Skip to main content

CVE-2022-23764

8.8
HIGHCVSS v3.1 Base Score
0.44%
LOW RiskEPSS (64th percentile)

The vulnerability causing from insufficient verification procedures for downloaded files during WebCube update. Remote attackers can bypass this verification logic to update both digitally signed and unauthorized files, enabling remote code execution.

Published: 8/17/2022
Modified: 11/21/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

0.44%LOW Exploitation Risk
64th percentile

This vulnerability has a 0.44% probability of being exploited in the next 30 days, ranking higher than 64% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-346)

CVE-2026-6143MEDIUM 6.3

A security flaw has been discovered in farion1231 cc-switch up to 3.12.3. Affected by this issue is some unknown functionality of the file src-tauri/src/proxy/server.rs of the component ProxyServer. The manipulation results in permissive cross-domain policy with untrusted domains. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

4/13/2026
CVE-2025-34291HIGH 8.8

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.

12/5/2025
CVE-2025-25306CRITICAL 9.3

Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate the relation between the `id` and `url` fields of ActivityPub objects. An attacker can forge an object where they claim authority in the `url` field even if the specific ActivityPub object type require authority in the `id` field. Version 2025.2.1 addresses the issue.

3/10/2025
CVE-2024-57965NONE

In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability.

1/29/2025
CVE-2024-25996MEDIUM 5.3

An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user.

3/12/2024

Similar SeverityHIGH