstat (sub_41E730) function. | 9.8 |
2022-12-30 | CVE-2022-46591 | Trendnet | Out-of-bounds Write vulnerability in Trendnet Tew-755Ap Firmware 1.13B01 TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reject_url parameter in the reject (sub_41BD60) function. | 9.8 |
2022-12-30 | CVE-2022-46592 | Trendnet | Out-of-bounds Write vulnerability in Trendnet Tew-755Ap Firmware 1.13B01 TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wps_sta_enrollee_pin parameter in the set_sta_enrollee_pin_5g function. | 9.8 |
2022-12-30 | CVE-2022-46593 | Trendnet | Out-of-bounds Write vulnerability in Trendnet Tew-755Ap Firmware 1.13B01 TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wps_sta_enrollee_pin parameter in the do_sta_enrollee_wifi function. | 9.8 |
2022-12-30 | CVE-2022-46594 | Trendnet | Out-of-bounds Write vulnerability in Trendnet Tew-755Ap Firmware 1.13B01 TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the update_file_name parameter in the auto_up_fw (sub_420A04) function. | 9.8 |
2022-12-30 | CVE-2022-46596 | Trendnet | Out-of-bounds Write vulnerability in Trendnet Tew-755Ap Firmware 1.13B01 TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the del_num parameter in the icp_delete_img (sub_41DEDC) function. | 9.8 |
2022-12-30 | CVE-2022-46597 | Trendnet | Out-of-bounds Write vulnerability in Trendnet Tew-755Ap Firmware 1.13B01 TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the sys_service parameter in the setup_wizard_mydlink (sub_4104B8) function. | 9.8 |
2022-12-30 | CVE-2022-46598 | Trendnet | Out-of-bounds Write vulnerability in Trendnet Tew-755Ap Firmware 1.13B01 TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the wps_sta_enrollee_pin parameter in the action set_sta_enrollee_pin_5g function. | 9.8 |
2022-12-30 | CVE-2022-46599 | Trendnet | Out-of-bounds Write vulnerability in Trendnet Tew-755Ap Firmware 1.13B01 TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setlogo_num parameter in the icp_setlogo_img (sub_41DBF4) function. | 9.8 |
2022-12-30 | CVE-2022-46600 | Trendnet | Out-of-bounds Write vulnerability in Trendnet Tew-755Ap Firmware 1.13B01 TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wps_sta_enrollee_pin parameter in the action set_sta_enrollee_pin_24g function. | 9.8 |
2022-12-30 | CVE-2022-46601 | Trendnet | Out-of-bounds Write vulnerability in Trendnet Tew-755Ap Firmware 1.13B01 TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setbg_num parameter in the icp_setbg_img (sub_41DD68) function. | 9.8 |
2022-12-30 | CVE-2022-47115 | Tenda | Out-of-bounds Write vulnerability in Tenda A15 Firmware 15.13.07.13 Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepauth parameter at /goform/WifiBasicSet. | 9.8 |
2022-12-30 | CVE-2022-47117 | Tenda | Out-of-bounds Write vulnerability in Tenda A15 Firmware 15.13.07.13 Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the security parameter at /goform/WifiBasicSet. | 9.8 |
2022-12-30 | CVE-2022-47118 | Tenda | Out-of-bounds Write vulnerability in Tenda A15 Firmware 15.13.07.13 Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey1 parameter at /goform/WifiBasicSet. | 9.8 |
2022-12-30 | CVE-2022-47119 | Tenda | Out-of-bounds Write vulnerability in Tenda A15 Firmware 15.13.07.13 Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the ssid parameter at /goform/WifiBasicSet. | 9.8 |
2022-12-30 | CVE-2022-47120 | Tenda | Out-of-bounds Write vulnerability in Tenda A15 Firmware 15.13.07.13 Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet. | 9.8 |
2022-12-30 | CVE-2022-47121 | Tenda | Out-of-bounds Write vulnerability in Tenda A15 Firmware 15.13.07.13 Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey parameter at /goform/WifiBasicSet. | 9.8 |
2022-12-30 | CVE-2022-47122 | Tenda | Out-of-bounds Write vulnerability in Tenda A15 Firmware 15.13.07.13 Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlPwd_5g parameter at /goform/WifiBasicSet. | 9.8 |
2022-12-30 | CVE-2022-47123 | Tenda | Out-of-bounds Write vulnerability in Tenda A15 Firmware 15.13.07.13 Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey3 parameter at /goform/WifiBasicSet. | 9.8 |
2022-12-30 | CVE-2022-47124 | Tenda | Out-of-bounds Write vulnerability in Tenda A15 Firmware 15.13.07.13 Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey4 parameter at /goform/WifiBasicSet. | 9.8 |
2022-12-30 | CVE-2022-47125 | Tenda | Out-of-bounds Write vulnerability in Tenda A15 Firmware 15.13.07.13 Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlEn_5g parameter at /goform/WifiBasicSet. | 9.8 |
2022-12-30 | CVE-2022-47126 | Tenda | Out-of-bounds Write vulnerability in Tenda A15 Firmware 15.13.07.13 Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlEn parameter at /goform/WifiBasicSet. | 9.8 |
