CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2022-42511

    Last Modified: 18 Apr 2025

    In EmbmsSessionData::encode of embmsdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-241762712References: N/A

    Published: 16 Dec 2022
    4.4
    Medium

    CVE-2022-42512

    Last Modified: 18 Apr 2025

    In VsimOperationDataExt::encode of vsimdata.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-241763050References: N/A

    Published: 16 Dec 2022
    5.5
    Medium

    CVE-2022-20199

    Last Modified: 21 Apr 2025

    In multiple locations of NfcService.java, there is a possible disclosure of NFC tags due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-199291025

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-20505

    Last Modified: 21 Apr 2025

    In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitationProduct: AndroidVersions: Android-13Android ID: A-225981754

    Published: 16 Dec 2022
    7.8
    High

    CVE-2022-20506

    Last Modified: 21 Apr 2025

    In onCreate of WifiDialogActivity.java, there is a missing permission check. This could lead to local escalation of privilege from a guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-226133034

    Published: 16 Dec 2022
    5.5
    Medium

    CVE-2022-20510

    Last Modified: 21 Apr 2025

    In getNearbyNotificationStreamingPolicy of DevicePolicyManagerService.java, there is a possible way to learn about the notification streaming policy of other users due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-235822336

    Published: 16 Dec 2022
    7.8
    High

    CVE-2022-20512

    Last Modified: 21 Apr 2025

    In navigateUpTo of Task.java, there is a possible way to launch an intent handler with a mismatched intent due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-238602879

    Published: 16 Dec 2022
    5.5
    Medium

    CVE-2022-20513

    Last Modified: 21 Apr 2025

    In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-244569759

    Published: 16 Dec 2022
    5.5
    Medium

    CVE-2022-20518

    Last Modified: 18 Apr 2025

    In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224770203

    Published: 16 Dec 2022
    3.3
    Low

    CVE-2022-20519

    Last Modified: 18 Apr 2025

    In onCreate of AddAppNetworksActivity.java, there is a possible way for a guest user to configure WiFi networks due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224772678

    Published: 16 Dec 2022
    7.8
    High

    CVE-2022-20524

    Last Modified: 21 Apr 2025

    In compose of Vibrator.cpp, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-228523213

    Published: 16 Dec 2022
    3.3
    Low

    CVE-2022-20525

    Last Modified: 21 Apr 2025

    In enforceVisualVoicemailPackage of PhoneInterfaceManager.java, there is a possible leak of visual voicemail package name due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-229742768

    Published: 16 Dec 2022
    5.3
    Medium

    CVE-2022-20530

    Last Modified: 18 Apr 2025

    In strings.xml, there is a possible permission bypass due to a misleading string. This could lead to remote information disclosure of call logs with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-231585645

    Published: 16 Dec 2022
    3.3
    Low

    CVE-2022-20536

    Last Modified: 18 Apr 2025

    In registerBroadcastReceiver of RcsService.java, there is a possible way to change preferred TTY mode due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-235100180

    Published: 16 Dec 2022
    7.8
    High

    CVE-2022-20540

    Last Modified: 18 Apr 2025

    In SurfaceFlinger::doDump of SurfaceFlinger.cpp, there is possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-237291506

    Published: 16 Dec 2022
    4.2
    Medium

    CVE-2022-20541

    Last Modified: 21 Apr 2025

    In phNxpNciHal_ioctl of phNxpNciHal.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-238083126

    Published: 16 Dec 2022
    4.4
    Medium

    CVE-2022-20544

    Last Modified: 21 Apr 2025

    In onOptionsItemSelected of ManageApplications.java, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-238745070

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-20554

    Last Modified: 18 Apr 2025

    In removeEventHubDevice of InputDevice.cpp, there is a possible OOB read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-245770596

    Published: 16 Dec 2022
    4.4
    Medium

    CVE-2022-20555

    Last Modified: 18 Apr 2025

    In ufdt_get_node_by_path_len of ufdt_convert.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-246194233

    Published: 16 Dec 2022
    3.3
    Low

    CVE-2022-20558

    Last Modified: 18 Apr 2025

    In registerReceivers of DeviceCapabilityListener.java, there is a possible way to change preferred TTY mode due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-236264289

