CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-44681

    Last Modified: 22 Jul 2025

    Windows Print Spooler Elevation of Privilege Vulnerability

    Published: 13 Dec 2022
    6.8
    Medium

    CVE-2022-44682

    Last Modified: 22 Jul 2025

    Windows Hyper-V Denial of Service Vulnerability

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-44697

    Last Modified: 22 Jul 2025

    Windows Graphics Component Elevation of Privilege Vulnerability

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2022-44699

    Last Modified: 22 Jul 2025

    Azure Network Watcher Agent Security Feature Bypass Vulnerability

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-44702

    Last Modified: 22 Jul 2025

    Windows Terminal Remote Code Execution Vulnerability

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-44704

    Last Modified: 22 Jul 2025

    Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability

    Published: 13 Dec 2022
    6.5
    Medium

    CVE-2022-44707

    Last Modified: 22 Jul 2025

    Windows Kernel Denial of Service Vulnerability

    Published: 13 Dec 2022
    5.4
    Medium

    CVE-2022-44731

    Last Modified: 21 Apr 2025

    A vulnerability has been identified in SIMATIC WinCC OA V3.15 (All versions < V3.15 P038), SIMATIC WinCC OA V3.16 (All versions < V3.16 P035), SIMATIC WinCC OA V3.17 (All versions < V3.17 P024), SIMATIC WinCC OA V3.18 (All versions < V3.18 P014). The affected component allows to inject custom arguments to the Ultralight Client backend application under certain circumstances. This could allow an authenticated remote attacker to inject arbitrary parameters when starting the client via the web interface (e.g., open attacker chosen panels with the attacker's credentials or start a Ctrl script).

    Published: 13 Dec 2022
    9.8
    Critical

    CVE-2022-45005

    Last Modified: 22 Apr 2025

    IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the cmd_get_ping_output function.

    Published: 13 Dec 2022
    3.3
    Low

    CVE-2022-45484

    Last Modified: 21 Apr 2025

    A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.9), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.5), Teamcenter Visualization V14.0 (All versions < V14.0.0.4), Teamcenter Visualization V14.1 (All versions < V14.1.0.6). The CCITT_G4Decode.dll contains an out of bounds read vulnerability when parsing a RAS file. An attacker can leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-19056)

    Published: 13 Dec 2022
    7.1
    High

    CVE-2022-46140

    Last Modified: 21 Apr 2025

    Affected devices use a weak encryption scheme to encrypt the debug zip file. This could allow an authenticated attacker to decrypt the contents of the file and retrieve debug information about the system.

    Published: 13 Dec 2022
    4.8
    Medium

    CVE-2022-46058

    Last Modified: 22 Apr 2025

    AeroCMS v0.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field.

    Published: 13 Dec 2022
    4.9
    Medium

    CVE-2022-46047

    Last Modified: 22 Apr 2025

    AeroCMS v0.0.1 is vulnerable to SQL Injection via the delete parameter.

    Published: 13 Dec 2022
    8.1
    High

    CVE-2022-45936

    Last Modified: 22 Apr 2025

    A vulnerability has been identified in Mendix Email Connector (All versions < V2.0.0). Affected versions of the module improperly handle access control for some module entities. This could allow authenticated remote attackers to read and manipulate sensitive information.

    Published: 13 Dec 2022
    8.8
    High

    CVE-2022-45937

    Last Modified: 21 Apr 2025

    A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), TALON TC Compact (BACnet) (All versions < V3.5.5), TALON TC Modular (BACnet) (All versions < V3.5.5). A low privilege authenticated attacker with network access to the integrated web server could download sensitive information from the device containing user account credentials.

    Published: 13 Dec 2022
    4.3
    Medium

    CVE-2022-45871

    Last Modified: 22 Apr 2025

    A Denial-of-Service (DoS) vulnerability was discovered in the fsicapd component used in WithSecure products whereby the service may crash while parsing ICAP request. The exploit can be triggered remotely by an attacker.

    Published: 13 Dec 2022
    5.4
    Medium

    CVE-2022-46265

    Last Modified: 21 Apr 2025

    A vulnerability has been identified in Polarion ALM (All versions < V2304.0). The affected application contains a Host header injection vulnerability that could allow an attacker to spoof a Host header information and redirect users to malicious websites.

