CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2022-40469

    Last Modified: 15 May 2025

    iKuai OS v3.6.7 was discovered to contain an authenticated remote code execution (RCE) vulnerability.

    Published: 12 Oct 2022
    9.8
    Critical

    CVE-2022-40664

    Last Modified: 15 May 2025

    Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.

    Published: 12 Oct 2022
    5.3
    Medium

    CVE-2022-41316

    Last Modified: 15 May 2025

    HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.

    Published: 12 Oct 2022
    6.1
    Medium

    CVE-2022-41348

    Last Modified: 15 May 2025

    An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via the onerror attribute of an IMG element, leading to information disclosure.

    Published: 12 Oct 2022
    6.1
    Medium

    CVE-2022-41349

    Last Modified: 15 May 2025

    In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/compose accepts an attachUrl parameter that is vulnerable to Reflected XSS. This allows executing arbitrary JavaScript on the victim's machine.

    Published: 12 Oct 2022
    6.1
    Medium

    CVE-2022-41350

    Last Modified: 15 May 2025

    In Zimbra Collaboration Suite (ZCS) 8.8.15, /h/search?action=voicemail&action=listen accepts a phone parameter that is vulnerable to Reflected XSS. This allows executing arbitrary JavaScript on the victim's machine.

    Published: 12 Oct 2022
    8.4
    High

    CVE-2022-22077

    Last Modified: 15 May 2025

    Memory corruption in graphics due to use-after-free in graphics dispatcher logic in Snapdragon Mobile

    Published: 12 Oct 2022
    4.6
    Medium

    CVE-2022-22078

    Last Modified: 15 May 2025

    Denial of service in BOOT when partition size for a particular partition is requested due to integer overflow when blocks are calculated in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 12 Oct 2022
    7.7
    High

    CVE-2022-2249

    Last Modified: 19 May 2025

    Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local administrative users to escalate their privileges. This issue affects Communication Manager versions 8.0.0.0 through 8.1.3.3 and 10.1.0.0.

    Published: 12 Oct 2022
    4.3
    Medium

    CVE-2022-3171

    Last Modified: 21 Apr 2025

    A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.

    Published: 12 Oct 2022
    7.8
    High

    CVE-2022-25660

    Last Modified: 15 May 2025

    Memory corruption due to double free issue in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 12 Oct 2022
    8.4
    High

    CVE-2022-25661

    Last Modified: 15 May 2025

    Memory corruption due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 12 Oct 2022
    5.3
    Medium

    CVE-2022-25662

    Last Modified: 15 May 2025

    Information disclosure due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 12 Oct 2022
    6.8
    Medium

    CVE-2022-25665

    Last Modified: 15 May 2025

    Information disclosure due to buffer over read in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Mobile

    Published: 12 Oct 2022
    5.5
    Medium

    CVE-2023-38665

    Last Modified: 21 Nov 2024

    Null pointer dereference in ieee_write_file in nasm 2.16rc0 allows attackers to cause a denial of service (crash).

    Published: 12 Oct 2022
    5.9
    Medium

    CVE-2022-39283

    Last Modified: 3 Nov 2025

    FreeRDP is a free remote desktop protocol library and clients. All FreeRDP based clients when using the `/video` command line switch might read uninitialized data, decode it as audio/video and display the result. FreeRDP based server implementations are not affected. This issue has been patched in version 2.8.1. If you cannot upgrade do not use the `/video` switch.

    Published: 12 Oct 2022
    3.5
    Low

    CVE-2022-39282

    Last Modified: 3 Nov 2025

    FreeRDP is a free remote desktop protocol library and clients. FreeRDP based clients on unix systems using `/parallel` command line switch might read uninitialized data and send it to the server the client is currently connected to. FreeRDP based server implementations are not affected. Please upgrade to 2.8.1 where this issue is patched. If unable to upgrade, do not use parallel port redirection (`/parallel` command line switch) as a workaround.

    Published: 12 Oct 2022
    4.3
    Medium

    CVE-2022-3464

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The manipulation of the argument site_name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-210699.

    Published: 12 Oct 2022
    7.3
    High

    CVE-2022-3465

    Last Modified: 14 Apr 2025

    A vulnerability classified as critical was found in Mediabridge Medialink. This vulnerability affects unknown code of the file /index.asp. The manipulation leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-210700.

