CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2022-44674

    Last Modified: 22 Jul 2025

    Windows Bluetooth Driver Information Disclosure Vulnerability

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2022-41074

    Last Modified: 22 Jul 2025

    Windows Graphics Component Information Disclosure Vulnerability

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-41077

    Last Modified: 22 Jul 2025

    Windows Fax Compose Form Elevation of Privilege Vulnerability

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-41094

    Last Modified: 22 Jul 2025

    Windows Hyper-V Elevation of Privilege Vulnerability

    Published: 13 Dec 2022
    6.6
    Medium

    CVE-2022-41115

    Last Modified: 22 Jul 2025

    Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability

    Published: 13 Dec 2022
    8.1
    High

    CVE-2022-44676

    Last Modified: 22 Jul 2025

    Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

    Published: 13 Dec 2022
    3.3
    Low

    CVE-2022-41278

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.4), Teamcenter Visualization V14.1 (All versions < V14.1.0.6). The CGM_NIST_Loader.dll contains a null pointer dereference vulnerability while parsing specially crafted CGM files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.

    Published: 13 Dec 2022
    3.3
    Low

    CVE-2022-41280

    Last Modified: 21 Apr 2025

    A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.4), Teamcenter Visualization V14.1 (All versions < V14.1.0.6). The CGM_NIST_Loader.dll contains a null pointer dereference vulnerability while parsing specially crafted CGM files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-41284

    Last Modified: 21 Apr 2025

    A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.4), Teamcenter Visualization V14.1 (All versions < V14.1.0.6). The CGM_NIST_Loader.dll contains an out of bounds read vulnerability when parsing a CGM file. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-41285

    Last Modified: 21 Apr 2025

    A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.4), Teamcenter Visualization V14.1 (All versions < V14.1.0.6). The CGM_NIST_Loader.dll contains a use-after-free vulnerability that could be triggered while parsing specially crafted CGM files. An attacker could leverage this vulnerability to execute code in the context of the current process.

    Published: 13 Dec 2022
    3.3
    Low

    CVE-2022-41288

    Last Modified: 21 Apr 2025

    A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.4), Teamcenter Visualization V14.1 (All versions < V14.1.0.6). The CGM_NIST_Loader.dll contains stack exhaustion vulnerability when parsing a CGM file. An attacker could leverage this vulnerability to crash the application causing denial of service condition.

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-44683

    Last Modified: 22 Jul 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-44687

    Last Modified: 22 Jul 2025

    Raw Image Extension Remote Code Execution Vulnerability

    Published: 13 Dec 2022
    7.5
    High

    CVE-2021-40365

    Last Modified: 21 Apr 2025

    Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.

    Published: 13 Dec 2022
    4.9
    Medium

    CVE-2021-44693

    Last Modified: 21 Apr 2025

    Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2023-0615

    Last Modified: 25 Mar 2025

    A memory leak flaw and potential divide by zero and Integer overflow was found in the Linux kernel V4L2 and vivid test code functionality. This issue occurs when a user triggers ioctls, such as VIDIOC_S_DV_TIMINGS ioctl. This could allow a local user to crash the system if vivid test code enabled.

    Published: 13 Dec 2022
    2.3
    Low

    CVE-2022-20240

    Last Modified: 22 Apr 2025

    In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location information due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-231496105

    Published: 13 Dec 2022
    7.3
    High

    CVE-2022-20442

    Last Modified: 22 Apr 2025

    In onCreate of ReviewPermissionsActivity.java, there is a possible way to grant permissions for a separate app with API level < 23 due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-176094367

    Published: 13 Dec 2022
    6.5
    Medium

    CVE-2022-20468

    Last Modified: 22 Apr 2025

    In BNEP_ConnectResp of bnep_api.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-228450451

    Published: 13 Dec 2022
    9.8
    Critical

    CVE-2022-20472

    Last Modified: 22 Apr 2025

    In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-239210579

    Published: 13 Dec 2022
    9.8
    Critical

    CVE-2022-20473

    Last Modified: 22 Apr 2025

    In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-239267173

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-20474

    Last Modified: 22 Apr 2025

    In readLazyValue of Parcel.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-240138294

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-20477

    Last Modified: 22 Apr 2025

    In shouldHideNotification of KeyguardNotificationVisibilityProvider.kt, there is a possible way to show hidden notifications due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-241611867

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-20478

    Last Modified: 22 Apr 2025

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-241764135

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-20479

    Last Modified: 22 Apr 2025

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-241764340

    Published: 13 Dec 2022
    7.5
    High

    CVE-2022-20483

    Last Modified: 22 Apr 2025

    In several functions that parse avrc response in avrc_pars_ct.cc and related files, there are possible out of bounds reads due to integer overflows. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242459126

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-20484

    Last Modified: 22 Apr 2025

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242702851

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-20485

    Last Modified: 22 Apr 2025

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242702935

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-20488

    Last Modified: 22 Apr 2025

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242703217

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-20495

    Last Modified: 22 Apr 2025

    In getEnabledAccessibilityServiceList of AccessibilityManager.java, there is a possible way to hide an accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-243849844

