CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2022-3483

    Last Modified: 1 May 2025

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 15.3.5, all versions starting from 15.4 before 15.4.4, all versions starting from 15.5 before 15.5.2. A malicious maintainer could exfiltrate a Datadog integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

    Published: 9 Nov 2022
    4.7
    Medium

    CVE-2022-3486

    Last Modified: 1 May 2025

    An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows an attacker to redirect users to an arbitrary location if they trust the URL.

    Published: 9 Nov 2022
    4.8
    Medium

    CVE-2022-3726

    Last Modified: 1 May 2025

    Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account.

    Published: 9 Nov 2022
    5.3
    Medium

    CVE-2022-3818

    Last Modified: 1 May 2025

    An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to cause performance issues and potentially a denial of service on the GitLab instance.

    Published: 9 Nov 2022
    3.5
    Low

    CVE-2022-3819

    Last Modified: 1 May 2025

    An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a malicious users to set emojis on internal notes they don't have access to.

    Published: 9 Nov 2022
    8.8
    High

    CVE-2022-3885

    Last Modified: 21 Nov 2024

    Use after free in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Nov 2022
    8.8
    High

    CVE-2022-3887

    Last Modified: 21 Nov 2024

    Use after free in Web Workers in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Nov 2022
    8.8
    High

    CVE-2022-3888

    Last Modified: 21 Nov 2024

    Use after free in WebCodecs in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Nov 2022
    8.8
    High

    CVE-2022-3889

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Nov 2022
    —
    Unknown

    CVE-2022-3905

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 9 Nov 2022
    5.9
    Medium

    CVE-2022-39879

    Last Modified: 1 May 2025

    Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid.

    Published: 9 Nov 2022
    7.1
    High

    CVE-2022-39880

    Last Modified: 1 May 2025

    Improper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to perform an arbitrary code execution.

    Published: 9 Nov 2022
    5.3
    Medium

    CVE-2022-39881

    Last Modified: 1 May 2025

    Improper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2022 Release allows remote attacker to read out of bounds memory.

    Published: 9 Nov 2022
    8
    High

    CVE-2022-39882

    Last Modified: 1 May 2025

    Heap overflow vulnerability in sflacf_fal_bytes_peek function in libsmat.so library prior to SMR Nov-2022 Release 1 allows local attacker to execute arbitrary code.

    Published: 9 Nov 2022
    4.3
    Medium

    CVE-2022-39884

    Last Modified: 1 May 2025

    Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local attacker to access to Call information.

    Published: 9 Nov 2022
    5.9
    Medium

    CVE-2022-39885

    Last Modified: 1 May 2025

    Improper access control vulnerability in BootCompletedReceiver_CMCC in DeviceManagement prior to SMR Nov-2022 Release 1 allows local attacker to access to Device information.

    Published: 9 Nov 2022
    6.2
    Medium

    CVE-2022-39890

    Last Modified: 1 May 2025

    Improper Authorization in Samsung Billing prior to version 5.0.56.0 allows attacker to get sensitive information.

    Published: 9 Nov 2022
    4.3
    Medium

    CVE-2022-39891

    Last Modified: 1 May 2025

    Heap overflow vulnerability in parse_pce function in libsavsaudio.so in Editor Lite prior to version 4.0.41.3 allows attacker to get information.

    Published: 9 Nov 2022
    3.6
    Low

    CVE-2022-39892

    Last Modified: 1 May 2025

    Improper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep open feature.

