CVE-2022-44551
Last Modified: 1 May 2025The iaware module has a vulnerability in thread security. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.
CVE-2022-44552
Last Modified: 1 May 2025The lock screen module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.
CVE-2022-44553
Last Modified: 1 May 2025The HiView module has a vulnerability of not filtering third-party apps out when the HiView module traverses to invoke the system provider. Successful exploitation of this vulnerability may cause third-party apps to start periodically.
CVE-2022-44554
Last Modified: 1 May 2025The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module on the device.
CVE-2022-44555
Last Modified: 1 May 2025The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable.
CVE-2022-29836
Last Modified: 1 May 2025Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability was discovered via an HTTP API on Western Digital My Cloud Home; My Cloud Home Duo; and SanDisk ibi devices that could allow an attacker to abuse certain parameters to point to random locations on the file system. This could also allow the attacker to initiate the installation of custom packages at these locations. This can only be exploited once the attacker has been authenticated to the device. This issue affects: Western Digital My Cloud Home and My Cloud Home Duo versions prior to 8.11.0-113 on Linux; SanDisk ibi versions prior to 8.11.0-113 on Linux.
CVE-2022-41073
Last Modified: 30 Oct 2025Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2022-41080
Last Modified: 30 Oct 2025Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2022-45061
Last Modified: 3 Nov 2025An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied supposed hostname. For example, the attack payload could be placed in the Location header of an HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16.
CVE-2022-3265
Last Modified: 1 May 2025A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.
CVE-2022-3280
Last Modified: 1 May 2025An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick users into visiting a trustworthy URL and being redirected to arbitrary content.
CVE-2022-3447
Last Modified: 21 Nov 2024Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 106.0.5249.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
CVE-2022-3706
Last Modified: 1 May 2025Improper authorization in GitLab CE/EE affecting all versions from 7.14 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user retrying a job in a downstream pipeline to take ownership of the retried jobs in the upstream pipeline even if the user doesn't have access to that project.
CVE-2022-37967
Last Modified: 2 Jan 2025Windows Kerberos Elevation of Privilege Vulnerability
CVE-2022-37992
Last Modified: 2 Jan 2025Windows Group Policy Elevation of Privilege Vulnerability
CVE-2022-38014
Last Modified: 2 Jan 2025Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability
CVE-2022-38015
Last Modified: 2 Jan 2025Windows Hyper-V Denial of Service Vulnerability
CVE-2022-38023
Last Modified: 2 Jan 2025Netlogon RPC Elevation of Privilege Vulnerability
CVE-2022-3886
Last Modified: 21 Nov 2024Use after free in Speech Recognition in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2022-3890
Last Modified: 21 Nov 2024Heap buffer overflow in Crashpad in Google Chrome on Android prior to 107.0.5304.106 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2022-3916
Last Modified: 21 Nov 2024A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user authentication sessions. This enables an attacker to resolve a user session attached to a previously authenticated user; when utilizing the refresh token, they will be issued a token for the original user.
CVE-2022-39886
Last Modified: 1 May 2025Improper access control vulnerability in IpcRxServiceModeBigDataInfo in RIL prior to SMR Nov-2022 Release 1 allows local attacker to access Device information.
CVE-2022-41039
Last Modified: 2 Jan 2025Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
CVE-2022-41047
Last Modified: 2 Jan 2025Microsoft ODBC Driver Remote Code Execution Vulnerability
CVE-2022-41051
Last Modified: 2 Jan 2025Azure RTOS GUIX Studio Remote Code Execution Vulnerability
CVE-2022-41054
Last Modified: 10 Aug 2026Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVE-2022-41052
Last Modified: 2 Jan 2025Windows Graphics Component Remote Code Execution Vulnerability
CVE-2022-41056
Last Modified: 2 Jan 2025Network Policy Server (NPS) RADIUS Protocol Denial of Service Vulnerability
CVE-2022-41057
Last Modified: 2 Jan 2025Windows HTTP.sys Elevation of Privilege Vulnerability
CVE-2022-41096
Last Modified: 2 Jan 2025Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2022-41097
Last Modified: 2 Jan 2025Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability
CVE-2022-41101
Last Modified: 2 Jan 2025Windows Overlay Filter Elevation of Privilege Vulnerability
CVE-2022-42966
Last Modified: 1 May 2025An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the cleo PyPI package, when an attacker is able to supply arbitrary input to the Table.set_rows method
CVE-2022-43121
Last Modified: 1 May 2025A cross-site scripting (XSS) vulnerability in the CMS Field Add page of Intelliants Subrion CMS v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tooltip text field.
CVE-2022-43320
Last Modified: 1 May 2025FeehiCMS v2.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /web/admin/index.php?r=log%2Fview-layer.
CVE-2022-44550
Last Modified: 1 May 2025The graphics display module has a UAF vulnerability when traversing graphic layers. Successful exploitation of this vulnerability may affect system availability.
CVE-2022-44557
Last Modified: 1 May 2025The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-44559
Last Modified: 1 May 2025The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
CVE-2022-45062
Last Modified: 1 May 2025In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.
CVE-2022-2761
Last Modified: 1 May 2025An information disclosure issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to use GitLab Flavored Markdown (GFM) references in a Jira issue to disclose the names of resources they don't have access to.
CVE-2022-41128
Last Modified: 14 Jan 2026Windows Scripting Languages Remote Code Execution Vulnerability
CVE-2022-42965
Last Modified: 6 Mar 2026An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the snowflake-connector-python PyPI package, when an attacker is able to supply arbitrary input to the undocumented get_file_transfer_type method
CVE-2022-41060
Last Modified: 19 May 2026Microsoft Word Information Disclosure Vulnerability
CVE-2022-41063
Last Modified: 19 May 2026Microsoft Excel Remote Code Execution Vulnerability
CVE-2022-41103
Last Modified: 19 May 2026Microsoft Word Information Disclosure Vulnerability
CVE-2022-41105
Last Modified: 19 May 2026Microsoft Excel Information Disclosure Vulnerability
CVE-2022-41107
Last Modified: 19 May 2026Microsoft Office Graphics Remote Code Execution Vulnerability
CVE-2022-41061
Last Modified: 10 Aug 2026Microsoft Word Remote Code Execution Vulnerability
CVE-2022-41066
Last Modified: 10 Aug 2026Microsoft Dynamics Business Central Information Disclosure Vulnerability
CVE-2022-27516
Last Modified: 1 May 2025User login brute force protection functionality bypass
