Common Vulnerabilities and Exposures (CVE) is a critical tool for maintaining software security, providing a standardized way to track and manage vulnerabilities across systems. Organizations should regularly monitor CVE databases, assess the impact of vulnerabilities, and apply patches promptly to reduce the risk of exploitation.
CVE (Common Vulnerabilities and Exposures) is a public database that provides a standardized method for identifying, tracking, and referencing publicly disclosed security vulnerabilities in software and hardware.
Each vulnerability receives a unique identifier called a CVE ID (e.g., CVE-2023-12345), making it easier to reference specific vulnerabilities across different tools and databases.
Total Search Results: 158437
CVE ID | Description | Severity | Published Date | Affected Vendor | Action |
---|---|---|---|---|---|
CVE-2022-35068 | OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e420d. | Unknown | N/A | n/a | |
CVE-2022-35069 | OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b544e. | Unknown | N/A | n/a | |
CVE-2022-35070 | OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x65fc97. | Unknown | N/A | n/a | |
CVE-2022-35080 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_load at /lib/png.c. | Unknown | N/A | n/a | |
CVE-2022-35081 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_read_header at /src/png2swf.c. | Unknown | N/A | n/a | |
CVE-2022-35085 | SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c. | Unknown | N/A | n/a | |
CVE-2022-35086 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S. | Unknown | N/A | n/a | |
CVE-2022-35087 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via MovieAddFrame at /src/gif2swf.c. | Unknown | N/A | n/a | |
CVE-2022-35088 | SWFTools commit 772e55a2 was discovered to contain a heap buffer-overflow via getGifDelayTime at /home/bupt/Desktop/swftools/src/src/gif2swf.c. | Unknown | N/A | n/a | |
CVE-2022-35089 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer-overflow via getTransparentColor at /home/bupt/Desktop/swftools/src/gif2swf. | Unknown | N/A | n/a | |
CVE-2022-3509 | A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above. | Unknown | N/A | ||
CVE-2022-35090 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via __asan_memcpy at /asan/asan_interceptors_memintrinsics.cpp:. | Unknown | N/A | n/a | |
CVE-2022-35091 | SWFTools commit 772e55a2 was discovered to contain a floating point exception (FPE) via DCTStream::readMCURow() at /xpdf/Stream.cc.ow() | Unknown | N/A | n/a | |
CVE-2022-35092 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via convert_gfxline at /gfxpoly/convert.c. | Unknown | N/A | n/a | |
CVE-2022-35093 | SWFTools commit 772e55a2 was discovered to contain a global buffer overflow via DCTStream::transformDataUnit at /xpdf/Stream.cc. | Unknown | N/A | n/a | |
CVE-2022-35094 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/Stream.cc. | Unknown | N/A | n/a | |
CVE-2022-35095 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via InfoOutputDev::type3D1 at /pdf/InfoOutputDev.cc. | Unknown | N/A | n/a | |
CVE-2022-35096 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via draw_stroke at /gfxpoly/stroke.c. | Unknown | N/A | n/a | |
CVE-2022-35097 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via FoFiTrueType::writeTTF at /xpdf/FoFiTrueType.cc. | Unknown | N/A | n/a | |
CVE-2022-35098 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via GfxICCBasedColorSpace::getDefaultColor(GfxColor*) at /xpdf/GfxState.cc. | Unknown | N/A | n/a | |
CVE-2022-35099 | SWFTools commit 772e55a2 was discovered to contain a stack overflow via ImageStream::getPixel(unsigned char*) at /xpdf/Stream.cc. | Unknown | N/A | n/a | |
CVE-2022-3510 | A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above. | Unknown | N/A | ||
CVE-2022-35100 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via gfxline_getbbox at /lib/gfxtools.c. | Unknown | N/A | n/a | |
CVE-2022-35101 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via /multiarch/memset-vec-unaligned-erms.S. | Unknown | N/A | n/a | |
CVE-2022-35104 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via DCTStream::reset() at /xpdf/Stream.cc. | Unknown | N/A | n/a | |
CVE-2022-35105 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via /bin/png2swf+0x552cea. | Unknown | N/A | n/a | |
CVE-2022-35106 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via FoFiTrueType::computeTableChecksum(unsigned char*, int) at /xpdf/FoFiTrueType.cc. | Unknown | N/A | n/a | |
CVE-2022-35107 | SWFTools commit 772e55a2 was discovered to contain a stack overflow via vfprintf at /stdio-common/vfprintf.c. | Unknown | N/A | n/a | |
CVE-2022-35108 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via DCTStream::getChar() at /xpdf/Stream.cc. | Unknown | N/A | n/a | |
CVE-2022-35109 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via draw_stroke at /gfxpoly/stroke.c. | Unknown | N/A | n/a | |
CVE-2022-3511 | The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded belongs to the user making the request, allowing a low privileged user, such as subscriber to download arbitrary exported tickets via an IDOR vector | Unknown | N/A | Unknown | |
CVE-2022-35110 | SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c. | Unknown | N/A | n/a | |
CVE-2022-35111 | SWFTools commit 772e55a2 was discovered to contain a stack overflow via __sanitizer::StackDepotNode::hash(__sanitizer::StackTrace const&) at /sanitizer_common/sanitizer_stackdepot.cpp. | Unknown | N/A | n/a | |
