CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2022-4538

    Last Modified: 30 Aug 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error and is not a valid vulnerability. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-20563

    Last Modified: 21 Apr 2025

    In TBD of ufdt_convert, there is a possible out of bounds read due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-242067561References: N/A

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-20578

    Last Modified: 18 Apr 2025

    In RadioImpl::setGsmBroadcastConfig of ril_service_legacy.cpp, there is a possible stack clash leading to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-243509749References: N/A

    Published: 16 Dec 2022
    7.8
    High

    CVE-2022-20584

    Last Modified: 18 Apr 2025

    In page_number of shared_mem.c, there is a possible code execution in secure world due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-238366009References: N/A

    Published: 16 Dec 2022
    5.5
    Medium

    CVE-2022-20590

    Last Modified: 18 Apr 2025

    In valid_va_sec_mfc_check of drm_access_control.c, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-238932493References: N/A

    Published: 16 Dec 2022
    5.5
    Medium

    CVE-2022-20591

    Last Modified: 18 Apr 2025

    In ppmpu_set of ppmpu.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-238939706References: N/A

    Published: 16 Dec 2022
    7.8
    High

    CVE-2022-20597

    Last Modified: 18 Apr 2025

    In ppmpu_set of ppmpu.c, there is a possible EoP due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-243480506References: N/A

    Published: 16 Dec 2022
    5.5
    Medium

    CVE-2022-20604

    Last Modified: 18 Apr 2025

    In SAECOMM_SetDcnIdForPlmn of SAECOMM_DbManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure from a single device with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-230463606References: N/A

    Published: 16 Dec 2022
    7.5
    High

    CVE-2022-20605

    Last Modified: 18 Apr 2025

    In SAECOMM_CopyBufferBytes of SAECOMM_Utility.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-231722405References: N/A

    Published: 16 Dec 2022
    5.5
    Medium

    CVE-2022-20609

    Last Modified: 18 Apr 2025

    In Pixel cellular firmware, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239240808References: N/A

    Published: 16 Dec 2022
    9.1
    Critical

    CVE-2022-45796

    Last Modified: 17 Apr 2025

    Command injection vulnerability in nw_interface.html in SHARP multifunction printers (MFPs)'s Digital Full-color Multifunctional System 202 or earlier, 120 or earlier, 600 or earlier, 121 or earlier, 500 or earlier, 402 or earlier, 790 or earlier, and Digital Multifunctional System (Monochrome) 200 or earlier, 211 or earlier, 102 or earlier, 453 or earlier, 400 or earlier, 202 or earlier, 602 or earlier, 500 or earlier, 401 or earlier allows remote attackers to execute arbitrary commands via unspecified vectors.

    Published: 16 Dec 2022
    7.5
    High

    CVE-2022-46109

    Last Modified: 17 Apr 2025

    Tenda AC15 V15.03.06.23 is vulnerable to Buffer Overflow via function formSetClientState.

    Published: 16 Dec 2022
    7.2
    High

    CVE-2022-46135

    Last Modified: 17 Apr 2025

    In AeroCms v0.0.1, there is an arbitrary file upload vulnerability at /admin/posts.php?source=edit_post , through which we can upload webshell and control the web server.

    Published: 16 Dec 2022
    7.5
    High

    CVE-2022-46137

    Last Modified: 17 Apr 2025

    AeroCMS v0.0.1 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: AeroCMS v0.0.1.

    Published: 16 Dec 2022
    8.8
    High

    CVE-2022-47209

    Last Modified: 17 Apr 2025

    A support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “support” and cannot be changed by a user via any normally accessible means.

    Published: 16 Dec 2022
    7.8
    High

    CVE-2022-47210

    Last Modified: 17 Apr 2025

    The default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, however, appear to be fed directly into a system call or other similar function. This allows any authenticated user to execute arbitrary commands on the device.

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-25627

    Last Modified: 18 Apr 2025

    An authenticated administrator who has physical access to the environment can carry out Remote Command Execution on Management Console in Symantec Identity Manager 14.4

    Published: 16 Dec 2022
    8.8
    High

    CVE-2022-25628

    Last Modified: 18 Apr 2025

    An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4

    Published: 16 Dec 2022
    7.8
    High

    CVE-2022-26582

    Last Modified: 21 Nov 2024

    PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an attacker to gain root access through command injection in systool client. The attacker must have shell access to the device in order to exploit this vulnerability.

