CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2022-42341

    Last Modified: 23 Apr 2025

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.

    Published: 14 Oct 2022
    7.2
    High

    CVE-2022-38424

    Last Modified: 23 Apr 2025

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary file system write. Exploitation of this issue does not require user interaction, but does require administrator privileges.

    Published: 14 Oct 2022
    7.5
    High

    CVE-2022-42340

    Last Modified: 23 Apr 2025

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.

    Published: 14 Oct 2022
    4.9
    Medium

    CVE-2022-38423

    Last Modified: 23 Apr 2025

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in information disclosure. Exploitation of this issue does not require user interaction, but does require administrator privileges.

    Published: 14 Oct 2022
    7.5
    High

    CVE-2022-38422

    Last Modified: 23 Apr 2025

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in information disclosure. Exploitation of this issue does not require user interaction.

    Published: 14 Oct 2022
    7.2
    High

    CVE-2022-38421

    Last Modified: 23 Apr 2025

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, but does require administrator privileges.

    Published: 14 Oct 2022
    7.5
    High

    CVE-2022-38419

    Last Modified: 23 Apr 2025

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.

    Published: 14 Oct 2022
    9.8
    Critical

    CVE-2022-35711

    Last Modified: 23 Apr 2025

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent to the server.

    Published: 14 Oct 2022
    7.5
    High

    CVE-2022-38420

    Last Modified: 23 Apr 2025

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Use of Hard-coded Credentials vulnerability that could result in application denial-of-service by gaining access to start/stop arbitrary services. Exploitation of this issue does not require user interaction.

    Published: 14 Oct 2022
    9.8
    Critical

    CVE-2022-35690

    Last Modified: 23 Apr 2025

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent to the server.

    Published: 14 Oct 2022
    9.8
    Critical

    CVE-2022-35712

    Last Modified: 23 Apr 2025

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent to the server.

    Published: 14 Oct 2022
    9.8
    Critical

    CVE-2022-35710

    Last Modified: 23 Apr 2025

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent to the server.

    Published: 14 Oct 2022
    9.8
    Critical

    CVE-2022-38418

    Last Modified: 23 Apr 2025

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

    Published: 14 Oct 2022
    7.5
    High

    CVE-2022-41623

    Last Modified: 20 Feb 2025

    Sensitive Data Exposure in Villatheme ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 on WordPress.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-28761

    Last Modified: 14 May 2025

    Zoom On-Premise Meeting Connector MMR before version 4.8.20220916.131 contains an improper access control vulnerability. As a result, a malicious actor in a meeting or webinar they are authorized to join could prevent participants from receiving audio and video causing meeting disruptions.

    Published: 14 Oct 2022
    8.2
    High

    CVE-2022-28759

    Last Modified: 14 May 2025

    Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-28760

    Last Modified: 14 May 2025

    Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.

    Published: 14 Oct 2022
    7.3
    High

    CVE-2022-28762

    Last Modified: 14 May 2025

    Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with 5.10.6 and prior to 5.12.0 contains a debugging port misconfiguration. When camera mode rendering context is enabled as part of the Zoom App Layers API by running certain Zoom Apps, a local debugging port is opened by the Zoom client. A local malicious user could use this debugging port to connect to and control the Zoom Apps running in the Zoom client.

    Published: 14 Oct 2022
    6.7
    Medium

    CVE-2022-42464

    Last Modified: 14 May 2025

    OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have a Kernel memory pool override vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could disclose sensitive information including kernel pointer, which could be used in further attacks. The processes with system user UID run on the device would be able to mmap memory pools used by kernel and override them which could be used to gain kernel code execution on the device, gain root privileges, or cause device reboot.

    Published: 14 Oct 2022
    8.3
    High

    CVE-2022-42463

    Last Modified: 14 May 2025

    OpenHarmony-v3.1.2 and prior versions have an authenication bypass vulnerability in a callback handler function of Softbus_server in communication subsystem. Attackers can launch attacks on distributed networks by sending Bluetooth rfcomm packets to any remote device and executing arbitrary commands.

    Published: 14 Oct 2022
    5.1
    Medium

    CVE-2022-41686

    Last Modified: 14 May 2025

    OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have an Out-of-bound memory read and write vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could read out-of-bound memory leading sensitive to information disclosure. The processes with system user UID run on the device would be able to write out-of-bound memory which could lead to unspecified memory corruption.

    Published: 14 Oct 2022
    8.4
    High

    CVE-2022-42488

    Last Modified: 14 May 2025

    OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup subsystem. An malicious application installed on the device could elevate its privileges to the root user, disable security features, or cause DoS by disabling particular services.

    Published: 14 Oct 2022
    9
    Critical

    CVE-2022-32177

    Last Modified: 14 May 2025

    In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the 'Normal Upload' functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin’s cookie leading to account takeover.

