CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2022-25692

    Last Modified: 22 Apr 2025

    Denial of service in Modem due to reachable assertion while processing the common config procedure in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 13 Dec 2022
    8.4
    High

    CVE-2022-25698

    Last Modified: 22 Apr 2025

    Memory corruption in SPI buses due to improper input validation while reading address configuration from spi buses in Snapdragon Mobile, Snapdragon Wearables

    Published: 13 Dec 2022
    7.5
    High

    CVE-2022-25702

    Last Modified: 22 Apr 2025

    Denial of service in modem due to reachable assertion while processing reconfiguration message in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 13 Dec 2022
    6.7
    Medium

    CVE-2022-25711

    Last Modified: 22 Apr 2025

    Memory corruption in camera due to improper validation of array index in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 13 Dec 2022
    6.5
    Medium

    CVE-2022-27581

    Last Modified: 22 Apr 2025

    Use of a Broken or Risky Cryptographic Algorithm in SICK RFU61x firmware version <v2.25 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encryption via the SSH interface. The patch and installation procedure for the firmware update is available from the responsible SICK customer contact person.

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2022-3105

    Last Modified: 22 Apr 2025

    An issue was discovered in the Linux kernel through 5.16-rc6. uapi_finalize in drivers/infiniband/core/uverbs_uapi.c lacks check of kmalloc_array().

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2022-3107

    Last Modified: 22 Apr 2025

    An issue was discovered in the Linux kernel through 5.16-rc6. netvsc_get_ethtool_stats in drivers/net/hyperv/netvsc_drv.c lacks check of the return value of kvmalloc_array() and will cause the null pointer dereference.

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2022-3108

    Last Modified: 22 Apr 2025

    An issue was discovered in the Linux kernel through 5.16-rc6. kfd_parse_subtype_iolink in drivers/gpu/drm/amd/amdkfd/kfd_crat.c lacks check of the return value of kmemdup().

    Published: 13 Dec 2022
    7.5
    High

    CVE-2022-45688

    Last Modified: 19 Sept 2025

    A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.

    Published: 13 Dec 2022
    7.5
    High

    CVE-2022-45690

    Last Modified: 25 Sept 2025

    A stack overflow in the org.json.JSONTokener.nextValue::JSONTokener.java component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.

    Published: 13 Dec 2022
    5.3
    Medium

    CVE-2022-31698

    Last Modified: 31 Oct 2025

    The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to trigger a denial-of-service condition by sending a specially crafted header.

    Published: 13 Dec 2022
    7.5
    High

    CVE-2022-23514

    Last Modified: 3 Nov 2025

    Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah < 2.19.1 contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption. This issue is patched in version 2.19.1.

    Published: 13 Dec 2022
    6.1
    Medium

    CVE-2022-23515

    Last Modified: 3 Nov 2025

    Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.1.0, < 2.19.1 is vulnerable to cross-site scripting via the image/svg+xml media type in data URIs. This issue is patched in version 2.19.1.

    Published: 13 Dec 2022
    7.5
    High

    CVE-2022-23516

    Last Modified: 3 Nov 2025

    Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.2.0, < 2.19.1 uses recursion for sanitizing CDATA sections, making it susceptible to stack exhaustion and raising a SystemStackError exception. This may lead to a denial of service through CPU resource consumption. This issue is patched in version 2.19.1. Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized.

    Published: 13 Dec 2022
    6.1
    Medium

    CVE-2022-23518

    Last Modified: 3 Nov 2025

    rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, < 1.4.4 are vulnerable to cross-site scripting via data URIs when used in combination with Loofah >= 2.1.0. This issue is patched in version 1.4.4.

    Published: 13 Dec 2022
    7.2
    High

    CVE-2022-23519

    Last Modified: 3 Nov 2025

    rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer may allow an attacker to inject content if the application developer has overridden the sanitizer's allowed tags in either of the following ways: allow both "math" and "style" elements, or allow both "svg" and "style" elements. Code is only impacted if allowed tags are being overridden. . This issue is fixed in version 1.4.4. All users overriding the allowed tags to include "math" or "svg" and "style" should either upgrade or use the following workaround immediately: Remove "style" from the overridden allowed tags, or remove "math" and "svg" from the overridden allowed tags.