2022-12-30 | CVE-2022-47127 | Tenda | Out-of-bounds Write vulnerability in Tenda A15 Firmware 15.13.07.13 Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlPwd parameter at /goform/WifiBasicSet. | 9.8 |
2022-12-30 | CVE-2022-47128 | Tenda | Out-of-bounds Write vulnerability in Tenda A15 Firmware 15.13.07.13 Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey2 parameter at /goform/WifiBasicSet. | 9.8 |
2022-12-30 | CVE-2017-20151 | Itextpdf | XXE vulnerability in Itextpdf Rups A vulnerability classified as problematic was found in iText RUPS. | 9.8 |
2022-12-30 | CVE-2022-4860 | Kbase | SQL Injection vulnerability in Kbase Metrics A vulnerability was found in KBase Metrics. | 9.8 |
2022-12-30 | CVE-2022-44621 | Apache | Command Injection vulnerability in Apache Kylin Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request. | 9.8 |
2022-12-30 | CVE-2022-4855 | Lead Management System Project | SQL Injection vulnerability in Lead Management System Project Lead Management System 1.0 A vulnerability, which was classified as critical, was found in SourceCodester Lead Management System 1.0. | 9.8 |
2022-12-30 | CVE-2022-48196 | Netgear | Classic Buffer Overflow vulnerability in Netgear products Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. | 9.8 |
2022-12-29 | CVE-2021-4295 | Healthit | XXE vulnerability in Healthit Code-Validator-Api A vulnerability classified as problematic was found in ONC code-validator-api up to 1.0.30. | 9.8 |
2022-12-29 | CVE-2022-4779 | Elvexys | Improper Authentication vulnerability in Elvexys Streamx StreamX applications from versions 6.02.01 to 6.04.34 are affected by a logic bug that allows to bypass the implemented authentication scheme. | 9.8 |
2022-12-28 | CVE-2018-25057 | Simple PHP Link Shortener Project | SQL Injection vulnerability in Simple PHP Link Shortener Project Simple PHP Link Shortener A vulnerability was found in simple_php_link_shortener. | 9.8 |
2022-12-27 | CVE-2021-4290 | Fallstudie Project | SQL Injection vulnerability in Fallstudie Project Fallstudie A vulnerability was found in DHBW Fallstudie. | 9.8 |
2022-12-27 | CVE-2022-4768 | A vulnerability was found in Dropbox merou. | 9.8 | |
2022-12-27 | CVE-2014-125026 | Cloudflare | Out-of-bounds Write vulnerability in Cloudflare Golz4 LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input. | 9.8 |
2022-12-27 | CVE-2017-20146 | Gorillatoolkit | Origin Validation Error vulnerability in Gorillatoolkit Handlers 1.1/1.2/1.2.1 Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy. | 9.8 |
2022-12-27 | CVE-2021-4236 | Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the returned UserData pointer is assumed to be non-nil, or authentication bypass. | 9.8 | |
2022-12-27 | CVE-2022-45778 | https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect Access Control. | 9.8 | |
2022-12-27 | CVE-2022-45963 | H3C | Unspecified vulnerability in H3C products h3c firewall <= 3.10 ESS6703 has a privilege bypass vulnerability. | 9.8 |
2022-12-27 | CVE-2022-46442 | dedecms <=V5.7.102 is vulnerable to SQL Injection. | 9.8 | |
2022-12-27 | CVE-2022-4719 | Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5. | 9.8 | |
2022-12-27 | CVE-2022-4724 | Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5. | 9.8 | |
2022-12-27 | CVE-2022-4725 | A vulnerability was found in AWS SDK 2.59.0. | 9.8 | |
2022-12-27 | CVE-2022-4726 | Sanitization Management System Project | SQL Injection vulnerability in Sanitization Management System Project Sanitization Management System 1.0 A vulnerability classified as critical was found in SourceCodester Sanitization Management System 1.0. | 9.8 |
2022-12-27 | CVE-2022-4748 | Flatpress | Path Traversal vulnerability in Flatpress A vulnerability was found in FlatPress. | 9.8 |
2022-12-27 | CVE-2022-46764 | Trueconf | SQL Injection vulnerability in Trueconf Server A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution. | 9.8 |
2022-12-26 | CVE-2019-11851 | Sierrawireless | Classic Buffer Overflow vulnerability in Sierrawireless Aleos The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to execute arbitrary code via a buffer overflow. | 9.8 |
2022-12-26 | CVE-2020-24600 | Capexweb Project | SQL Injection vulnerability in Capexweb Project Capexweb 1.1 Shilpi CAPExWeb 1.1 allows SQL injection via a servlet/capexweb.cap_sendMail GET request. | 9.8 |
2022-12-26 | CVE-2020-11101 | Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges. | 9.8 | |
2022-12-26 | CVE-2021-4281 | A vulnerability was found in Brave UX for-the-badge and classified as critical. | 9.8 | |
2022-12-26 | CVE-2020-12069 | In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), the password-hashing feature requires insufficient computational effort. | 9.8 | |
2022-12-26 | CVE-2022-4047 | The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE | 9.8 | |
2022-12-26 | CVE-2022-4117 | The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection. | 9.8 | |
