CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-45338

    Last Modified: 21 Apr 2025

    An arbitrary file upload vulnerability in the profile picture upload function of Exact Synergy Enterprise 267 before 267SP13 and Exact Synergy Enterprise 500 before 500SP6 allows attackers to execute arbitrary code via a crafted SVG file.

    Published: 15 Dec 2022
    5.5
    Medium

    CVE-2022-42821

    Last Modified: 21 Apr 2025

    A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Big Sur 11.7.2, macOS Ventura 13. An app may bypass Gatekeeper checks.

    Published: 15 Dec 2022
    9.8
    Critical

    CVE-2022-42837

    Last Modified: 21 Apr 2025

    An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, watchOS 9.2. A remote user may be able to cause unexpected app termination or arbitrary code execution.

    Published: 15 Dec 2022
    7.8
    High

    CVE-2022-42840

    Last Modified: 21 Apr 2025

    The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to execute arbitrary code with kernel privileges.

    Published: 15 Dec 2022
    9.8
    Critical

    CVE-2022-42842

    Last Modified: 21 Apr 2025

    The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.

    Published: 15 Dec 2022
    5.5
    Medium

    CVE-2022-42843

    Last Modified: 21 Apr 2025

    This issue was addressed with improved data protection. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. A user may be able to view sensitive user information.

    Published: 15 Dec 2022
    8.6
    High

    CVE-2022-42844

    Last Modified: 21 Apr 2025

    The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to break out of its sandbox.

    Published: 15 Dec 2022
    7.2
    High

    CVE-2022-42845

    Last Modified: 21 Apr 2025

    The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app with root privileges may be able to execute arbitrary code with kernel privileges.

    Published: 15 Dec 2022
    5.5
    Medium

    CVE-2022-42846

    Last Modified: 21 Apr 2025

    The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2. Parsing a maliciously crafted video file may lead to unexpected system termination.

    Published: 15 Dec 2022
    7.8
    High

    CVE-2022-42847

    Last Modified: 21 Apr 2025

    An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.1. An app may be able to execute arbitrary code with kernel privileges.

    Published: 15 Dec 2022
    7.8
    High

    CVE-2022-42848

    Last Modified: 21 Apr 2025

    A logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2, tvOS 16.2. An app may be able to execute arbitrary code with kernel privileges.

    Published: 15 Dec 2022
    7.8
    High

    CVE-2022-42849

    Last Modified: 21 Apr 2025

    An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue is fixed in iOS 16.2 and iPadOS 16.2, tvOS 16.2, watchOS 9.2. A user may be able to elevate privileges.

    Published: 15 Dec 2022
    7.8
    High

    CVE-2022-42850

    Last Modified: 21 Apr 2025

    The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to execute arbitrary code with kernel privileges.

    Published: 15 Dec 2022
    5.5
    Medium

    CVE-2022-42851

    Last Modified: 21 Apr 2025

    The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, tvOS 16.2. Parsing a maliciously crafted TIFF file may lead to disclosure of user information.

    Published: 15 Dec 2022
    5.5
    Medium

    CVE-2022-42853

    Last Modified: 21 Apr 2025

    An access issue was addressed with improved access restrictions. This issue is fixed in macOS Ventura 13.1. An app may be able to modify protected parts of the file system.

    Published: 15 Dec 2022
    5.5
    Medium

    CVE-2022-42854

    Last Modified: 21 Apr 2025

    The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1. An app may be able to disclose kernel memory.

    Published: 15 Dec 2022
    5.5
    Medium

    CVE-2022-42859

    Last Modified: 21 Apr 2025

    Multiple issues were addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, watchOS 9.2. An app may be able to bypass Privacy preferences.

    Published: 15 Dec 2022
    8.8
    High

    CVE-2022-42861

    Last Modified: 21 Apr 2025

    This issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2. An app may be able to break out of its sandbox.

    Published: 15 Dec 2022
    5.5
    Medium

    CVE-2022-42862

    Last Modified: 21 Apr 2025

    This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. An app may be able to bypass Privacy preferences.

    Published: 15 Dec 2022
    7
    High

    CVE-2022-42864

    Last Modified: 23 Apr 2025

    A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.

    Published: 15 Dec 2022
    5.5
    Medium

    CVE-2022-42866

    Last Modified: 21 Apr 2025

    The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to read sensitive location information.

    Published: 15 Dec 2022
    8.8
    High

    CVE-2022-42867

    Last Modified: 21 Apr 2025

    A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 15 Dec 2022
    9.8
    Critical

    CVE-2022-44236

    Last Modified: 21 Apr 2025

    Beijing Zed-3 Technologies Co.,Ltd VoIP simpliclty ASG 8.5.0.17807 (20181130-16:12) has a Weak password vulnerability.

    Published: 15 Dec 2022
    9.8
    Critical

    CVE-2022-46631

    Last Modified: 21 Apr 2025

    TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiSignalCfg function.

    Published: 15 Dec 2022
    7.8
    High

    CVE-2022-46693

    Last Modified: 21 Apr 2025

    An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing a maliciously crafted file may lead to arbitrary code execution.

    Published: 15 Dec 2022
    7.8
    High

    CVE-2022-46694

    Last Modified: 21 Apr 2025

    An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2, tvOS 16.2, watchOS 9.2. Parsing a maliciously crafted video file may lead to kernel code execution.