    Published: 14 Oct 2022
    3.5
    Low

    CVE-2022-3595

    Last Modified: 15 Apr 2025

    A vulnerability was found in Linux Kernel. It has been rated as problematic. Affected by this issue is the function sess_free_buffer of the file fs/cifs/sess.c of the component CIFS Handler. The manipulation leads to double free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211364.

    Published: 14 Oct 2022
    8.8
    High

    CVE-2022-36803

    Last Modified: 21 Nov 2024

    The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use the MasterUserEdit API to modify any users role to Super Admin. This vulnerability was reported by Jacob Shafer from Bishop Fox.

    Published: 14 Oct 2022
    4.9
    Medium

    CVE-2022-36802

    Last Modified: 21 Nov 2024

    The ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2 allows remote attackers to exploit this issue to access internal network resources via a Server-Side Request Forgery. This can be exploited by a remote, unauthenticated attacker with Super Admin privileges by sending a specially crafted HTTP request.

    Published: 14 Oct 2022
    7.5
    High

    CVE-2022-41583

    Last Modified: 14 May 2025

    The storage maintenance and debugging module has an array out-of-bounds read vulnerability.Successful exploitation of this vulnerability will cause incorrect statistics of this module.

    Published: 14 Oct 2022
    3.4
    Low

    CVE-2022-41597

    Last Modified: 14 May 2025

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

    Published: 14 Oct 2022
    3.4
    Low

    CVE-2022-41602

    Last Modified: 14 May 2025

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

    Published: 14 Oct 2022
    3.4
    Low

    CVE-2022-41603

    Last Modified: 14 May 2025

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

    Published: 14 Oct 2022
    7.2
    High

    CVE-2022-42232

    Last Modified: 21 Nov 2024

    Simple Cold Storage Management System v1.0 is vulnerable to SQL Injection via /csms/classes/Master.php?f=delete_storage.

    Published: 14 Oct 2022
    8.8
    High

    CVE-2022-42234

    Last Modified: 14 May 2025

    There is a file inclusion vulnerability in the template management module in UCMS 1.6

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-2984

    Last Modified: 15 May 2025

    In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-2985

    Last Modified: 15 May 2025

    In music service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.

    Published: 14 Oct 2022
    9.8
    Critical

    CVE-2022-3439

    Last Modified: 14 May 2025

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.

    Published: 14 Oct 2022
    6.3
    Medium

    CVE-2022-3496

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Human Resource Management System 1.0 and classified as critical. This issue affects some unknown processing of the file employeeadd.php of the component Admin Panel. The manipulation leads to improper access controls. The attack may be initiated remotely. The identifier VDB-210785 was assigned to this vulnerability.

    Published: 14 Oct 2022
    3.5
    Low

    CVE-2022-3505

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Sanitization Management System. It has been classified as problematic. Affected is an unknown function of the file /php-sms/admin/. The manipulation of the argument page leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-210840.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-35051

    Last Modified: 21 Nov 2024

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b55af.

    Published: 14 Oct 2022
    5.4
    Medium

    CVE-2022-3506

    Last Modified: 14 May 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-38670

    Last Modified: 15 May 2025

    In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-38697

    Last Modified: 15 May 2025

    In messaging service, there is a missing permission check. This could lead to access unexpected provider in contacts service with no additional execution privileges needed.

    Published: 14 Oct 2022
    7.5
    High

    CVE-2022-38977

    Last Modified: 15 May 2025

    The HwAirlink module has a heap overflow vulnerability.Successful exploitation of this vulnerability may cause out-of-bounds writes, resulting in modification of sensitive data.

    Published: 14 Oct 2022
    7.5
    High

    CVE-2022-38998

    Last Modified: 15 May 2025

    The HISP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability will cause out-of-bounds read, which affects data confidentiality.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-39080

    Last Modified: 15 May 2025

    In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-39108

    Last Modified: 15 May 2025

    In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-39123

    Last Modified: 14 May 2025

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

    Published: 14 Oct 2022
    9.1
    Critical

    CVE-2022-39311

    Last Modified: 23 Apr 2025

    GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 are vulnerable to remote code execution on the server from a malicious or compromised agent. The Spring RemoteInvocation endpoint exposed agent communication and allowed deserialization of arbitrary java objects, as well as subsequent remote code execution. Exploitation requires agent-level authentication, thus an attacker would need to either compromise an existing agent, its network communication or register a new agent to practically exploit this vulnerability. This issue is fixed in GoCD version 21.1.0. There are currently no known workarounds.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-41302

    Last Modified: 14 May 2025

    An Out-Of-Bounds Read Vulnerability in Autodesk FBX SDK version 2020. and prior may lead to code execution or information disclosure through maliciously crafted FBX files. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 14 Oct 2022
    8.8
    High

    CVE-2022-41539

    Last Modified: 14 May 2025

    Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /admin/users_add.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-41576

    Last Modified: 14 May 2025

    The rphone module has a script that can be maliciously modified.Successful exploitation of this vulnerability may cause irreversible programs to be implanted on user devices.

    Published: 14 Oct 2022