CVE-2022-35113 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via swf_DefineLosslessBitsTagToImage at /modules/swfbits.c. | Unknown | N/A | n/a | |
CVE-2022-35114 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via extractFrame at /readers/swf.c. | Unknown | N/A | n/a | |
CVE-2022-35115 | IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /webmail/server/webmail.php. | Unknown | N/A | n/a | |
CVE-2022-35117 | Clinic's Patient Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via update_medicine_details.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Packing text box under the Update Medical Details module. | Unknown | N/A | n/a | |
CVE-2022-35118 | PyroCMS v3.9 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities. | Unknown | N/A | n/a | |
CVE-2022-3512 | Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" feature resulting in Zero Trust policies not being enforced on an affected endpoint. | Unknown | N/A | Cloudflare | |
CVE-2022-35120 | IXPdata EasyInstall 6.6.14725 contains an access control issue. | Unknown | N/A | n/a | |
CVE-2022-35121 | Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java. | Unknown | N/A | n/a | |
CVE-2022-35122 | An access control issue in Ecowitt GW1100 Series Weather Stations <=GW1100B_v2.1.5 allows unauthenticated attackers to access sensitive information including device and local WiFi passwords. | Unknown | N/A | n/a | |
CVE-2022-3513 | An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A specially crafted payload could lead to a reflected XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims on self-hosted instances running without strict CSP. | Unknown | N/A | GitLab | |
CVE-2022-35131 | Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles. | Unknown | N/A | n/a | |
CVE-2022-35132 | Usermin through 1.850 allows a remote authenticated user to execute OS commands via command injection in a filename for the GPG module. | Unknown | N/A | n/a | |
CVE-2022-35133 | A cross-site scripting (XSS) vulnerability in CherryTree v0.99.30 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field when creating a node. | Unknown | N/A | n/a | |
CVE-2022-35134 | Boodskap IoT Platform v4.4.9-02 contains a cross-site scripting (XSS) vulnerability. | Unknown | N/A | n/a | |
CVE-2022-35135 | Boodskap IoT Platform v4.4.9-02 allows attackers to escalate privileges via a crafted request sent to /api/user/upsert/ |
Unknown | N/A | n/a | |
CVE-2022-35136 | Boodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests. | Unknown | N/A | n/a | |
CVE-2022-35137 | DGIOT Lightweight industrial IoT v4.5.4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities. | Unknown | N/A | n/a | |
CVE-2022-3514 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 6.6 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in the submodule URL parser. | Unknown | N/A | GitLab | |
CVE-2022-35142 | An issue in Renato v0.17.0 allows attackers to cause a Denial of Service (DoS) via a crafted payload injected into the Search parameter. | Unknown | N/A | n/a | |
CVE-2022-35143 | Renato v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks. | Unknown | N/A | n/a | |
CVE-2022-35144 | Renato v0.17.0 was discovered to contain a cross-site scripting (XSS) vulnerability. | Unknown | N/A | n/a | |
CVE-2022-35147 | DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request. | Unknown | N/A | n/a | |
CVE-2022-35148 | maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html. | Unknown | N/A | n/a | |
CVE-2022-3515 | A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment. | Unknown | N/A | n/a | |
CVE-2022-35150 | Baijicms v4 was discovered to contain an arbitrary file upload vulnerability. | Unknown | N/A | n/a | |
CVE-2022-35151 | kkFileView v4.1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the urls and currentUrl parameters at /controller/OnlinePreviewController.java. | Unknown | N/A | n/a | |
CVE-2022-35153 | FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php. | Unknown | N/A | n/a | |
CVE-2022-35154 | Shopro Mall System v1.3.8 was discovered to contain a SQL injection vulnerability via the value parameter. | Unknown | N/A | n/a | |
CVE-2022-35155 | Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the searchdata parameter. | Unknown | N/A | n/a | |
CVE-2022-35156 | Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php.. | Unknown | N/A | n/a | |
CVE-2022-35158 | A vulnerability in the lua parser of TscanCode tsclua v2.15.01 allows attackers to cause a Denial of Service (DoS) via a crafted lua script. | Unknown | N/A | n/a | |
CVE-2022-3516 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. | Unknown | N/A | librenms | |
CVE-2022-35161 | GVRET Stable Release as of Aug 15, 2015 was discovered to contain a buffer overflow via the handleConfigCmd function at SerialConsole.cpp. | Unknown | N/A | n/a | |
CVE-2022-35162 | Complete Online Job Search System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the CATEGORY parameter at /category/controller.php?action=edit. | Unknown | N/A | n/a | |
CVE-2022-35163 | Complete Online Job Search System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the U_NAME parameter at /category/controller.php?action=edit. | Unknown | N/A | n/a | |
CVE-2022-35164 | LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via bit_copy_chain. | Unknown | N/A | n/a | |
CVE-2022-35165 | An issue in AP4_SgpdAtom::AP4_SgpdAtom() of Bento4-1.6.0-639 allows attackers to cause a Denial of Service (DoS) via a crafted mp4 input. | Unknown | N/A | n/a | |