    Published: 16 Dec 2022
    3.3
    Low

    CVE-2022-20559

    Last Modified: 18 Apr 2025

    In revokeOwnPermissionsOnKill of PermissionManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-219739967

    Published: 16 Dec 2022
    7.5
    High

    CVE-2022-20560

    Last Modified: 18 Apr 2025

    Product: AndroidVersions: Android kernelAndroid ID: A-212623833References: N/A

    Published: 16 Dec 2022
    4.3
    Medium

    CVE-2022-41960

    Last Modified: 17 Apr 2025

    BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3, are subject to Insufficient Verification of Data Authenticity, resulting in Denial of Service. An attacker can make a Meteor call to `validateAuthToken` using a victim's userId, meetingId, and an invalid authToken. This forces the victim to leave the conference, because the resulting verification failure is also observed and handled by the victim's client. The attacker must be a participant in any meeting on the server. This issue is patched in version 2.4.3. There are no workarounds.

    Published: 15 Dec 2022
    —
    Unknown

    CVE-2022-4531

    Last Modified: 7 Nov 2023

    Not a valid vulnerability.

    Published: 15 Dec 2022
    —
    Unknown

    CVE-2022-4530

    Last Modified: 30 Aug 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error and is not a valid vulnerability. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 15 Dec 2022
    —
    Unknown

    CVE-2022-4528

    Last Modified: 30 Aug 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error and is not a valid vulnerability. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 15 Dec 2022
    2
    Low

    CVE-2022-38653

    Last Modified: 18 Apr 2025

    In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.

    Published: 15 Dec 2022
    6.1
    Medium

    CVE-2022-38662

    Last Modified: 18 Apr 2025

     In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.

    Published: 15 Dec 2022
    5.5
    Medium

    CVE-2022-4519

    Last Modified: 8 Apr 2026

    The WP User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters in versions up to, and including, 7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 15 Dec 2022
    9.8
    Critical

    CVE-2021-4226

    Last Modified: 27 May 2025

    RSFirewall tries to identify the original IP address by looking at different HTTP headers. A bypass is possible due to the way it is implemented.

    Published: 15 Dec 2022
    9.9
    Critical

    CVE-2022-44588

    Last Modified: 28 Apr 2026

    Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.

    Published: 15 Dec 2022
    5.9
    Medium

    CVE-2022-32531

    Last Modified: 17 Apr 2025

    The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verification fails. This leaves the bookkeeper client vulnerable to a man in the middle attack. The problem affects BookKeeper client prior to versions 4.14.6 and 4.15.1.

    Published: 15 Dec 2022
    6.1
    Medium

    CVE-2022-32763

    Last Modified: 15 Apr 2025

    A cross-site scripting (xss) sanitization vulnerability bypass exists in the SanitizeHtml functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 15 Dec 2022
    9.9
    Critical

    CVE-2022-32573

    Last Modified: 15 Apr 2025

    A directory traversal vulnerability exists in the AssetActions.aspx addDoc functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 15 Dec 2022
    9.9
    Critical

    CVE-2022-29517

    Last Modified: 15 Apr 2025

    A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 15 Dec 2022
    6.5
    Medium

    CVE-2022-29511

    Last Modified: 15 Apr 2025

    A directory traversal vulnerability exists in the KnowledgebasePageActions.aspx ImportArticles functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 15 Dec 2022
    5.4
    Medium

    CVE-2022-28703

    Last Modified: 15 Apr 2025

    A stored cross-site scripting vulnerability exists in the HdConfigActions.aspx altertextlanguages functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 15 Dec 2022
    6.5
    Medium

    CVE-2022-27498

    Last Modified: 15 Apr 2025

    A directory traversal vulnerability exists in the TicketTemplateActions.aspx GetTemplateAttachment functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 15 Dec 2022
    5.9
    Medium

    CVE-2022-46768

    Last Modified: 16 Apr 2025

    Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files.

