U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, misconfigurations, product names, and impact metrics.

For information on how to the cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2022-46413 - An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Authenticated remote command execution can occur via the management portal.
    Published: December 04, 2022; 12:15:10 AM -0500

    V3.1: 8.8 HIGH

  • CVE-2022-46412 - An issue was discovered in Veritas NetBackup Flex Scale through 3.0. A non-privileged user may escape a restricted shell and execute privileged commands.
    Published: December 04, 2022; 12:15:10 AM -0500

    V3.1: 8.8 HIGH

  • CVE-2022-46411 - An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after installation and may be discovered and used to escalate privileges.
    Published: December 04, 2022; 12:15:10 AM -0500

    V3.1: 8.8 HIGH

  • CVE-2022-46410 - An issue was discovered in Veritas NetBackup Flex Scale through 3.0. An attacker with non-root privileges may escalate privileges to root by using specific commands.
    Published: December 04, 2022; 12:15:09 AM -0500

    V3.1: 8.8 HIGH

  • CVE-2022-46391 - AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
    Published: December 03, 2022; 10:15:09 PM -0500

    V3.1: 6.1 MEDIUM

  • CVE-2022-4272 - A vulnerability, which was classified as critical, has been found in FeMiner wms. Affected by this issue is some unknown functionality of the file /product/savenewproduct.php?flag=1. The manipulation of the argument upfile leads to unrestricted up... read CVE-2022-4272
    Published: December 03, 2022; 4:15:08 AM -0500

    V3.1: 9.8 CRITICAL

  • CVE-2022-3086 - An attacker with physical access to Moxa's bootloader versions of UC-8580 Series V1.1, UC-8540 Series V1.0 to V1.2, UC-8410A Series V2.2, UC-8200 Series V1.0 to V2.4, UC-8100A-ME-T Series V1.0 to V1.1, UC-8100 Series V1.2 to V1.3, UC-5100 Series V... read CVE-2022-3086
    Published: December 02, 2022; 3:15:13 PM -0500

    V3.1: 7.6 HIGH

  • CVE-2022-2642 - Horner Automation’s RCC 972 firmware version 15.40 contains global variables. This could allow an attacker to read out sensitive values and variable keys from the device.
    Published: December 02, 2022; 3:15:13 PM -0500

    V3.1: 7.5 HIGH

  • CVE-2022-2641 - Horner Automation’s RCC 972 with firmware version 15.40 has a static encryption key on the device. This could allow an attacker to perform unauthorized changes to the device, remotely execute arbitrary code, or cause a denial-of-service condition.
    Published: December 02, 2022; 3:15:13 PM -0500

    V3.1: 9.8 CRITICAL

  • CVE-2022-2640 - The Config-files of Horner Automation’s RCC 972 with firmware version 15.40 are encrypted with weak XOR encryption vulnerable to reverse engineering. This could allow an attacker to obtain credentials to run services such as File Transfer Protocol... read CVE-2022-2640
    Published: December 02, 2022; 3:15:12 PM -0500

    V3.1: 7.5 HIGH

  • CVE-2022-46167 - Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to version 0.1.3, a ServiceAccount deployed in a Tenant Namespace, when granted with `PATCH` capabilities on its own Namespace, is able to edit it and remove the Owner Ref... read CVE-2022-46167
    Published: December 02, 2022; 2:15:11 PM -0500

    V3.1: 8.8 HIGH

  • CVE-2022-3520 - Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.
    Published: December 02, 2022; 2:15:11 PM -0500

    V3.1: 9.8 CRITICAL

  • CVE-2022-46145 - authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential account takeover. With the default flows, unauthenticated users can create new accounts in authenti... read CVE-2022-46145
    Published: December 02, 2022; 1:15:12 PM -0500

    V3.1: 9.8 CRITICAL

  • CVE-2022-4273 - A vulnerability, which was classified as critical, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the file /hrm/controller/employee.php of the component Content-Type Handler. Th... read CVE-2022-4273
    Published: December 03, 2022; 4:15:10 AM -0500

    V3.1: 9.8 CRITICAL

  • CVE-2022-4274 - A vulnerability, which was classified as critical, was found in House Rental System. Affected is an unknown function of the file /view-property.php. The manipulation of the argument property_id leads to sql injection. It is possible to launch the ... read CVE-2022-4274
    Published: December 03, 2022; 11:15:09 AM -0500

    V3.1: 9.8 CRITICAL

  • CVE-2022-4275 - A vulnerability has been found in House Rental System and classified as critical. Affected by this vulnerability is an unknown functionality of the file search-property.php of the component POST Request Handler. The manipulation of the argument se... read CVE-2022-4275
    Published: December 03, 2022; 11:15:10 AM -0500

    V3.1: 9.8 CRITICAL

  • CVE-2022-4276 - A vulnerability was found in House Rental System and classified as critical. Affected by this issue is some unknown functionality of the file tenant-engine.php of the component POST Request Handler. The manipulation of the argument id_photo leads ... read CVE-2022-4276
    Published: December 03, 2022; 11:15:10 AM -0500

    V3.1: 9.8 CRITICAL

  • CVE-2022-4277 - A vulnerability was found in Shaoxing Background Management System. It has been declared as critical. This vulnerability affects unknown code of the file /Default/Bd. The manipulation of the argument id leads to sql injection. The attack can be in... read CVE-2022-4277
    Published: December 03, 2022; 1:15:09 PM -0500

    V3.1: 9.8 CRITICAL

  • CVE-2022-4278 - A vulnerability was found in SourceCodester Human Resource Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /hrm/employeeadd.php. The manipulation of the argument empid leads to sql injec... read CVE-2022-4278
    Published: December 03, 2022; 1:15:10 PM -0500

    V3.1: 7.2 HIGH

  • CVE-2022-4279 - A vulnerability classified as problematic has been found in SourceCodester Human Resource Management System 1.0. Affected is an unknown function of the file /hrm/employeeview.php. The manipulation of the argument search leads to cross site scripti... read CVE-2022-4279
    Published: December 03, 2022; 1:15:10 PM -0500

    V3.1: 6.1 MEDIUM