    Published: 13 Dec 2022
    6.1
    Medium

    CVE-2022-23520

    Last Modified: 3 Nov 2025

    rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, there is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer due to an incomplete fix of CVE-2022-32209. Rails::Html::Sanitizer may allow an attacker to inject content if the application developer has overridden the sanitizer's allowed tags to allow both "select" and "style" elements. Code is only impacted if allowed tags are being overridden. This issue is patched in version 1.4.4. All users overriding the allowed tags to include both "select" and "style" should either upgrade or use this workaround: Remove either "select" or "style" from the overridden allowed tags. NOTE: Code is _not_ impacted if allowed tags are overridden using either the :tags option to the Action View helper method sanitize or the :tags option to the instance method SafeListSanitizer#sanitize.

    Published: 13 Dec 2022
    8.6
    High

    CVE-2022-4904

    Last Modified: 2 Dec 2025

    A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.

    Published: 13 Dec 2022
    9.8
    Critical

    CVE-2022-27518

    Last Modified: 25 Feb 2026

    Unauthenticated remote arbitrary code execution

    Published: 13 Dec 2022
    5.3
    Medium

    CVE-2022-45044

    Last Modified: 11 Nov 2025

    A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.50), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions < V9.50), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions < V9.50), SIPROTEC 5 6MD89 (CP300) (All versions < V9.64), SIPROTEC 5 6MU85 (CP300) (All versions < V9.50), SIPROTEC 5 7KE85 (CP200) (All versions), SIPROTEC 5 7KE85 (CP300) (All versions < V9.64), SIPROTEC 5 7SA82 (CP100) (All versions < V8.90), SIPROTEC 5 7SA82 (CP150) (All versions < V9.50), SIPROTEC 5 7SA84 (CP200) (All versions), SIPROTEC 5 7SA86 (CP200) (All versions), SIPROTEC 5 7SA86 (CP300) (All versions < V9.50), SIPROTEC 5 7SA87 (CP200) (All versions), SIPROTEC 5 7SA87 (CP300) (All versions < V9.50), SIPROTEC 5 7SD82 (CP100) (All versions < V8.90), SIPROTEC 5 7SD82 (CP150) (All versions < V9.50), SIPROTEC 5 7SD84 (CP200) (All versions), SIPROTEC 5 7SD86 (CP200) (All versions), SIPROTEC 5 7SD86 (CP300) (All versions < V9.50), SIPROTEC 5 7SD87 (CP200) (All versions), SIPROTEC 5 7SD87 (CP300) (All versions < V9.50), SIPROTEC 5 7SJ81 (CP100) (All versions < V8.89), SIPROTEC 5 7SJ81 (CP150) (All versions < V9.50), SIPROTEC 5 7SJ82 (CP100) (All versions < V8.89), SIPROTEC 5 7SJ82 (CP150) (All versions < V9.50), SIPROTEC 5 7SJ85 (CP200) (All versions), SIPROTEC 5 7SJ85 (CP300) (All versions < V9.50), SIPROTEC 5 7SJ86 (CP200) (All versions), SIPROTEC 5 7SJ86 (CP300) (All versions < V9.50), SIPROTEC 5 7SK82 (CP100) (All versions < V8.89), SIPROTEC 5 7SK82 (CP150) (All versions < V9.50), SIPROTEC 5 7SK85 (CP200) (All versions), SIPROTEC 5 7SK85 (CP300) (All versions < V9.50), SIPROTEC 5 7SL82 (CP100) (All versions < V8.90), SIPROTEC 5 7SL82 (CP150) (All versions < V9.50), SIPROTEC 5 7SL86 (CP200) (All versions), SIPROTEC 5 7SL86 (CP300) (All versions < V9.50), SIPROTEC 5 7SL87 (CP200) (All versions), SIPROTEC 5 7SL87 (CP300) (All versions < V9.50), SIPROTEC 5 7SS85 (CP200) (All versions), SIPROTEC 5 7SS85 (CP300) (All versions < V9.50), SIPROTEC 5 7ST85 (CP200) (All versions), SIPROTEC 5 7ST85 (CP300) (All versions < V9.64), SIPROTEC 5 7ST86 (CP300) (All versions < V9.64), SIPROTEC 5 7SX82 (CP150) (All versions < V9.50), SIPROTEC 5 7SX85 (CP300) (All versions < V9.50), SIPROTEC 5 7UM85 (CP300) (All versions < V9.50), SIPROTEC 5 7UT82 (CP100) (All versions < V8.90), SIPROTEC 5 7UT82 (CP150) (All versions < V9.50), SIPROTEC 5 7UT85 (CP200) (All versions), SIPROTEC 5 7UT85 (CP300) (All versions < V9.50), SIPROTEC 5 7UT86 (CP200) (All versions), SIPROTEC 5 7UT86 (CP300) (All versions < V9.50), SIPROTEC 5 7UT87 (CP200) (All versions), SIPROTEC 5 7UT87 (CP300) (All versions < V9.50), SIPROTEC 5 7VE85 (CP300) (All versions < V9.50), SIPROTEC 5 7VK87 (CP200) (All versions), SIPROTEC 5 7VK87 (CP300) (All versions < V9.50), SIPROTEC 5 7VU85 (CP300) (All versions < V9.50), SIPROTEC 5 Communication Module ETH-BA-2EL (Rev.1) (All versions installed on CP200 devices), SIPROTEC 5 Communication Module ETH-BA-2EL (Rev.1) (All versions < V9.50 installed on CP150 and CP300 devices), SIPROTEC 5 Communication Module ETH-BA-2EL (Rev.1) (All versions < V8.89 installed on CP100 devices), SIPROTEC 5 Communication Module ETH-BB-2FO (Rev. 1) (All versions installed on CP200 devices), SIPROTEC 5 Communication Module ETH-BB-2FO (Rev. 1) (All versions < V9.50 installed on CP150 and CP300 devices), SIPROTEC 5 Communication Module ETH-BB-2FO (Rev. 1) (All versions < V8.89 installed on CP100 devices), SIPROTEC 5 Communication Module ETH-BD-2FO (All versions < V9.50), SIPROTEC 5 Compact 7SX800 (CP050) (All versions < V9.50). Affected devices do not properly restrict secure client-initiated renegotiations within the SSL and TLS protocols. This could allow an attacker to create a denial of service condition on the ports 443/tcp and 4443/tcp for the duration of the attack.