    Published: 13 Dec 2022
    5.4
    Medium

    CVE-2022-44698

    Last Modified: 12 Jan 2026

    Windows SmartScreen Security Feature Bypass Vulnerability

    Published: 13 Dec 2022
    5.3
    Medium

    CVE-2019-25078

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic was found in pacparser up to 1.3.x. Affected by this vulnerability is the function pacparser_find_proxy of the file src/pacparser.c. The manipulation of the argument url leads to buffer overflow. Attacking locally is a requirement. Upgrading to version 1.4.0 is able to address this issue. The name of the patch is 853e8f45607cb07b877ffd270c63dbcdd5201ad9. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-215443.

    Published: 13 Dec 2022
    8.5
    High

    CVE-2022-41076

    Last Modified: 22 Jul 2025

    PowerShell Remote Code Execution Vulnerability

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-41281

    Last Modified: 21 Apr 2025

    A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.4), Teamcenter Visualization V14.1 (All versions < V14.1.0.6). The CGM_NIST_Loader.dll contains an out of bounds read vulnerability when parsing a CGM file. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-41283

    Last Modified: 21 Apr 2025

    A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.4), Teamcenter Visualization V14.1 (All versions < V14.1.0.6). The CGM_NIST_Loader.dll contains an out of bounds write vulnerability when parsing a CGM file. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 13 Dec 2022
    6.5
    Medium

    CVE-2022-41915

    Last Modified: 22 Apr 2025

    Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior to 4.1.86.Final, when calling `DefaultHttpHeadesr.set` with an _iterator_ of values, header value validation was not performed, allowing malicious header values in the iterator to perform HTTP Response Splitting. This issue has been patched in version 4.1.86.Final. Integrators can work around the issue by changing the `DefaultHttpHeaders.set(CharSequence, Iterator<?>)` call, into a `remove()` call, and call `add()` in a loop over the iterator of values.

    Published: 13 Dec 2022
    7.5
    High

    CVE-2022-43723

    Last Modified: 22 Apr 2025

    A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0), SICAM PAS/PQS (All versions >= 7.0 < V8.06). Affected software does not properly validate the input for a certain parameter in the s7ontcp.dll. This could allow an unauthenticated remote attacker to send messages and create a denial of service condition as the application crashes. At the time of assigning the CVE, the affected firmware version of the component has already been superseded by succeeding mainline versions.

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-46348

    Last Modified: 21 Apr 2025

    A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.264), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34.1 (All versions < V34.1.242), Parasolid V35.0 (All versions < V35.0.170), Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2022 (All versions), Solid Edge SE2023 (All versions < V223.0Update2). The affected applications contain an out of bounds write past the end of an allocated structure while parsing specially crafted X_B files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19383)

    Published: 13 Dec 2022
    6.1
    Medium

    CVE-2022-46350

    Last Modified: 22 Apr 2025

    A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The integrated web server could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. This can be used by an attacker to trigger a malicious request on the affected device.

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2022-46351

    Last Modified: 22 Apr 2025

    A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). Specially crafted PROFINET DCP packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2).

    Published: 13 Dec 2022
    9.8
    Critical

    CVE-2022-46353

    Last Modified: 22 Apr 2025

    A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The webserver of affected devices calculates session ids and nonces in an insecure manner. This could allow an unauthenticated remote attacker to brute-force session ids and hijack existing sessions.

    Published: 13 Dec 2022
    7.5
    High

    CVE-2022-46363

    Last Modified: 22 Apr 2025

    A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vulnerability only applies when the CXFServlet is configured with both the static-resources-list and redirect-query-check attributes. These attributes are not supposed to be used together, and so the vulnerability can only arise if the CXF service is misconfigured.

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-44678

    Last Modified: 22 Jul 2025

    Windows Print Spooler Elevation of Privilege Vulnerability

    Published: 13 Dec 2022
    8.3
    High

    CVE-2022-44708

    Last Modified: 22 Jul 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2022-44874

    Last Modified: 22 Apr 2025

    wasm3 commit 7890a2097569fde845881e0b352d813573e371f9 was discovered to contain a segmentation fault via the component op_CallIndirect at /m3_exec.h.

