CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2022-39124

    Last Modified: 14 May 2025

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-39125

    Last Modified: 14 May 2025

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-39126

    Last Modified: 14 May 2025

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-39127

    Last Modified: 14 May 2025

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

    Published: 14 Oct 2022
    5.5
    Medium

    CVE-2022-39128

    Last Modified: 14 May 2025

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-41304

    Last Modified: 14 May 2025

    An Out-Of-Bounds Write Vulnerability in Autodesk FBX SDK 2020 version and prior may lead to code execution through maliciously crafted FBX files or information disclosure.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-41305

    Last Modified: 14 May 2025

    A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-41306

    Last Modified: 14 May 2025

    A maliciously crafted PCT file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-41307

    Last Modified: 14 May 2025

    A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-41308

    Last Modified: 14 May 2025

    A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 14 Oct 2022
    2.8
    Low

    CVE-2022-4134

    Last Modified: 6 Mar 2025

    A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.

    Published: 14 Oct 2022
    7.2
    High

    CVE-2022-41416

    Last Modified: 14 May 2025

    Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /user/update_booking.php.

    Published: 14 Oct 2022
    9.1
    Critical

    CVE-2022-41436

    Last Modified: 14 May 2025

    An issue in OXHOO TP50 OXH1.50 allows unauthenticated attackers to access the administrative panel via browsing to the URL http://device_ip/index1.html.

    Published: 14 Oct 2022
    9.1
    Critical

    CVE-2022-41477

    Last Modified: 14 May 2025

    A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attackers to inject payloads via theme parameters to read files across directories.

    Published: 14 Oct 2022
    7.2
    High

    CVE-2022-41535

    Last Modified: 14 May 2025

    Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/manage_borrower.php.

    Published: 14 Oct 2022
    7.2
    High

    CVE-2022-41536

    Last Modified: 14 May 2025

    Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/manage_user.php.

    Published: 14 Oct 2022
    8.8
    High

    CVE-2022-41538

    Last Modified: 14 May 2025

    Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /Wedding-Management-PHP/admin/photos_add.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 14 Oct 2022
    9.8
    Critical

    CVE-2022-41578

    Last Modified: 14 May 2025

    The MPTCP module has an out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause root privilege escalation attacks implemented by modifying program information.

    Published: 14 Oct 2022
    9.8
    Critical

    CVE-2022-41580

    Last Modified: 14 May 2025

    The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.

    Published: 14 Oct 2022
    9.1
    Critical

    CVE-2022-41581

    Last Modified: 14 May 2025

    The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-41584

    Last Modified: 14 May 2025

    The kernel module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause memory overwriting.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-41585

    Last Modified: 14 May 2025

    The kernel module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause memory overwriting.

    Published: 14 Oct 2022
    7.5
    High

    CVE-2022-41586

    Last Modified: 14 May 2025

    The communication framework module has a vulnerability of not truncating data properly.Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 14 Oct 2022
    5.3
    Medium

    CVE-2022-41587

    Last Modified: 14 May 2025

    Uncaptured exceptions in the home screen module. Successful exploitation of this vulnerability may affect stability.

    Published: 14 Oct 2022
    7.5
    High

    CVE-2022-41588

    Last Modified: 14 May 2025

    The home screen module has a vulnerability in service logic processing.Successful exploitation of this vulnerability may affect data integrity.

    Published: 14 Oct 2022
    7.5
    High

    CVE-2022-41589

    Last Modified: 14 May 2025

    The DFX unwind stack module of the ArkCompiler has a vulnerability in interface calling.Successful exploitation of this vulnerability affects system services and device availability.

