CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2022-20469

    Last Modified: 22 Apr 2025

    In avct_lcb_msg_asmbl of avct_lcb_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-230867224

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-20470

    Last Modified: 22 Apr 2025

    In bindRemoteViewsService of AppWidgetServiceImpl.java, there is a possible way to bypass background activity launch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-234013191

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2022-20471

    Last Modified: 22 Apr 2025

    In SendIncDecRestoreCmdPart2 of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-238177877

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-20475

    Last Modified: 22 Apr 2025

    In test of ResetTargetTaskHelper.java, there is a possible hijacking of any app which sets allowTaskReparenting="true" due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-240663194

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2022-20476

    Last Modified: 22 Apr 2025

    In setEnabledSetting of PackageManager.java, there is a possible way to get the device into an infinite reboot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-240936919

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-20480

    Last Modified: 22 Apr 2025

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-241764350

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2022-20482

    Last Modified: 22 Apr 2025

    In createNotificationChannel of NotificationManager.java, there is a possible way to make the device unusable and require factory reset due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-240422263

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-20486

    Last Modified: 22 Apr 2025

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242703118

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-20487

    Last Modified: 22 Apr 2025

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242703202

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-20491

    Last Modified: 22 Apr 2025

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242703556

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2022-20496

    Last Modified: 22 Apr 2025

    In setDataSource of initMediaExtractor.cpp, there is a possibility of arbitrary code execution due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-245242273

    Published: 13 Dec 2022
    4.6
    Medium

    CVE-2022-20497

    Last Modified: 22 Apr 2025

    In updatePublicMode of NotificationLockscreenUserManagerImpl.java, there is a possible way to reveal sensitive notifications on the lockscreen due to an incorrect state transition. This could lead to local information disclosure with physical access required and an app that runs above the lockscreen, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-246301979

    Published: 13 Dec 2022
    4.4
    Medium

    CVE-2022-20498

    Last Modified: 22 Apr 2025

    In fdt_path_offset_namelen of fdt_ro.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-246465319

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2022-20500

    Last Modified: 22 Apr 2025

    In loadFromXml of ShortcutPackage.java, there is a possible crash on boot due to an uncaught exception. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-246540168

    Published: 13 Dec 2022
    7.3
    High

    CVE-2022-20501

    Last Modified: 22 Apr 2025

    In onCreate of EnableAccountPreferenceActivity.java, there is a possible way to mislead the user into enabling a malicious phone account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-246933359

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2022-20502

    Last Modified: 22 Apr 2025

    In GetResolvedMethod of entrypoint_utils-inl.h, there is a possible use after free due to a stale cache. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-222166527

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-20611

    Last Modified: 22 Apr 2025

    In deletePackageVersionedInternal of DeletePackageHelper.java, there is a possible way to bypass carrier restrictions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242996180

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-43517

    Last Modified: 21 Apr 2025

    A vulnerability has been identified in Simcenter STAR-CCM+ (All versions < V2306). The affected application improperly assigns file permissions to installation folders. This could allow a local attacker with an unprivileged account to override or modify the service executables and subsequently gain elevated privileges.

    Published: 13 Dec 2022
    7.5
    High

    CVE-2022-23517

    Last Modified: 3 Nov 2025

    rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails-html-sanitizer < 1.4.4 use an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption. This issue has been patched in version 1.4.4.

    Published: 13 Dec 2022
    6.3
    Medium

    CVE-2022-24480

    Last Modified: 22 Jul 2025

    Outlook for Android Elevation of Privilege Vulnerability

    Published: 13 Dec 2022
    4.5
    Medium

    CVE-2022-46062

    Last Modified: 22 Apr 2025

    Gym Management System v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF).

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-43722

    Last Modified: 22 Apr 2025

    A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software does not properly secure a folder containing library files. This could allow an attacker to place a custom malicious DLL in this folder which is then run with SYSTEM rights when a service is started that requires this DLL. At the time of assigning the CVE, the affected firmware version of the component has already been superseded by succeeding mainline versions.

    Published: 13 Dec 2022
    9.8
    Critical

    CVE-2022-43724

    Last Modified: 22 Apr 2025

    A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software transmits the database credentials for the inbuilt SQL server in cleartext. In combination with the by default enabled xp_cmdshell feature unauthenticated remote attackers could execute custom OS commands. At the time of assigning the CVE, the affected firmware version of the component has already been superseded by succeeding mainline versions.

    Published: 13 Dec 2022
    7.5
    High

    CVE-2022-45689

    Last Modified: 22 Apr 2025

    hutool-json v5.8.10 was discovered to contain an out of memory error.