    Published: 12 Oct 2022
    4.8
    Medium

    CVE-2022-3466

    Last Modified: 21 Nov 2024

    The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing the fix for CVE-2022-27652, which was previously fixed in OCP 4.9.41 and 4.10.12 via RHBA-2022:5433 and RHSA-2022:1600. This issue could allow an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. For more details, see https://access.redhat.com/security/cve/CVE-2022-27652.

    Published: 12 Oct 2022
    6.3
    Medium

    CVE-2022-3471

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Human Resource Management System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file city.php. The manipulation of the argument searccity leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-210715.

    Published: 12 Oct 2022
    6.3
    Medium

    CVE-2022-3472

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Human Resource Management System. It has been rated as critical. Affected by this issue is some unknown functionality of the file city.php. The manipulation of the argument cityedit leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-210716.

    Published: 12 Oct 2022
    9.8
    Critical

    CVE-2022-37601

    Last Modified: 21 Nov 2024

    Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.

    Published: 12 Oct 2022
    9.8
    Critical

    CVE-2022-37614

    Last Modified: 15 May 2025

    Prototype pollution vulnerability in function enable in mockery.js in mfncooper mockery commit 822f0566fd6d72af8c943ae5ca2aa92e516aa2cf via the key variable in mockery.js.

    Published: 12 Oct 2022
    7.7
    High

    CVE-2022-39298

    Last Modified: 23 Apr 2025

    MelisFront is the engine that displays website hosted on Melis Platform. It deals with showing pages, plugins, URL rewritting, search optimization and SEO, etc. Attackers can deserialize arbitrary data on affected versions of `melisplatform/melis-front`, and ultimately leads to the execution of arbitrary PHP code on the system. Conducting this attack does not require authentication. Users should immediately upgrade to `melisplatform/melis-front` >= 5.0.1. This issue was addressed by restricting allowed classes when deserializing user-controlled data.

    Published: 12 Oct 2022
    7.4
    High

    CVE-2022-39299

    Last Modified: 23 Apr 2025

    Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. A remote attacker may be able to bypass SAML authentication on a website using passport-saml. A successful attack requires that the attacker is in possession of an arbitrary IDP signed XML element. Depending on the IDP used, fully unauthenticated attacks (e.g without access to a valid user) might also be feasible if generation of a signed message can be triggered. Users should upgrade to passport-saml version 3.2.2 or newer. The issue was also present in the beta releases of `node-saml` before version 4.0.0-beta.5. If you cannot upgrade, disabling SAML authentication may be done as a workaround.

    Published: 12 Oct 2022
    9.8
    Critical

    CVE-2022-41403

    Last Modified: 15 May 2025

    OpenCart 3.x Newsletter Custom Popup was discovered to contain a SQL injection vulnerability via the email parameter at index.php?route=extension/module/so_newletter_custom_popup/newsletter.

    Published: 12 Oct 2022
    9.8
    Critical

    CVE-2022-42897

    Last Modified: 15 May 2025

    Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege escalation and control of the system. NOTE: ArrayOS AG 10.x is unaffected.

    Published: 12 Oct 2022
    5.5
    Medium

    CVE-2022-25663

    Last Modified: 15 May 2025

    Possible buffer overflow due to lack of buffer length check during management frame Rx handling lead to denial of service in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity

    Published: 12 Oct 2022
    6.2
    Medium

    CVE-2022-25664

    Last Modified: 15 May 2025

    Information disclosure due to exposure of information while GPU reads the data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 12 Oct 2022
    4.3
    Medium

    CVE-2022-28887

    Last Modified: 15 May 2025

    Multiple Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl.dll unpacker handler function crashes. This can lead to a possible scanning engine crash.

    Published: 12 Oct 2022
    4.3
    Medium

    CVE-2021-36201

    Last Modified: 15 May 2025

    Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versions.

    Published: 11 Oct 2022
    5.4
    Medium

    CVE-2022-38086

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Shortcodes Ultimate plugin <= 5.12.0 at WordPress leading to plugin preset settings change.

    Published: 11 Oct 2022
    4.2
    Medium

    CVE-2021-36915

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder plugin <= 3.6.0 at WordPress allows uploading the JSON file and updating the options. Requires Import and Export add-on.

