Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-35120 | 1 Ixpdata | 1 Easyinstall | 2022-12-06 | N/A | 8.8 HIGH |
IXPdata EasyInstall 6.6.14725 contains an access control issue. | |||||
CVE-2022-45045 | 1 Xiongmaitech | 144 Mbd6304t, Mbd6304t Firmware, Nbd6808t-pl and 141 more | 2022-12-06 | N/A | 8.8 HIGH |
Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow authenticated users to execute arbitrary commands as root, as exploited in the wild starting in approximately 2019. A remote and authenticated attacker, possibly using the default admin:tlJwpbo6 credentials, can connect to port 34567 and execute arbitrary operating system commands via a crafted JSON file during an upgrade request. Since at least 2021, Xiongmai has applied patches to prevent attackers from using this mechanism to execute telnetd. | |||||
CVE-2022-23746 | 1 Checkpoint | 1 Ssl Network Extender | 2022-12-06 | N/A | 7.5 HIGH |
The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the portal is configured for username/password authentication, it is vulnerable to a brute-force attack on usernames and passwords. | |||||
CVE-2022-42718 | 1 Ni | 1 Labview Command Line Interface | 2022-12-06 | N/A | 7.8 HIGH |
Incorrect default permissions in the installation folder for NI LabVIEW Command Line Interface (CLI) may allow an authenticated user to potentially enable escalation of privilege via local access. | |||||
CVE-2022-44037 | 1 Apsystems | 2 Ecu-c, Ecu-c Firmware | 2022-12-06 | N/A | 8.8 HIGH |
An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V4.1SAA, C1.2.2 allows attackers to access sensitive data and execute specific commands and functions with full admin rights without authenticating allows him to perform multiple attacks, such as attacking wireless network in the product's range. | |||||
CVE-2022-44211 | 1 Gl-inet | 1 Goodcloud | 2022-12-06 | N/A | 7.4 HIGH |
In GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings. | |||||
CVE-2022-44212 | 1 Gl-inet | 1 Goodcloud | 2022-12-06 | N/A | 5.9 MEDIUM |
In GL.iNet Goodcloud 1.0, insecure design allows remote attacker to access devices' admin panel. | |||||
CVE-2022-41970 | 1 Nextcloud | 1 Nextcloud Server | 2022-12-06 | N/A | 5.3 MEDIUM |
Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares still allow download through preview images. Images could be downloaded and previews of documents (first page) can be downloaded without being watermarked. Versions 24.0.7 and 25.0.1 contain a fix for this issue. No known workarounds are available. | |||||
CVE-2022-41971 | 1 Nextcloud | 1 Nextcloud Talk | 2022-12-06 | N/A | 6.5 MEDIUM |
Nextcould Talk android is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.8, 13.0.10, 14.0.6, and 15.0.0, guests can continue to receive video streams from a call after being removed from a conversation. An attacker would be able to see videos on a call in a public conversation after being removed from that conversation, provided that they were removed while being in the call. Versions 12.2.8, 13.0.10, 14.0.6, and 15.0.0 contain patches for the issue. No known workarounds are available. | |||||
CVE-2022-35730 | 1 Oceanwp | 1 Sticky Header | 2022-12-06 | N/A | 6.5 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in Oceanwp sticky header plugin <= 1.0.8 on WordPress. | |||||
CVE-2022-45824 | 1 Elbtide | 1 Advanced Booking Calendar | 2022-12-06 | N/A | 6.5 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress. | |||||
CVE-2022-45822 | 1 Elbtide | 1 Advanced Booking Calendar | 2022-12-06 | N/A | 9.8 CRITICAL |
Unauth. SQL Injection (SQLi) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress. | |||||
CVE-2022-43479 | 1 Ss-proj | 1 Shirasagi | 2022-12-06 | N/A | 6.1 MEDIUM |
Open redirect vulnerability in SHIRASAGI v1.14.4 to v1.15.0 allows a remote unauthenticated attacker to redirect users to an arbitrary web site and conduct a phishing attack. | |||||
CVE-2022-43487 | 1 Salonbookingsystem | 1 Salon Booking System | 2022-12-06 | N/A | 6.1 MEDIUM |
Cross-site scripting vulnerability in Salon booking system versions prior to 7.9 allows a remote unauthenticated attacker to inject an arbitrary script. | |||||
CVE-2022-43499 | 1 Ss-proj | 1 Shirasagi | 2022-12-06 | N/A | 5.4 MEDIUM |
Stored cross-site scripting vulnerability in SHIRASAGI versions prior to v1.16.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. | |||||
CVE-2022-4280 | 1 Dottech | 1 Smart Campus System | 2022-12-06 | N/A | 7.5 HIGH |
A vulnerability, which was classified as problematic, has been found in Dot Tech Smart Campus System. Affected by this issue is some unknown functionality of the file /services/Card/findUser. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-214778 is the identifier assigned to this vulnerability. | |||||
CVE-2022-46405 | 1 Joinmastodon | 1 Mastodon | 2022-12-06 | N/A | 7.5 HIGH |
Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attacker-controlled accounts on certain other servers associated with a wildcard DNS A record, such that there is uncontrolled recursion of attacker-generated messages. | |||||
CVE-2022-46414 | 1 Veritas | 2 Access Appliance, Netbackup Flex Scale Appliance | 2022-12-06 | N/A | 9.8 CRITICAL |
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command execution can occur via the management portal. | |||||
CVE-2022-46413 | 1 Veritas | 2 Access Appliance, Netbackup Flex Scale Appliance | 2022-12-06 | N/A | 8.8 HIGH |
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Authenticated remote command execution can occur via the management portal. | |||||
CVE-2022-46412 | 1 Veritas | 1 Netbackup Flex Scale Appliance | 2022-12-06 | N/A | 8.8 HIGH |
An issue was discovered in Veritas NetBackup Flex Scale through 3.0. A non-privileged user may escape a restricted shell and execute privileged commands. |