CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2022-48216

    Last Modified: 10 Apr 2025

    Uniswap Universal Router before 1.1.0 mishandles reentrancy. This would have allowed theft of funds.

    Published: 4 Jan 2023
    8.1
    High

    CVE-2022-48217

    Last Modified: 21 Nov 2024

    The tf_remapper_node component 1.1.1 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in the same ROS application, to change a robot's behavior. This occurs because a topic name depends on the attacker-controlled old_tf_topic_name and/or new_tf_topic_name parameter. NOTE: the vendor's position is "it is the responsibility of the programmer to make sure that only known and required parameters are set and unexpected parameters are not."

    Published: 4 Jan 2023
    5.5
    Medium

    CVE-2022-44422

    Last Modified: 10 Apr 2025

    In music service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

    Published: 4 Jan 2023
    5.5
    Medium

    CVE-2022-44423

    Last Modified: 10 Apr 2025

    In music service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

    Published: 4 Jan 2023
    5.5
    Medium

    CVE-2022-44425

    Last Modified: 10 Apr 2025

    In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

    Published: 4 Jan 2023
    5.5
    Medium

    CVE-2022-44426

    Last Modified: 10 Apr 2025

    In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

    Published: 4 Jan 2023
    5.5
    Medium

    CVE-2022-44427

    Last Modified: 10 Apr 2025

    In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

    Published: 4 Jan 2023
    5.5
    Medium

    CVE-2022-44428

    Last Modified: 10 Apr 2025

    In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

    Published: 4 Jan 2023
    5.5
    Medium

    CVE-2022-44429

    Last Modified: 10 Apr 2025

    In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

    Published: 4 Jan 2023
    5.5
    Medium

    CVE-2022-44435

    Last Modified: 10 Apr 2025

    In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

    Published: 4 Jan 2023
    5.5
    Medium

    CVE-2022-44436

    Last Modified: 10 Apr 2025

    In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

    Published: 4 Jan 2023
    5.5
    Medium

    CVE-2022-44437

    Last Modified: 10 Apr 2025

    In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

    Published: 4 Jan 2023
    5.5
    Medium

    CVE-2022-44438

    Last Modified: 10 Apr 2025

    In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

    Published: 4 Jan 2023
    5.5
    Medium

    CVE-2022-44439

    Last Modified: 10 Apr 2025

    In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

    Published: 4 Jan 2023
    8.8
    High

    CVE-2023-0048

    Last Modified: 9 Apr 2025

    Code Injection in GitHub repository lirantal/daloradius prior to master-branch.

    Published: 4 Jan 2023
    —
    Unknown

    CVE-2023-0047

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2023. Notes: none.

    Published: 4 Jan 2023
    5.3
    Medium

    CVE-2023-0055

    Last Modified: 9 Apr 2025

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository pyload/pyload prior to 0.5.0b3.dev32.

    Published: 4 Jan 2023
    7.8
    High

    CVE-2023-0049

    Last Modified: 24 Sept 2026

    Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.

    Published: 4 Jan 2023
    6.7
    Medium

    CVE-2022-39081

    Last Modified: 10 Apr 2025

    In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

    Published: 4 Jan 2023
    6.7
    Medium

    CVE-2022-39082

    Last Modified: 10 Apr 2025

    In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

    Published: 4 Jan 2023
    5.5
    Medium

    CVE-2022-39104

    Last Modified: 10 Apr 2025

    In contacts service, there is a missing permission check. This could lead to local denial of service in Contacts service with no additional execution privileges needed.

    Published: 4 Jan 2023
    7.5
    High

    CVE-2022-46081

    Last Modified: 10 Apr 2025

    In Garmin Connect 4.61, terminating a LiveTrack session wouldn't prevent the LiveTrack API from continued exposure of private personal information. NOTE: this is disputed by the vendor because the LiveTrack API service is not a customer-controlled product.