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-42503

    Last Modified: 18 Apr 2025

    In ProtocolMiscBuilder::BuildSetLinkCapaReportCriteria of protocolmiscbuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-241231983References: N/A

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-42505

    Last Modified: 17 Apr 2025

    In ProtocolMiscBuilder::BuildSetSignalReportCriteria of protocolmiscbuilder.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-241232492References: N/A

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-42508

    Last Modified: 17 Apr 2025

    In ProtocolCallBuilder::BuildSendUssd of protocolcallbuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-241388966References: N/A

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-42519

    Last Modified: 17 Apr 2025

    In CdmaBroadcastSmsConfigsRequestData::encode of cdmasmsdata.cpp, there is a possible stack clash leading to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-242540694References: N/A

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-42523

    Last Modified: 17 Apr 2025

    In fillSetupDataCallInfo_V1_6 of ril_service_1_6.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-243376893References: N/A

    Published: 16 Dec 2022
    7.8
    High

    CVE-2022-42544

    Last Modified: 17 Apr 2025

    In getView of AddAppNetworksFragment.java, there is a possible way to mislead the user about network add requests due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224545390

    Published: 16 Dec 2022
    9.8
    Critical

    CVE-2022-45141

    Last Modified: 6 Mar 2025

    Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting better encryption (eg aes256-cts-hmac-sha1-96).

    Published: 16 Dec 2022
    3.5
    Low

    CVE-2022-4556

    Last Modified: 15 Apr 2025

    A vulnerability was found in Alinto SOGo up to 5.7.1 and classified as problematic. Affected by this issue is the function _migrateMailIdentities of the file SoObjects/SOGo/SOGoUserDefaults.m of the component Identity Handler. The manipulation of the argument fullName leads to cross site scripting. The attack may be launched remotely. Upgrading to version 5.8.0 is able to address this issue. The name of the patch is efac49ae91a4a325df9931e78e543f707a0f8e5e. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-215960.

    Published: 16 Dec 2022
    3.5
    Low

    CVE-2022-4558

    Last Modified: 15 Apr 2025

    A vulnerability was found in Alinto SOGo up to 5.7.1. It has been classified as problematic. This affects an unknown part of the file SoObjects/SOGo/NSString+Utilities.m of the component Folder/Mail Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 5.8.0 is able to address this issue. The name of the patch is 1e0f5f00890f751e84d67be4f139dd7f00faa5f3. It is recommended to upgrade the affected component. The identifier VDB-215961 was assigned to this vulnerability.

    Published: 16 Dec 2022
    3.5
    Low

    CVE-2022-4559

    Last Modified: 15 Apr 2025

    A vulnerability was found in INEX IPX-Manager up to 6.2.0. It has been declared as problematic. This vulnerability affects unknown code of the file resources/views/customer/list.foil.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 6.3.0 is able to address this issue. The name of the patch is bc9b14c6f70cccdb89b559e8bc3a7318bfe9c243. It is recommended to upgrade the affected component. VDB-215962 is the identifier assigned to this vulnerability.

    Published: 16 Dec 2022
    3.5
    Low

    CVE-2022-4560

    Last Modified: 15 Apr 2025

    A vulnerability was found in Joget up to 7.0.31. It has been rated as problematic. This issue affects the function getInternalJsCssLib of the file wflow-core/src/main/java/org/joget/plugin/enterprise/UniversalTheme.java of the component wflow-core. The manipulation of the argument key leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 7.0.32 is able to address this issue. The name of the patch is ecf8be8f6f0cb725c18536ddc726d42a11bdaa1b. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-215963.

    Published: 16 Dec 2022
    3.5
    Low

    CVE-2022-4561

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in SemanticDrilldown Extension. Affected is the function printFilterLine of the file includes/specials/SDBrowseDataPage.php of the component GET Parameter Handler. The manipulation of the argument value leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is 6e18cf740a4548166c1d95f6d3a28541d298a3aa. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-215964.

    Published: 16 Dec 2022
    7.8
    High

    CVE-2022-4563

    Last Modified: 15 Apr 2025

    A vulnerability was found in Freedom of the Press SecureDrop. It has been rated as critical. Affected by this issue is some unknown functionality of the file gpg-agent.conf. The manipulation leads to symlink following. Local access is required to approach this attack. The name of the patch is b0526a06f8ca713cce74b63e00d3730618d89691. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-215972.