    Published: 15 Dec 2022
    7.5
    High

    CVE-2022-4379

    Last Modified: 8 Apr 2025

    A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allows an attacker to conduct a remote denial

    Published: 15 Dec 2022
    8.8
    High

    CVE-2022-3427

    Last Modified: 8 Apr 2026

    The Corner Ad plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.56. This is due to missing or incorrect nonce validation on its corner_ad_settings_page function. This makes it possible for unauthenticated attackers to trigger the deletion of ads via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 15 Dec 2022
    5.3
    Medium

    CVE-2022-2536

    Last Modified: 8 Apr 2026

    The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient validation of settings on the 'tp_translation' AJAX action which makes it possible for unauthenticated attackers to bypass any restrictions and influence the data shown on the site. Please note this is a separate issue from CVE-2022-2461. Notes from the researcher: When installed Transposh comes with a set of pre-configured options, one of these is the "Who can translate" setting under the "Settings" tab. However, this option is largely ignored, if Transposh has enabled its "autotranslate" feature (it's enabled by default) and the HTTP POST parameter "sr0" is larger than 0. This is caused by a faulty validation in "wp/transposh_db.php."

    Published: 15 Dec 2022
    6.1
    Medium

    CVE-2022-23474

    Last Modified: 17 Apr 2025

    Editor.js is a block-style editor with clean JSON output. Versions prior to 2.26.0 are vulnerable to Code Injection via pasted input. The processHTML method passes pasted input into wrapper’s innerHTML. This issue is patched in version 2.26.0.

    Published: 15 Dec 2022
    5.4
    Medium

    CVE-2022-23507

    Last Modified: 18 Apr 2025

    Tendermint is a high-performance blockchain consensus engine for Byzantine fault tolerant applications. Versions prior to 0.28.0 contain a potential attack via Improper Verification of Cryptographic Signature, affecting anyone using the tendermint-light-client and related packages to perform light client verification (e.g. IBC-rs, Hermes). The light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. This issue is patched in version 0.28.0. There are no workarounds.

    Published: 15 Dec 2022
    9.8
    Critical

    CVE-2022-46393

    Last Modified: 5 Jun 2026

    An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL_CID_IN_LEN_MAX > 2 * MBEDTLS_SSL_CID_OUT_LEN_MAX.

    Published: 15 Dec 2022
    9.8
    Critical

    CVE-2022-45969

    Last Modified: 13 Feb 2026

    Alist v3.4.0 is vulnerable to Directory Traversal,

    Published: 15 Dec 2022
    4.3
    Medium

    CVE-2022-32945

    Last Modified: 21 Apr 2025

    An access issue was addressed with additional sandbox restrictions on third-party apps. This issue is fixed in macOS Ventura 13. An app may be able to record audio with paired AirPods.

    Published: 15 Dec 2022
    5.3
    Medium

    CVE-2022-23525

    Last Modified: 18 Apr 2025

    Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the _repo_package. The _repo_ package contains a handler that processes the index file of a repository. For example, the Helm client adds references to chart repositories where charts are managed. The _repo_ package parses the index file of the repository and loads it into structures Go can work with. Some index files can cause array data structures to be created causing a memory violation. Applications that use the _repo_ package in the Helm SDK to parse an index file can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The Helm Client will panic with an index file that causes a memory violation panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. This issue has been patched in 3.10.3. SDK users can validate index files that are correctly formatted before passing them to the _repo_ functions.

    Published: 15 Dec 2022
    5.3
    Medium

    CVE-2022-4511

    Last Modified: 14 Apr 2025

    A vulnerability has been found in RainyGao DocSys and classified as critical. Affected by this vulnerability is an unknown functionality of the component com.DocSystem.controller.UserController#getUserImg. The manipulation leads to path traversal: '../filedir'. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-215851.

    Published: 15 Dec 2022
    3.5
    Low

    CVE-2022-4513

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in European Environment Agency eionet.contreg. This issue affects some unknown processing. The manipulation of the argument searchTag/resourceUri leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 2022-06-27T0948 is able to address this issue. The name of the patch is a120c2153e263e62c4db34a06ab96a9f1c6bccb6. It is recommended to upgrade the affected component. The identifier VDB-215885 was assigned to this vulnerability.

    Published: 15 Dec 2022