    Published: 4 Jan 2023
    5.5
    Medium

    CVE-2022-44430

    Last Modified: 10 Apr 2025

    In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

    Published: 4 Jan 2023
    5.5
    Medium

    CVE-2022-44434

    Last Modified: 10 Apr 2025

    In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

    Published: 4 Jan 2023
    5.5
    Medium

    CVE-2022-44440

    Last Modified: 10 Apr 2025

    In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

    Published: 4 Jan 2023
    5.5
    Medium

    CVE-2022-44441

    Last Modified: 10 Apr 2025

    In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

    Published: 4 Jan 2023
    5.5
    Medium

    CVE-2022-44442

    Last Modified: 10 Apr 2025

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

    Published: 4 Jan 2023
    5.5
    Medium

    CVE-2022-44445

    Last Modified: 10 Apr 2025

    In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

    Published: 4 Jan 2023
    4.3
    Medium

    CVE-2022-42435

    Last Modified: 10 Apr 2025

    IBM Business Automation Workflow 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, and 22.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 238054.

    Published: 3 Jan 2023
    6.5
    Medium

    CVE-2022-2967

    Last Modified: 16 Jan 2025

    Prosys OPC UA Simulation Server version prior to v5.3.0-64 and UA Modbus Server versions 1.4.18-5 and prior do not sufficiently protect credentials, which could allow an attacker to obtain user credentials and gain access to system data.

    Published: 3 Jan 2023
    5.5
    Medium

    CVE-2022-43540

    Last Modified: 10 Apr 2025

    A vulnerability exists in the ClearPass OnGuard macOS agent that allows for an attacker with local macOS instance access to potentially obtain sensitive information. A successful exploit could allow an attacker to retrieve information that is of a sensitive nature in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below.

    Published: 3 Jan 2023
    5.7
    Medium

    CVE-2022-43539

    Last Modified: 10 Apr 2025

    A vulnerability exists in the ClearPass Policy Manager cluster communications that allow for an attacker in a privileged network position to potentially obtain sensitive information. A successful exploit could allow an attacker to retrieve information that allows for unauthorized actions as a privileged user on the ClearPass Policy Manager cluster in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below.

    Published: 3 Jan 2023
    7.2
    High

    CVE-2022-43538

    Last Modified: 10 Apr 2025

    Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below.

    Published: 3 Jan 2023
    7.2
    High

    CVE-2022-43537

    Last Modified: 10 Apr 2025

    Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below.

    Published: 3 Jan 2023
    4.3
    Medium

    CVE-2022-23506

    Last Modified: 10 Mar 2025

    Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes, and Spinnaker's Rosco microservice produces machine images. Rosco prior to versions 1.29.2, 1.28.4, and 1.27.3 does not property mask secrets generated via packer builds. This can lead to exposure of sensitive AWS credentials in packer log files. Versions 1.29.2, 1.28.4, and 1.27.3 of Rosco contain fixes for this issue. A workaround is available. It's recommended to use short lived credentials via role assumption and IAM profiles. Additionally, credentials can be set in `/home/spinnaker/.aws/credentials` and `/home/spinnaker/.aws/config` as a volume mount for Rosco pods vs. setting credentials in roscos bake config properties. Last even with those it's recommend to use IAM Roles vs. long lived credentials. This drastically mitigates the risk of credentials exposure. If users have used static credentials, it's recommended to purge any bake logs for AWS, evaluate whether AWS_ACCESS_KEY, SECRET_KEY and/or other sensitive data has been introduced in log files and bake job logs. Then, rotate these credentials and evaluate potential improper use of those credentials.

    Published: 3 Jan 2023
    7.2
    High

    CVE-2022-43536

    Last Modified: 10 Apr 2025

    Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below.

    Published: 3 Jan 2023
    7.8
    High

    CVE-2022-43535

    Last Modified: 10 Apr 2025

    A vulnerability in the ClearPass OnGuard Windows agent could allow malicious users on a Windows instance to elevate their user privileges. A successful exploit could allow these users to execute arbitrary code with NT AUTHORITY\SYSTEM level privileges on the Windows instance in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below.