    Published: 13 Dec 2022
    5.1
    Medium

    CVE-2022-4455

    Last Modified: 15 Dec 2025

    A vulnerability was identified in sproctor php-calendar up to 2.0.13. This impacts an unknown function of the file index.php. Such manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be launched remotely. The name of the patch is a2941109b42201c19733127ced763e270a357809. It is advisable to implement a patch to correct this issue.

    Published: 13 Dec 2022
    7.5
    High

    CVE-2022-45685

    Last Modified: 22 Apr 2025

    A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.

    Published: 13 Dec 2022
    7.5
    High

    CVE-2022-45693

    Last Modified: 22 Apr 2025

    Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

    Published: 13 Dec 2022
    8.2
    High

    CVE-2022-33235

    Last Modified: 22 Apr 2025

    Information disclosure due to buffer over-read in WLAN firmware while parsing security context info attributes. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 13 Dec 2022
    8.2
    High

    CVE-2022-33268

    Last Modified: 22 Apr 2025

    Information disclosure due to buffer over-read in Bluetooth HOST while pairing and connecting A2DP. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 13 Dec 2022
    6.1
    Medium

    CVE-2022-38628

    Last Modified: 22 Apr 2025

    Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a cross-site scripting (XSS) vulnerability which is chained with a local session fixation. This vulnerability allows attackers to escalate privileges via unspecified vectors.

    Published: 13 Dec 2022
    7.2
    High

    CVE-2022-46051

    Last Modified: 22 Apr 2025

    The approve parameter from the AeroCMS-v0.0.1 CMS system is vulnerable to SQL injection attacks.

    Published: 13 Dec 2022
    6.5
    Medium

    CVE-2022-46059

    Last Modified: 22 Apr 2025

    AeroCMS v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF).

    Published: 13 Dec 2022
    6.1
    Medium

    CVE-2022-46061

    Last Modified: 22 Apr 2025

    AeroCMS v0.0.1 is vulnerable to ClickJacking.

