Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-40799 | 1 Dlink | 2 Dnr-322l, Dnr-322l Firmware | 2022-12-01 | N/A | 8.8 HIGH |
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device. | |||||
CVE-2022-45204 | 1 Gpac | 1 Gpac | 2022-12-01 | N/A | 5.5 MEDIUM |
GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a memory leak via the function dimC_box_read at isomedia/box_code_3gpp.c. | |||||
CVE-2022-36960 | 1 Solarwinds | 1 Orion Platform | 2022-12-01 | N/A | 8.8 HIGH |
SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to escalate user privileges. | |||||
CVE-2022-45343 | 1 Gpac | 1 Gpac | 2022-12-01 | N/A | 7.8 HIGH |
GPAC v2.1-DEV-rev478-g696e6f868-master was discovered to contain a heap use-after-free via the Q_IsTypeOn function at /gpac/src/bifs/unquantize.c. | |||||
CVE-2022-45202 | 1 Gpac | 1 Gpac | 2022-12-01 | N/A | 7.8 HIGH |
GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a stack overflow via the function dimC_box_read at isomedia/box_code_3gpp.c. | |||||
CVE-2022-21126 | 1 Samtools | 1 Htsjdk | 2022-12-01 | N/A | 7.8 HIGH |
The package com.github.samtools:htsjdk before 3.0.1 are vulnerable to Creation of Temporary File in Directory with Insecure Permissions due to the createTempDir() function in util/IOUtil.java not checking for the existence of the temporary directory before attempting to create it. | |||||
CVE-2022-25848 | 1 Static-dev-server Project | 1 Static-dev-server | 2022-12-01 | N/A | 7.5 HIGH |
This affects all versions of package static-dev-server. This is because when paths from users to the root directory are joined, the assets for the path accessed are relative to that of the root directory. | |||||
CVE-2022-3747 | 1 Muffingroup | 1 Becustom | 2022-12-01 | N/A | 6.5 MEDIUM |
The Becustom plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5.2. This is due to missing nonce validation when saving the plugin's settings. This makes it possible for unauthenticated attackers to update the plugin's settings like betheme_url_slug, replaced_theme_author, and betheme_label to name a few, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
CVE-2022-3751 | 1 Owncast Project | 1 Owncast | 2022-12-01 | N/A | 9.8 CRITICAL |
SQL Injection in GitHub repository owncast/owncast prior to 0.0.13. | |||||
CVE-2022-39339 | 1 Nextcloud | 1 Openid Connect User Backend | 2022-12-01 | N/A | 4.3 MEDIUM |
user_oidc is an OpenID Connect user backend for Nextcloud. In versions prior to 1.2.1 sensitive information such as the OIDC client credentials and tokens are sent in plain text of HTTP without TLS. Any malicious actor with access to monitor user traffic may have been able to compromise account security. This issue has been addressed in in user_oidc v1.2.1. Users are advised to upgrade. Users unable to upgrade may use https to access Nextcloud. Set an HTTPS discovery URL in the provider settings (in Nextcloud OIDC admin settings). | |||||
CVE-2022-39338 | 1 Nextcloud | 1 Openid Connect User Backend | 2022-12-01 | N/A | 5.4 MEDIUM |
user_oidc is an OpenID Connect user backend for Nextcloud. Versions prior to 1.2.1 did not properly validate discovery urls which may lead to a stored cross site scripting attack vector. The impact is limited due to the restrictive CSP that is applied on this endpoint. Additionally this vulnerability has only been shown to be exploitable in the Safari web browser. This issue has been addressed in version 1.2.1. Users are advised to upgrade. Users unable to upgrade should urge their users to avoid using the Safari web browser. | |||||
CVE-2022-41957 | 2 Hummus Project, Muhammara Project | 2 Hummus, Muhammara | 2022-12-01 | N/A | 7.5 HIGH |
Muhammara is a node module with c/cpp bindings to modify PDF with JavaScript for node or electron. The package muhammara before 2.6.2 and from 3.0.0 and before 3.3.0, as well as all versions of muhammara's predecessor package hummus, are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed. The issue has been patched in muhammara version 3.4.0 and the fix has been backported to version 2.6.2. As a workaround, do not process files from untrusted sources. If using hummus, replace the package with muhammara. | |||||
CVE-2022-3384 | 1 Ultimatemember | 1 Ultimate Member | 2022-12-01 | N/A | 7.2 HIGH |
The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the populate_dropdown_options function that accepts user supplied input and passes it through call_user_func(). This is restricted to non-parameter PHP functions like phpinfo(); since user supplied parameters are not passed through the function. This makes it possible for authenticated attackers, with administrative privileges, to execute code on the server. | |||||
CVE-2022-41944 | 1 Discourse | 1 Discourse | 2022-12-01 | N/A | 4.3 MEDIUM |
Discourse is an open-source discussion platform. In stable versions prior to 2.8.12 and beta or tests-passed versions prior to 2.9.0.beta.13, under certain conditions, a user can see notifications for topics they no longer have access to. If there is sensitive information in the topic title, it will therefore have been exposed. This issue is patched in stable version 2.8.12, beta version 2.9.0.beta13, and tests-passed version 2.9.0.beta13. There are no workarounds available. | |||||
CVE-2022-3361 | 1 Ultimatemember | 1 Ultimate Member | 2022-12-01 | N/A | 4.3 MEDIUM |
The Ultimate Member plugin for WordPress is vulnerable to directory traversal in versions up to, and including 2.5.0 due to insufficient input validation on the 'template' attribute used in shortcodes. This makes it possible for attackers with administrative privileges to supply arbitrary paths using traversal (../../) to access and include files outside of the intended directory. If an attacker can successfully upload a php file then remote code execution via inclusion may also be possible. Note: for users with less than administrative capabilities, /wp-admin access needs to be enabled for that user in order for this to be exploitable by those users. | |||||
CVE-2022-44038 | 1 Russound | 2 Xsourceplayer 777d, Xsourceplayer 777d Firmware | 2022-12-01 | N/A | 9.8 CRITICAL |
Russound XSourcePlayer 777D v06.08.03 was discovered to contain a remote code execution vulnerability via the scriptRunner.cgi component. | |||||
CVE-2022-38900 | 1 Decode-uri-component Project | 1 Decode-uri-component | 2022-12-01 | N/A | 7.5 HIGH |
decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS. | |||||
CVE-2022-4020 | 1 Acer | 10 Aspire A115-21, Aspire A115-21 Firmware, Aspire A315-22 and 7 more | 2022-12-01 | N/A | 8.2 HIGH |
Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privileges to modify UEFI Secure Boot settings by modifying an NVRAM variable. | |||||
CVE-2022-41921 | 1 Discourse | 1 Discourse | 2022-12-01 | N/A | 4.3 MEDIUM |
Discourse is an open-source discussion platform. Prior to version 2.9.0.beta13, users can post chat messages of an unlimited length, which can cause a denial of service for other users when posting huge amounts of text. Users should upgrade to version 2.9.0.beta13, where a limit has been introduced. No known workarounds are available. | |||||
CVE-2022-3383 | 1 Ultimatemember | 1 Ultimate Member | 2022-12-01 | N/A | 7.2 HIGH |
The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the get_option_value_from_callback function that accepts user supplied input and passes it through call_user_func(). This makes it possible for authenticated attackers, with administrative capabilities, to execute code on the server. |