2022-12-26 | CVE-2022-4120 | The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2022.6 passes base64 encoded user input to the unserialize() PHP function when CAPTCHA are used as second challenge, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain | 9.8 | |
2022-12-26 | CVE-2022-4742 | A vulnerability, which was classified as critical, has been found in json-pointer. | 9.8 | |
2022-12-26 | CVE-2022-26969 | In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true. | 9.8 | |
2022-12-26 | CVE-2021-45466 | Control Webpanel | Incorrect Authorization vulnerability in Control-Webpanel Webpanel In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the /resources/ folder. | 9.8 |
2022-12-26 | CVE-2021-45467 | Control Webpanel | Unspecified vulnerability in Control-Webpanel Webpanel In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts= .%00./.%00./api/account_new_create&acc=guadaapi URI. | 9.8 |
2022-12-26 | CVE-2022-24116 | Certain General Electric Renewable Energy products have inadequate encryption strength. | 9.8 | |
2022-12-26 | CVE-2022-24117 | Certain General Electric Renewable Energy products download firmware without an integrity check. | 9.8 | |
2022-12-26 | CVE-2022-24119 | Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell. | 9.8 | |
2022-12-29 | CVE-2022-36437 | Hazelcast | Session Fixation vulnerability in Hazelcast Hazelcast-Jet The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. | 9.1 |
2022-12-27 | CVE-2018-25046 | Cloudfoundry | Path Traversal vulnerability in Cloudfoundry Archiver Due to improper path santization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | 9.1 |
2022-12-27 | CVE-2020-36560 | Due to improper path santization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | 9.1 | |
2022-12-27 | CVE-2020-36561 | Due to improper path santization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | 9.1 | |
2022-12-27 | CVE-2020-36566 | Due to improper path santization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | 9.1 | |
2022-12-27 | CVE-2020-36569 | Digitalocean | Improper Authentication vulnerability in Digitalocean Golang-Nanoauth Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token. | 9.1 |
2022-12-27 | CVE-2021-4238 | Randomly-generated alphanumeric strings contain significantly less entropy than expected. | 9.1 | |
2022-12-26 | CVE-2022-24118 | Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory default configuration. | 9.1 | |
2023-01-01 | CVE-2022-34322 | Sage | Cross-site Scripting vulnerability in Sage Enterprise Intelligence 2021R1.1 Multiple XSS issues were discovered in Sage Enterprise Intelligence 2021 R1.1 that allow an attacker to execute JavaScript code in the context of users' browsers. | 9.0 |
2022-12-31 | CVE-2022-4865 | Usememos | Cross-site Scripting vulnerability in Usememos Memos Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | 9.0 |
2022-12-31 | CVE-2022-4866 | Usememos | Cross-site Scripting vulnerability in Usememos Memos Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | 9.0 |
111 High Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2023-01-01 | CVE-2022-34324 | Sage | SQL Injection vulnerability in Sage XRT Business Exchange 12.4.302 Multiple SQL injections in Sage XRT Business Exchange 12.4.302 allow an authenticated attacker to inject malicious data in SQL queries: Add Currencies, Payment Order, and Transfer History. | 8.8 |
2022-12-31 | CVE-2014-125028 | Valtech | Cross-Site Request Forgery (CSRF) vulnerability in Valtech IDP Test Clients A vulnerability was found in valtech IDP Test Client and classified as problematic. | 8.8 |
2022-12-30 | CVE-2022-34671 | Nvidia | Out-of-bounds Write vulnerability in Nvidia GPU Display Driver NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds write, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering. | 8.8 |
2022-12-30 | CVE-2022-43396 | Apache | Command Injection vulnerability in Apache Kylin In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. | 8.8 |
2022-12-30 | CVE-2022-48194 | TP Link | Unrestricted Upload of File with Dangerous Type vulnerability in Tp-Link Tl-Wr902Ac Firmware TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploading a crafted firmware update because the signature check is inadequate. | 8.8 |
2022-12-29 | CVE-2022-46178 | MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. | 8.8 | |
2022-12-29 | CVE-2022-4844 | Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1. | 8.8 | |
2022-12-28 | CVE-2017-20150 | Challenge Website Project | SQL Injection vulnerability in Challenge Website Project Challenge Website A vulnerability was found in challenge website. | 8.8 |
2022-12-28 | CVE-2022-4803 | Usememos | Authorization Bypass Through User-Controlled Key vulnerability in Usememos Memos Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. | 8.8 |