    Published: 15 Dec 2022
    8.8
    High

    CVE-2022-46696

    Last Modified: 21 Apr 2025

    A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 15 Dec 2022
    9.8
    Critical

    CVE-2022-46634

    Last Modified: 21 Apr 2025

    TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiWpsCfg function.

    Published: 15 Dec 2022
    6.5
    Medium

    CVE-2022-46698

    Last Modified: 21 Apr 2025

    A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may disclose sensitive user information.

    Published: 15 Dec 2022
    8.8
    High

    CVE-2022-46699

    Last Modified: 21 Apr 2025

    A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 15 Dec 2022
    8.8
    High

    CVE-2022-46700

    Last Modified: 21 Apr 2025

    A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 15 Dec 2022
    9.8
    Critical

    CVE-2021-33420

    Last Modified: 21 Apr 2025

    A deserialization issue discovered in inikulin replicator before 1.0.4 allows remote attackers to run arbitrary code via the fromSerializable function in TypedArray object.

    Published: 15 Dec 2022
    6.1
    Medium

    CVE-2021-36572

    Last Modified: 21 Apr 2025

    Cross Site Scripting (XSS) vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via the user name field of the login page.

    Published: 15 Dec 2022
    5.4
    Medium

    CVE-2021-36573

    Last Modified: 21 Apr 2025

    File Upload vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via crafted image upload.

    Published: 15 Dec 2022
    9.8
    Critical

    CVE-2021-39426

    Last Modified: 21 Apr 2025

    An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 parameter when the action parameter equals set.

    Published: 15 Dec 2022
    5.4
    Medium

    CVE-2021-39427

    Last Modified: 21 Apr 2025

    Cross site scripting vulnerability in 188Jianzhan 2.10 allows attackers to execute arbitrary code via the username parameter to /admin/reg.php.

    Published: 15 Dec 2022
    5.4
    Medium

    CVE-2021-39428

    Last Modified: 21 Apr 2025

    Cross Site Scripting (XSS) vulnerability in Users.php in eyoucms 1.5.4 allows remote attackers to run arbitrary code and gain escalated privilege via the filename for edit_users_head_pic.

    Published: 15 Dec 2022
    5.3
    Medium

    CVE-2022-23524

    Last Modified: 18 Apr 2025

    Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption, resulting in Denial of Service. Input to functions in the _strvals_ package can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the _strvals_ package in the Helm SDK can have a Denial of Service attack when they use this package and it panics. This issue has been patched in 3.10.3. SDK users can validate strings supplied by users won't create large arrays causing significant memory usage before passing them to the _strvals_ functions.

    Published: 15 Dec 2022
    8.8
    High

    CVE-2020-20588

    Last Modified: 21 Apr 2025

    File upload vulnerability in function upload in action/Core.class.php in zhimengzhe iBarn 1.5 allows remote attackers to run arbitrary code via avatar upload to index.php.

    Published: 15 Dec 2022
    6.1
    Medium

    CVE-2020-20589

    Last Modified: 21 Apr 2025

    Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag.

    Published: 15 Dec 2022
    6.1
    Medium

    CVE-2020-21219

    Last Modified: 25 Apr 2025

    Cross Site Scripting (XSS) vulnerability in Netgate pf Sense 2.4.4-Release-p3 and Netgate ACME package 0.6.3 allows remote attackers to to run arbitrary code via the RootFolder field to acme_certificate_edit.php page of the ACME package.

    Published: 15 Dec 2022
    5.3
    Medium

    CVE-2020-24855

    Last Modified: 12 May 2025

    Directory Traversal vulnerability in easywebpack-cli before 4.5.2 allows attackers to obtain sensitive information via crafted GET request.

    Published: 15 Dec 2022
    6.1
    Medium

    CVE-2020-36607

    Last Modified: 21 Apr 2025

    Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag.

    Published: 15 Dec 2022
    6.1
    Medium

    CVE-2022-4502

    Last Modified: 14 Apr 2025

    Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2.

    Published: 15 Dec 2022
    6.1
    Medium

    CVE-2022-4503

    Last Modified: 14 Apr 2025

    Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.0.2.

    Published: 15 Dec 2022
    5.3
    Medium

    CVE-2022-32833

    Last Modified: 21 Apr 2025

    An issue existed with the file paths used to store website data. The issue was resolved by improving how website data is stored. This issue is fixed in iOS 16. An unauthorized user may be able to access browsing history.

    Published: 15 Dec 2022
    7.8
    High

    CVE-2022-32860

    Last Modified: 21 Apr 2025

    An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, macOS Big Sur 11.6.8. An app may be able to execute arbitrary code with kernel privileges.

    Published: 15 Dec 2022
    5.5
    Medium

    CVE-2022-32916

    Last Modified: 21 Apr 2025

    An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 16. An app may be able to disclose kernel memory.

    Published: 15 Dec 2022
    7.8
    High

    CVE-2022-32942

    Last Modified: 21 Apr 2025

    The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2. An app may be able to execute arbitrary code with kernel privileges.

    Published: 15 Dec 2022
    5.3
    Medium

    CVE-2022-32943

    Last Modified: 21 Apr 2025

    The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Shake-to-undo may allow a deleted photo to be re-surfaced without authentication.

    Published: 15 Dec 2022