CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2022-41582

    Last Modified: 14 May 2025

    The security module has configuration defects.Successful exploitation of this vulnerability may affect system availability.

    Published: 14 Oct 2022
    9.8
    Critical

    CVE-2022-42064

    Last Modified: 14 May 2025

    Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploads a shell.

    Published: 14 Oct 2022
    6.1
    Medium

    CVE-2022-42066

    Last Modified: 14 May 2025

    Online Examination System version 1.0 suffers from a cross site scripting vulnerability via index.php.

    Published: 14 Oct 2022
    4.3
    Medium

    CVE-2022-42067

    Last Modified: 14 May 2025

    Online Birth Certificate Management System version 1.0 suffers from an Insecure Direct Object Reference (IDOR) vulnerability

    Published: 14 Oct 2022
    5.4
    Medium

    CVE-2022-42069

    Last Modified: 14 May 2025

    Online Birth Certificate Management System version 1.0 suffers from a persistent Cross Site Scripting (XSS) vulnerability.

    Published: 14 Oct 2022
    8.8
    High

    CVE-2022-42070

    Last Modified: 14 May 2025

    Online Birth Certificate Management System version 1.0 is vulnerable to Cross Site Request Forgery (CSRF).

    Published: 14 Oct 2022
    6.1
    Medium

    CVE-2022-42071

    Last Modified: 14 May 2025

    Online Birth Certificate Management System version 1.0 suffers from a Cross Site Scripting (XSS) Vulnerability.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-20464

    Last Modified: 15 May 2025

    In various functions of ap_input_processor.c, there is a possible way to record audio during a phone call due to a logic error in the code. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-236042696References: N/A

    Published: 14 Oct 2022
    8.1
    High

    CVE-2022-2780

    Last Modified: 15 May 2025

    In affected versions of Octopus Server it is possible to use the Git Connectivity test function on the VCS project to initiate an SMB request resulting in the potential for an NTLM relay attack.

    Published: 14 Oct 2022
    3.5
    Low

    CVE-2022-3502

    Last Modified: 21 Nov 2024

    A vulnerability was found in Human Resource Management System 1.0. It has been classified as problematic. This affects an unknown part of the component Leave Handler. The manipulation of the argument Reason leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-210831.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-35041

    Last Modified: 15 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b558f.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-35043

    Last Modified: 15 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c08a6.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-35046

    Last Modified: 15 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b0466.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-35047

    Last Modified: 15 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b05aa.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-35048

    Last Modified: 15 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b0b2c.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-35049

    Last Modified: 15 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b03b5.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-35050

    Last Modified: 15 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b04de.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-35053

    Last Modified: 15 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x61731f.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-35054

    Last Modified: 15 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6171b2.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-35055

    Last Modified: 15 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c0473.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-35056

    Last Modified: 15 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b0478.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-35058

    Last Modified: 15 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b05ce.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-35059

    Last Modified: 15 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c0414.

    Published: 14 Oct 2022
    9.8
    Critical

    CVE-2022-37602

    Last Modified: 15 May 2025

    Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-38671

    Last Modified: 21 Nov 2024

    In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-38672

    Last Modified: 15 May 2025

    In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-38673

    Last Modified: 15 May 2025

    In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-38676

    Last Modified: 15 May 2025

    In gpu driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-38677

    Last Modified: 15 May 2025

    In cell service, there is a missing permission check. This could lead to local denial of service in cell service with no additional execution privileges needed.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-38679

    Last Modified: 15 May 2025

    In music service, there is a missing permission check. This could lead to local denial of service in music service with no additional execution privileges needed.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-38687

    Last Modified: 15 May 2025

    In messaging service, there is a missing permission check. This could lead to local denial of service in messaging service with no additional execution privileges needed.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-38688

    Last Modified: 15 May 2025

    In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-38689

    Last Modified: 15 May 2025

    In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-38698

    Last Modified: 15 May 2025

    In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.

    Published: 14 Oct 2022
    7.5
    High

    CVE-2022-38981

    Last Modified: 15 May 2025

    The HwAirlink module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause information leakage.

    Published: 14 Oct 2022
    9.8
    Critical

    CVE-2022-38982

    Last Modified: 15 May 2025

    The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked.

    Published: 14 Oct 2022
    7.5
    High

    CVE-2022-38984

    Last Modified: 15 May 2025

    The HIPP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability will cause out-of-bounds read, which affects data confidentiality.

    Published: 14 Oct 2022
    9.1
    Critical

    CVE-2022-38986

    Last Modified: 15 May 2025

    The HIPP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause out-of-bounds access to the HIPP module and page table tampering, affecting device confidentiality and availability.

    Published: 14 Oct 2022
    7.5
    High

    CVE-2022-39011

    Last Modified: 15 May 2025

    The HISP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause unauthorized access to the HISP module.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-39065

    Last Modified: 15 May 2025

    A single malformed IEEE 802.15.4 (Zigbee) frame makes the TRÅDFRI gateway unresponsive, such that connected lighting cannot be controlled with the IKEA Home Smart app and TRÅDFRI remote control. The malformed Zigbee frame is an unauthenticated broadcast message, which means all vulnerable devices within radio range are affected. CVSS 3.1 Base Score: 6.5 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-39105

    Last Modified: 15 May 2025

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-39107

    Last Modified: 15 May 2025

    In Soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in Soundrecorder service with no additional execution privileges needed.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-39110

    Last Modified: 15 May 2025

    In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-39111

    Last Modified: 15 May 2025

    In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-39112

    Last Modified: 15 May 2025

    In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-39115

    Last Modified: 15 May 2025

    In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-39117

    Last Modified: 15 May 2025

    In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-39120

    Last Modified: 15 May 2025

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-39121

    Last Modified: 14 May 2025

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-39122

    Last Modified: 14 May 2025

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

    Published: 14 Oct 2022