2022-12-28 | CVE-2022-4808 | Improper Privilege Management in GitHub repository usememos/memos prior to 0.9.1. | 8.8 | |
2022-12-28 | CVE-2022-4809 | Improper Access Control in GitHub repository usememos/memos prior to 0.9.1. | 8.8 | |
2022-12-28 | CVE-2022-23555 | Goauthentik | Improper Authentication vulnerability in Goauthentik Authentik authentik is an open-source Identity Provider focused on flexibility and versatility. | 8.8 |
2022-12-27 | CVE-2016-15005 | Golf Project | Cross-Site Request Forgery (CSRF) vulnerability in Golf Project Golf 0.1.0/0.1.1/0.2.0 CSRF tokens are generated using math/rand, which is not a cryptographically secure random number generator, allowing an attacker to predict values and bypass CSRF protections with relatively few requests. | 8.8 |
2022-12-27 | CVE-2022-46763 | Trueconf | SQL Injection vulnerability in Trueconf Server 5.2.0.10225 A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code. | 8.8 |
2022-12-26 | CVE-2020-28191 | The console in Togglz before 2.9.4 allows CSRF. | 8.8 | |
2022-12-26 | CVE-2019-25085 | A vulnerability was found in GNOME gvdb. | 8.8 | |
2023-01-01 | CVE-2022-47634 | Isode | Unspecified vulnerability in Isode M-Link M-Link Archive Server in Isode M-Link R16.2v1 through R17.0 before R17.0v24 allows non-administrative users to access and manipulate archive data via certain HTTP endpoints, aka LINK-2867. | 8.1 |
2022-12-28 | CVE-2022-4796 | Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1. | 8.1 | |
2022-12-26 | CVE-2019-9579 | Illumos Oracle | An issue was discovered in Illumos in Nexenta NexentaStor 4.0.5 and 5.1.2, and other products. | 8.1 |
2022-12-26 | CVE-2020-10650 | Oracle | Deserialization of Untrusted Data vulnerability in Oracle Retail Merchandising System and Retail Sales Audit A deserialization flaw was discovered in jackson-databind through 2.9.10.4. | 8.1 |
2022-12-26 | CVE-2021-35954 | Fastrack | Unspecified vulnerability in Fastrack Reflex 2.0 Firmware 90.89 fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows physically proximate attackers to dump the firmware, flash custom malicious firmware, and brick the device via the Serial Wire Debug (SWD) feature. | 8.1 |
2022-12-30 | CVE-2022-42269 | Nvidia | Improper Input Validation vulnerability in Nvidia Jetson Linux NVIDIA Trusted OS contains a vulnerability in an SMC call handler, where failure to validate untrusted input may allow a highly privileged local attacker to cause information disclosure and compromise integrity. | 7.9 |
2022-12-30 | CVE-2022-34669 | Nvidia | Externally Controlled Reference to a Resource in Another Sphere vulnerability in Nvidia Cloud Gaming and Virtual GPU NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can access or modify system files or other files that are critical to the application, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering. | 7.8 |
2022-12-30 | CVE-2022-34670 | Nvidia | Incorrect Conversion between Numeric Types vulnerability in Nvidia Cloud Gaming, GPU Display Driver and Virtual GPU NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause truncation errors when casting a primitive to a primitive of smaller size causes data to be lost in the conversion, which may lead to denial of service or information disclosure. | 7.8 |
2022-12-30 | CVE-2022-34672 | Nvidia | Unspecified vulnerability in Nvidia Cloud Gaming and Virtual GPU NVIDIA Control Panel for Windows contains a vulnerability where an unauthorized user or an unprivileged regular user can compromise the security of the software by gaining privileges, reading sensitive information, or executing commands. | 7.8 |
2022-12-30 | CVE-2022-34676 | Nvidia | Out-of-bounds Read vulnerability in Nvidia Cloud Gaming and Virtual GPU NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds read may lead to denial of service, information disclosure, or data tampering. | 7.8 |
2022-12-30 | CVE-2022-42254 | Nvidia | Improper Validation of Array Index vulnerability in Nvidia Cloud Gaming, GPU Display Driver and Virtual GPU NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, data tampering, or information disclosure. | 7.8 |
2022-12-30 | CVE-2022-42255 | Nvidia | Improper Validation of Array Index vulnerability in Nvidia Cloud Gaming and Virtual GPU NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, information disclosure, or data tampering. | 7.8 |
2022-12-30 | CVE-2022-42256 | Nvidia | Integer Overflow or Wraparound vulnerability in Nvidia Cloud Gaming and Virtual GPU NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow in index validation may lead to denial of service, information disclosure, or data tampering. | 7.8 |
2022-12-30 | CVE-2022-42260 | Nvidia | Unspecified vulnerability in Nvidia Cloud Gaming, GPU Display Driver and Virtual GPU NVIDIA vGPU Display Driver for Linux guest contains a vulnerability in a D-Bus configuration file, where an unauthorized user in the guest VM can impact protected D-Bus endpoints, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering. | 7.8 |