    Published: 13 Dec 2022
    5.2
    Medium

    CVE-2022-46142

    Last Modified: 21 Apr 2025

    Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device could retrieve the file and decrypt the CLI user passwords.

    Published: 13 Dec 2022
    6.5
    Medium

    CVE-2022-46833

    Last Modified: 22 Apr 2025

    Use of a Broken or Risky Cryptographic Algorithm in SICK RFU63x firmware version < v2.21 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encryption via the SSH interface. The patch and installation procedure for the firmware update is available from the responsible SICK customer contact person.

    Published: 13 Dec 2022
    6.5
    Medium

    CVE-2022-46875

    Last Modified: 15 Apr 2025

    The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.

    Published: 13 Dec 2022
    8.8
    High

    CVE-2022-46878

    Last Modified: 15 Apr 2025

    Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.

    Published: 13 Dec 2022
    6.5
    Medium

    CVE-2022-46880

    Last Modified: 15 Apr 2025

    A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.<br />*Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue. The fix was included in the original release of Firefox 105. This vulnerability affects Firefox ESR < 102.6, Firefox < 105, and Thunderbird < 102.6.

    Published: 13 Dec 2022
    6.5
    Medium

    CVE-2022-46832

    Last Modified: 21 Apr 2025

    Use of a Broken or Risky Cryptographic Algorithm in SICK RFU62x firmware version < 2.21 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encryption via the SSH interface. The patch and installation procedure for the firmware update is available from the responsible SICK customer contact person.

    Published: 13 Dec 2022
    6.5
    Medium

    CVE-2022-46834

    Last Modified: 22 Apr 2025

    Use of a Broken or Risky Cryptographic Algorithm in SICK RFU65x firmware version < v2.21 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encryption via the SSH interface. The patch and installation procedure for the firmware update is available from the responsible SICK customer contact person.

    Published: 13 Dec 2022
    8.8
    High

    CVE-2022-46874

    Last Modified: 15 Apr 2025

    A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code.<br/>*Note*: This issue was originally included in the advisories for Thunderbird 102.6, but a patch (specific to Thunderbird) was omitted, resulting in it actually being fixed in Thunderbird 102.6.1. This vulnerability affects Firefox < 108, Thunderbird < 102.6.1, Thunderbird < 102.6, and Firefox ESR < 102.6.

    Published: 13 Dec 2022
    9.8
    Critical

    CVE-2022-46882

    Last Modified: 15 Apr 2025

    A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firefox < 107, Firefox ESR < 102.6, and Thunderbird < 102.6.

    Published: 13 Dec 2022
    7
    High

    CVE-2021-39660

    Last Modified: 22 Apr 2025

    In TBD of TBD, there is a possible way to archive arbitrary code execution in kernel due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-254742984

    Published: 13 Dec 2022
    8.8
    High

    CVE-2022-42139

    Last Modified: 22 Apr 2025

    Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL.

    Published: 13 Dec 2022
    7.2
    High

    CVE-2022-42140

    Last Modified: 22 Apr 2025

    Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.

    Published: 13 Dec 2022
    5.4
    Medium

    CVE-2022-42141

    Last Modified: 22 Apr 2025

    Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Cross Site Scripting (XSS) via lform/urlfilter.

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2021-44694

    Last Modified: 21 Apr 2025

    Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.

    Published: 13 Dec 2022
    4.9
    Medium

    CVE-2021-44695

    Last Modified: 21 Apr 2025

    Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.

    Published: 13 Dec 2022
    8.8
    High

    CVE-2022-20411

    Last Modified: 22 Apr 2025

    In avdt_msg_asmbl of avdt_msg.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-232023771

    Published: 13 Dec 2022
    4.4
    Medium

    CVE-2022-20449

    Last Modified: 22 Apr 2025

    In writeApplicationRestrictionsLAr of UserManagerService.java, there is a possible overwrite of system files due to a path traversal error. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-239701237

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2022-20466

    Last Modified: 22 Apr 2025

    In applyKeyguardFlags of NotificationShadeWindowControllerImpl.java, there is a possible way to observe the user's password on a secondary display due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-179725730

    Published: 13 Dec 2022