    Published: 13 Dec 2022
    4.3
    Medium

    CVE-2022-44688

    Last Modified: 22 Jul 2025

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2021-0934

    Last Modified: 22 Apr 2025

    In findAllDeAccounts of AccountsDb.java, there is a possible denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-169762606

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-44689

    Last Modified: 22 Jul 2025

    Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability

    Published: 13 Dec 2022
    8.8
    High

    CVE-2022-44690

    Last Modified: 22 Jul 2025

    Microsoft SharePoint Server Remote Code Execution Vulnerability

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-44691

    Last Modified: 27 Aug 2025

    Microsoft Office OneNote Remote Code Execution Vulnerability

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-44692

    Last Modified: 22 Jul 2025

    Microsoft Office Graphics Remote Code Execution Vulnerability

    Published: 13 Dec 2022
    8.8
    High

    CVE-2022-44693

    Last Modified: 22 Jul 2025

    Microsoft SharePoint Server Remote Code Execution Vulnerability

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-44710

    Last Modified: 22 Jul 2025

    DirectX Graphics Kernel Elevation of Privilege Vulnerability

    Published: 13 Dec 2022
    7.5
    High

    CVE-2022-44713

    Last Modified: 22 Jul 2025

    Microsoft Outlook for Mac Spoofing Vulnerability

    Published: 13 Dec 2022
    7.5
    High

    CVE-2022-25673

    Last Modified: 22 Apr 2025

    Denial of service in MODEM due to reachable assertion while processing configuration from network in Snapdragon Mobile

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2022-25675

    Last Modified: 22 Apr 2025

    Denial of service due to reachable assertion in modem while processing filter rule from application client in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 13 Dec 2022
    6.7
    Medium

    CVE-2022-25712

    Last Modified: 22 Apr 2025

    Memory corruption in camera due to buffer copy without checking size of input in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 13 Dec 2022
    3.5
    Low

    CVE-2022-4456

    Last Modified: 15 Apr 2025

    A vulnerability has been found in falling-fruit and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. The name of the patch is 15adb8e1ea1f1c3e3d152fc266071f621ef0c621. It is recommended to apply a patch to fix this issue. VDB-215446 is the identifier assigned to this vulnerability.

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-26805

    Last Modified: 22 Jul 2025

    Microsoft Office Graphics Remote Code Execution Vulnerability

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-26806

    Last Modified: 22 Jul 2025

    Microsoft Office Graphics Remote Code Execution Vulnerability

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2022-3104

    Last Modified: 22 Apr 2025

    An issue was discovered in the Linux kernel through 5.16-rc6. lkdtm_ARRAY_BOUNDS in drivers/misc/lkdtm/bugs.c lacks check of the return value of kmalloc() and will cause the null pointer dereference.

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2022-3106

    Last Modified: 22 Apr 2025

    An issue was discovered in the Linux kernel through 5.16-rc6. ef100_update_stats in drivers/net/ethernet/sfc/ef100_nic.c lacks check of the return value of kmalloc().

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2022-3111

    Last Modified: 22 Apr 2025

    An issue was discovered in the Linux kernel through 5.16-rc6. free_charger_irq() in drivers/power/supply/wm8350_power.c lacks free of WM8350_IRQ_CHG_FAST_RDY, which is registered in wm8350_init_charger().

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2022-3113

    Last Modified: 22 Apr 2025

    An issue was discovered in the Linux kernel through 5.16-rc6. mtk_vcodec_fw_vpu_init in drivers/media/platform/mtk-vcodec/mtk_vcodec_fw_vpu.c lacks check of the return value of devm_kzalloc() and will cause the null pointer dereference.

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2022-3114

    Last Modified: 22 Apr 2025

    An issue was discovered in the Linux kernel through 5.16-rc6. imx_register_uart_clocks in drivers/clk/imx/clk.c lacks check of the return value of kcalloc() and will cause the null pointer dereference.

    Published: 13 Dec 2022
    8.8
    High

    CVE-2022-31696

    Last Modified: 22 Apr 2025

    VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox.

    Published: 13 Dec 2022
    6.1
    Medium

    CVE-2022-45028

    Last Modified: 22 Apr 2025

    A cross-site scripting (XSS) vulnerability in Arris NVG443B 9.3.0h3d36 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request sent to /cgi-bin/logs.ha.

    Published: 13 Dec 2022
    7.5
    High

    CVE-2022-33238

    Last Modified: 22 Apr 2025

    Transient DOS due to loop with unreachable exit condition in WLAN while processing an incoming FTM frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 13 Dec 2022
    8.8
    High

    CVE-2022-37155

    Last Modified: 22 Apr 2025

    RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.

    Published: 13 Dec 2022
    7.5
    High

    CVE-2022-3996

    Last Modified: 21 Nov 2024

    If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy processing being enabled on a publicly facing server is not considered to be a common setup. Policy processing is enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function. Update (31 March 2023): The description of the policy processing enablement was corrected based on CVE-2023-0466.

    Published: 13 Dec 2022
    7
    High

    CVE-2022-44673

    Last Modified: 22 Jul 2025

    Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

    Published: 13 Dec 2022