2022-12-30 | CVE-2022-42261 | Nvidia | Classic Buffer Overflow vulnerability in Nvidia Cloud Gaming, GPU Display Driver and Virtual GPU NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer overrun, which in turn may cause data tampering, information disclosure, or denial of service. | 7.8 |
2022-12-30 | CVE-2022-42262 | Nvidia | Classic Buffer Overflow vulnerability in Nvidia Cloud Gaming, GPU Display Driver and Virtual GPU NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer overrun, which in turn may cause data tampering, information disclosure, or denial of service. | 7.8 |
2022-12-30 | CVE-2022-42264 | Nvidia | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Nvidia Cloud Gaming, GPU Display Driver and Virtual GPU NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause the use of an out-of-range pointer offset, which may lead to data tampering, data loss, information disclosure, or denial of service. | 7.8 |
2022-12-30 | CVE-2022-42267 | Nvidia | Out-of-bounds Read vulnerability in Nvidia Virtual GPU NVIDIA GPU Display Driver for Windows contains a vulnerability where a regular user can cause an out-of-bounds read, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering. | 7.8 |
2022-12-30 | CVE-2022-42270 | Nvidia | Out-of-bounds Write vulnerability in Nvidia Jetson Linux NVIDIA distributions of Linux contain a vulnerability in nvdla_emu_task_submit, where unvalidated input may allow a local attacker to cause stack-based buffer overflow in kernel code, which may lead to escalation of privileges, compromised integrity and confidentiality, and denial of service. | 7.8 |
2022-12-30 | CVE-2022-4856 | Modbustools | Classic Buffer Overflow vulnerability in Modbustools Modbus Slave A vulnerability has been found in Modbus Tools Modbus Slave up to 7.5.1 and classified as critical. | 7.8 |
2022-12-30 | CVE-2022-4857 | Modbustools | Classic Buffer Overflow vulnerability in Modbustools Modbus Poll A vulnerability was found in Modbus Tools Modbus Poll up to 9.10.0 and classified as critical. | 7.8 |
2022-12-29 | CVE-2022-4780 | Elvexys | Use of Hard-coded Credentials vulnerability in Elvexys Isos Firmware ISOS firmwares from versions 1.81 to 2.00 contain hardcoded credentials from embedded StreamX installer that integrators are not forced to change. | 7.8 |
2022-12-28 | CVE-2022-4817 | Jgit Cookbook Project | Exposure of Resource to Wrong Sphere vulnerability in Jgit-Cookbook Project Jgit-Cookbook A vulnerability was found in centic9 jgit-cookbook. | 7.8 |
2022-12-28 | CVE-2022-44564 | Huawei Aslan Children's Watch has a path traversal vulnerability. | 7.8 | |
2022-12-28 | CVE-2022-46179 | Liuos Project | Authorization Bypass Through User-Controlled Key vulnerability in Liuos Project Liuos 0.1.0 LiuOS is a small Python project meant to imitate the functions of a regular operating system. | 7.8 |
2022-12-27 | CVE-2022-4772 | A vulnerability was found in Widoco and classified as critical. | 7.8 | |
2022-12-27 | CVE-2022-3156 | Rockwellautomation | Improper Authentication vulnerability in Rockwellautomation Studio 5000 Logix Emulate A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software. | 7.8 |
2022-12-26 | CVE-2019-19705 | Lenovo | Unquoted Search Path or Element vulnerability in Lenovo products Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles DLL preloading. | 7.8 |
2022-12-26 | CVE-2022-30260 | Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). | 7.8 | |
2023-01-01 | CVE-2023-22551 | FTP Project | Unspecified vulnerability in FTP Project FTP The FTP (aka "Implementation of a simple FTP client and server") project through 96c1a35 allows remote attackers to cause a denial of service (memory consumption) by engaging in client activity, such as establishing and then terminating a connection. | 7.5 |
2023-01-01 | CVE-2013-10006 | Ziftrshop | Information Exposure Through Discrepancy vulnerability in Ziftrshop Primecoin 0.8.4 A vulnerability classified as problematic was found in Ziftr primecoin up to 0.8.4rc1. | 7.5 |
2023-01-01 | CVE-2023-0029 | Multilaserempresas | Unspecified vulnerability in Multilaserempresas Re708 Firmware Re1200R4Gc2T2Rv3V3411Bmul029B A vulnerability was found in Multilaser RE708 RE1200R4GC-2T2R-V3_v3411b_MUL029B. | 7.5 |
2023-01-01 | CVE-2018-25062 | Elementalx | Improper Resource Shutdown or Release vulnerability in Elementalx A vulnerability classified as problematic has been found in flar2 ElementalX up to 6.x. | 7.5 |
2023-01-01 | CVE-2022-37785 | Wecube Platform Project | Cleartext Storage of Sensitive Information vulnerability in Wecube-Platform Project Wecube-Platform 3.2.2 An issue was discovered in WeCube Platform 3.2.2. | 7.5 |
