CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2022-46317

    Last Modified: 16 Apr 2025

    The power consumption module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability.

    Published: 20 Dec 2022
    7.8
    High

    CVE-2022-42046

    Last Modified: 17 Apr 2025

    wfshbr64.sys and wfshbr32.sys specially crafted IOCTL allows arbitrary user to perform local privilege escalation

    Published: 20 Dec 2022
    5.3
    Medium

    CVE-2022-46318

    Last Modified: 16 Apr 2025

    The HAware module has a function logic error. Successful exploitation of this vulnerability will affect the account removal function in Settings.

    Published: 20 Dec 2022
    9.8
    Critical

    CVE-2022-46319

    Last Modified: 16 Apr 2025

    Fingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of this vulnerability may cause out-of-bounds write.

    Published: 20 Dec 2022
    9.8
    Critical

    CVE-2022-46327

    Last Modified: 17 Apr 2025

    Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation, which results in system service exceptions.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46328

    Last Modified: 17 Apr 2025

    Some smartphones have the input validation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2021-46856

    Last Modified: 17 Apr 2025

    The multi-screen collaboration module has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 20 Dec 2022
    9.8
    Critical

    CVE-2022-46538

    Last Modified: 16 Apr 2025

    Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteFacMac.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46539

    Last Modified: 16 Apr 2025

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the security_5g parameter at /goform/WifiBasicSet.

    Published: 20 Dec 2022
    8.6
    High

    CVE-2022-38733

    Last Modified: 16 Apr 2025

    OnCommand Insight versions 7.3.1 through 7.3.14 are susceptible to an authentication bypass vulnerability in the Data Warehouse component.

    Published: 20 Dec 2022
    9.8
    Critical

    CVE-2022-40624

    Last Modified: 17 Apr 2025

    pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-41591

    Last Modified: 16 Apr 2025

    The backup module has a path traversal vulnerability. Successful exploitation of this vulnerability causes unauthorized access to other system files.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-41599

    Last Modified: 16 Apr 2025

    The system service has a vulnerability that causes incorrect return values. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 20 Dec 2022
    9.8
    Critical

    CVE-2022-4338

    Last Modified: 21 Nov 2024

    An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.

    Published: 20 Dec 2022
    8.8
    High

    CVE-2022-45942

    Last Modified: 17 Apr 2025

    A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4.

    Published: 20 Dec 2022
    9.8
    Critical

    CVE-2022-46020

    Last Modified: 17 Apr 2025

    WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46076

    Last Modified: 17 Apr 2025

    D-Link DIR-869 DIR869Ax_FW102B15 is vulnerable to Authentication Bypass via phpcgi.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46535

    Last Modified: 16 Apr 2025

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the deviceId parameter at /goform/SetClientState.

    Published: 20 Dec 2022
    —
    Unknown

    CVE-2022-4618

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 20 Dec 2022
    9.8
    Critical

    CVE-2022-46316

    Last Modified: 17 Apr 2025

    A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46311

    Last Modified: 17 Apr 2025

    The contacts component has a free (undefined) provider vulnerability. Successful exploitation of this vulnerability may affect data integrity.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46312

    Last Modified: 17 Apr 2025

    The application management module has a vulnerability in permission verification. Successful exploitation of this vulnerability causes unexpected clear of device applications.

    Published: 20 Dec 2022
    5.3
    Medium

    CVE-2022-46313

    Last Modified: 17 Apr 2025

    The sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause unavailability of the smartphone's camera and microphone.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46314

    Last Modified: 17 Apr 2025

    The IPC module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46315

    Last Modified: 17 Apr 2025

    The ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46321

    Last Modified: 16 Apr 2025

    The Wi-Fi module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46322

    Last Modified: 16 Apr 2025

    Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.

    Published: 20 Dec 2022
    9.8
    Critical

    CVE-2022-46323

    Last Modified: 16 Apr 2025

    Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.

    Published: 20 Dec 2022
    9.8
    Critical

    CVE-2022-46324

    Last Modified: 16 Apr 2025

    Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.

    Published: 20 Dec 2022
    9.8
    Critical

    CVE-2022-46325

    Last Modified: 16 Apr 2025

    Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46536

    Last Modified: 16 Apr 2025

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the limitSpeedUp parameter at /goform/SetClientState.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46547

    Last Modified: 16 Apr 2025

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the page parameter at /goform/VirtualSer.

    Published: 20 Dec 2022
    4.8
    Medium

    CVE-2022-46422

    Last Modified: 17 Apr 2025

    An issue in Netgear WNR2000 v1 1.2.3.7 and earlier allows authenticated attackers to cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process.

    Published: 20 Dec 2022
    8.1
    High

    CVE-2022-46423

    Last Modified: 17 Apr 2025

    An exploitable firmware modification vulnerability was discovered on the Netgear WNR2000v1 router. An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-uploaded firmware image and bypass the CRC check, allowing attackers to execute arbitrary code or cause a Denial of Service (DoS). This affects v1.2.3.7 and earlier.

    Published: 20 Dec 2022
    8.1
    High

    CVE-2022-46424

    Last Modified: 16 Apr 2025

    An exploitable firmware modification vulnerability was discovered on the Netgear XWN5001 Powerline 500 WiFi Access Point. An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-uploaded firmware image and bypass the CRC check, allowing attackers to execute arbitrary code or cause a Denial of Service (DoS). This affects v0.4.1.1 and earlier.

    Published: 20 Dec 2022
    4.8
    Medium

    CVE-2022-46428

    Last Modified: 16 Apr 2025

    TP-Link TL-WR1043ND V1 3.13.15 and earlier allows authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process.

    Published: 20 Dec 2022
    4.8
    Medium

    CVE-2022-46430

    Last Modified: 16 Apr 2025

    TP-Link TL-WR740N V1 and V2 v3.12.4 and earlier allows authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46434

    Last Modified: 16 Apr 2025

    An issue in the firmware update process of TP-Link TL-WA7510N v1 v3.12.6 and earlier allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.

    Published: 20 Dec 2022
    8.8
    High

    CVE-2022-46435

    Last Modified: 16 Apr 2025

    An issue in the firmware update process of TP-Link TL-WR941ND V2/V3 up to 3.13.9 and TL-WR941ND V4 up to 3.12.8 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46548

    Last Modified: 16 Apr 2025

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the page parameter at /goform/DhcpListClient.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46530

    Last Modified: 16 Apr 2025

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the mac parameter at /goform/GetParentControlInfo.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46531

    Last Modified: 16 Apr 2025

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the deviceId parameter at /goform/addWifiMacFilter.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46532

    Last Modified: 16 Apr 2025

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the deviceMac parameter at /goform/addWifiMacFilter.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46533

    Last Modified: 16 Apr 2025

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the limitSpeed parameter at /goform/SetClientState.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46534

    Last Modified: 16 Apr 2025

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the speed_dir parameter at /goform/SetSpeedWan.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46540

    Last Modified: 16 Apr 2025

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the entrys parameter at /goform/addressNat.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46541

    Last Modified: 16 Apr 2025

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the ssid parameter at /goform/fast_setting_wifi_set.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46542

    Last Modified: 16 Apr 2025

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the page parameter at /goform/addressNat.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46543

    Last Modified: 16 Apr 2025

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the mitInterface parameter at /goform/addressNat.

    Published: 20 Dec 2022
    7.5
    High

    CVE-2022-46544

    Last Modified: 16 Apr 2025

    Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the cmdinput parameter at /goform/exeCommand.

    Published: 20 Dec 2022