    Published: 11 Oct 2022
    7.5
    High

    CVE-2021-36913

    Last Modified: 20 Feb 2025

    Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows attackers to change options and inject scripts into the footer HTML. Requires an additional extension (plugin) AccessiBe.

    Published: 11 Oct 2022
    4.8
    Medium

    CVE-2021-36899

    Last Modified: 20 Feb 2025

    Authenticated (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Gabe Livan's Asset CleanUp: Page Speed Booster plugin <= 1.3.8.4 at WordPress.

    Published: 11 Oct 2022
    6.1
    Medium

    CVE-2022-33978

    Last Modified: 20 Feb 2025

    Reflected Cross-Site Scripting (XSS) vulnerability FontMeister plugin <= 1.08 at WordPress.

    Published: 11 Oct 2022
    6.7
    Medium

    CVE-2022-34434

    Last Modified: 19 May 2025

    Cloud Mobility for Dell Storage versions 1.3.0 and earlier contains an Improper Access Control vulnerability within the Postgres database. A threat actor with root level access to either the vApp or containerized versions of Cloud Mobility may potentially exploit this vulnerability, leading to the modification or deletion of tables that are required for many of the core functionalities of Cloud Mobility. Exploitation may lead to the compromise of integrity and availability of the normal functionality of the Cloud Mobility application.

    Published: 11 Oct 2022
    7.3
    High

    CVE-2022-34432

    Last Modified: 19 May 2025

    Dell Hybrid Client below 1.8 version contains a gedit vulnerability. A guest attacker could potentially exploit this vulnerability, allowing deletion of user and some system files and folders.

    Published: 11 Oct 2022
    6.5
    Medium

    CVE-2022-34431

    Last Modified: 19 May 2025

    Dell Hybrid Client below 1.8 version contains a guest user profile corruption vulnerability. A WMS privilege attacker could potentially exploit this vulnerability, leading to DHC system not being accessible.

    Published: 11 Oct 2022
    7.1
    High

    CVE-2022-34430

    Last Modified: 19 May 2025

    Dell Hybrid Client below 1.8 version contains a Zip Bomb Vulnerability in UI. A guest privilege attacker could potentially exploit this vulnerability, leading to system files modification.

    Published: 11 Oct 2022
    8.8
    High

    CVE-2022-34427

    Last Modified: 16 May 2025

    Dell Container Storage Modules 1.2 contains an OS Command Injection in goiscsi and gobrick libraries. A remote unauthenticated attacker could exploit this vulnerability leading to modification of intended OS command execution.

    Published: 11 Oct 2022
    8.8
    High

    CVE-2022-34426

    Last Modified: 16 May 2025

    Dell Container Storage Modules 1.2 contains an Improper Limitation of a Pathname to a Restricted Directory in goiscsi and gobrick libraries which could lead to OS command injection. A remote unauthenticated attacker could exploit this vulnerability leading to unintentional access to path outside of restricted directory.

    Published: 11 Oct 2022
    7.5
    High

    CVE-2022-32492

    Last Modified: 16 May 2025

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

    Published: 11 Oct 2022
    7.5
    High

    CVE-2022-32486

    Last Modified: 16 May 2025

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-38388

    Last Modified: 15 May 2025

    IBM Navigator Mobile Android 3.4.1.1 and 3.4.1.2 app could allow a local user to obtain sensitive information due to improper access control. IBM X-Force ID: 233968.

    Published: 11 Oct 2022
    9
    Critical

    CVE-2022-32174

    Last Modified: 27 May 2025

    In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.

    Published: 11 Oct 2022
    5.4
    Medium

    CVE-2022-32175

    Last Modified: 20 May 2025

    In AdGuardHome, versions v0.95 through v0.108.0-b.13 are vulnerable to Cross-Site Request Forgery (CSRF), in the custom filtering rules functionality. An attacker can persuade an authorized user to follow a malicious link, resulting in deleting/modifying the custom filtering rules.

    Published: 11 Oct 2022
    8.8
    High

    CVE-2022-31765

    Last Modified: 14 Apr 2026

    Affected devices do not properly authorize the change password function of the web interface. This could allow low privileged users to escalate their privileges.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41198

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated SketchUp (.skp, SketchUp.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022