CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-41125

    Last Modified: 30 Oct 2025

    Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    8.8
    High

    CVE-2022-3445

    Last Modified: 21 Nov 2024

    Use after free in Skia in Google Chrome prior to 106.0.5249.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Nov 2022
    4.3
    Medium

    CVE-2022-3793

    Last Modified: 1 May 2025

    An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to read variables set directly in a GitLab CI/CD configuration file they don't have access to.

    Published: 9 Nov 2022
    8.1
    High

    CVE-2022-37966

    Last Modified: 2 Jan 2025

    Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    8.2
    High

    CVE-2022-39368

    Last Modified: 23 Apr 2025

    Eclipse Californium is a Java implementation of RFC7252 - Constrained Application Protocol for IoT Cloud services. In versions prior to 3.7.0, and 2.7.4, Californium is vulnerable to a Denial of Service. Failing handshakes don't cleanup counters for throttling, causing the threshold to be reached without being released again. This results in permanently dropping records. The issue was reported for certificate based handshakes, but may also affect PSK based handshakes. It generally affects client and server as well. This issue is patched in version 3.7.0 and 2.7.4. There are no known workarounds. main: commit 726bac57659410da463dcf404b3e79a7312ac0b9 2.7.x: commit 5648a0c27c2c2667c98419254557a14bac2b1f3f

    Published: 9 Nov 2022
    4
    Medium

    CVE-2022-39883

    Last Modified: 1 May 2025

    Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.

    Published: 9 Nov 2022
    4.3
    Medium

    CVE-2022-39887

    Last Modified: 1 May 2025

    Improper access control vulnerability in clearAllGlobalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to configure EDM setting.

    Published: 9 Nov 2022
    4
    Medium

    CVE-2022-39889

    Last Modified: 1 May 2025

    Improper access control vulnerability in GalaxyWatch4Plugin prior to versions 2.2.11.22101351 and 2.2.12.22101351 allows attackers to access wearable device information.

    Published: 9 Nov 2022
    3.3
    Low

    CVE-2022-39893

    Last Modified: 1 May 2025

    Sensitive information exposure vulnerability in FmmBaseModel in Galaxy Buds Pro Manage prior to version 4.1.22092751 allows local attackers with log access permission to get device identifier data through device log.

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41045

    Last Modified: 2 Jan 2025

    Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    8.8
    High

    CVE-2022-41048

    Last Modified: 2 Jan 2025

    Microsoft ODBC Driver Remote Code Execution Vulnerability

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41050

    Last Modified: 2 Jan 2025

    Windows Extensible File Allocation Table Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    7.5
    High

    CVE-2022-41058

    Last Modified: 2 Jan 2025

    Windows Network Address Translation (NAT) Denial of Service Vulnerability

    Published: 9 Nov 2022
    6.4
    Medium

    CVE-2022-41086

    Last Modified: 2 Jan 2025

    Windows Group Policy Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41095

    Last Modified: 2 Jan 2025

    Windows Digital Media Receiver Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41100

    Last Modified: 2 Jan 2025

    Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41109

    Last Modified: 2 Jan 2025

    Windows Win32k Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41113

    Last Modified: 2 Jan 2025

    Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41119

    Last Modified: 2 Jan 2025

    Visual Studio Remote Code Execution Vulnerability

    Published: 9 Nov 2022
    5.9
    Medium

    CVE-2022-42964

    Last Modified: 1 May 2025

    An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the pymatgen PyPI package, when an attacker is able to supply arbitrary input to the GaussianInput.from_string method

    Published: 9 Nov 2022
    8.8
    High

    CVE-2022-43031

    Last Modified: 1 May 2025

    DedeCMS v6.1.9 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add Administrator accounts and modify Admin passwords.

    Published: 9 Nov 2022
    9.8
    Critical

    CVE-2022-43058

    Last Modified: 1 May 2025

    Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms//classes/Master.php?f=delete_activity.

    Published: 9 Nov 2022
    6.1
    Medium

    CVE-2022-43118

    Last Modified: 1 May 2025

    A cross-site scripting (XSS) vulnerability in flatCore-CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username text field.

    Published: 9 Nov 2022
    6.1
    Medium

    CVE-2022-43119

    Last Modified: 30 Apr 2025

    A cross-site scripting (XSS) vulnerability in Clansphere CMS v2011.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username parameter.

    Published: 9 Nov 2022
    7.2
    High

    CVE-2022-43277

    Last Modified: 1 May 2025

    Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via ip/youthappam/php_action/editFile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 9 Nov 2022
    7.2
    High

    CVE-2022-43278

    Last Modified: 1 May 2025

    Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the categoriesId parameter at /php_action/fetchSelectedCategories.php.

