CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2022-34676

    Last Modified: 11 Apr 2025

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds read may lead to denial of service, information disclosure, or data tampering.

    Published: 30 Dec 2022
    5.5
    Medium

    CVE-2022-34677

    Last Modified: 11 Apr 2025

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause an integer to be truncated, which may lead to denial of service or data tampering.

    Published: 30 Dec 2022
    6.5
    Medium

    CVE-2022-34678

    Last Modified: 10 Apr 2025

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged user can cause a null-pointer dereference, which may lead to denial of service.

    Published: 30 Dec 2022
    5.5
    Medium

    CVE-2022-34681

    Last Modified: 10 Apr 2025

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler, where improper input validation of a display-related data structure may lead to denial of service.

    Published: 30 Dec 2022
    5.5
    Medium

    CVE-2022-34683

    Last Modified: 11 Apr 2025

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a null-pointer dereference occurs, which may lead to denial of service.

    Published: 30 Dec 2022
    7.4
    High

    CVE-2022-48196

    Last Modified: 10 Apr 2025

    Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects RAX40 before 1.0.2.60, RAX35 before 1.0.2.60, R6400v2 before 1.0.4.122, R6700v3 before 1.0.4.122, R6900P before 1.3.3.152, R7000P before 1.3.3.152, R7000 before 1.0.11.136, R7960P before 1.4.4.94, and R8000P before 1.4.4.94.

    Published: 30 Dec 2022
    9.8
    Critical

    CVE-2022-46580

    Last Modified: 11 Apr 2025

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the user_edit_page parameter in the wifi_captive_portal function.

    Published: 30 Dec 2022
    9.8
    Critical

    CVE-2022-46581

    Last Modified: 11 Apr 2025

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.nslookup_target parameter in the tools_nslookup function.

    Published: 30 Dec 2022
    9.8
    Critical

    CVE-2022-46582

    Last Modified: 11 Apr 2025

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the login_name parameter in the do_graph_auth (sub_4061E0) function.

    Published: 30 Dec 2022
    9.8
    Critical

    CVE-2022-46583

    Last Modified: 11 Apr 2025

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reboot_type parameter in the wizard_ipv6 (sub_41C380) function.

    Published: 30 Dec 2022
    9.8
    Critical

    CVE-2022-47120

    Last Modified: 11 Apr 2025

    Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.

    Published: 30 Dec 2022
    9.8
    Critical

    CVE-2022-47121

    Last Modified: 11 Apr 2025

    Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey parameter at /goform/WifiBasicSet.

    Published: 30 Dec 2022
    9.8
    Critical

    CVE-2022-47122

    Last Modified: 11 Apr 2025

    Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlPwd_5g parameter at /goform/WifiBasicSet.

    Published: 30 Dec 2022
    9.8
    Critical

    CVE-2022-47123

    Last Modified: 11 Apr 2025

    Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey3 parameter at /goform/WifiBasicSet.

    Published: 30 Dec 2022
    9.8
    Critical

    CVE-2022-47124

    Last Modified: 11 Apr 2025

    Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey4 parameter at /goform/WifiBasicSet.

    Published: 30 Dec 2022
    9.8
    Critical

    CVE-2022-47125

    Last Modified: 11 Apr 2025

    Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlEn_5g parameter at /goform/WifiBasicSet.

    Published: 30 Dec 2022
    9.8
    Critical

    CVE-2022-47126

    Last Modified: 11 Apr 2025

    Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlEn parameter at /goform/WifiBasicSet.

    Published: 30 Dec 2022
    8.8
    High

    CVE-2022-48194

    Last Modified: 10 Apr 2025

    TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploading a crafted firmware update because the signature check is inadequate.

    Published: 30 Dec 2022
    6.5
    Medium

    CVE-2022-4863

    Last Modified: 9 Apr 2025

    Improper Handling of Insufficient Permissions or Privileges in GitHub repository usememos/memos prior to 0.9.1.

