CVE-2022-3483
Last Modified: 1 May 2025An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 15.3.5, all versions starting from 15.4 before 15.4.4, all versions starting from 15.5 before 15.5.2. A malicious maintainer could exfiltrate a Datadog integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.
CVE-2022-3486
Last Modified: 1 May 2025An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows an attacker to redirect users to an arbitrary location if they trust the URL.
CVE-2022-3726
Last Modified: 1 May 2025Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick a user to click on the Swagger OpenAPI viewer and issue HTTP requests that affect the victim's account.
CVE-2022-3818
Last Modified: 1 May 2025An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to cause performance issues and potentially a denial of service on the GitLab instance.
CVE-2022-3819
Last Modified: 1 May 2025An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a malicious users to set emojis on internal notes they don't have access to.
CVE-2022-3885
Last Modified: 21 Nov 2024Use after free in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2022-3887
Last Modified: 21 Nov 2024Use after free in Web Workers in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2022-3888
Last Modified: 21 Nov 2024Use after free in WebCodecs in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2022-3889
Last Modified: 21 Nov 2024Type confusion in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2022-3905
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.
CVE-2022-39879
Last Modified: 1 May 2025Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid.
CVE-2022-39880
Last Modified: 1 May 2025Improper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to perform an arbitrary code execution.
CVE-2022-39881
Last Modified: 1 May 2025Improper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2022 Release allows remote attacker to read out of bounds memory.
CVE-2022-39882
Last Modified: 1 May 2025Heap overflow vulnerability in sflacf_fal_bytes_peek function in libsmat.so library prior to SMR Nov-2022 Release 1 allows local attacker to execute arbitrary code.
CVE-2022-39884
Last Modified: 1 May 2025Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local attacker to access to Call information.
CVE-2022-39885
Last Modified: 1 May 2025Improper access control vulnerability in BootCompletedReceiver_CMCC in DeviceManagement prior to SMR Nov-2022 Release 1 allows local attacker to access to Device information.
CVE-2022-39890
Last Modified: 1 May 2025Improper Authorization in Samsung Billing prior to version 5.0.56.0 allows attacker to get sensitive information.
CVE-2022-39891
Last Modified: 1 May 2025Heap overflow vulnerability in parse_pce function in libsavsaudio.so in Editor Lite prior to version 4.0.41.3 allows attacker to get information.
CVE-2022-39892
Last Modified: 1 May 2025Improper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep open feature.
CVE-2022-40797
Last Modified: 1 May 2025Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)
CVE-2022-41044
Last Modified: 2 Jan 2025Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
CVE-2022-41049
Last Modified: 30 Oct 2025Windows Mark of the Web Security Feature Bypass Vulnerability
CVE-2022-41053
Last Modified: 2 Jan 2025Windows Kerberos Denial of Service Vulnerability
CVE-2022-41055
Last Modified: 2 Jan 2025Windows Human Interface Device Information Disclosure Vulnerability
CVE-2022-41062
Last Modified: 2 Jan 2025Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2022-41064
Last Modified: 2 Jan 2025.NET Framework Information Disclosure Vulnerability
CVE-2022-41078
Last Modified: 2 Jan 2025Microsoft Exchange Server Spoofing Vulnerability
CVE-2022-41079
Last Modified: 2 Jan 2025Microsoft Exchange Server Spoofing Vulnerability
CVE-2022-41085
Last Modified: 2 Jan 2025Azure CycleCloud Elevation of Privilege Vulnerability
CVE-2022-41088
Last Modified: 2 Jan 2025Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
CVE-2022-41090
Last Modified: 2 Jan 2025Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
CVE-2022-41092
Last Modified: 2 Jan 2025Windows Win32k Elevation of Privilege Vulnerability
CVE-2022-41093
Last Modified: 2 Jan 2025Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
CVE-2022-41091
Last Modified: 30 Oct 2025Windows Mark of the Web Security Feature Bypass Vulnerability
CVE-2022-41098
Last Modified: 2 Jan 2025Windows GDI+ Information Disclosure Vulnerability
CVE-2022-41099
Last Modified: 2 Jan 2025BitLocker Security Feature Bypass Vulnerability
CVE-2022-41104
Last Modified: 19 May 2026Microsoft Excel Security Feature Bypass Vulnerability
CVE-2022-41102
Last Modified: 2 Jan 2025Windows Overlay Filter Elevation of Privilege Vulnerability
CVE-2022-41106
Last Modified: 19 May 2026Microsoft Excel Remote Code Execution Vulnerability
CVE-2022-41114
Last Modified: 2 Jan 2025Windows Bind Filter Driver Elevation of Privilege Vulnerability
CVE-2022-41116
Last Modified: 2 Jan 2025Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
CVE-2022-41118
Last Modified: 2 Jan 2025Windows Scripting Languages Remote Code Execution Vulnerability
CVE-2022-41120
Last Modified: 2 Jan 2025Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability
CVE-2022-41122
Last Modified: 2 Jan 2025Microsoft SharePoint Server Spoofing Vulnerability
CVE-2022-41123
Last Modified: 2 Jan 2025Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2021-46851
Last Modified: 1 May 2025The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerability may cause abnormal video playback.
CVE-2021-46852
Last Modified: 1 May 2025The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-31688
Last Modified: 1 May 2025VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.
CVE-2022-31689
Last Modified: 1 May 2025VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token.
CVE-2022-43321
Last Modified: 1 May 2025Shopwind v3.4.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the component /common/library/Page.php.