    Published: 14 Oct 2022
    3.4
    Low

    CVE-2022-41592

    Last Modified: 14 May 2025

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

    Published: 14 Oct 2022
    3.4
    Low

    CVE-2022-41593

    Last Modified: 14 May 2025

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

    Published: 14 Oct 2022
    3.4
    Low

    CVE-2022-41594

    Last Modified: 14 May 2025

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

    Published: 14 Oct 2022
    3.4
    Low

    CVE-2022-41595

    Last Modified: 14 May 2025

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

    Published: 14 Oct 2022
    3.4
    Low

    CVE-2022-41598

    Last Modified: 14 May 2025

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

    Published: 14 Oct 2022
    3.4
    Low

    CVE-2022-41600

    Last Modified: 14 May 2025

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

    Published: 14 Oct 2022
    3.4
    Low

    CVE-2022-41601

    Last Modified: 14 May 2025

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

    Published: 14 Oct 2022
    9.1
    Critical

    CVE-2021-46839

    Last Modified: 15 May 2025

    The HW_KEYMASTER module has a vulnerability of missing bounds check on length.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.

    Published: 14 Oct 2022
    9.1
    Critical

    CVE-2021-46840

    Last Modified: 15 May 2025

    The HW_KEYMASTER module has an out-of-bounds access vulnerability in parameter set verification.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-20397

    Last Modified: 15 May 2025

    In SitRilClient_OnResponse of SitRilSe.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-223086933References: N/A

    Published: 14 Oct 2022
    8.8
    High

    CVE-2021-27406

    Last Modified: 16 Apr 2025

    An attacker can take leverage on PerFact OpenVPN-Client versions 1.4.1.0 and prior to send the config command from any application running on the local host machine to force the back-end server into initializing a new open-VPN instance with arbitrary open-VPN configuration. This could result in the attacker achieving execution with privileges of a SYSTEM user.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2021-0699

    Last Modified: 15 May 2025

    In HTBLogKM of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-242345178

    Published: 14 Oct 2022
    6.2
    Medium

    CVE-2021-22685

    Last Modified: 16 Apr 2025

    An attacker may be able to use minify route with a relative path to view any file on the Cassia Networks Access Controller prior to 2.0.1.

    Published: 14 Oct 2022
    7.3
    High

    CVE-2022-3495

    Last Modified: 14 Apr 2025

    A vulnerability has been found in SourceCodester Simple Online Public Access Catalog 1.0 and classified as critical. This vulnerability affects unknown code of the file /opac/Actions.php?a=login of the component Admin Login. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-210784.

    Published: 14 Oct 2022
    3.5
    Low

    CVE-2022-3497

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Human Resource Management System 1.0. It has been classified as problematic. Affected is an unknown function of the component Master List. The manipulation of the argument city/state/country/position leads to cross site scripting. It is possible to launch the attack remotely. VDB-210786 is the identifier assigned to this vulnerability.

    Published: 14 Oct 2022
    3.5
    Low

    CVE-2022-3503

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Purchase Order Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the component Supplier Handler. The manipulation of the argument Supplier Name/Address/Contact person/Contact leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-210832.

    Published: 14 Oct 2022
    6.3
    Medium

    CVE-2022-3504

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Sanitization Management System and classified as critical. This issue affects some unknown processing of the file /php-sms/?p=services/view_service. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-210839.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-35040

    Last Modified: 15 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b5567.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-35042

    Last Modified: 15 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x4adb11.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-35044

    Last Modified: 15 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x617087.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-35045

    Last Modified: 15 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b0d63.

    Published: 14 Oct 2022
    6.5
    Medium

    CVE-2022-35052

    Last Modified: 15 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b84b1.

    Published: 14 Oct 2022
    3.5
    Low

    CVE-2022-3704

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in Ruby on Rails. This affects an unknown part of the file actionpack/lib/action_dispatch/middleware/templates/routes/_table.html.erb. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The real existence of this vulnerability is still doubted at the moment. The name of the patch is be177e4566747b73ff63fd5f529fab564e475ed4. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-212319. NOTE: Maintainer declares that there isn’t a valid attack vector. The issue was wrongly reported as a security vulnerability by a non-member of the Rails team.

    Published: 14 Oct 2022
    7.8
    High

    CVE-2022-38669

    Last Modified: 15 May 2025

    In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.

    Published: 14 Oct 2022