CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2022-46788

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Dec 2022
    —
    Unknown

    CVE-2022-46789

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Dec 2022
    9.8
    Critical

    CVE-2022-45497

    Last Modified: 23 Apr 2025

    Tenda W6-S v1.0.0.4(510) was discovered to contain a command injection vulnerability in the tpi_get_ping_output function at /goform/exeCommand.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-45498

    Last Modified: 23 Apr 2025

    An issue in the component tpi_systool_handle(0) (/goform/SysToolReboot) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to arbitrarily reboot the device.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-45499

    Last Modified: 23 Apr 2025

    Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/WifiMacFilterGet.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-45501

    Last Modified: 23 Apr 2025

    Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/wifiSSIDset.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-45504

    Last Modified: 23 Apr 2025

    An issue in the component tpi_systool_handle(0) (/goform/SysToolRestoreSet) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to arbitrarily reboot the device.

    Published: 8 Dec 2022
    9.8
    Critical

    CVE-2022-45506

    Last Modified: 23 Apr 2025

    Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /goform/delFileName.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-45507

    Last Modified: 23 Apr 2025

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the editNameMit parameter at /goform/editFileName.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-45508

    Last Modified: 23 Apr 2025

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the new_account parameter at /goform/editUserName.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-45509

    Last Modified: 23 Apr 2025

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the account parameter at /goform/addUserName.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-45510

    Last Modified: 23 Apr 2025

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the mit_ssid_index parameter at /goform/AdvSetWrlsafeset.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-45513

    Last Modified: 23 Apr 2025

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/P2pListFilter.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-45515

    Last Modified: 23 Apr 2025

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the entries parameter at /goform/addressNat.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-45516

    Last Modified: 23 Apr 2025

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/NatStaticSetting.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-45517

    Last Modified: 23 Apr 2025

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/VirtualSer.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-45518

    Last Modified: 23 Apr 2025

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SetIpBind.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-45519

    Last Modified: 23 Apr 2025

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the Go parameter at /goform/SafeMacFilter.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-45520

    Last Modified: 23 Apr 2025

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/qossetting.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-45521

    Last Modified: 23 Apr 2025

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeUrlFilter.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-45522

    Last Modified: 23 Apr 2025

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeClientFilter.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-45523

    Last Modified: 23 Apr 2025

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/L7Im.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-45524

    Last Modified: 23 Apr 2025

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the opttype parameter at /goform/IPSECsave.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-45525

    Last Modified: 23 Apr 2025

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the downaction parameter at /goform/CertListInfo.

    Published: 8 Dec 2022
    6.8
    Medium

    CVE-2022-44455

    Last Modified: 21 Nov 2024

    The appspawn and nwebspawn services within OpenHarmony-v3.1.2 and prior versions were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation. An unprivileged malicious application would be able to gain code execution within any application installed on the device or cause application crash.

    Published: 8 Dec 2022
    5.5
    Medium

    CVE-2022-4364

    Last Modified: 15 Oct 2025

    A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality of the file palette.php of the component Web Service Handler. The manipulation of the argument palette leads to command injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.49.16 can resolve this issue. Upgrading the affected component is advised. The vendor points out: "FLIR AX8 internal web site has been refactored to be able to handle the reported vulnerabilities."

    Published: 8 Dec 2022
    3.5
    Low

    CVE-2022-4350

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, was found in Mingsoft MCMS 5.2.8. Affected is an unknown function of the file search.do. The manipulation of the argument content_title leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-215112.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-23476

    Last Modified: 23 Apr 2025

    Nokogiri is an open source XML and HTML library for the Ruby programming language. Nokogiri `1.13.8` and `1.13.9` fail to check the return value from `xmlTextReaderExpand` in the method `Nokogiri::XML::Reader#attribute_hash`. This can lead to a null pointer exception when invalid markup is being parsed. For applications using `XML::Reader` to parse untrusted inputs, this may potentially be a vector for a denial of service attack. Users are advised to upgrade to Nokogiri `>= 1.13.10`. Users may be able to search their code for calls to either `XML::Reader#attributes` or `XML::Reader#attribute_hash` to determine if they are affected.

    Published: 8 Dec 2022
    7.5
    High

    CVE-2022-44932

    Last Modified: 23 Apr 2025

    An access control issue in Tenda A18 v15.13.07.09 allows unauthenticated attackers to access the Telnet service.

    Published: 8 Dec 2022
    9.8
    Critical

    CVE-2022-44938

    Last Modified: 23 Apr 2025

    Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.

    Published: 8 Dec 2022
    8.1
    High

    CVE-2022-37917

    Last Modified: 23 Apr 2025

    Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change network configurations with privileges at a higher effective level in Aruba AirWave Management Platform version(s): 8.2.15.0 and below.