    Published: 30 Dec 2022
    5.4
    Medium

    CVE-2022-4864

    Last Modified: 9 Apr 2025

    Argument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

    Published: 30 Dec 2022
    8.5
    High

    CVE-2022-34671

    Last Modified: 11 Apr 2025

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user-mode layer, where an unprivileged user can cause an out-of-bounds write, which may lead to code execution, information disclosure, and denial of service.

    Published: 30 Dec 2022
    6.8
    Medium

    CVE-2022-34674

    Last Modified: 11 Apr 2025

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where a helper function maps more physical pages than were requested, which may lead to undefined behavior or an information leak.

    Published: 30 Dec 2022
    5.5
    Medium

    CVE-2022-34675

    Last Modified: 11 Apr 2025

    NVIDIA Display Driver for Linux contains a vulnerability in the Virtual GPU Manager, where it does not check the return value from a null-pointer dereference, which may lead to denial of service.

    Published: 30 Dec 2022
    5.5
    Medium

    CVE-2022-34680

    Last Modified: 10 Apr 2025

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an integer truncation can lead to an out-of-bounds read, which may lead to denial of service.

    Published: 30 Dec 2022
    5.5
    Medium

    CVE-2022-34682

    Last Modified: 11 Apr 2025

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a null-pointer dereference, which may lead to denial of service.

    Published: 30 Dec 2022
    5.3
    Medium

    CVE-2022-34684

    Last Modified: 10 Apr 2025

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an off-by-one error may lead to data tampering or information disclosure.

    Published: 30 Dec 2022
    5.3
    Medium

    CVE-2022-42258

    Last Modified: 10 Apr 2025

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of service, data tampering, or information disclosure.

    Published: 30 Dec 2022
    7.8
    High

    CVE-2022-42260

    Last Modified: 11 Apr 2025

    NVIDIA vGPU Display Driver for Linux guest contains a vulnerability in a D-Bus configuration file, where an unauthorized user in the guest VM can impact protected D-Bus endpoints, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

    Published: 30 Dec 2022
    7.1
    High

    CVE-2022-42264

    Last Modified: 11 Apr 2025

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause the use of an out-of-range pointer offset, which may lead to data tampering, data loss, information disclosure, or denial of service.

    Published: 30 Dec 2022
    7.9
    High

    CVE-2022-42269

    Last Modified: 10 Apr 2025

    NVIDIA Trusted OS contains a vulnerability in an SMC call handler, where failure to validate untrusted input may allow a highly privileged local attacker to cause information disclosure and compromise integrity. The scope of the impact can extend to other components.

    Published: 30 Dec 2022
    7.5
    High

    CVE-2022-38212

    Last Modified: 10 Apr 2025

    Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8.1 and below were not fully honored and may allow a remote, unauthenticated attacker to forge requests to arbitrary URLs from the system, potentially leading to network enumeration or reading from hosts inside the network perimeter, a different issue than CVE-2022-38211 and CVE-2022-38203.

    Published: 29 Dec 2022
    7.5
    High

    CVE-2022-38211

    Last Modified: 10 Apr 2025

    Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.9.1 and below were not fully honored and may allow a remote, unauthenticated attacker to forge requests to arbitrary URLs from the system, potentially leading to network enumeration or reading from hosts inside the network perimeter, a different issue than CVE-2022-38211 and CVE-2022-38212.

    Published: 29 Dec 2022
    6.1
    Medium

    CVE-2022-38210

    Last Modified: 10 Apr 2025

    There is a reflected HTML injection vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below that may allow a remote, unauthenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser.

    Published: 29 Dec 2022
    6.1
    Medium

    CVE-2022-38209

    Last Modified: 10 Apr 2025

    There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could execute arbitrary JavaScript code in the victim’s browser.

    Published: 29 Dec 2022
    6.1
    Medium

    CVE-2022-38208

    Last Modified: 10 Apr 2025

    There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

    Published: 29 Dec 2022
    6.1
    Medium

    CVE-2022-38207

    Last Modified: 10 Apr 2025

    There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote remote, unauthenticated attacker to create a crafted link which when clicked which could execute arbitrary JavaScript code in the victim’s browser.

    Published: 29 Dec 2022
    6.1
    Medium

    CVE-2022-38206

    Last Modified: 10 Apr 2025

    There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote remote, unauthenticated attacker to create a crafted link which when clicked could execute arbitrary JavaScript code in the victim’s browser.

