CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-44551

    Last Modified: 1 May 2025

    The iaware module has a vulnerability in thread security. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.

    Published: 9 Nov 2022
    7.5
    High

    CVE-2022-44552

    Last Modified: 1 May 2025

    The lock screen module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.

    Published: 9 Nov 2022
    5.3
    Medium

    CVE-2022-44553

    Last Modified: 1 May 2025

    The HiView module has a vulnerability of not filtering third-party apps out when the HiView module traverses to invoke the system provider. Successful exploitation of this vulnerability may cause third-party apps to start periodically.

    Published: 9 Nov 2022
    7.5
    High

    CVE-2022-44554

    Last Modified: 1 May 2025

    The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module on the device.

    Published: 9 Nov 2022
    7.5
    High

    CVE-2022-44555

    Last Modified: 1 May 2025

    The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable.

    Published: 9 Nov 2022
    1.9
    Low

    CVE-2022-29836

    Last Modified: 1 May 2025

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability was discovered via an HTTP API on Western Digital My Cloud Home; My Cloud Home Duo; and SanDisk ibi devices that could allow an attacker to abuse certain parameters to point to random locations on the file system. This could also allow the attacker to initiate the installation of custom packages at these locations. This can only be exploited once the attacker has been authenticated to the device. This issue affects: Western Digital My Cloud Home and My Cloud Home Duo versions prior to 8.11.0-113 on Linux; SanDisk ibi versions prior to 8.11.0-113 on Linux.

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41073

    Last Modified: 30 Oct 2025

    Windows Print Spooler Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    8.8
    High

    CVE-2022-41080

    Last Modified: 30 Oct 2025

    Microsoft Exchange Server Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    7.5
    High

    CVE-2022-45061

    Last Modified: 3 Nov 2025

    An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied supposed hostname. For example, the attack payload could be placed in the Location header of an HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16.

    Published: 9 Nov 2022
    7.3
    High

    CVE-2022-3265

    Last Modified: 1 May 2025

    A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.

    Published: 9 Nov 2022
    3.5
    Low

    CVE-2022-3280

    Last Modified: 1 May 2025

    An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick users into visiting a trustworthy URL and being redirected to arbitrary content.

    Published: 9 Nov 2022
    4.3
    Medium

    CVE-2022-3447

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 106.0.5249.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Nov 2022
    3.1
    Low

    CVE-2022-3706

    Last Modified: 1 May 2025

    Improper authorization in GitLab CE/EE affecting all versions from 7.14 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user retrying a job in a downstream pipeline to take ownership of the retried jobs in the upstream pipeline even if the user doesn't have access to that project.

    Published: 9 Nov 2022
    7.2
    High

    CVE-2022-37967

    Last Modified: 2 Jan 2025

    Windows Kerberos Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-37992

    Last Modified: 2 Jan 2025

    Windows Group Policy Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    7
    High

    CVE-2022-38014

    Last Modified: 2 Jan 2025

    Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    6.5
    Medium

    CVE-2022-38015

    Last Modified: 2 Jan 2025

    Windows Hyper-V Denial of Service Vulnerability

    Published: 9 Nov 2022
    8.1
    High

    CVE-2022-38023

    Last Modified: 2 Jan 2025

    Netlogon RPC Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    8.8
    High

    CVE-2022-3886

    Last Modified: 21 Nov 2024

    Use after free in Speech Recognition in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Nov 2022
    9.6
    Critical

    CVE-2022-3890

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Crashpad in Google Chrome on Android prior to 107.0.5304.106 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 9 Nov 2022
    6.8
    Medium

    CVE-2022-3916

    Last Modified: 21 Nov 2024

    A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user authentication sessions. This enables an attacker to resolve a user session attached to a previously authenticated user; when utilizing the refresh token, they will be issued a token for the original user.

    Published: 9 Nov 2022
    5.9
    Medium

    CVE-2022-39886

    Last Modified: 1 May 2025

    Improper access control vulnerability in IpcRxServiceModeBigDataInfo in RIL prior to SMR Nov-2022 Release 1 allows local attacker to access Device information.