2022-12-31 | CVE-2018-25061 | Rgb2Hex Project | Unspecified vulnerability in Rgb2Hex Project Rgb2Hex A vulnerability was found in rgb2hex up to 0.1.5. | 7.5 |
2022-12-30 | CVE-2017-20154 | Phoenixcoin Project | Improper Resource Shutdown or Release vulnerability in Phoenixcoin Project Phoenixcoin A vulnerability was found in ghostlander Phoenixcoin. | 7.5 |
2022-12-30 | CVE-2022-47116 | Tenda | Out-of-bounds Write vulnerability in Tenda A15 Firmware 15.13.07.13 Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the SYSPS parameter at /goform/SysToolChangePwd. | 7.5 |
2022-12-30 | CVE-2017-20152 | Imageserve Project | Path Traversal vulnerability in Imageserve Project Imageserve A vulnerability, which was classified as problematic, was found in aerouk imageserve. | 7.5 |
2022-12-30 | CVE-2018-25060 | GO Macaron | Missing Encryption of Sensitive Data vulnerability in Go-Macaron CSRF A vulnerability was found in Macaron csrf and classified as problematic. | 7.5 |
2022-12-30 | CVE-2022-4858 | M Files | Information Exposure Through Log Files vulnerability in M-Files Server 22.2.11051.0 Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set. | 7.5 |
2022-12-29 | CVE-2022-38203 | Esri | Server-Side Request Forgery (SSRF) vulnerability in Esri Portal for Arcgis Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8.1 and below were not fully honored and may allow a remote, unauthenticated attacker to forge requests to arbitrary URLs from the system, potentially leading to network enumeration or reading from hosts inside the network perimeter, a different issue than CVE-2022-38211 and CVE-2022-38212. | 7.5 |
2022-12-29 | CVE-2022-38205 | In some non-default installations of Esri Portal for ArcGIS versions 10.9.1 and below, a directory traversal issue may allow a remote, unauthenticated attacker to traverse the file system and lead to the disclosure of sensitive data (not customer-published content). | 7.5 | |
2022-12-29 | CVE-2022-38211 | Esri | Server-Side Request Forgery (SSRF) vulnerability in Esri Portal for Arcgis Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.9.1 and below were not fully honored and may allow a remote, unauthenticated attacker to forge requests to arbitrary URLs from the system, potentially leading to network enumeration or reading from hosts inside the network perimeter, a different issue than CVE-2022-38211 and CVE-2022-38212. | 7.5 |
2022-12-29 | CVE-2022-38212 | Esri | Server-Side Request Forgery (SSRF) vulnerability in Esri Portal for Arcgis Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8.1 and below were not fully honored and may allow a remote, unauthenticated attacker to forge requests to arbitrary URLs from the system, potentially leading to network enumeration or reading from hosts inside the network perimeter, a different issue than CVE-2022-38211 and CVE-2022-38203. | 7.5 |
2022-12-29 | CVE-2022-4843 | NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.8.2. | 7.5 | |
2022-12-28 | CVE-2022-23553 | Alpine Project | Incorrect Authorization vulnerability in Alpine Project Alpine Alpine is a scaffolding library in Java. | 7.5 |
2022-12-28 | CVE-2022-39012 | Huawei Aslan Children's Watch has an improper input validation vulnerability. | 7.5 | |
2022-12-28 | CVE-2022-38202 | Esri | Path Traversal vulnerability in Esri Arcgis Server There is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and below. | 7.5 |
2022-12-28 | CVE-2020-36562 | DHT Project | Reachable Assertion vulnerability in DHT Project DHT Due to unchecked type assertions, maliciously crafted messages can cause panics, which may be used as a denial of service vector. | 7.5 |
2022-12-28 | CVE-2022-3347 | GO Resolver Project | Insufficient Verification of Data Authenticity vulnerability in Go-Resolver Project Go-Resolver DNSSEC validation is not performed correctly. | 7.5 |
2022-12-28 | CVE-2022-41966 | Xstream Project | Stack-based Buffer Overflow vulnerability in Xstream Project Xstream XStream serializes Java objects to XML and back again. | 7.5 |
2022-12-28 | CVE-2022-41967 | Hypera | XXE vulnerability in Hypera Dragonfly 0.3.0Snapshot Dragonfly is a Java runtime dependency management library. | 7.5 |
2022-12-27 | CVE-2013-10005 | Socks5 Project | Infinite Loop vulnerability in Socks5 Project Socks5 The RemoteAddr and LocalAddr methods on the returned net.Conn may call themselves, leading to an infinite loop which will crash the program due to a stack overflow. | 7.5 |
2022-12-27 | CVE-2015-10004 | Json WEB Token Project | Exposure of Resource to Wrong Sphere vulnerability in Json web Token Project Json web Token Token validation methods are susceptible to a timing side-channel during HMAC comparison. | 7.5 |
2022-12-27 | CVE-2019-25072 | Tendermint | Resource Exhaustion vulnerability in Tendermint Due to support of Gzip compression in request bodies, as well as a lack of limiting response body sizes, a malicious server can cause a client to consume a significant amount of system resources, which may be used as a denial of service vector. | 7.5 |