    Published: 29 Dec 2022
    8.6
    High

    CVE-2022-38205

    Last Modified: 10 Apr 2025

    In some non-default installations of Esri Portal for ArcGIS versions 10.9.1 and below, a directory traversal issue may allow a remote, unauthenticated attacker to traverse the file system and lead to the disclosure of sensitive data (not customer-published content).

    Published: 29 Dec 2022
    6.1
    Medium

    CVE-2022-38204

    Last Modified: 10 Apr 2025

    There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.

    Published: 29 Dec 2022
    7.5
    High

    CVE-2022-38203

    Last Modified: 10 Apr 2025

    Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8.1 and below were not fully honored and may allow a remote, unauthenticated attacker to forge requests to arbitrary URLs from the system, potentially leading to network enumeration or reading from hosts inside the network perimeter, a different issue than CVE-2022-38211 and CVE-2022-38212.

    Published: 29 Dec 2022
    6.1
    Medium

    CVE-2022-46181

    Last Modified: 10 Apr 2025

    Gotify server is a simple server for sending and receiving messages in real-time per WebSocket. Versions prior to 2.2.2 contain an XSS vulnerability that allows authenticated users to upload .html files. An attacker could execute client side scripts **if** another user opened a link. The attacker could potentially take over the account of the user that clicked the link. The Gotify UI won't natively expose such a malicious link, so an attacker has to get the user to open the malicious link in a context outside of Gotify. The vulnerability has been fixed in version 2.2.2. As a workaround, you can block access to non image files via a reverse proxy in the `./image` directory.

    Published: 29 Dec 2022
    7.4
    High

    CVE-2022-46178

    Last Modified: 10 Apr 2025

    MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions prior to 2.5.1 allow users to upload a file, but do not validate the file name, which may lead to upload file to any path. The vulnerability has been fixed in v2.5.1. There are no workarounds.

    Published: 29 Dec 2022
    —
    Unknown

    CVE-2022-4854

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 29 Dec 2022
    —
    Unknown

    CVE-2022-48190

    Last Modified: 7 Nov 2023

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 29 Dec 2022
    —
    Unknown

    CVE-2022-48185

    Last Modified: 29 Jul 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 29 Dec 2022
    3.5
    Low

    CVE-2021-4296

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, has been found in w3c Unicorn. This issue affects the function ValidatorNuMessage of the file src/org/w3c/unicorn/response/impl/ValidatorNuMessage.java. The manipulation of the argument message leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 51f75c31f7fc33859a9a571311c67ae4e95d9c68. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217019.

    Published: 29 Dec 2022
    5.5
    Medium

    CVE-2021-4295

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic was found in ONC code-validator-api up to 1.0.30. This vulnerability affects the function vocabularyValidationConfigurations of the file src/main/java/org/sitenv/vocabularies/configuration/CodeValidatorApiConfiguration.java of the component XML Handler. The manipulation leads to xml external entity reference. Upgrading to version 1.0.31 is able to address this issue. The name of the patch is fbd8ea121755a2d3d116b13f235bc8b61d8449af. It is recommended to upgrade the affected component. VDB-217018 is the identifier assigned to this vulnerability.

    Published: 29 Dec 2022
    4.2
    Medium

    CVE-2018-25058

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in Twitter-Post-Fetcher up to 17.x. This affects an unknown part of the file js/twitterFetcher.js of the component Link Target Handler. The manipulation leads to use of web link to untrusted target with window.opener access. It is possible to initiate the attack remotely. Upgrading to version 18.0.0 is able to address this issue. The name of the patch is 7d281c6fb5acbc29a2cad295262c1f0c19ca56f3. It is recommended to upgrade the affected component. The identifier VDB-217017 was assigned to this vulnerability.

    Published: 29 Dec 2022
    5.4
    Medium

    CVE-2022-4841

    Last Modified: 9 Apr 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

    Published: 29 Dec 2022
    5.4
    Medium

    CVE-2022-4840

    Last Modified: 9 Apr 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

    Published: 29 Dec 2022