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-41121

    Last Modified: 22 Jul 2025

    Windows Graphics Component Elevation of Privilege Vulnerability

    Published: 13 Dec 2022
    8.5
    High

    CVE-2022-41127

    Last Modified: 22 Jul 2025

    Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability

    Published: 13 Dec 2022
    3.3
    Low

    CVE-2022-41279

    Last Modified: 21 Apr 2025

    A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.4), Teamcenter Visualization V14.1 (All versions < V14.1.0.6). The CGM_NIST_Loader.dll contains a null pointer dereference vulnerability while parsing specially crafted CGM files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-41282

    Last Modified: 21 Apr 2025

    A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.4), Teamcenter Visualization V14.1 (All versions < V14.1.0.6). The CGM_NIST_Loader.dll contains an out of bounds read vulnerability when parsing a CGM file. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-41286

    Last Modified: 21 Apr 2025

    A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.4), Teamcenter Visualization V14.1 (All versions < V14.1.0.6). The CGM_NIST_Loader.dll contains an out of bounds write vulnerability when parsing a CGM file. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 13 Dec 2022
    3.3
    Low

    CVE-2022-41287

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.4), Teamcenter Visualization V14.1 (All versions < V14.1.0.6). The CGM_NIST_Loader.dll contains divide by zero vulnerability when parsing a CGM file. An attacker could leverage this vulnerability to crash the application causing denial of service condition.

    Published: 13 Dec 2022
    6.1
    Medium

    CVE-2022-44303

    Last Modified: 22 Apr 2025

    Resque Scheduler version 1.27.4 is vulnerable to Cross-site scripting (XSS). A remote attacker could inject javascript code to the "{schedule_job}" or "args" parameter in /resque/delayed/jobs/{schedule_job}?args={args_id} to execute javascript at client side.

    Published: 13 Dec 2022
    3.5
    Low

    CVE-2022-4444

    Last Modified: 15 Apr 2025

    A vulnerability was found in ipti br.tag. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 2.13.0 is able to address this issue. The name of the patch is 7e311be22d3a0a1b53e61cb987ba13d681d85f06. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-215431.

    Published: 13 Dec 2022
    9.8
    Critical

    CVE-2022-4446

    Last Modified: 14 Apr 2025

    PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.

    Published: 13 Dec 2022
    6.1
    Medium

    CVE-2022-44575

    Last Modified: 22 Apr 2025

    A vulnerability has been identified in PLM Help Server V4.2 (All versions). A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the affected application that could allow an attacker to execute malicious javascript code by tricking users into accessing a malicious link.

    Published: 13 Dec 2022
    4.6
    Medium

    CVE-2022-44636

    Last Modified: 22 Apr 2025

    The Samsung TV (2021 and 2022 model) smart remote control allows attackers to enable microphone access via Bluetooth spoofing when a user is activating remote control by pressing a button. This is fixed in xxx72510, E9172511 for 2021 models, xxxA1000, 4x2A0200 for 2022 models.

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-44666

    Last Modified: 27 Aug 2025

    Windows Contacts Remote Code Execution Vulnerability

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-44667

    Last Modified: 22 Jul 2025

    Windows Media Remote Code Execution Vulnerability

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-44668

    Last Modified: 22 Jul 2025

    Windows Media Remote Code Execution Vulnerability

    Published: 13 Dec 2022
    7
    High

    CVE-2022-44669

    Last Modified: 22 Jul 2025

    Windows Error Reporting Elevation of Privilege Vulnerability

    Published: 13 Dec 2022
    8.1
    High

    CVE-2022-44670

    Last Modified: 22 Jul 2025

    Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-44671

    Last Modified: 22 Jul 2025

    Windows Graphics Component Elevation of Privilege Vulnerability

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-44675

    Last Modified: 22 Jul 2025

    Windows Bluetooth Driver Elevation of Privilege Vulnerability

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-44677

    Last Modified: 22 Jul 2025

    Windows Projected File System Elevation of Privilege Vulnerability

    Published: 13 Dec 2022
    6.5
    Medium

    CVE-2022-44679

    Last Modified: 22 Jul 2025

    Windows Graphics Component Information Disclosure Vulnerability

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-44680

    Last Modified: 22 Jul 2025

    Windows Graphics Component Elevation of Privilege Vulnerability

    Published: 13 Dec 2022