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-26804

    Last Modified: 22 Jul 2025

    Microsoft Office Graphics Remote Code Execution Vulnerability

    Published: 13 Dec 2022
    7.8
    High

    CVE-2022-41089

    Last Modified: 27 May 2026

    .NET Framework Remote Code Execution Vulnerability

    Published: 13 Dec 2022
    5.4
    Medium

    CVE-2022-43996

    Last Modified: 22 Apr 2025

    The csaf_provider package before 0.8.2 allows XSS via a crafted CSAF document uploaded as text/html. The endpoint upload allows valid CSAF advisories (JSON format) to be uploaded with Content-Type text/html and filenames ending in .html. When subsequently accessed via web browser, these advisories are served and interpreted as HTML pages. Such uploaded advisories can contain JavaScript code that will execute within the browser context of users inspecting the advisory.

    Published: 13 Dec 2022
    5.5
    Medium

    CVE-2022-4454

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, has been found in m0ver bible-online. Affected by this issue is the function query of the file src/main/java/custom/application/search.java of the component Search Handler. The manipulation leads to sql injection. The name of the patch is 6ef0aabfb2d4ccd53fcaa9707781303af357410e. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-215444.

    Published: 13 Dec 2022
    4.3
    Medium

    CVE-2022-41263

    Last Modified: 22 Apr 2025

    Due to a missing authentication check, SAP Business Objects Business Intelligence Platform (Web Intelligence) - versions 420, 430, allows an authenticated non-administrator attacker to modify the data source information for a document that is otherwise restricted. On successful exploitation, the attacker can modify information causing a limited impact on the integrity of the application.

    Published: 12 Dec 2022
    6.1
    Medium

    CVE-2022-41262

    Last Modified: 22 Apr 2025

    Due to insufficient input validation, SAP NetWeaver AS Java (HTTP Provider Service) - version 7.50, allows an unauthenticated attacker to inject a script into a web request header. On successful exploitation, an attacker can view or modify information causing a limited impact on the confidentiality and integrity of the application.

    Published: 12 Dec 2022
    6
    Medium

    CVE-2022-41261

    Last Modified: 22 Apr 2025

    SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a file containing sensitive data which can be used to access a configuration file which contains credentials to access other system files. Successful exploitation can make the attacker access files and systems for which he/she is not authorized.

    Published: 12 Dec 2022
    6.5
    Medium

    CVE-2022-4016

    Last Modified: 22 Apr 2025

    The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.6, Booster Elite for WooCommerce WordPress plugin before 1.1.8 does not properly check for CSRF when creating and deleting Customer roles, allowing attackers to make logged admins create and delete arbitrary custom roles via CSRF attacks

    Published: 12 Dec 2022
    9.8
    Critical

    CVE-2022-3921

    Last Modified: 22 Apr 2025

    The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE

    Published: 12 Dec 2022
    9.8
    Critical

    CVE-2022-3900

    Last Modified: 22 Apr 2025

    The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before unserializing it in the cooked_loadmore action, allowing an unauthenticated attacker to trigger a PHP Object injection vulnerability.

    Published: 12 Dec 2022
    8.8
    High

    CVE-2022-3989

    Last Modified: 22 Apr 2025

    The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.

    Published: 12 Dec 2022
    4.8
    Medium

    CVE-2022-3862

    Last Modified: 22 Apr 2025

    The Livemesh Addons for Elementor WordPress plugin before 7.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 12 Dec 2022
    4.8
    Medium

    CVE-2022-4000

    Last Modified: 22 Apr 2025

    The WooCommerce Shipping WordPress plugin through 1.2.11 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 12 Dec 2022
    6.5
    Medium

    CVE-2022-3946

    Last Modified: 22 Apr 2025

    The Welcart e-Commerce WordPress plugin before 2.8.4 does not have authorisation and CSRF in an AJAX action, allowing any logged-in user to create, update and delete shipping methods.

    Published: 12 Dec 2022
    5.7
    Medium

    CVE-2022-3881

    Last Modified: 22 Apr 2025

    The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log WordPress plugin before 3.43 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

    Published: 12 Dec 2022
    6.5
    Medium

    CVE-2022-3880

    Last Modified: 22 Apr 2025

    The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan WordPress plugin before 4.20 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

    Published: 12 Dec 2022
    6.5
    Medium

    CVE-2022-3879

    Last Modified: 22 Apr 2025

    The Car Dealer (Dealership) and Vehicle sales WordPress Plugin WordPress plugin before 3.05 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

    Published: 12 Dec 2022
    4.8
    Medium

    CVE-2022-3906

    Last Modified: 22 Apr 2025

    The Easy Form Builder WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 12 Dec 2022
    6.5
    Medium

    CVE-2022-3930

    Last Modified: 22 Apr 2025

    The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.

    Published: 12 Dec 2022
    4.8
    Medium

    CVE-2022-4010

    Last Modified: 22 Apr 2025

    The Image Hover Effects WordPress plugin before 5.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 12 Dec 2022