LiveActive security incident?Get immediate response
CVE archive

September 2022

Browse CVE records published in September 2022, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2323 matching CVEs · Page 16 of 47.

Critical · CVSS 9.1

CVE-2022-32847: This issue was addressed with improved checks.

This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

Published Sep 23, 2022 · Updated May 22, 2025

High · CVSS 7.1

CVE-2022-32831: An out-of-bounds read was addressed with improved bounds checking.

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary may result in unexpected termination or disclosure of process memory.

Published Sep 23, 2022 · Updated May 22, 2025

Medium · CVSS 5.5

CVE-2022-32841: The issue was addressed with improved memory handling.

The issue was addressed with improved memory handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. Processing a maliciously crafted image may result in disclosure of process memory.

Published Sep 23, 2022 · Updated May 22, 2025

High · CVSS 7.1

CVE-2022-32851: An out-of-bounds read issue was addressed with improved input validation.

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary may result in unexpected termination or disclosure of process memory.

Published Sep 23, 2022 · Updated May 22, 2025

Medium · CVSS 5.5

CVE-2022-32800: This issue was addressed with improved checks.

This issue was addressed with improved checks. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to modify protected parts of the file system.

Published Sep 23, 2022 · Updated May 22, 2025

Medium · CVSS 5.4

CVE-2022-3024: Simple Bitcoin Faucets <= 1.7.0 - Unauthorised AJAX Call to Stored XSS

The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscribers to call it and add/delete/edit Bonds. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

Published Sep 26, 2022 · Updated May 22, 2025

High · CVSS 7.5

CVE-2022-2987: Ldap WP Login / Active Directory Integration < 3.0.2 - Unauthenticated Settings Update to Auth Bypass

The Ldap WP Login / Active Directory Integration WordPress plugin before 3.0.2 does not have any authorisation and CSRF checks when updating it's settings (which are hooked to the init action), allowing unauthenticated attackers to update them. Attackers could set their own LDAP server to be used to authenticated users, therefore bypassing the current authentication

Published Sep 26, 2022 · Updated May 22, 2025

Medium · CVSS 5.4

CVE-2022-3025: Bitcoin / Altcoin Faucet <= 1.6.0 - Settings Update to Stored XSS via CSRF

The Bitcoin / Altcoin Faucet WordPress plugin through 1.6.0 does not have any CSRF check when saving its settings, allowing attacker to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

Published Sep 26, 2022 · Updated May 22, 2025

Medium · CVSS 4.8

CVE-2022-3069: Wordlift < 3.37.2 - Admin+ Stored Cross-Site Scripting

The WordLift WordPress plugin before 3.37.2 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Published Sep 26, 2022 · Updated May 22, 2025

High · CVSS 8.8

CVE-2022-41604: Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges.

Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges. This occurs because of weak permissions for the %PROGRAMDATA%\CheckPoint\ZoneAlarm\Data\Updates directory, and a self-protection driver bypass that allows creation of a junction directory. This can be leveraged to perform an arbitrary file move as NT AUTHORITY\SYSTEM.

Published Sep 27, 2022 · Updated May 22, 2025

High · CVSS 8.8

CVE-2022-37209: JFinal CMS 5.1.0 is affected by: SQL Injection.

JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

Published Sep 27, 2022 · Updated May 22, 2025

High · CVSS 7.3

CVE-2022-21169: Prototype Pollution

The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization.

Published Sep 26, 2022 · Updated May 21, 2025