    Published: 9 Nov 2022
    7.2
    High

    CVE-2022-43290

    Last Modified: 1 May 2025

    Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthappam/editcategory.php.

    Published: 9 Nov 2022
    7.2
    High

    CVE-2022-43291

    Last Modified: 1 May 2025

    Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthappam/editclient.php.

    Published: 9 Nov 2022
    7.2
    High

    CVE-2022-43292

    Last Modified: 1 May 2025

    Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthappam/editfood.php.

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-43310

    Last Modified: 1 May 2025

    An Uncontrolled Search Path Element in Foxit Software released Foxit Reader v11.2.118.51569 allows attackers to escalate privileges when searching for DLL libraries without specifying an absolute path.

    Published: 9 Nov 2022
    6.6
    Medium

    CVE-2022-44244

    Last Modified: 1 May 2025

    An authentication bypass in Lin-CMS v0.2.1 allows attackers to escalate privileges to Super Administrator.

    Published: 9 Nov 2022
    6.1
    Medium

    CVE-2022-43120

    Last Modified: 1 May 2025

    A cross-site scripting (XSS) vulnerability in the /panel/fields/add component of Intelliants Subrion CMS v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Field default value text field.

    Published: 9 Nov 2022
    7.5
    High

    CVE-2022-44546

    Last Modified: 1 May 2025

    The kernel module has the vulnerability that the mapping is not cleared after the memory is automatically released. Successful exploitation of this vulnerability may cause a system restart.

    Published: 9 Nov 2022
    7.5
    High

    CVE-2022-44547

    Last Modified: 1 May 2025

    The Display Service module has a UAF vulnerability. Successful exploitation of this vulnerability may affect the display service availability.

    Published: 9 Nov 2022
    4.3
    Medium

    CVE-2022-44548

    Last Modified: 1 May 2025

    There is a vulnerability in permission verification during the Bluetooth pairing process. Successful exploitation of this vulnerability may cause the dialog box for confirming the pairing not to be displayed during Bluetooth pairing.

    Published: 9 Nov 2022
    7.5
    High

    CVE-2022-44549

    Last Modified: 1 May 2025

    The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the geofencing APIs without authorization, affecting user confidentiality.

    Published: 9 Nov 2022
    9.8
    Critical

    CVE-2022-44558

    Last Modified: 1 May 2025

    The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.

    Published: 9 Nov 2022
    5.3
    Medium

    CVE-2022-44560

    Last Modified: 1 May 2025

    The launcher module has an Intent redirection vulnerability. Successful exploitation of this vulnerability may cause launcher module data to be modified.

    Published: 9 Nov 2022
    7.5
    High

    CVE-2022-44561

    Last Modified: 1 May 2025

    The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arbitrary widgets and shortcuts without interaction.

    Published: 9 Nov 2022
    9.8
    Critical

    CVE-2022-44562

    Last Modified: 1 May 2025

    The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.

    Published: 9 Nov 2022
    5.9
    Medium

    CVE-2022-44563

    Last Modified: 1 May 2025

    There is a race condition vulnerability in SD upgrade mode. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 9 Nov 2022
    9.8
    Critical

    CVE-2022-31685

    Last Modified: 1 May 2025

    VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.

    Published: 9 Nov 2022
    9.8
    Critical

    CVE-2022-31686

    Last Modified: 1 May 2025

    VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.

    Published: 9 Nov 2022
    9.8
    Critical

    CVE-2022-31687

    Last Modified: 1 May 2025

    VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.

    Published: 9 Nov 2022
    5.3
    Medium

    CVE-2022-3285

    Last Modified: 1 May 2025

    Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab

    Published: 9 Nov 2022
    4.3
    Medium

    CVE-2022-3413

    Last Modified: 1 May 2025

    Incorrect authorization during display of Audit Events in GitLab EE affecting all versions from 14.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allowed Developers to view the project's Audit Events and Developers or Maintainers to view the group's Audit Events. These should have been restricted to Project Maintainers, Group Owners, and above.

    Published: 9 Nov 2022
    8.8
    High

    CVE-2022-3446

    Last Modified: 21 Nov 2024

    Heap buffer overflow in WebSQL in Google Chrome prior to 106.0.5249.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Nov 2022
    8.8
    High

    CVE-2022-3448

    Last Modified: 21 Nov 2024

    Use after free in Permissions API in Google Chrome prior to 106.0.5249.119 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Nov 2022
    8.8
    High

    CVE-2022-3449

    Last Modified: 21 Nov 2024

    Use after free in Safe Browsing in Google Chrome prior to 106.0.5249.119 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)

    Published: 9 Nov 2022
    8.8
    High

    CVE-2022-3450

    Last Modified: 21 Nov 2024

    Use after free in Peer Connection in Google Chrome prior to 106.0.5249.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Nov 2022