    Published: 3 Jan 2023
    7.8
    High

    CVE-2022-43534

    Last Modified: 10 Apr 2025

    A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. A successful exploit could allow these users to execute arbitrary code with root level privileges on the Linux instance in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below.

    Published: 3 Jan 2023
    7.8
    High

    CVE-2022-43533

    Last Modified: 10 Apr 2025

    A vulnerability in the ClearPass OnGuard macOS agent could allow malicious users on a macOS instance to elevate their user privileges. A successful exploit could allow these users to execute arbitrary code with root level privileges on the macOS instance in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below.

    Published: 3 Jan 2023
    8
    High

    CVE-2022-43532

    Last Modified: 10 Apr 2025

    A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below.

    Published: 3 Jan 2023
    8.8
    High

    CVE-2022-43531

    Last Modified: 10 Apr 2025

    Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below.

    Published: 3 Jan 2023
    8.8
    High

    CVE-2022-43530

    Last Modified: 10 Apr 2025

    Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below.

    Published: 3 Jan 2023
    8.8
    High

    CVE-2022-44535

    Last Modified: 10 Apr 2025

    A vulnerability in the Aruba EdgeConnect Enterprise Orchestrator web-based management interface allows remote low-privileged authenticated users to escalate their privileges to those of an administrative user. A successful exploit could allow an attacker to achieve administrative privilege on the web-management interface leading to complete system compromise in Aruba EdgeConnect Enterprise Orchestration Software version(s): Aruba EdgeConnect Enterprise Orchestrator (on-premises), Aruba EdgeConnect Enterprise Orchestrator-as-a-Service, Aruba EdgeConnect Enterprise Orchestrator-SP and Aruba EdgeConnect Enterprise Orchestrator Global Enterprise Tenant Orchestrators - Orchestrator 9.2.1.40179 and below, - Orchestrator 9.1.4.40436 and below, - Orchestrator 9.0.7.40110 and below, - Orchestrator 8.10.23.40015 and below, - Any older branches of Orchestrator not specifically mentioned.

    Published: 3 Jan 2023
    7.2
    High

    CVE-2022-44534

    Last Modified: 10 Apr 2025

    A vulnerability in the Aruba EdgeConnect Enterprise Orchestrator web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Orchestration Software version(s): Aruba EdgeConnect Enterprise Orchestrator (on-premises), Aruba EdgeConnect Enterprise Orchestrator-as-a-Service, Aruba EdgeConnect Enterprise Orchestrator-SP and Aruba EdgeConnect Enterprise Orchestrator Global Enterprise Tenant Orchestrators - Orchestrator 9.2.1.40179 and below, - Orchestrator 9.1.4.40436 and below, - Orchestrator 9.0.7.40110 and below, - Orchestrator 8.10.23.40015 and below, - Any older branches of Orchestrator not specifically mentioned.

    Published: 3 Jan 2023
    4.6
    Medium

    CVE-2022-43529

    Last Modified: 10 Apr 2025

    A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an remote attacker to persist a session after a password reset or similar session clearing event. Successful exploitation of this vulnerability could allow an authenticated attacker to remain on the system with the permissions of their current session after the session should be invalidated in Aruba EdgeConnect Enterprise Orchestration Software version(s): Aruba EdgeConnect Enterprise Orchestrator (on-premises), Aruba EdgeConnect Enterprise Orchestrator-as-a-Service, Aruba EdgeConnect Enterprise Orchestrator-SP and Aruba EdgeConnect Enterprise Orchestrator Global Enterprise Tenant Orchestrators - Orchestrator 9.2.1.40179 and below, - Orchestrator 9.1.4.40436 and below, - Orchestrator 9.0.7.40110 and below, - Orchestrator 8.10.23.40015 and below, - Any older branches of Orchestrator not specifically mentioned.