    Published: 8 Dec 2022
    4
    Medium

    CVE-2022-39894

    Last Modified: 23 Apr 2025

    Improper access control vulnerability in ContactListStartActivityHelper in Phone prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.

    Published: 8 Dec 2022
    4
    Medium

    CVE-2022-39895

    Last Modified: 23 Apr 2025

    Improper access control vulnerability in ContactListUtils in Phone prior to SMR Dec-2022 Release 1 allows to access contact group information via implicit intent.

    Published: 8 Dec 2022
    4
    Medium

    CVE-2022-39896

    Last Modified: 23 Apr 2025

    Improper access control vulnerabilities in Contacts prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.

    Published: 8 Dec 2022
    4.4
    Medium

    CVE-2022-39897

    Last Modified: 23 Apr 2025

    Exposure of Sensitive Information vulnerability in kernel prior to SMR Dec-2022 Release 1 allows attackers to access the kernel address information via log.

    Published: 8 Dec 2022
    4
    Medium

    CVE-2022-39898

    Last Modified: 23 Apr 2025

    Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attackers to access some information of usim.

    Published: 8 Dec 2022
    5.7
    Medium

    CVE-2022-39899

    Last Modified: 23 Apr 2025

    Improper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release 1 allows attacker to send the input event using S Pen gesture.

    Published: 8 Dec 2022
    6.5
    Medium

    CVE-2022-39901

    Last Modified: 23 Apr 2025

    Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between UE and gNodeB.

    Published: 8 Dec 2022
    6.5
    Medium

    CVE-2022-39902

    Last Modified: 22 Apr 2025

    Improper authorization in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to get sensitive information including IMEI via emergency call.

    Published: 8 Dec 2022
    4
    Medium

    CVE-2022-39903

    Last Modified: 22 Apr 2025

    Improper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attackers to access RCS incoming call number.

    Published: 8 Dec 2022
    3.3
    Low

    CVE-2022-39904

    Last Modified: 23 Apr 2025

    Exposure of Sensitive Information vulnerability in Samsung Settings prior to SMR Dec-2022 Release 1 allows local attackers to access the Network Access Identifier via log.

    Published: 8 Dec 2022
    4
    Medium

    CVE-2022-39905

    Last Modified: 23 Apr 2025

    Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive information via implicit intent.

    Published: 8 Dec 2022
    2.3
    Low

    CVE-2022-39906

    Last Modified: 23 Apr 2025

    Improper access control vulnerability in SecTelephonyProvider prior to SMR Dec-2022 Release 1 allows attackers to access message information.

    Published: 8 Dec 2022
    6.9
    Medium

    CVE-2022-39907

    Last Modified: 23 Apr 2025

    Integer overflow vulnerability in Samsung decoding library for video thumbnails prior to SMR Dec-2022 Release 1 allows local attacker to perform Out-Of-Bounds Write.

    Published: 8 Dec 2022
    3.9
    Low

    CVE-2022-39910

    Last Modified: 23 Apr 2025

    Improper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allow physical attackers to access data of Samsung Pass on a certain state of an unlocked device using pop-up view.

    Published: 8 Dec 2022
    4.8
    Medium

    CVE-2022-39911

    Last Modified: 23 Apr 2025

    Improper check or handling of exceptional conditions vulnerability in Samsung Pass prior to version 4.0.06.1 allows attacker to access Samsung Pass.

    Published: 8 Dec 2022
    6.2
    Medium

    CVE-2022-39912

    Last Modified: 23 Apr 2025

    Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows local attackers to set some setting value in Secure folder.

    Published: 8 Dec 2022
    6.8
    Medium

    CVE-2022-39913

    Last Modified: 23 Apr 2025

    Exposure of Sensitive Information to an Unauthorized Actor in Persona Manager prior to Android T(13) allows local attacker to access user profiles information.

    Published: 8 Dec 2022
    4.9
    Medium

    CVE-2022-40939

    Last Modified: 22 Apr 2025

    In certain Secustation products the administrator account password can be read. This affects V2.5.5.3116-S50-SMA-B20171107A, V2.3.4.1301-M20-TSA-B20150617A, V2.5.5.3116-S50-RXA-B20180502A, V2.5.5.3116-S50-SMA-B20190723A, V2.5.5.3116-S50-SMB-B20161012A, V2.3.4.2103-S50-NTD-B20170508B, V2.5.5.3116-S50-SMB-B20160601A, V2.5.5.2601-S50-TSA-B20151229A, and V2.5.5.3116-S50-SMA-B20170217.

    Published: 8 Dec 2022
    4
    Medium

    CVE-2022-41802

    Last Modified: 21 Nov 2024

    Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.

    Published: 8 Dec 2022