CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2022-42344

    Last Modified: 21 Nov 2024

    Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Incorrect Authorization vulnerability. An authenticated attacker can exploit this vulnerability to achieve information exposure and privilege escalation.

    Published: 20 Oct 2022
    5.3
    Medium

    CVE-2022-3576

    Last Modified: 5 May 2025

    A vulnerability regarding out-of-bounds read is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to obtain sensitive information via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.

    Published: 20 Oct 2022
    10
    Critical

    CVE-2022-27624

    Last Modified: 7 May 2025

    A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the packet decryption functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.

    Published: 20 Oct 2022
    10
    Critical

    CVE-2022-27625

    Last Modified: 7 May 2025

    A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the message processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.

    Published: 20 Oct 2022
    10
    Critical

    CVE-2022-27626

    Last Modified: 8 May 2025

    A vulnerability regarding concurrent execution using shared resource with improper synchronization ('Race Condition') is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.

    Published: 20 Oct 2022
    5.6
    Medium

    CVE-2022-3620

    Last Modified: 23 May 2025

    A vulnerability was found in Exim and classified as problematic. This issue affects the function dmarc_dns_lookup of the file dmarc.c of the component DMARC Handler. The manipulation leads to use after free. The attack may be initiated remotely. The name of the patch is 12fb3842f81bcbd4a4519d5728f2d7e0e3ca1445. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211919.

    Published: 20 Oct 2022
    7.5
    High

    CVE-2022-37453

    Last Modified: 8 May 2025

    An issue was discovered in Softing OPC UA C++ SDK before 6.10. A buffer overflow or an excess allocation happens due to unchecked array and matrix bounds in structure data types.

    Published: 20 Oct 2022
    5.5
    Medium

    CVE-2022-44369

    Last Modified: 18 Feb 2025

    NASM 2.16 (development) is vulnerable to 476: Null Pointer Dereference via output/outaout.c.

    Published: 20 Oct 2022
    7.8
    High

    CVE-2022-42176

    Last Modified: 8 May 2025

    In PCTechSoft PCSecure V5.0.8.xw, use of Hard-coded Credentials in configuration files leads to admin panel access.

    Published: 20 Oct 2022
    6.5
    Medium

    CVE-2022-42197

    Last Modified: 8 May 2025

    In Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modify user permissions to higher privileges.

    Published: 20 Oct 2022
    8.8
    High

    CVE-2022-42198

    Last Modified: 8 May 2025

    In Simple Exam Reviewer Management System v1.0 the User List function suffers from insecure file upload.

    Published: 20 Oct 2022
    8.8
    High

    CVE-2022-42199

    Last Modified: 8 May 2025

    Simple Exam Reviewer Management System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Exam List.

    Published: 20 Oct 2022
    7.8
    High

    CVE-2022-2069

    Last Modified: 16 Apr 2025

    The APDFL.dll in Siemens JT2Go prior to V13.3.0.5 and Siemens Teamcenter Visualization prior to V14.0.0.2 contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.

    Published: 20 Oct 2022
    5.4
    Medium

    CVE-2022-42200

    Last Modified: 8 May 2025

    Simple Exam Reviewer Management System v1.0 is vulnerable to Stored Cross Site Scripting (XSS) via the Exam List.

    Published: 20 Oct 2022
    7.2
    High

    CVE-2022-42201

    Last Modified: 8 May 2025

    Simple Exam Reviewer Management System v1.0 is vulnerable to Insecure file upload.

    Published: 20 Oct 2022
    9.8
    Critical

    CVE-2022-42021

    Last Modified: 8 May 2025

    Best Student Result Management System v1.0 is vulnerable to SQL Injection via /upresult/upresult/notice-details.php?nid=.

    Published: 20 Oct 2022
    7.8
    High

    CVE-2020-12744

    Last Modified: 8 May 2025

    The MSI installer in Verint Desktop Resources 15.2 allows an unprivileged local user to elevate their privileges during install or repair.

    Published: 20 Oct 2022
    6.8
    Medium

    CVE-2020-9285

    Last Modified: 8 May 2025

    Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attached to the Mini-PCI Express slot on the motherboard that hosts the WiFi card on the device.

