Common Vulnerabilities and Exposures (CVE) is a critical tool for maintaining software security, providing a standardized way to track and manage vulnerabilities across systems. Organizations should regularly monitor CVE databases, assess the impact of vulnerabilities, and apply patches promptly to reduce the risk of exploitation.
CVE (Common Vulnerabilities and Exposures) is a public database that provides a standardized method for identifying, tracking, and referencing publicly disclosed security vulnerabilities in software and hardware.
Each vulnerability receives a unique identifier called a CVE ID (e.g., CVE-2023-12345), making it easier to reference specific vulnerabilities across different tools and databases.
Total Search Results: 158437
CVE ID | Description | Severity | Published Date | Affected Vendor | Action |
---|---|---|---|---|---|
CVE-2022-40337 | OASES (aka Open Aviation Strategic Engineering System) 8.8.0.2 allows attackers to execute arbitrary code via the Open Print Folder menu. | Unknown | N/A | n/a | |
CVE-2022-4034 | The Appointment Hour Booking Plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.72. This makes it possible for unauthenticated attackers to embed untrusted input into content during booking creation that may be exported as a CSV file when a site's administrator exports booking details. This can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration. | Unknown | N/A | codepeople | |
CVE-2022-40341 | mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PNG file. | Unknown | N/A | n/a | |
CVE-2022-40347 | SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allows attackers to execute arbitrary code and gain sensitive information. | Unknown | N/A | n/a | |
CVE-2022-40348 | Cross Site Scripting (XSS) vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'name' and 'email' parameters, allows attackers to execute arbitrary code. | Unknown | N/A | n/a | |
CVE-2022-4035 | The Appointment Hour Booking plugin for WordPress is vulnerable to iFrame Injection via the ‘email’ or general field parameters in versions up to, and including, 1.3.72 due to insufficient input sanitization and output escaping that makes injecting iFrame tags possible. This makes it possible for unauthenticated attackers to inject iFrames when submitting a booking that will execute whenever a user accesses the injected booking details page. | Unknown | N/A | codepeople | |
CVE-2022-40352 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_traveller.php. | Unknown | N/A | n/a | |
CVE-2022-40353 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/up_booking.php. | Unknown | N/A | n/a | |
CVE-2022-40354 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_booking.php. | Unknown | N/A | n/a | |
CVE-2022-40357 | A security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the zb_users/plugin/UEditor/php/action_crawler.php file allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the source parameter. | Unknown | N/A | n/a | |
CVE-2022-40358 | An issue was discovered in AjaXplorer 4.2.3, allows attackers to cause cross site scripting vulnerabilities via a crafted svg file upload. | Unknown | N/A | n/a | |
CVE-2022-40359 | Cross site scripting (XSS) vulnerability in kfm through 1.4.7 via crafted GET request to /kfm/index.php. | Unknown | N/A | n/a | |
CVE-2022-4036 | The Appointment Hour Booking plugin for WordPress is vulnerable to CAPTCHA bypass in versions up to, and including, 1.3.72. This is due to the use of insufficiently strong hashing algorithm on the CAPTCHA secret that is also displayed to the user via a cookie. | Unknown | N/A | codepeople | |
CVE-2022-40361 | Cross Site Scripting Vulnerability in Elite CRM v1.2.11 allows attacker to execute arbitrary code via the language parameter to the /ngs/login endpoint. | Unknown | N/A | n/a | |
CVE-2022-40363 | A buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 allows attackers to cause a Denial of Service (DoS) via a crafted NFC file. | Unknown | N/A | n/a | |
CVE-2022-40365 | Cross site scripting (XSS) vulnerability in ouqiang gocron through 1.5.3, allows attackers to execute arbitrary code via scope.row.hostname in web/vue/src/pages/taskLog/list.vue. | Unknown | N/A | n/a | |
CVE-2022-4037 | An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth provider. | Unknown | N/A | GitLab | |
CVE-2022-40373 | Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file. | Unknown | N/A | n/a | |
CVE-2022-4039 | A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use this interface to deploy malicious code and access and modify potentially sensitive information in the app server configuration. | Unknown | N/A | Red Hat | |
CVE-2022-40402 | Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_assign.php. | Unknown | N/A | n/a | |
CVE-2022-40403 | Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/feature_edit.php. | Unknown | N/A | n/a | |
CVE-2022-40404 | Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/select.php. | Unknown | N/A | n/a | |
CVE-2022-40405 | WoWonder Social Network Platform v4.1.2 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=load-my-blogs. | Unknown | N/A | n/a | |
CVE-2022-40407 | A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file. | Unknown | N/A | n/a | |
CVE-2022-40408 | FeehiCMS v2.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted payload injected into the Comment box under the Single Page module. | Unknown | N/A | n/a | |