    Published: 16 Dec 2022
    4.3
    Medium

    CVE-2022-4564

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in University of Central Florida Materia up to 9.0.0. This affects the function before of the file fuel/app/classes/controller/api.php of the component API Controller. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 9.0.1-alpha1 is able to address this issue. The name of the patch is af259115d2e8f17068e61902151ee8a9dbac397b. It is recommended to upgrade the affected component. The identifier VDB-215973 was assigned to this vulnerability.

    Published: 16 Dec 2022
    5.5
    Medium

    CVE-2022-4566

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, has been found in y_project RuoYi 4.7.5. This issue affects some unknown processing of the file com/ruoyi/generator/controller/GenController. The manipulation leads to sql injection. The name of the patch is 167970e5c4da7bb46217f576dc50622b83f32b40. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-215975.

    Published: 16 Dec 2022
    9.8
    Critical

    CVE-2021-31650

    Last Modified: 21 Apr 2025

    A SQL injection vulnerability in Sourcecodester Online Grading System 1.0 allows remote attackers to execute arbitrary SQL commands via the uname parameter.

    Published: 16 Dec 2022
    3.3
    Low

    CVE-2022-20535

    Last Modified: 18 Apr 2025

    In registerLocalOnlyHotspotSoftApCallback of WifiManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-233605242

    Published: 16 Dec 2022
    7.8
    High

    CVE-2022-20548

    Last Modified: 18 Apr 2025

    In setParameter of EqualizerEffect.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-240919398

    Published: 16 Dec 2022
    3.3
    Low

    CVE-2022-20556

    Last Modified: 18 Apr 2025

    In launchConfigNewNetworkFragment of NetworkProviderSettings.java, there is a possible way for the guest user to add a new WiFi network due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-246301667

    Published: 16 Dec 2022
    6.8
    Medium

    CVE-2022-26581

    Last Modified: 21 Nov 2024

    PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an unauthorized attacker to perform privileged actions through the execution of specific binaries listed in ADB daemon. The attacker must have physical USB access to the device in order to exploit this vulnerability.

    Published: 16 Dec 2022
    7.5
    High

    CVE-2022-3109

    Last Modified: 7 Aug 2025

    An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability.

    Published: 16 Dec 2022
    7.8
    High

    CVE-2022-20561

    Last Modified: 18 Apr 2025

    In TBD of aud_hal_tunnel.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-222162870References: N/A

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-20583

    Last Modified: 18 Apr 2025

    In ppmp_unprotect_mfcfw_buf of drm_fw.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege in S-EL1 with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-234859169References: N/A

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-20596

    Last Modified: 18 Apr 2025

    In sendChunk of WirelessCharger.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239700400References: N/A

    Published: 16 Dec 2022
    7.5
    High

    CVE-2022-20602

    Last Modified: 18 Apr 2025

    Product: AndroidVersions: Android kernelAndroid ID: A-211081867References: N/A

    Published: 16 Dec 2022
    7.2
    High

    CVE-2022-20603

    Last Modified: 18 Apr 2025

    In SetDecompContextDb of RohcDeCompContextOfRbId.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-219265339References: N/A

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-42506

    Last Modified: 17 Apr 2025

    In SimUpdatePbEntry::encode of simdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-241388399References: N/A

    Published: 16 Dec 2022
    4.3
    Medium

    CVE-2022-4565

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic was found in Dromara HuTool up to 5.8.10. This vulnerability affects unknown code of the file cn.hutool.core.util.ZipUtil.java. The manipulation leads to resource consumption. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 5.8.11 is able to address this issue. It is recommended to upgrade the affected component. VDB-215974 is the identifier assigned to this vulnerability.

    Published: 16 Dec 2022
    8.8
    High

    CVE-2022-47208

    Last Modified: 17 Apr 2025

    The “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticated attacker on the same network segment as the router can execute arbitrary commands on the device without authentication.

    Published: 16 Dec 2022
    9.8
    Critical

    CVE-2022-47377

    Last Modified: 16 Apr 2025

    Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase in their privileges on the system and thereby affecting the confidentiality integrity and availability of the system. An attacker can expect repeatable success by exploiting the vulnerability. The recommended solution is to update the firmware to a version >= 1.13.4 as soon as possible (available in SICK Support Portal).

    Published: 16 Dec 2022
    5.4
    Medium

    CVE-2022-38106

    Last Modified: 25 Feb 2026

    This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function.

    Published: 16 Dec 2022