CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-41395

    Last Modified: 30 Apr 2025

    Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the dmzHost parameter in the setDMZ function.

    Published: 15 Nov 2022
    5.9
    Medium

    CVE-2022-41916

    Last Modified: 23 Apr 2025

    Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of service vulnerability in Heimdal's PKI certificate validation library, affecting the KDC (via PKINIT) and kinit (via PKINIT), as well as any third-party applications using Heimdal's libhx509. Users should upgrade to Heimdal 7.7.1 or 7.8. There are no known workarounds for this issue.

    Published: 15 Nov 2022
    4.3
    Medium

    CVE-2022-41917

    Last Modified: 23 Apr 2025

    OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. OpenSearch allows users to specify a local file when defining text analyzers to process data for text analysis. An issue in the implementation of this feature allows certain specially crafted queries to return a response containing the first line of text from arbitrary files. The list of potentially impacted files is limited to text files with read permissions allowed in the Java Security Manager policy configuration. OpenSearch version 1.3.7 and 2.4.0 contain a fix for this issue. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 15 Nov 2022
    7.5
    High

    CVE-2022-42978

    Last Modified: 30 Apr 2025

    In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated attacker could access files on the remote system.

    Published: 15 Nov 2022
    8.1
    High

    CVE-2022-45381

    Last Modified: 30 Apr 2025

    Jenkins Pipeline Utility Steps Plugin 2.13.1 and earlier does not restrict the set of enabled prefix interpolators and bundles versions of Apache Commons Configuration library that enable the 'file:' prefix interpolator by default, allowing attackers able to configure Pipelines to read arbitrary files from the Jenkins controller file system.

    Published: 15 Nov 2022
    5.4
    Medium

    CVE-2022-45382

    Last Modified: 30 Apr 2025

    Jenkins Naginator Plugin 1.18.1 and earlier does not escape display names of source builds in builds that were triggered via Retry action, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to edit build display names.

    Published: 15 Nov 2022
    6.5
    Medium

    CVE-2022-45383

    Last Modified: 30 Apr 2025

    An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Support/DownloadBundle permission to download a previously created support bundle containing information limited to users with Overall/Administer permission.

    Published: 15 Nov 2022
    6.5
    Medium

    CVE-2022-45384

    Last Modified: 30 Apr 2025

    Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.

    Published: 15 Nov 2022
    7.5
    High

    CVE-2022-45385

    Last Modified: 30 Apr 2025

    A missing permission check in Jenkins CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository.

    Published: 15 Nov 2022
    5.5
    Medium

    CVE-2022-45386

    Last Modified: 30 Apr 2025

    Jenkins Violations Plugin 0.7.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 15 Nov 2022
    4.3
    Medium

    CVE-2022-45390

    Last Modified: 30 Apr 2025

    A missing permission check in Jenkins loader.io Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

    Published: 15 Nov 2022
    6.5
    Medium

    CVE-2022-45392

    Last Modified: 30 Apr 2025

    Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins controller file system.

    Published: 15 Nov 2022
    3.5
    Low

    CVE-2022-45393

    Last Modified: 30 Apr 2025

    A cross-site request forgery (CSRF) vulnerability in Jenkins Delete log Plugin 1.0 and earlier allows attackers to delete build logs.

    Published: 15 Nov 2022
    4.3
    Medium

    CVE-2022-45394

    Last Modified: 30 Apr 2025

    A missing permission check in Jenkins Delete log Plugin 1.0 and earlier allows attackers with Item/Read permission to delete build logs.

    Published: 15 Nov 2022
    9.8
    Critical

    CVE-2022-45395

    Last Modified: 30 Apr 2025

    Jenkins CCCC Plugin 0.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 15 Nov 2022
    9.8
    Critical

    CVE-2022-45396

    Last Modified: 30 Apr 2025

    Jenkins SourceMonitor Plugin 0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 15 Nov 2022
    6.1
    Medium

    CVE-2022-45402

    Last Modified: 30 Apr 2025

    In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint.