CVE-2022-4041 | Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.8.0 before 04.9.1. | Unknown | N/A | Hitachi | |
CVE-2022-4042 | The Paytium: Mollie payment forms & donations WordPress plugin before 4.3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | Unknown | N/A | Unknown | |
CVE-2022-40424 | The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-networking package. The affected version of d8s-urls is 0.1.0 | Unknown | N/A | n/a | |
CVE-2022-40425 | The d8s-html for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0. | Unknown | N/A | n/a | |
CVE-2022-40426 | The d8s-asns for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0. | Unknown | N/A | n/a | |
CVE-2022-40427 | The d8s-domains for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0 | Unknown | N/A | n/a | |
CVE-2022-40428 | The d8s-mpeg for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0. | Unknown | N/A | n/a | |
CVE-2022-40429 | The d8s-ip-addresses for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0. | Unknown | N/A | n/a | |
CVE-2022-4043 | The WP Custom Admin Interface WordPress plugin before 7.29 unserialize user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present. | Unknown | N/A | Unknown | |
CVE-2022-40430 | The d8s-utility for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0. | Unknown | N/A | n/a | |
CVE-2022-40431 | The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0. | Unknown | N/A | n/a | |
CVE-2022-40432 | The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0. | Unknown | N/A | n/a | |
CVE-2022-40434 | Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page. | Unknown | N/A | n/a | |
CVE-2022-40435 | Employee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via adding new entries under the Departments and Designations module. | Unknown | N/A | n/a | |
CVE-2022-40438 | Buffer overflow vulnerability in function AP4_MemoryByteStream::WritePartial in mp42aac in Bento4 v1.6.0-639, allows attackers to cause a denial of service via a crafted file. | Unknown | N/A | n/a | |
CVE-2022-40439 | An memory leak issue was discovered in AP4_StdcFileByteStream::Create in mp42ts in Bento4 v1.6.0-639, allows attackers to cause a denial of service via a crafted file. | Unknown | N/A | n/a | |
CVE-2022-4044 | A denial-of-service vulnerability in Mattermost allows an authenticated user to crash the server via multiple large autoresponder messages. | Unknown | N/A | Mattermost | |
CVE-2022-40440 | mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function. | Unknown | N/A | n/a | |
CVE-2022-40443 | An absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GET request sent to /one/siteinfo.php. | Unknown | N/A | n/a | |
CVE-2022-40444 | ZZCMS 2022 was discovered to contain a full path disclosure vulnerability via the page /admin/index.PHP? _server. | Unknown | N/A | n/a | |
CVE-2022-40446 | ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&groupid=. | Unknown | N/A | n/a | |
CVE-2022-40447 | ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php. | Unknown | N/A | n/a | |
CVE-2022-4045 | A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple requests to one of the API endpoints which could fetch a large amount of data. | Unknown | N/A | Mattermost | |
CVE-2022-4046 | In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device. | Unknown | N/A | CODESYS | |
CVE-2022-40468 | Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier use uninitialized buffers in process_request() function. | Unknown | N/A | n/a | |
CVE-2022-40469 | iKuai OS v3.6.7 was discovered to contain an authenticated remote code execution (RCE) vulnerability. | Unknown | N/A | n/a | |
CVE-2022-4047 | The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE | Unknown | N/A | Unknown | |
CVE-2022-40470 | Phpgurukul Blood Donor Management System 1.0 allows Cross Site Scripting via Add Blood Group Name Feature. | Unknown | N/A | n/a | |
CVE-2022-40471 | Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functionality in users.php | Unknown | N/A | n/a | |
CVE-2022-40472 | ZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build: 20220721.14829 was discovered to contain a CSV injection vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the Content text field of the Add New Message module. | Unknown | N/A | n/a | |
CVE-2022-40475 | TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection via the component /cgi-bin/downloadFile.cgi. | Unknown | N/A | n/a | |
CVE-2022-40476 | A null pointer dereference issue was discovered in fs/io_uring.c in the Linux kernel before 5.15.62. A local user could use this flaw to crash the system or potentially cause a denial of service. | Unknown | N/A | n/a | |
CVE-2022-4048 | Inadequate Encryption Strength in CODESYS Development System V3 versions prior to V3.5.18.40 allows an unauthenticated local attacker to access and manipulate code of the encrypted boot application. | Unknown | N/A | CODESYS | |
CVE-2022-40480 | Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers to cause a Denial of Service (DoS) via a crafted ConReq packet. | Unknown | N/A | n/a | |
CVE-2022-40482 | The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the Illuminate\Auth\SessionGuard class when a user is found to not exist. | Unknown | N/A | n/a | |
CVE-2022-40483 | Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /wedding_details.php. | Unknown | N/A | n/a | |
CVE-2022-40484 | Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_edit.php. | Unknown | N/A | n/a | |