2022-12-27 | CVE-2019-25073 | GOA Design | Path Traversal vulnerability in Goa.Design GOA Improper path santiziation in github.com/goadesign/goa before v3.0.9, v2.0.10, or v1.4.3 allow remote attackers to read files outside of the intended directory. | 7.5 |
2022-12-27 | CVE-2020-36559 | Aahframework | Path Traversal vulnerability in Aahframework AAH Due to improper santization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read. | 7.5 |
2022-12-27 | CVE-2020-36564 | Due to improper validation of caller input, validation is silently disabled if the provided expected token is malformed, causing any user supplied token to be considered valid. | 7.5 | |
2022-12-27 | CVE-2020-36568 | Unsanitized input in the query parser in github.com/revel/revel before v1.0.0 allows remote attackers to cause resource exhaustion via memory allocation. | 7.5 | |
2022-12-27 | CVE-2021-4239 | Noiseprotocol | Missing Encryption of Sensitive Data vulnerability in Noiseprotocol Noise The Noise protocol implementation suffers from weakened cryptographic security after encrypting 2^64 messages, and a potential denial of service attack. | 7.5 |
2022-12-27 | CVE-2022-2584 | Protocol | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Protocol Go-Codec-Dagpb The dag-pb codec can panic when decoding invalid blocks. | 7.5 |
2022-12-27 | CVE-2022-3064 | Yaml Project | Resource Exhaustion vulnerability in Yaml Project Yaml Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory. | 7.5 |
2022-12-27 | CVE-2020-36567 | GIN Gonic | Improper Encoding or Escaping of Output vulnerability in Gin-Gonic GIN Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbitrary log lines. | 7.5 |
2022-12-27 | CVE-2022-45423 | Dahuasecurity | Insufficiently Protected Credentials vulnerability in Dahuasecurity products Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials. | 7.5 |
2022-12-27 | CVE-2022-45425 | Dahuasecurity | Use of Hard-coded Credentials vulnerability in Dahuasecurity products Some Dahua software products have a vulnerability of using of hard-coded cryptographic key. | 7.5 |
2022-12-27 | CVE-2022-45429 | Dahuasecurity | Server-Side Request Forgery (SSRF) vulnerability in Dahuasecurity products Some Dahua software products have a vulnerability of server-side request forgery (SSRF). | 7.5 |
2022-12-27 | CVE-2022-45431 | Dahuasecurity | Improper Authentication vulnerability in Dahuasecurity products Some Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. | 7.5 |
2022-12-27 | CVE-2022-4767 | Denial of Service in GitHub repository usememos/memos prior to 0.9.1. | 7.5 | |
2022-12-27 | CVE-2019-25089 | Muon Project | Use of Insufficiently Random Values vulnerability in Muon Project Muon 0.1.1 A vulnerability has been found in Morgawr Muon 0.1.1 and classified as problematic. | 7.5 |
2022-12-27 | CVE-2021-4286 | Pysrp Project | Information Exposure Through Discrepancy vulnerability in Pysrp Project Pysrp A vulnerability, which was classified as problematic, has been found in cocagne pysrp up to 1.0.16. | 7.5 |
2022-12-27 | CVE-2015-10005 | A vulnerability was found in markdown-it up to 2.x. | 7.5 | |
2022-12-27 | CVE-2018-25049 | Email Existence Project | Unspecified vulnerability in Email-Existence Project Email-Existence A vulnerability was found in email-existence. | 7.5 |
2022-12-27 | CVE-2019-25087 | Httpserver Project | Path Traversal vulnerability in Httpserver Project Httpserver A vulnerability was found in RamseyK httpserver. | 7.5 |
2022-12-26 | CVE-2020-12067 | In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password. | 7.5 | |
2022-12-26 | CVE-2022-4156 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the user_id POST parameter before concatenating it to an SQL query in ajax-functions-backend.php. | 7.5 | |
2022-12-26 | CVE-2022-4158 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_Fields POST parameter before concatenating it to an SQL query in users-registry-check-registering-and-login.php. | 7.5 | |
2022-12-26 | CVE-2021-35065 | Gulpjs | Unspecified vulnerability in Gulpjs Glob-Parent 6.0.0 The glob-parent package before 6.0.1 for Node.js allows ReDoS (regular expression denial of service) attacks against the enclosure regular expression. | 7.5 |
2022-12-26 | CVE-2021-35951 | Fastrack | Unspecified vulnerability in Fastrack Reflex 2.0 Firmware 90.89 fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows an Unauthenticated Remote attacker to send a malicious firmware update via BLE and brick the device. | 7.5 |
2022-12-26 | CVE-2021-35953 | Fastrack | Unspecified vulnerability in Fastrack Reflex 2.0 Firmware 90.89 fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows a Remote attacker to cause a Denial of Service (device outage) via crafted choices of the last three bytes of a characteristic value. | 7.5 |