    Published: 15 Nov 2022
    6.5
    Medium

    CVE-2022-45403

    Last Modified: 15 Apr 2025

    Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media combined with Range requests might have allowed them to determine the presence or length of a media file. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

    Published: 15 Nov 2022
    6.5
    Medium

    CVE-2022-45404

    Last Modified: 15 Apr 2025

    Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

    Published: 15 Nov 2022
    6.5
    Medium

    CVE-2022-45405

    Last Modified: 15 Apr 2025

    Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

    Published: 15 Nov 2022
    9.8
    Critical

    CVE-2022-45406

    Last Modified: 15 Apr 2025

    If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while references to it lived on in a BaseShape. This could lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

    Published: 15 Nov 2022
    8.8
    High

    CVE-2022-45409

    Last Modified: 15 Apr 2025

    The garbage collector could have been aborted in several states and zones and <code>GCRuntime::finishCollection</code> may not have been called, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

    Published: 15 Nov 2022
    6.5
    Medium

    CVE-2022-45410

    Last Modified: 15 Apr 2025

    When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was addressed in the spec and then in browsers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

    Published: 15 Nov 2022
    6.1
    Medium

    CVE-2022-45411

    Last Modified: 15 Apr 2025

    Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and cookies inaccessible to JavaScript (such as cookies protected by HTTPOnly). To mitigate this attack, browsers placed limits on <code>fetch()</code> and XMLHttpRequest; however some webservers have implemented non-standard headers such as <code>X-Http-Method-Override</code> that override the HTTP method, and made this attack possible again. Thunderbird has applied the same mitigations to the use of this and similar headers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

    Published: 15 Nov 2022
    8.8
    High

    CVE-2022-45412

    Last Modified: 15 Apr 2025

    When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. <br>*This bug only affects Thunderbird on Unix-based operated systems (Android, Linux, MacOS). Windows is unaffected.*. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

    Published: 15 Nov 2022
    6.5
    Medium

    CVE-2022-45416

    Last Modified: 15 Apr 2025

    Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing attacks such as Prime+Probe could have possibly figured out which keys were being pressed. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

    Published: 15 Nov 2022
    6.1
    Medium

    CVE-2022-45418

    Last Modified: 15 Apr 2025

    If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the browser UI, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

    Published: 15 Nov 2022
    6.5
    Medium

    CVE-2022-45420

    Last Modified: 15 Apr 2025

    Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

    Published: 15 Nov 2022
    8.8
    High

    CVE-2022-45421

    Last Modified: 15 Apr 2025

    Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

    Published: 15 Nov 2022
    6.5
    Medium

    CVE-2022-25674

    Last Modified: 22 Apr 2025

    Cryptographic issues in WLAN during the group key handshake of the WPA/WPA2 protocol in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music

    Published: 15 Nov 2022
    7.5
    High

    CVE-2022-25710

    Last Modified: 22 Apr 2025

    Denial of service due to null pointer dereference when GATT is disconnected in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

    Published: 15 Nov 2022
    7.5
    High

    CVE-2022-25742

    Last Modified: 22 Apr 2025

    Denial of service in modem due to infinite loop while parsing IGMPv2 packet from server in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music

    Published: 15 Nov 2022
    8.2
    High

    CVE-2022-29275

    Last Modified: 30 Apr 2025

    In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers could allow OS or SMRAM memory tampering leading to escalation of privileges. This issue was discovered by Insyde during security review. It was fixed in: Kernel 5.0: version 05.09.21 Kernel 5.1: version 05.17.21 Kernel 5.2: version 05.27.21 Kernel 5.3: version 05.36.21 Kernel 5.4: version 05.44.21 Kernel 5.5: version 05.52.21 https://www.insyde.com/security-pledge/SA-2022058

    Published: 15 Nov 2022
    8.8
    High

    CVE-2022-29277

    Last Modified: 30 Apr 2025

    Incorrect pointer checks within the the FwBlockServiceSmm driver can allow arbitrary RAM modifications During review of the FwBlockServiceSmm driver, certain instances of SpiAccessLib could be tricked into writing 0xff to arbitrary system and SMRAM addresses. Fixed in: INTEL Purley-R: 05.21.51.0048 Whitley: 05.42.23.0066 Cedar Island: 05.42.11.0021 Eagle Stream: 05.44.25.0052 Greenlow/Greenlow-R(skylake/kabylake): Trunk Mehlow/Mehlow-R (CoffeeLake-S): Trunk Tatlow (RKL-S): Trunk Denverton: 05.10.12.0042 Snow Ridge: Trunk Graneville DE: 05.05.15.0038 Grangeville DE NS: 05.27.26.0023 Bakerville: 05.21.51.0026 Idaville: 05.44.27.0030 Whiskey Lake: Trunk Comet Lake-S: Trunk Tiger Lake H/UP3: 05.43.12.0052 Alder Lake: 05.44.23.0047 Gemini Lake: Not Affected Apollo Lake: Not Affected Elkhart Lake: 05.44.30.0018 AMD ROME: trunk MILAN: 05.36.10.0017 GENOA: 05.52.25.0006 Snowy Owl: Trunk R1000: 05.32.50.0018 R2000: 05.44.30.0005 V2000: Trunk V3000: 05.44.30.0007 Ryzen 5000: 05.44.30.0004 Embedded ROME: Trunk Embedded MILAN: Trunk Hygon Hygon #1/#2: 05.36.26.0016 Hygon #3: 05.44.26.0007 https://www.insyde.com/security-pledge/SA-2022060