CVE-2022-40485 | Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /package_detail.php. | Unknown | N/A | n/a | |
CVE-2022-40486 | TP Link Archer AX10 V1 Firmware Version 1.3.1 Build 20220401 Rel. 57450(5553) was discovered to allow authenticated attackers to execute arbitrary code via a crafted backup file. | Unknown | N/A | n/a | |
CVE-2022-40487 | ProcessWire v3.0.200 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Search Users and Search Pages function. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via injection of a crafted payload. | Unknown | N/A | n/a | |
CVE-2022-40488 | ProcessWire v3.0.200 was discovered to contain a Cross-Site Request Forgery (CSRF). | Unknown | N/A | n/a | |
CVE-2022-40489 | ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrator user to be injected into administrative users. | Unknown | N/A | n/a | |
CVE-2022-4049 | The WP User WordPress plugin through 7.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users. | Unknown | N/A | Unknown | |
CVE-2022-40494 | NPS before v0.26.10 was discovered to contain an authentication bypass vulnerability via constantly generating and sending the Auth key and Timestamp parameters. | Unknown | N/A | n/a | |
CVE-2022-40497 | Wazuh v3.6.1 - v3.13.5, v4.0.0 - v4.2.7, and v4.3.0 - v4.3.7 were discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Response endpoint. | Unknown | N/A | n/a | |
CVE-2022-4050 | The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users | Unknown | N/A | Unknown | |
CVE-2022-40502 | Transient DOS due to improper input validation in WLAN Host. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40503 | Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40504 | Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40505 | Information disclosure due to buffer over-read in Modem while parsing DNS hostname. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40507 | Memory corruption due to double free in Core while mapping HLOS address to the list. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40508 | Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-4051 | A vulnerability has been found in Hostel Searching Project and classified as critical. This vulnerability affects unknown code of the file view-property.php. The manipulation of the argument property_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-213844. | Unknown | N/A | unspecified | |
CVE-2022-40510 | Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40512 | Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40513 | Transient DOS due to uncontrolled resource consumption in WLAN firmware when peer is freed in non qos state. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40514 | Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc response frame. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40515 | Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40516 | Memory corruption in Core due to stack-based buffer overflow. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40517 | Memory corruption in core due to stack-based buffer overflow | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40518 | Information disclosure due to buffer overread in Core | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40519 | Information disclosure due to buffer overread in Core | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-4052 | A vulnerability was found in Student Attendance Management System and classified as critical. This issue affects some unknown processing of the file /Admin/createClass.php. The manipulation of the argument Id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-213845 was assigned to this vulnerability. | Unknown | N/A | unspecified | |
CVE-2022-40520 | Memory corruption due to stack-based buffer overflow in Core | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40521 | Transient DOS due to improper authorization in Modem | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40522 | Memory corruption in Linux Networking due to double free while handling a hyp-assign. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40523 | Information disclosure in Kernel due to indirect branch misprediction. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40524 | Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40525 | Information disclosure in Linux Networking Firmware due to unauthorized information leak during side channel analysis. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40527 | Transient DOS due to reachable assertion in WLAN while processing PEER ID populated by TQM. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40529 | Memory corruption due to improper access control in kernel while processing a mapping request from root process. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-4053 | A vulnerability was found in Student Attendance Management System. It has been classified as problematic. Affected is an unknown function of the file createClass.php. The manipulation of the argument className leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-213846 is the identifier assigned to this vulnerability. | Unknown | N/A | unspecified | |
CVE-2022-40530 | Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40531 | Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message. | Unknown | N/A | Qualcomm, Inc. | |
CVE-2022-40532 | Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. | Unknown | N/A | Qualcomm, Inc. |
vunerability-insight.com © 2023 - 2025. All Rights Reserved.
Vulnerability Data Repositories v