CVE-2022-35166 | libjpeg commit 842c7ba was discovered to contain an infinite loop via the component JPEG::ReadInternal. | Unknown | N/A | n/a | |
CVE-2022-35167 | Printix Cloud Print Management v1.3.1149.0 for Windows was discovered to contain insecure permissions. | Unknown | N/A | n/a | |
CVE-2022-35168 | Due to improper input sanitization of XML input in SAP Business One - version 10.0, an attacker can perform a denial-of-service attack rendering the system temporarily inoperative. | Unknown | N/A | SAP SE | |
CVE-2022-35169 | SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege to read and decrypt LCMBIAR file's password under certain conditions, enabling the attacker to modify the password or import the file into another system causing high impact on confidentiality but a limited impact on the availability and integrity of the application. | Unknown | N/A | SAP SE | |
CVE-2022-3517 | A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service. | Unknown | N/A | n/a | |
CVE-2022-35170 | SAP NetWeaver Enterprise Portal does - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. This leads to limited impact on confidentiality and integrity of data. | Unknown | N/A | SAP SE | |
CVE-2022-35171 | When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below | Unknown | N/A | SAP SE | |
CVE-2022-35172 | SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability. | Unknown | N/A | SAP SE | |
CVE-2022-35173 | An issue was discovered in Nginx NJS v0.7.5. The JUMP offset for a break instruction was not set to a correct offset during code generation, leading to a segmentation violation. | Unknown | N/A | n/a | |
CVE-2022-35174 | A stored cross-site scripting (XSS) vulnerability in Kirby's Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tags field. | Unknown | N/A | n/a | |
CVE-2022-35175 | Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /blotter/blotter.php. | Unknown | N/A | n/a | |
CVE-2022-3518 | A vulnerability classified as problematic has been found in SourceCodester Sanitization Management System 1.0. Affected is an unknown function of the component User Creation Handler. The manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting. It is possible to launch the attack remotely. VDB-211014 is the identifier assigned to this vulnerability. | Unknown | N/A | SourceCodester | |
CVE-2022-3519 | A vulnerability classified as problematic was found in SourceCodester Sanitization Management System 1.0. Affected by this vulnerability is an unknown functionality of the component Quote Requests Tab. The manipulation of the argument Manage Remarks leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-211015. | Unknown | N/A | SourceCodester | |
CVE-2022-35191 | D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted HTTP connection request. | Unknown | N/A | n/a | |
CVE-2022-35192 | D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via the User parameter or Pwd parameter to Login.asp. | Unknown | N/A | n/a | |
CVE-2022-35193 | TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php. | Unknown | N/A | n/a | |
CVE-2022-35194 | TestLink v1.9.20 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /lib/inventory/inventoryView.php. | Unknown | N/A | n/a | |
CVE-2022-35195 | TestLink 1.9.20 Raijin was discovered to contain a broken access control vulnerability at /lib/attachments/attachmentdownload.php | Unknown | N/A | n/a | |
CVE-2022-35196 | TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php. | Unknown | N/A | n/a | |
CVE-2022-35198 | Contract Management System v2.0 contains a weak default password which gives attackers to access database connection information. | Unknown | N/A | n/a | |
CVE-2022-3520 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765. | Unknown | N/A | vim | |
CVE-2022-35201 | Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability. | Unknown | N/A | n/a | |
CVE-2022-35203 | An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system information. | Unknown | N/A | n/a | |
CVE-2022-35204 | Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service. | Unknown | N/A | n/a | |
CVE-2022-35205 | An issue was discovered in Binutils readelf 2.38.50, reachable assertion failure in function display_debug_names allows attackers to cause a denial of service. | Unknown | N/A | n/a | |
CVE-2022-35206 | Null pointer dereference vulnerability in Binutils readelf 2.38.50 via function read_and_display_attr_value in file dwarf.c. | Unknown | N/A | n/a | |
CVE-2022-3521 | A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function kcm_tx_work of the file net/kcm/kcmsock.c of the component kcm. The manipulation leads to race condition. It is recommended to apply a patch to fix this issue. VDB-211018 is the identifier assigned to this vulnerability. | Unknown | N/A | Linux | |
CVE-2022-35212 | osCommerce2 before v2.3.4.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the function tep_db_error(). | Unknown | N/A | n/a | |
CVE-2022-35213 | Ecommerce-CodeIgniter-Bootstrap before commit 56465f was discovered to contain a cross-site scripting (XSS) vulnerability via the function base_url() at /blog/blogpublish.php. | Unknown | N/A | n/a | |
CVE-2022-35216 | OMICARD EDM’s mail image relay function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to by-pass authentication and access arbitrary system files. | Unknown | N/A | ITPison |
vunerability-insight.com © 2023 - 2025. All Rights Reserved.
Vulnerability Data Repositories v