    Published: 9 Nov 2022
    9.8
    Critical

    CVE-2022-40797

    Last Modified: 1 May 2025

    Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)

    Published: 9 Nov 2022
    8.1
    High

    CVE-2022-41044

    Last Modified: 2 Jan 2025

    Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

    Published: 9 Nov 2022
    5.4
    Medium

    CVE-2022-41049

    Last Modified: 30 Oct 2025

    Windows Mark of the Web Security Feature Bypass Vulnerability

    Published: 9 Nov 2022
    7.5
    High

    CVE-2022-41053

    Last Modified: 2 Jan 2025

    Windows Kerberos Denial of Service Vulnerability

    Published: 9 Nov 2022
    5.5
    Medium

    CVE-2022-41055

    Last Modified: 2 Jan 2025

    Windows Human Interface Device Information Disclosure Vulnerability

    Published: 9 Nov 2022
    8.8
    High

    CVE-2022-41062

    Last Modified: 2 Jan 2025

    Microsoft SharePoint Server Remote Code Execution Vulnerability

    Published: 9 Nov 2022
    5.8
    Medium

    CVE-2022-41064

    Last Modified: 2 Jan 2025

    .NET Framework Information Disclosure Vulnerability

    Published: 9 Nov 2022
    8
    High

    CVE-2022-41078

    Last Modified: 2 Jan 2025

    Microsoft Exchange Server Spoofing Vulnerability

    Published: 9 Nov 2022
    8
    High

    CVE-2022-41079

    Last Modified: 2 Jan 2025

    Microsoft Exchange Server Spoofing Vulnerability

    Published: 9 Nov 2022
    7.5
    High

    CVE-2022-41085

    Last Modified: 2 Jan 2025

    Azure CycleCloud Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    8.1
    High

    CVE-2022-41088

    Last Modified: 2 Jan 2025

    Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

    Published: 9 Nov 2022
    5.9
    Medium

    CVE-2022-41090

    Last Modified: 2 Jan 2025

    Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41092

    Last Modified: 2 Jan 2025

    Windows Win32k Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41093

    Last Modified: 2 Jan 2025

    Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    5.4
    Medium

    CVE-2022-41091

    Last Modified: 30 Oct 2025

    Windows Mark of the Web Security Feature Bypass Vulnerability

    Published: 9 Nov 2022
    5.5
    Medium

    CVE-2022-41098

    Last Modified: 2 Jan 2025

    Windows GDI+ Information Disclosure Vulnerability

    Published: 9 Nov 2022
    4.6
    Medium

    CVE-2022-41099

    Last Modified: 2 Jan 2025

    BitLocker Security Feature Bypass Vulnerability

    Published: 9 Nov 2022
    5.5
    Medium

    CVE-2022-41104

    Last Modified: 19 May 2026

    Microsoft Excel Security Feature Bypass Vulnerability

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41102

    Last Modified: 2 Jan 2025

    Windows Overlay Filter Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    8.8
    High

    CVE-2022-41106

    Last Modified: 19 May 2026

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 9 Nov 2022
    7
    High

    CVE-2022-41114

    Last Modified: 2 Jan 2025

    Windows Bind Filter Driver Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    5.9
    Medium

    CVE-2022-41116

    Last Modified: 2 Jan 2025

    Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability

    Published: 9 Nov 2022
    7.5
    High

    CVE-2022-41118

    Last Modified: 2 Jan 2025

    Windows Scripting Languages Remote Code Execution Vulnerability

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41120

    Last Modified: 2 Jan 2025

    Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    6.5
    Medium

    CVE-2022-41122

    Last Modified: 2 Jan 2025

    Microsoft SharePoint Server Spoofing Vulnerability

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41123

    Last Modified: 2 Jan 2025

    Microsoft Exchange Server Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    9.8
    Critical

    CVE-2021-46851

    Last Modified: 1 May 2025

    The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerability may cause abnormal video playback.

    Published: 9 Nov 2022
    7.5
    High

    CVE-2021-46852

    Last Modified: 1 May 2025

    The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 9 Nov 2022
    6.1
    Medium

    CVE-2022-31688

    Last Modified: 1 May 2025

    VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.

    Published: 9 Nov 2022
    9.8
    Critical

    CVE-2022-31689

    Last Modified: 1 May 2025

    VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token.

    Published: 9 Nov 2022
    6.1
    Medium

    CVE-2022-43321

    Last Modified: 1 May 2025

    Shopwind v3.4.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the component /common/library/Page.php.

    Published: 9 Nov 2022