CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2022-38650

    Last Modified: 21 Nov 2024

    A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to run arbitrary code or malware within Hyperic Server and the host operating system with the privileges of the Hyperic server process. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 12 Nov 2022
    9.9
    Critical

    CVE-2022-38652

    Last Modified: 21 Nov 2024

    A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authenticated user to run arbitrary code or malware within a Hyperic Agent instance and its host operating system with the privileges of the Hyperic Agent process (often SYSTEM on Windows platforms). NOTE: prior exploitation of CVE-2022-38650 results in the disclosure of the authentication material required to exploit this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 12 Nov 2022
    7.8
    High

    CVE-2022-41339

    Last Modified: 1 May 2025

    In Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege escalation.

    Published: 12 Nov 2022
    3.5
    Low

    CVE-2022-3963

    Last Modified: 15 Apr 2025

    A vulnerability was found in gnuboard5. It has been classified as problematic. Affected is an unknown function of the file bbs/faq.php of the component FAQ Key ID Handler. The manipulation of the argument fm_id leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 5.5.8.2.1 is able to address this issue. The name of the patch is ba062ca5b62809106d5a2f7df942ffcb44ecb5a9. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-213540.

    Published: 12 Nov 2022
    8.8
    High

    CVE-2022-40773

    Last Modified: 1 May 2025

    Zoho ManageEngine ServiceDesk Plus MSP before 10609 and SupportCenter Plus before 11025 are vulnerable to privilege escalation. This allows users to obtain sensitive data during an exportMickeyList export of requests from the list view.

    Published: 12 Nov 2022
    5.3
    Medium

    CVE-2022-45195

    Last Modified: 1 May 2025

    SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, which can interfere with forward secrecy and can have other impacts if there is a compromise of a single private key. This occurs in the X3DH key exchange for the double ratchet protocol.

    Published: 12 Nov 2022
    5.3
    Medium

    CVE-2022-31772

    Last Modified: 1 May 2025

    IBM MQ 8.0, 9.0 LTS, 9.1 CD, 9.1 LTS, 9.2 CD, and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service to the MQTT channels. IBM X-Force ID: 228335.

    Published: 11 Nov 2022
    5.4
    Medium

    CVE-2022-40753

    Last Modified: 1 May 2025

    IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 236688.

    Published: 11 Nov 2022
    5.4
    Medium

    CVE-2022-36776

    Last Modified: 1 May 2025

    IBM Cloud Pak for Security (CP4S) 1.10.0.0 79and 1.10.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 233663.

    Published: 11 Nov 2022
    5.4
    Medium

    CVE-2022-40750

    Last Modified: 1 May 2025

    IBM WebSphere Application Server 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 236588.

    Published: 11 Nov 2022
    7.1
    High

    CVE-2022-38385

    Last Modified: 1 May 2025

    IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow an authenticated user to obtain highly sensitive information or perform unauthorized actions due to improper input validation. IBM X-Force ID: 233777.

    Published: 11 Nov 2022
    7.1
    High

    CVE-2022-38387

    Last Modified: 1 May 2025

    IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 233786.

    Published: 11 Nov 2022
    5.5
    Medium

    CVE-2022-34331

    Last Modified: 1 May 2025

    After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly configured leading to desired VEPA configuration being disabled. IBM X-Force ID: 229695.

    Published: 11 Nov 2022
    7.5
    High

    CVE-2022-3510

    Last Modified: 22 Apr 2025

    A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.

    Published: 11 Nov 2022
    6.7
    Medium

    CVE-2022-26028

    Last Modified: 29 Jan 2025

    Uncontrolled search path in the Intel(R) VTune(TM) Profiler software before version 2022.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    6.7
    Medium

    CVE-2021-33064

    Last Modified: 29 Jan 2025

    Uncontrolled search path in the software installer for Intel(R) System Studio for all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    6.5
    Medium

    CVE-2022-28667

    Last Modified: 29 Jan 2025

    Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi software before version 22.140 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 11 Nov 2022
    6.7
    Medium

    CVE-2022-26024

    Last Modified: 29 Jan 2025

    Improper access control in the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN and NUC7i7DN before version 1.78.2.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    4.3
    Medium

    CVE-2022-26047

    Last Modified: 29 Jan 2025

    Improper input validation for some Intel(R) PROSet/Wireless WiFi, Intel vPro(R) CSME WiFi and Killer(TM) WiFi products may allow unauthenticated user to potentially enable denial of service via local access.

    Published: 11 Nov 2022
    3.3
    Low

    CVE-2022-33973

    Last Modified: 29 Jan 2025

    Improper access control in the Intel(R) WAPI Security software for Windows 10/11 before version 22.2150.0.1 may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 11 Nov 2022
    6.7
    Medium

    CVE-2022-36377

    Last Modified: 5 Feb 2025

    Insecure inherited permissions in some Intel(R) Wireless Adapter Driver installation software for Intel(R) NUC Kits & Mini PCs before version 22.190.0.3 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    6.7
    Medium

    CVE-2022-36380

    Last Modified: 4 Feb 2025

    Uncontrolled search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    6.7
    Medium

    CVE-2022-36384

    Last Modified: 4 Feb 2025

    Unquoted search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    6.7
    Medium

    CVE-2022-36400

    Last Modified: 4 Feb 2025

    Path traversal in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    7.9
    High

    CVE-2022-21198

    Last Modified: 11 Aug 2026

    Time-of-check time-of-use race condition in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    8.2
    High

    CVE-2022-26006

    Last Modified: 5 Feb 2025

    Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    6
    Medium

    CVE-2022-25917

    Last Modified: 5 Feb 2025

    Uncaught exception in the firmware for some Intel(R) Server Board M50CYP Family before version R01.01.0005 may allow a privileged user to potentially enable a denial of service via local access.