    Published: 20 Oct 2022
    7.2
    High

    CVE-2022-31366

    Last Modified: 8 May 2025

    An arbitrary file upload vulnerability in the apiImportLabs function in api_labs.php of EVE-NG 2.0.3-112 Community allows attackers to execute arbitrary code via a crafted UNL file.

    Published: 20 Oct 2022
    5.5
    Medium

    CVE-2022-3344

    Last Modified: 7 May 2025

    A flaw was found in the KVM's AMD nested virtualization (SVM). A malicious L1 guest could purposely fail to intercept the shutdown of a cooperative nested guest (L2), possibly leading to a page fault and kernel panic in the host (L0).

    Published: 20 Oct 2022
    5.4
    Medium

    CVE-2021-33231

    Last Modified: 8 May 2025

    Cross Site Scripting (XSS) vulnerability in New equipment page in EasyVista Service Manager 2018.1.181.1 allows remote attackers to run arbitrary code via the notes field.

    Published: 20 Oct 2022
    7.5
    High

    CVE-2022-39823

    Last Modified: 8 May 2025

    An issue was discovered in Softing OPC UA C++ SDK 5.66 through 6.x before 6.10. An OPC/UA browse request exceeding the server limit on continuation points may cause a use-after-free error

    Published: 20 Oct 2022
    5.3
    Medium

    CVE-2022-40084

    Last Modified: 8 May 2025

    OpenCRX before v5.2.2 was discovered to be vulnerable to password enumeration due to the difference in error messages received during a password reset which could enable an attacker to determine if a username, email or ID is valid.

    Published: 20 Oct 2022
    3.5
    Low

    CVE-2022-3619

    Last Modified: 15 Apr 2025

    A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function l2cap_recv_acldata of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. VDB-211918 is the identifier assigned to this vulnerability.

    Published: 20 Oct 2022
    9.8
    Critical

    CVE-2022-37298

    Last Modified: 8 May 2025

    Shinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control. The SafeUnpickler class found in shinken/safepickle.py implements a weak authentication scheme when unserializing objects passed from monitoring nodes to the Shinken monitoring server.

    Published: 20 Oct 2022
    9.8
    Critical

    CVE-2022-37454

    Last Modified: 8 May 2025

    The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

    Published: 20 Oct 2022
    9.8
    Critical

    CVE-2022-37598

    Last Modified: 21 Nov 2024

    Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js. NOTE: the vendor considers this an invalid report.

    Published: 20 Oct 2022
    5.4
    Medium

    CVE-2022-41358

    Last Modified: 8 May 2025

    A stored cross-site scripting (XSS) vulnerability in Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the categoriesName parameter in createCategories.php.

    Published: 20 Oct 2022
    9.8
    Critical

    CVE-2022-42233

    Last Modified: 8 May 2025

    Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.

    Published: 20 Oct 2022
    5.5
    Medium

    CVE-2022-44368

    Last Modified: 18 Feb 2025

    NASM v2.16 was discovered to contain a null pointer deference in the NASM component

    Published: 20 Oct 2022
    6.1
    Medium

    CVE-2022-26954

    Last Modified: 8 May 2025

    Multiple open redirect vulnerabilities in NopCommerce 4.10 through 4.50.1 allow remote attackers to conduct phishing attacks by redirecting users to attacker-controlled web sites via the returnUrl parameter, processed by the (1) ChangePassword function, (2) SignInCustomerAsync function, (3) SuccessfulAuthentication method, or (4) NopRedirectResultExecutor class.

    Published: 20 Oct 2022
    3.7
    Low

    CVE-2022-41983

    Last Modified: 8 May 2025

    On specific hardware platforms, on BIG-IP versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, while Intel QAT (QuickAssist Technology) and the AES-GCM/CCM cipher is in use, undisclosed conditions can cause BIG-IP to send data unencrypted even with an SSL Profile applied.

    Published: 19 Oct 2022
    7.5
    High

    CVE-2022-41836

    Last Modified: 7 May 2025

    When an 'Attack Signature False Positive Mode' enabled security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.

    Published: 19 Oct 2022
    7.3
    High

    CVE-2022-41835

    Last Modified: 7 May 2025

    In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to execute limited set of commands in a container and impact the F5OS controller.

