CVE-2022-45152
- EPSS 0.27%
- Veröffentlicht 25.11.2022 19:15:12
- Zuletzt bearbeitet 29.04.2025 15:15:52
A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in...
CVE-2022-39346
- EPSS 0.25%
- Veröffentlicht 25.11.2022 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:18:05
Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit user display names which could allow a malicious users to overload the backing database and cause a denial of service. It is recomm...
CVE-2022-4141
- EPSS 0.04%
- Veröffentlicht 25.11.2022 14:15:10
- Zuletzt bearbeitet 03.11.2025 21:15:55
Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.
CVE-2022-45873
- EPSS 0.03%
- Veröffentlicht 23.11.2022 23:15:10
- Zuletzt bearbeitet 25.04.2025 19:15:48
systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same fu...
CVE-2022-44789
- EPSS 2.59%
- Veröffentlicht 23.11.2022 21:15:11
- Zuletzt bearbeitet 25.04.2025 20:15:35
A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.
CVE-2022-45866
- EPSS 0.63%
- Veröffentlicht 23.11.2022 20:15:10
- Zuletzt bearbeitet 25.04.2025 19:15:47
qpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allows directory traversal via ../ in a .qp file.
CVE-2022-45149
- EPSS 0.26%
- Veröffentlicht 23.11.2022 15:15:10
- Zuletzt bearbeitet 25.04.2025 20:15:35
A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a course they have just restored. A ...
CVE-2022-45150
- EPSS 0.72%
- Veröffentlicht 23.11.2022 15:15:10
- Zuletzt bearbeitet 25.04.2025 20:15:36
A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafted link that executes an arbitr...
CVE-2022-45151
- EPSS 0.29%
- Veröffentlicht 23.11.2022 15:15:10
- Zuletzt bearbeitet 25.04.2025 20:15:36
The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code in user's browser i...
CVE-2022-3500
- EPSS 0.15%
- Veröffentlicht 22.11.2022 19:15:17
- Zuletzt bearbeitet 29.04.2025 05:15:43
A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that stopped attestation attempts ...