    Published: 15 Nov 2022
    7.5
    High

    CVE-2022-30283

    Last Modified: 30 Apr 2025

    In UsbCoreDxe, tampering with the contents of the USB working buffer using DMA while certain USB transactions are in process leads to a TOCTOU problem that could be used by an attacker to cause SMRAM corruption and escalation of privileges The UsbCoreDxe module creates a working buffer for USB transactions outside of SMRAM. The code which uses can be inside of SMM, making the working buffer untrusted input. The buffer can be corrupted by DMA transfers. The SMM code code attempts to sanitize pointers to ensure all pointers refer to the working buffer, but when a pointer is not found in the list of pointers to sanitize, the current action is not aborted, leading to undefined behavior. This issue was discovered by Insyde engineering based on the general description provided by Intel's iSTARE group. Fixed in: Kernel 5.0: Version 05.09. 21 Kernel 5.1: Version 05.17.21 Kernel 5.2: Version 05.27.21 Kernel 5.3: Version 05.36.21 Kernel 5.4: Version 05.44.21 Kernel 5.5: Version 05.52.21 https://www.insyde.com/security-pledge/SA-2022063

    Published: 15 Nov 2022
    7.5
    High

    CVE-2022-33236

    Last Modified: 22 Apr 2025

    Transient DOS due to buffer over-read in WLAN firmware while parsing cipher suite info attributes. in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

    Published: 15 Nov 2022
    4.2
    Medium

    CVE-2022-27896

    Last Modified: 30 Apr 2025

    Information Exposure Through Log Files vulnerability discovered in Foundry Code-Workbooks where the endpoint backing that console was generating service log records of any Python code being run. These service logs included the Foundry token that represents the Code-Workbooks Python console. Upgrade to Code-Workbooks version 4.461.0. This issue affects Palantir Foundry Code-Workbooks version 4.144 to version 4.460.0 and is resolved in 4.461.0.

    Published: 14 Nov 2022
    3.3
    Low

    CVE-2022-28764

    Last Modified: 29 Apr 2025

    The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results in a local malicious user being able to obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account.

    Published: 14 Nov 2022
    5.9
    Medium

    CVE-2022-34320

    Last Modified: 29 Apr 2025

    IBM CICS TX 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 229464.

    Published: 14 Nov 2022
    5.4
    Medium

    CVE-2022-34317

    Last Modified: 29 Apr 2025

    IBM CICS TX 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229459.

    Published: 14 Nov 2022
    5.4
    Medium

    CVE-2022-34318

    Last Modified: 30 Apr 2025

    IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 229461.

    Published: 14 Nov 2022
    3.7
    Low

    CVE-2022-34316

    Last Modified: 30 Apr 2025

    IBM CICS TX 11.1 does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers. IBM X-Force ID: 229452.

    Published: 14 Nov 2022
    4
    Medium

    CVE-2022-34314

    Last Modified: 30 Apr 2025

    IBM CICS TX 11.1 could disclose sensitive information to a local user due to insecure permission settings. IBM X-Force ID: 229450.

    Published: 14 Nov 2022
    5.4
    Medium

    CVE-2022-34315

    Last Modified: 30 Apr 2025

    IBM CICS TX 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229451.

    Published: 14 Nov 2022
    5.3
    Medium

    CVE-2022-38705

    Last Modified: 30 Apr 2025

    IBM CICS TX 11.1 Standard and Advanced could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a victim to a phishing site. IBM X-Force ID: 234172.

    Published: 14 Nov 2022
    4
    Medium

    CVE-2022-34312

    Last Modified: 30 Apr 2025

    IBM CICS TX 11.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 229447.

    Published: 14 Nov 2022
    6.5
    Medium

    CVE-2022-24938

    Last Modified: 30 Apr 2025

    A malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.

    Published: 14 Nov 2022
    5.3
    Medium

    CVE-2022-34329

    Last Modified: 25 Apr 2025

    IBM CICS TX 11.7 could allow an attacker to obtain sensitive information from HTTP response headers. IBM X-Force ID: 229467.

    Published: 14 Nov 2022
    5.9
    Medium

    CVE-2022-34319

    Last Modified: 29 Apr 2025

    IBM CICS TX 11.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 229463.

    Published: 14 Nov 2022
    6.5
    Medium

    CVE-2022-24937

    Last Modified: 30 Apr 2025

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers.

    Published: 14 Nov 2022