CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2022-40440

    Last Modified: 21 Nov 2024

    mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function.

    Published: 11 Oct 2022
    7.2
    High

    CVE-2022-40921

    Last Modified: 21 Nov 2024

    DedeCMS V5.7.99 was discovered to contain an arbitrary file upload vulnerability via the component /dede/file_manage_control.php.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41031

    Last Modified: 2 Jan 2025

    Microsoft Word Remote Code Execution Vulnerability

    Published: 11 Oct 2022
    5.3
    Medium

    CVE-2022-41035

    Last Modified: 2 Jan 2025

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

    Published: 11 Oct 2022
    8.8
    High

    CVE-2022-41037

    Last Modified: 2 Jan 2025

    Microsoft SharePoint Server Remote Code Execution Vulnerability

    Published: 11 Oct 2022
    8.8
    High

    CVE-2022-41038

    Last Modified: 2 Jan 2025

    Microsoft SharePoint Server Remote Code Execution Vulnerability

    Published: 11 Oct 2022
    7.4
    High

    CVE-2022-41042

    Last Modified: 2 Jan 2025

    Visual Studio Code Information Disclosure Vulnerability

    Published: 11 Oct 2022
    3.3
    Low

    CVE-2022-41043

    Last Modified: 2 Jan 2025

    Microsoft Office Information Disclosure Vulnerability

    Published: 11 Oct 2022
    8.1
    High

    CVE-2022-41081

    Last Modified: 2 Jan 2025

    Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41083

    Last Modified: 2 Jan 2025

    Visual Studio Code Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41168

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated CATIA5 Part (.catpart, CatiaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-41166

    Last Modified: 21 Nov 2024

    Due to lack of proper memory management, when a victim opens manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-41169

    Last Modified: 21 Nov 2024

    Due to lack of proper memory management, when a victim opens manipulated CATIA5 Part (.catpart, CatiaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41175

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated Enhanced Metafile (.emf, emf.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-41171

    Last Modified: 21 Nov 2024

    Due to lack of proper memory management, when a victim opens manipulated CATIA4 Part (.model, CatiaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-41173

    Last Modified: 21 Nov 2024

    Due to lack of proper memory management, when a victim opens manipulated AutoCAD (.dxf, TeighaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-41174

    Last Modified: 21 Nov 2024

    Due to lack of proper memory management, when a victim opens manipulated Right Hemisphere Material (.rhm, rh.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-41178

    Last Modified: 21 Nov 2024

    Due to lack of proper memory management, when a victim opens manipulated Iges Part and Assembly (.igs, .iges, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-41181

    Last Modified: 21 Nov 2024

    Due to lack of proper memory management, when a victim opens manipulated Portable Document Format (.pdf, PDFPublishing.dll) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41185

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated Visual Design Stream (.vds, MataiPersistence.dll) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41187

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-41183

    Last Modified: 21 Nov 2024

    Due to lack of proper memory management, when a victim opens manipulated Windows Cursor File (.cur, ico.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41188

    Last Modified: 21 Nov 2024

    Due to lack of proper memory management, when a victim opens manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41191

    Last Modified: 20 May 2025

    Due to lack of proper memory management, when a victim opens a manipulated Jupiter Tesselation (.jt, JTReader.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41192

    Last Modified: 21 Nov 2024

    Due to lack of proper memory management, when a victim opens manipulated Jupiter Tesselation (.jt, JTReader.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41194

    Last Modified: 21 Nov 2024

    Due to lack of proper memory management, when a victim opens a manipulated Encapsulated Postscript (.eps, ai.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41200

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated Scalable Vector Graphic (.svg, svg.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41197

    Last Modified: 21 Nov 2024

    Due to lack of proper memory management, when a victim opens a manipulated VRML Worlds (.wrl, vrml.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41199

    Last Modified: 15 May 2025

    Due to lack of proper memory management, when a victim opens a manipulated Open Inventor File (.iv, vrml.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    8.8
    High

    CVE-2022-41204

    Last Modified: 20 May 2025

    An attacker can change the content of an SAP Commerce - versions 1905, 2005, 2105, 2011, 2205, login page through a manipulated URL. They can inject code that allows them to redirect submissions from the affected login form to their own server. This allows them to steal credentials and hijack accounts. A successful attack could compromise the Confidentiality, Integrity, and Availability of the system.

    Published: 11 Oct 2022
    5.4
    Medium

    CVE-2022-41206

    Last Modified: 20 May 2025

    SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) - versions 420, 430, allows an authenticated attacker to send user-controlled inputs when OLAP connections are created and edited in the Central Management Console. On successful exploitation, there could be a limited impact on confidentiality and integrity of the application.

    Published: 11 Oct 2022
    5.2
    Medium

    CVE-2022-41209

    Last Modified: 20 May 2025

    SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses encryption method which lacks proper diffusion and does not hide the patterns well. This can lead to information disclosure. In certain scenarios, application might also be susceptible to replay attacks.

    Published: 11 Oct 2022
    5.2
    Medium

    CVE-2022-41210

    Last Modified: 20 May 2025

    SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses insecure random number generator program which makes it easy for the attacker to predict future random numbers. This can lead to information disclosure and modification of certain user settings.

    Published: 11 Oct 2022
    6.1
    Medium

    CVE-2022-41376

    Last Modified: 20 May 2025

    Metro UI v4.4.0 to v4.5.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Javascript function.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-41381

    Last Modified: 20 May 2025

    The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-41382

    Last Modified: 20 May 2025

    The d8s-json package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-41384

    Last Modified: 20 May 2025

    The d8s-domains package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-41385

    Last Modified: 20 May 2025

    The d8s-html package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.

    Published: 11 Oct 2022
    7.2
    High

    CVE-2022-41406

    Last Modified: 20 May 2025

    An arbitrary file upload vulnerability in the /admin/admin_pic.php component of Church Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 11 Oct 2022
    7.2
    High

    CVE-2022-41407

    Last Modified: 19 May 2025

    Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/view_order.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-41408

    Last Modified: 19 May 2025

    Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/view_order.

    Published: 11 Oct 2022
    7.2
    High

    CVE-2022-41530

    Last Modified: 19 May 2025

    Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_borrower.

    Published: 11 Oct 2022
    6.5
    Medium

    CVE-2022-41606

    Last Modified: 20 May 2025

    HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid S3 or GCS URLs can be used to crash client agents. Fixed in 1.2.13, 1.3.6, and 1.4.0.

    Published: 11 Oct 2022
    8.1
    High

    CVE-2022-22035

    Last Modified: 2 Jan 2025

    Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-20351

    Last Modified: 21 Nov 2024

    In queryInternal of CallLogProvider.java, there is a possible access to voicemail information due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-224771921

    Published: 11 Oct 2022
    6.7
    Medium

    CVE-2022-20409

    Last Modified: 21 Nov 2024

    In io_identity_cow of io_uring.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-238177383References: Upstream kernel

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-20432

    Last Modified: 21 Nov 2024

    There is an missing authorization issue in the system service. Since the component does not have permission check and permission protection,, resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221899

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-20434

    Last Modified: 21 Nov 2024

    There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242244028

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-20436

    Last Modified: 21 Nov 2024

    There is an unauthorized service in the system service. Since the component does not have permission check, resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242248369

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-20440

    Last Modified: 21 Nov 2024

    In Messaging, There has unauthorized broadcast, this could cause Local Deny of Service.Product: AndroidVersions: Android SoCAndroid ID: A-242259918

    Published: 11 Oct 2022