    Published: 3 Jan 2023
    4.8
    Medium

    CVE-2022-43528

    Last Modified: 10 Apr 2025

    Under certain configurations, an attacker can login to Aruba EdgeConnect Enterprise Orchestrator without supplying a multi-factor authentication code. Successful exploitation allows an attacker to login using only a username and password and successfully bypass MFA requirements in Aruba EdgeConnect Enterprise Orchestration Software version(s): Aruba EdgeConnect Enterprise Orchestrator (on-premises), Aruba EdgeConnect Enterprise Orchestrator-as-a-Service, Aruba EdgeConnect Enterprise Orchestrator-SP and Aruba EdgeConnect Enterprise Orchestrator Global Enterprise Tenant Orchestrators - Orchestrator 9.2.1.40179 and below, - Orchestrator 9.1.4.40436 and below, - Orchestrator 9.0.7.40110 and below, - Orchestrator 8.10.23.40015 and below, - Any older branches of Orchestrator not specifically mentioned.

    Published: 3 Jan 2023
    6.1
    Medium

    CVE-2022-43527

    Last Modified: 10 Apr 2025

    Multiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface in Aruba EdgeConnect Enterprise Orchestration Software version(s): Aruba EdgeConnect Enterprise Orchestrator (on-premises), Aruba EdgeConnect Enterprise Orchestrator-as-a-Service, Aruba EdgeConnect Enterprise Orchestrator-SP and Aruba EdgeConnect Enterprise Orchestrator Global Enterprise Tenant Orchestrators - Orchestrator 9.2.1.40179 and below, - Orchestrator 9.1.4.40436 and below, - Orchestrator 9.0.7.40110 and below, - Orchestrator 8.10.23.40015 and below, - Any older branches of Orchestrator not specifically mentioned.

    Published: 3 Jan 2023
    6.1
    Medium

    CVE-2022-43526

    Last Modified: 10 Apr 2025

    Multiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface in Aruba EdgeConnect Enterprise Orchestration Software version(s): Aruba EdgeConnect Enterprise Orchestrator (on-premises), Aruba EdgeConnect Enterprise Orchestrator-as-a-Service, Aruba EdgeConnect Enterprise Orchestrator-SP and Aruba EdgeConnect Enterprise Orchestrator Global Enterprise Tenant Orchestrators - Orchestrator 9.2.1.40179 and below, - Orchestrator 9.1.4.40436 and below, - Orchestrator 9.0.7.40110 and below, - Orchestrator 8.10.23.40015 and below, - Any older branches of Orchestrator not specifically mentioned.

    Published: 3 Jan 2023
    6.1
    Medium

    CVE-2022-43525

    Last Modified: 10 Apr 2025

    Multiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface in Aruba EdgeConnect Enterprise Orchestration Software version(s): Aruba EdgeConnect Enterprise Orchestrator (on-premises), Aruba EdgeConnect Enterprise Orchestrator-as-a-Service, Aruba EdgeConnect Enterprise Orchestrator-SP and Aruba EdgeConnect Enterprise Orchestrator Global Enterprise Tenant Orchestrators - Orchestrator 9.2.1.40179 and below, - Orchestrator 9.1.4.40436 and below, - Orchestrator 9.0.7.40110 and below, - Orchestrator 8.10.23.40015 and below, - Any older branches of Orchestrator not specifically mentioned.

    Published: 3 Jan 2023
    8.7
    High

    CVE-2022-43524

    Last Modified: 10 Apr 2025

    A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface in Aruba EdgeConnect Enterprise Orchestration Software version(s): Aruba EdgeConnect Enterprise Orchestrator (on-premises), Aruba EdgeConnect Enterprise Orchestrator-as-a-Service, Aruba EdgeConnect Enterprise Orchestrator-SP and Aruba EdgeConnect Enterprise Orchestrator Global Enterprise Tenant Orchestrators - Orchestrator 9.2.1.40179 and below, - Orchestrator 9.1.4.40436 and below, - Orchestrator 9.0.7.40110 and below, - Orchestrator 8.10.23.40015 and below, - Any older branches of Orchestrator not specifically mentioned.

    Published: 3 Jan 2023