    Published: 11 Nov 2022
    8.2
    High

    CVE-2022-30542

    Last Modified: 5 Feb 2025

    Improper input validation in the firmware for some Intel(R) Server Board S2600WF, Intel(R) Server System R1000WF and Intel(R) Server System R2000WF families before version R02.01.0014 may allow a privileged user to potentially enable an escalation of privilege via local access.

    Published: 11 Nov 2022
    5.2
    Medium

    CVE-2022-36349

    Last Modified: 21 Nov 2024

    Insecure default variable initialization in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 11 Nov 2022
    7.8
    High

    CVE-2022-37334

    Last Modified: 5 Feb 2025

    Improper initialization in BIOS firmware for some Intel(R) NUC 11 Pro Kits and Intel(R) NUC 11 Pro Boards before version TNTGL357.0064 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    7.5
    High

    CVE-2022-36370

    Last Modified: 5 Feb 2025

    Improper authentication in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    7.5
    High

    CVE-2022-26124

    Last Modified: 5 Feb 2025

    Improper buffer restrictions in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC 8 Boards, Intel(R) NUC 8 Rugged Boards and Intel(R) NUC 8 Rugged Kits before version CHAPLCEL.0059 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    7.5
    High

    CVE-2022-38099

    Last Modified: 5 Feb 2025

    Improper input validation in BIOS firmware for some Intel(R) NUC 11 Compute Elements before version EBTGL357.0065 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    7.5
    High

    CVE-2022-35276

    Last Modified: 5 Feb 2025

    Improper access control in BIOS firmware for some Intel(R) NUC 8 Compute Elements before version CBWHL357.0096 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    7.5
    High

    CVE-2022-36789

    Last Modified: 5 Feb 2025

    Improper access control in BIOS firmware for some Intel(R) NUC 10 Performance Kits and Intel(R) NUC 10 Performance Mini PCs before version FNCML357.0053 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    7.5
    High

    CVE-2022-32569

    Last Modified: 5 Feb 2025

    Improper buffer restrictions in BIOS firmware for some Intel(R) NUC M15 Laptop Kits before version BCTGL357.0074 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    7.7
    High

    CVE-2022-34152

    Last Modified: 5 Feb 2025

    Improper input validation in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Kits before version TY0070 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    7.7
    High

    CVE-2022-21794

    Last Modified: 5 Feb 2025

    Improper authentication in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Business, Intel(R) NUC Enthusiast, Intel(R) NUC Kits before version HN0067 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    7.8
    High

    CVE-2022-37345

    Last Modified: 5 Feb 2025

    Improper authentication in BIOS firmware[A1] for some Intel(R) NUC Kits before version RY0386 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    8.2
    High

    CVE-2022-33176

    Last Modified: 5 Feb 2025

    Improper input validation in BIOS firmware for some Intel(R) NUC 11 Performance kits and Intel(R) NUC 11 Performance Mini PCs before version PATGL357.0042 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    8.2
    High

    CVE-2021-33164

    Last Modified: 21 Nov 2024

    Improper access control in BIOS firmware for some Intel(R) NUCs before version INWHL357.0046 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    3.3
    Low

    CVE-2022-26045

    Last Modified: 5 Feb 2025

    Improper buffer restrictions in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via physical access.

    Published: 11 Nov 2022
    5.4
    Medium

    CVE-2022-27639

    Last Modified: 5 Feb 2025

    Incomplete cleanup in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via adjacent access.

    Published: 11 Nov 2022
    6
    Medium

    CVE-2022-26079

    Last Modified: 5 Feb 2025

    Improper conditions check in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    6
    Medium

    CVE-2022-26367

    Last Modified: 5 Feb 2025

    Improper buffer restrictions in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    6
    Medium

    CVE-2022-28126

    Last Modified: 5 Feb 2025

    Improper input validation in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 11 Nov 2022
    6.2
    Medium

    CVE-2022-26369

    Last Modified: 5 Feb 2025

    Out-of-bounds read in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via adjacent access.

    Published: 11 Nov 2022
    6.8
    Medium

    CVE-2022-28611

    Last Modified: 5 Feb 2025

    Improper input validation in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via physical access.

    Published: 11 Nov 2022
    6.8
    Medium

    CVE-2022-27874

    Last Modified: 5 Feb 2025

    Improper authentication in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via physical access.

    Published: 11 Nov 2022
    8
    High

    CVE-2022-26513

    Last Modified: 5 Feb 2025

    Out-of-bounds write in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 11 Nov 2022