CVE Feed

    Dashboard / CVE

    3.3
    Low

    CVE-2022-34881

    Last Modified: 23 Apr 2025

    Generation of Error Message Containing Sensitive Information vulnerability in Hitachi JP1/Automatic Operation allows local users to gain sensitive information. This issue affects JP1/Automatic Operation: from 10-00 through 10-54-03, from 11-00 before 11-51-09, from 12-00 before 12-60-01.

    Published: 6 Dec 2022
    6.3
    Medium

    CVE-2022-46151

    Last Modified: 23 Apr 2025

    Querybook is an open source data querying UI. In affected versions user provided data is not escaped in the error field of the auth callback url in `querybook/server/app/auth/oauth_auth.py` and `querybook/server/app/auth/okta_auth.py`. This may allow attackers to perform reflected cross site scripting (XSS) if Content Security Policy (CSP) is not enabled or `unsafe-inline` is allowed. Users are advised to upgrade to the latest, patched version of querybook (version 3.14.2 or greater). Users unable to upgrade may enable CSP and not allow unsafe-inline or manually escape query parameters in a reverse proxy.

    Published: 6 Dec 2022
    7.8
    High

    CVE-2022-39092

    Last Modified: 23 Apr 2025

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

    Published: 6 Dec 2022
    5.5
    Medium

    CVE-2022-39129

    Last Modified: 24 Apr 2025

    In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

    Published: 6 Dec 2022
    5.5
    Medium

    CVE-2022-39133

    Last Modified: 24 Apr 2025

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

    Published: 6 Dec 2022
    4.8
    Medium

    CVE-2022-41910

    Last Modified: 23 Apr 2025

    TensorFlow is an open source platform for machine learning. The function MakeGrapplerFunctionItem takes arguments that determine the sizes of inputs and outputs. If the inputs given are greater than or equal to the sizes of the outputs, an out-of-bounds memory read or a crash is triggered. We have patched the issue in GitHub commit a65411a1d69edfb16b25907ffb8f73556ce36bb7. The fix will be included in TensorFlow 2.11.0. We will also cherrypick this commit on TensorFlow 2.8.4, 2.9.3, and 2.10.1.

    Published: 6 Dec 2022
    4.7
    Medium

    CVE-2022-42770

    Last Modified: 23 Apr 2025

    In wlan driver, there is a race condition, This could lead to local denial of service in wlan services.

    Published: 6 Dec 2022
    6.5
    Medium

    CVE-2022-4296

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in TP-Link TL-WR740N. Affected is an unknown function of the component ARP Handler. The manipulation leads to resource consumption. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214812.

    Published: 6 Dec 2022
    6.3
    Medium

    CVE-2022-4300

    Last Modified: 15 Apr 2025

    A vulnerability was found in FastCMS. It has been rated as critical. This issue affects some unknown processing of the file /template/edit of the component Template Handler. The manipulation leads to injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-214901 was assigned to this vulnerability.

    Published: 6 Dec 2022
    9.8
    Critical

    CVE-2022-4314

    Last Modified: 14 Apr 2025

    Improper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2.

    Published: 6 Dec 2022
    6.1
    Medium

    CVE-2022-43363

    Last Modified: 21 Nov 2024

    Telegram Web 15.3.1 allows XSS via a certain payload derived from a Target Corporation website. NOTE: some third parties have been unable to discern any relationship between the Pastebin information and a possible XSS finding.

    Published: 6 Dec 2022
    6.1
    Medium

    CVE-2022-43369

    Last Modified: 23 Apr 2025

    AutoTaxi Stand Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component search.php.

    Published: 6 Dec 2022
    8.8
    High

    CVE-2022-46382

    Last Modified: 23 Apr 2025

    RackN Digital Rebar through 4.6.14, 4.7 through 4.7.22, 4.8 through 4.8.5, 4.9 through 4.9.12, and 4.10 through 4.10.8 has Insecure Permissions. After signing into Digital Rebar, users are issued authentication tokens tied to their account to perform actions within Digital Rebar. During the validation process of these tokens, Digital Rebar did not check if the user account still exists. Deleted Digital Rebar users could still use their tokens to perform actions within Digital Rebar.

    Published: 6 Dec 2022
    9.8
    Critical

    CVE-2020-6627

    Last Modified: 23 Apr 2025

    The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a check_device_name request.

    Published: 6 Dec 2022
    —
    Unknown

    CVE-2022-46667

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 6 Dec 2022
    —
    Unknown

    CVE-2022-46666

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 6 Dec 2022
    —
    Unknown

    CVE-2022-46668

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 6 Dec 2022
    —
    Unknown

    CVE-2022-46669

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 6 Dec 2022
    8.8
    High

    CVE-2022-45548

    Last Modified: 23 Apr 2025

    AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability.