    Published: 9 Nov 2022
    8.1
    High

    CVE-2022-41039

    Last Modified: 2 Jan 2025

    Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

    Published: 9 Nov 2022
    8.8
    High

    CVE-2022-41047

    Last Modified: 2 Jan 2025

    Microsoft ODBC Driver Remote Code Execution Vulnerability

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41051

    Last Modified: 2 Jan 2025

    Azure RTOS GUIX Studio Remote Code Execution Vulnerability

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41054

    Last Modified: 10 Aug 2026

    Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41052

    Last Modified: 2 Jan 2025

    Windows Graphics Component Remote Code Execution Vulnerability

    Published: 9 Nov 2022
    7.5
    High

    CVE-2022-41056

    Last Modified: 2 Jan 2025

    Network Policy Server (NPS) RADIUS Protocol Denial of Service Vulnerability

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41057

    Last Modified: 2 Jan 2025

    Windows HTTP.sys Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41096

    Last Modified: 2 Jan 2025

    Microsoft DWM Core Library Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    6.5
    Medium

    CVE-2022-41097

    Last Modified: 2 Jan 2025

    Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41101

    Last Modified: 2 Jan 2025

    Windows Overlay Filter Elevation of Privilege Vulnerability

    Published: 9 Nov 2022
    5.9
    Medium

    CVE-2022-42966

    Last Modified: 1 May 2025

    An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the cleo PyPI package, when an attacker is able to supply arbitrary input to the Table.set_rows method

    Published: 9 Nov 2022
    6.1
    Medium

    CVE-2022-43121

    Last Modified: 1 May 2025

    A cross-site scripting (XSS) vulnerability in the CMS Field Add page of Intelliants Subrion CMS v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tooltip text field.

    Published: 9 Nov 2022
    6.1
    Medium

    CVE-2022-43320

    Last Modified: 1 May 2025

    FeehiCMS v2.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /web/admin/index.php?r=log%2Fview-layer.

    Published: 9 Nov 2022
    7.5
    High

    CVE-2022-44550

    Last Modified: 1 May 2025

    The graphics display module has a UAF vulnerability when traversing graphic layers. Successful exploitation of this vulnerability may affect system availability.

    Published: 9 Nov 2022
    7.5
    High

    CVE-2022-44557

    Last Modified: 1 May 2025

    The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 9 Nov 2022
    9.8
    Critical

    CVE-2022-44559

    Last Modified: 1 May 2025

    The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.

    Published: 9 Nov 2022
    9.8
    Critical

    CVE-2022-45062

    Last Modified: 1 May 2025

    In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.

    Published: 9 Nov 2022
    4.3
    Medium

    CVE-2022-2761

    Last Modified: 1 May 2025

    An information disclosure issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to use GitLab Flavored Markdown (GFM) references in a Jira issue to disclose the names of resources they don't have access to.

    Published: 9 Nov 2022
    8.8
    High

    CVE-2022-41128

    Last Modified: 14 Jan 2026

    Windows Scripting Languages Remote Code Execution Vulnerability

    Published: 9 Nov 2022
    3.7
    Low

    CVE-2022-42965

    Last Modified: 6 Mar 2026

    An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the snowflake-connector-python PyPI package, when an attacker is able to supply arbitrary input to the undocumented get_file_transfer_type method

    Published: 9 Nov 2022
    5.5
    Medium

    CVE-2022-41060

    Last Modified: 19 May 2026

    Microsoft Word Information Disclosure Vulnerability

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41063

    Last Modified: 19 May 2026

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 9 Nov 2022
    5.5
    Medium

    CVE-2022-41103

    Last Modified: 19 May 2026

    Microsoft Word Information Disclosure Vulnerability

    Published: 9 Nov 2022
    5.5
    Medium

    CVE-2022-41105

    Last Modified: 19 May 2026

    Microsoft Excel Information Disclosure Vulnerability

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41107

    Last Modified: 19 May 2026

    Microsoft Office Graphics Remote Code Execution Vulnerability

    Published: 9 Nov 2022
    7.8
    High

    CVE-2022-41061

    Last Modified: 10 Aug 2026

    Microsoft Word Remote Code Execution Vulnerability

    Published: 9 Nov 2022
    4.4
    Medium

    CVE-2022-41066

    Last Modified: 10 Aug 2026

    Microsoft Dynamics Business Central Information Disclosure Vulnerability

    Published: 9 Nov 2022
    5.3
    Medium

    CVE-2022-27516

    Last Modified: 1 May 2025

    User login brute force protection functionality bypass

    Published: 8 Nov 2022