2022-12-26 | CVE-2021-38561 | golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. | 7.5 | |
2022-12-26 | CVE-2022-26964 | Weak password derivation for export in Devolutions Remote Desktop Manager before 2022.1 allows information disclosure via a password brute-force attack. | 7.5 | |
2022-12-26 | CVE-2021-44758 | Heimdal Project | NULL Pointer Dereference vulnerability in Heimdal Project Heimdal Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_response value to send_accept. | 7.5 |
2022-12-30 | CVE-2022-34673 | Nvidia | Out-of-bounds Read vulnerability in Nvidia GPU Display Driver NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, information disclosure, or data tampering. | 7.3 |
2022-12-30 | CVE-2022-42257 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to information disclosure, data tampering or denial of service. | 7.3 | |
2022-12-30 | CVE-2022-42258 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of service, data tampering, or information disclosure. | 7.3 | |
2022-12-30 | CVE-2022-44137 | Sanitization Management System Project | SQL Injection vulnerability in Sanitization Management System Project Sanitization Management System 1.0 SourceCodester Sanitization Management System 1.0 is vulnerable to SQL Injection. | 7.2 |
2022-12-27 | CVE-2022-45427 | Dahuasecurity | Unrestricted Upload of File with Dangerous Type vulnerability in Dahuasecurity products Some Dahua software products have a vulnerability of unrestricted upload of file. | 7.2 |
2022-12-27 | CVE-2022-4722 | Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5. | 7.2 | |
2022-12-27 | CVE-2022-4732 | Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2. | 7.2 | |
2022-12-26 | CVE-2021-24942 | The Menu Item Visibility Control WordPress plugin through 0.5 doesn't sanitize and validate the "Visibility logic" option for WordPress menu items, which could allow highly privileged users to execute arbitrary PHP code even in a hardened environment. | 7.2 | |
2022-12-26 | CVE-2022-4268 | Plugin Logic Project | SQL Injection vulnerability in Plugin Logic Project Plugin Logic The Plugin Logic WordPress plugin before 1.0.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin | 7.2 |
2022-12-30 | CVE-2022-34677 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause an integer to be truncated, which may lead to denial of service or data tampering. | 7.1 | |
2022-12-30 | CVE-2022-34684 | Nvidia | Off-by-one Error vulnerability in Nvidia Cloud Gaming, GPU Display Driver and Virtual GPU NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an off-by-one error may lead to data tampering or information disclosure. | 7.1 |
2022-12-30 | CVE-2022-42263 | Nvidia | Integer Overflow or Wraparound vulnerability in Nvidia Cloud Gaming, GPU Display Driver and Virtual GPU NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an Integer overflow may lead to denial of service or information disclosure. | 7.1 |
2022-12-30 | CVE-2022-42265 | Nvidia | Integer Overflow or Wraparound vulnerability in Nvidia GPU Display Driver NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to information disclosure or data tampering. | 7.1 |
190 Medium Vulnerabilities
7 Low Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2022-12-27 | CVE-2022-2583 | A race condition can cause incorrect HTTP request routing. | 3.7 | |
2022-12-27 | CVE-2022-45430 | Dahuasecurity | Improper Authentication vulnerability in Dahuasecurity products Some Dahua software products have a vulnerability of unauthenticated enable or disable SSHD service. | 3.7 |
2022-12-27 | CVE-2022-45433 | Dahuasecurity | Improper Authentication vulnerability in Dahuasecurity products Some Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. | 3.7 |
2023-01-01 | CVE-2022-47952 | Linuxcontainers | Exposure of Resource to Wrong Sphere vulnerability in Linuxcontainers LXC lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "does not refer to a network namespace path" often indicates that a file exists. | 3.3 |
2022-12-30 | CVE-2022-42266 | Nvidia | Information Exposure vulnerability in Nvidia Cloud Gaming and Virtual GPU NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can cause exposure of sensitive information to an actor that is not explicitly authorized to have access to that information, which may lead to limited information disclosure. | 3.3 |
2022-12-28 | CVE-2022-4773 | Cloudsync Project | Path Traversal vulnerability in Cloudsync Project Cloudsync ** UNSUPPPORTED WHEN ASSIGNED **** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in cloudsync. | 3.3 |
2022-12-27 | CVE-2022-45428 | Dahuasecurity | Unspecified vulnerability in Dahuasecurity products Some Dahua software products have a vulnerability of sensitive information leakage. | 2.7 |