    Published: 6 Dec 2022
    5.5
    Medium

    CVE-2022-42754

    Last Modified: 23 Apr 2025

    In npu driver, there is a memory corruption due to a use after free. This could lead to local denial of service in kernel.

    Published: 6 Dec 2022
    5.5
    Medium

    CVE-2022-42755

    Last Modified: 23 Apr 2025

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

    Published: 6 Dec 2022
    5.5
    Medium

    CVE-2022-42756

    Last Modified: 23 Apr 2025

    In sensor driver, there is a possible buffer overflow due to a missing bounds check. This could lead to local denial of service in kernel.

    Published: 6 Dec 2022
    3.3
    Low

    CVE-2022-42757

    Last Modified: 23 Apr 2025

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

    Published: 6 Dec 2022
    3.3
    Low

    CVE-2022-42758

    Last Modified: 23 Apr 2025

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

    Published: 6 Dec 2022
    5.5
    Medium

    CVE-2022-42759

    Last Modified: 23 Apr 2025

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

    Published: 6 Dec 2022
    5.5
    Medium

    CVE-2022-42760

    Last Modified: 23 Apr 2025

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

    Published: 6 Dec 2022
    5.5
    Medium

    CVE-2022-42761

    Last Modified: 23 Apr 2025

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

    Published: 6 Dec 2022
    5.5
    Medium

    CVE-2022-42762

    Last Modified: 23 Apr 2025

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

    Published: 6 Dec 2022
    5.5
    Medium

    CVE-2022-42763

    Last Modified: 23 Apr 2025

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

    Published: 6 Dec 2022
    5.5
    Medium

    CVE-2022-42764

    Last Modified: 23 Apr 2025

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

    Published: 6 Dec 2022
    5.5
    Medium

    CVE-2022-42765

    Last Modified: 23 Apr 2025

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

    Published: 6 Dec 2022
    3.3
    Low

    CVE-2022-42767

    Last Modified: 23 Apr 2025

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

    Published: 6 Dec 2022
    4.3
    Medium

    CVE-2022-42768

    Last Modified: 23 Apr 2025

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

    Published: 6 Dec 2022
    4.7
    Medium

    CVE-2022-42771

    Last Modified: 23 Apr 2025

    In wlan driver, there is a race condition, This could lead to local denial of service in wlan services.

    Published: 6 Dec 2022
    5.5
    Medium

    CVE-2022-42772

    Last Modified: 23 Apr 2025

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

    Published: 6 Dec 2022
    5.5
    Medium

    CVE-2022-42773

    Last Modified: 23 Apr 2025

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

    Published: 6 Dec 2022
    5.5
    Medium

    CVE-2022-42774

    Last Modified: 23 Apr 2025

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

    Published: 6 Dec 2022
    5.5
    Medium

    CVE-2022-42775

    Last Modified: 23 Apr 2025

    In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.

    Published: 6 Dec 2022
    7.8
    High

    CVE-2022-42776

    Last Modified: 23 Apr 2025

    In UscAIEngine service, there is a missing permission check. This could lead to set up UscAIEngine service with no additional execution privileges needed.

    Published: 6 Dec 2022
    7.8
    High

    CVE-2022-42777

    Last Modified: 23 Apr 2025

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

    Published: 6 Dec 2022
    7.8
    High

    CVE-2022-42778

    Last Modified: 23 Apr 2025

    In windows manager service, there is a missing permission check. This could lead to set up windows manager service with no additional execution privileges needed.

    Published: 6 Dec 2022
    5.5
    Medium

    CVE-2022-42779

    Last Modified: 23 Apr 2025

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

    Published: 6 Dec 2022
    5.5
    Medium

    CVE-2022-42781

    Last Modified: 23 Apr 2025

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

    Published: 6 Dec 2022
    7.8
    High

    CVE-2022-39090

    Last Modified: 23 Apr 2025

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

    Published: 6 Dec 2022
    7.8
    High

    CVE-2022-39091

    Last Modified: 23 Apr 2025

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

    Published: 6 Dec 2022
    7.8
    High

    CVE-2022-39093

    Last Modified: 23 Apr 2025

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

    Published: 6 Dec 2022
    7.8
    High

    CVE-2022-39094

    Last Modified: 23 Apr 2025

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

    Published: 6 Dec 2022
    7.8
    High

    CVE-2022-39095

    Last Modified: 23 Apr 2025

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

    Published: 6 Dec 2022
    7.8
    High

    CVE-2022-39096

    Last Modified: 23 Apr 2025

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

    Published: 6 Dec 2022
    7.8
    High

    CVE-2022-39097

    Last Modified: 23 Apr 2025

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

    Published: 6 Dec 2022