    Published: 19 Oct 2022
    7.5
    High

    CVE-2022-41833

    Last Modified: 7 May 2025

    In all BIG-IP 13.1.x versions, when an iRule containing the HTTP::collect command is configured on a virtual server, undisclosed requests can cause Traffic Management Microkernel (TMM) to terminate.

    Published: 19 Oct 2022
    7.5
    High

    CVE-2022-41832

    Last Modified: 8 May 2025

    In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, when a SIP profile is configured on a virtual server, undisclosed messages can cause an increase in memory resource utilization.

    Published: 19 Oct 2022
    6.5
    Medium

    CVE-2022-41813

    Last Modified: 8 May 2025

    In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when BIG-IP is provisioned with PEM or AFM module, an undisclosed input can cause Traffic Management Microkernel (TMM) to terminate.

    Published: 19 Oct 2022
    7.5
    High

    CVE-2022-41806

    Last Modified: 8 May 2025

    In versions 16.1.x before 16.1.3.2 and 15.1.x before 15.1.5.1, when BIG-IP AFM Network Address Translation policy with IPv6/IPv4 translation rules is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.

    Published: 19 Oct 2022
    7.5
    High

    CVE-2022-41787

    Last Modified: 6 May 2025

    In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, when DNS profile is configured on a virtual server with DNS Express enabled, undisclosed DNS queries with DNSSEC can cause TMM to terminate.

    Published: 19 Oct 2022
    5.5
    Medium

    CVE-2022-41780

    Last Modified: 8 May 2025

    In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.4.0, a directory traversal vulnerability exists in an undisclosed location of the F5OS CLI that allows an attacker to read arbitrary files.

    Published: 19 Oct 2022
    6.5
    Medium

    CVE-2022-41770

    Last Modified: 8 May 2025

    In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ all versions of 8.x and 7.x, an authenticated iControl REST user can cause an increase in memory resource utilization, via undisclosed requests.

    Published: 19 Oct 2022
    7
    High

    CVE-2022-41743

    Last Modified: 8 May 2025

    NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_hls_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its crash or potential other impact using a specially crafted audio or video file. The issue affects only NGINX Plus when the hls directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_hls_module.

    Published: 19 Oct 2022
    4.9
    Medium

    CVE-2022-41694

    Last Modified: 8 May 2025

    In BIG-IP versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, and BIG-IQ versions 8.x before 8.2.0.1 and all versions of 7.x, when an SSL key is imported on a BIG-IP or BIG-IQ system, undisclosed input can cause MCPD to terminate.

    Published: 19 Oct 2022
    7.5
    High

    CVE-2022-41691

    Last Modified: 8 May 2025

    When a BIG-IP Advanced WAF/ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.

    Published: 19 Oct 2022
    7.5
    High

    CVE-2022-41624

    Last Modified: 8 May 2025

    In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.2, 15.1.x before 15.1.7, 14.1.x before 14.1.5.2, and 13.1.x before 13.1.5.1, when a sideband iRule is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization.

    Published: 19 Oct 2022
    7.2
    High

    CVE-2022-41617

    Last Modified: 8 May 2025

    In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, When the Advanced WAF / ASM module is provisioned, an authenticated remote code execution vulnerability exists in the BIG-IP iControl REST interface.

    Published: 19 Oct 2022
    5.3
    Medium

    CVE-2022-36795

    Last Modified: 8 May 2025

    In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, and 14.1.x before 14.1.5.1, when an LTM TCP profile with Auto Receive Window Enabled is configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections.

    Published: 19 Oct 2022
    5.3
    Medium

    CVE-2022-38107

    Last Modified: 8 May 2025

    Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details.

    Published: 19 Oct 2022
    6.1
    Medium

    CVE-2022-1523

    Last Modified: 16 Apr 2025

    Fuji Electric D300win prior to version 3.7.1.17 is vulnerable to a write-what-where condition, which could allow an attacker to overwrite program memory to manipulate the flow of information.

    Published: 19 Oct 2022
    8.7
    High

    CVE-2022-1738

    Last Modified: 16 Apr 2025

    Fuji Electric D300win prior to version 3.7.1.17 is vulnerable to an out-of-bounds read, which could allow an attacker to leak sensitive data from the process memory.

    Published: 19 Oct 2022