CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-41170

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated CATIA4 Part (.model, CatiaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-41182

    Last Modified: 21 Nov 2024

    Due to lack of proper memory management, when a victim opens manipulated Parasolid Part and Assembly (.x_b, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41202

    Last Modified: 20 May 2025

    Due to lack of proper memory management, when a victim opens a manipulated Visual Design Stream (.vds, vds.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-41383

    Last Modified: 20 May 2025

    The d8s-archives package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-41387

    Last Modified: 20 May 2025

    The d8s-pdfs package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.

    Published: 11 Oct 2022
    7.5
    High

    CVE-2022-41404

    Last Modified: 9 Jun 2025

    An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-42043

    Last Modified: 19 May 2025

    The d8s-xml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-html package. The affected version is 0.1.0.

    Published: 11 Oct 2022
    7.2
    High

    CVE-2022-42230

    Last Modified: 19 May 2025

    Simple Cold Storage Management System v1.0 is vulnerable to SQL Injection via /csms/admin/?page=user/manage_user&id=.

    Published: 11 Oct 2022
    5.4
    Medium

    CVE-2022-42235

    Last Modified: 19 May 2025

    A Stored XSS issue in Student Clearance System v.1.0 allows the injection of arbitrary JavaScript in the Student registration form.

    Published: 11 Oct 2022
    5.4
    Medium

    CVE-2022-42236

    Last Modified: 20 May 2025

    A Stored XSS issue in Merchandise Online Store v.1.0 allows to injection of Arbitrary JavaScript in edit account form.

    Published: 11 Oct 2022
    8.8
    High

    CVE-2022-42238

    Last Modified: 20 May 2025

    A Vertical Privilege Escalation issue in Merchandise Online Store v.1.0 allows an attacker to get access to the admin dashboard.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-42717

    Last Modified: 20 May 2025

    An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.

    Published: 11 Oct 2022
    7.5
    High

    CVE-2022-32149

    Last Modified: 15 May 2025

    An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-32234

    Last Modified: 21 Nov 2024

    An out of bounds write in hermes, while handling large arrays, prior to commit 06eaec767e376bfdb883d912cb15e987ddf2bda1 allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41033

    Last Modified: 13 Jan 2026

    Windows COM+ Event System Service Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    6.1
    Medium

    CVE-2022-35226

    Last Modified: 25 Feb 2026

    SAP Data Services Management allows an attacker to copy the data from a request and echoed into the application's immediate response, it will lead to a Cross-Site Scripting vulnerability. The attacker would have to log in to the management console to perform such as an attack, only few of the pages are vulnerable in the DS management console.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-39803

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated ACIS Part and Assembly (.sat, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-39804

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated SolidWorks Part (.sldprt, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-39806

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated SolidWorks Drawing (.slddrw, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-39808

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41167

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dwg, TeighaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41172

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dxf, TeighaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41177

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated Iges Part and Assembly (.igs, .iges, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41179

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated Jupiter Tesselation (.jt, JtTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41180

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated Portable Document Format (.pdf, PDFPublishing.dll) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41184

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated Windows Cursor File (.cur, ico.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41186

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, a Remote Code Execution can be triggered when payload forces a stack-based overflow and or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41190

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dxf, TeighaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41193

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated Encapsulated Post Script (.eps, ai.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41195

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated EAAmiga Interchange File Format (.iff, 2d.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41196

    Last Modified: 25 Feb 2026

    Due to lack of proper memory management, when a victim opens a manipulated VRML Worlds (.wrl, vrml.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-38028

    Last Modified: 12 Jan 2026

    Windows Print Spooler Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2020-14131

    Last Modified: 21 Nov 2024

    The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security Center (MiSRC) to jointly ensure the safe access of millions of Xiaomi users worldwide Life.

    Published: 11 Oct 2022
    3.5
    Low

    CVE-2022-3452

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Book Store Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /category.php. The manipulation of the argument category_name leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-210436.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-37609

    Last Modified: 21 Nov 2024

    Prototype pollution vulnerability in beautify-web js-beautify 1.13.7 via the name variable in options.js.

    Published: 11 Oct 2022
    5.9
    Medium

    CVE-2022-37965

    Last Modified: 2 Jan 2025

    Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-37970

    Last Modified: 2 Jan 2025

    Windows DWM Core Library Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-37995

    Last Modified: 2 Jan 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    6.5
    Medium

    CVE-2022-38001

    Last Modified: 2 Jan 2025

    Microsoft Office Spoofing Vulnerability

    Published: 11 Oct 2022
    7
    High

    CVE-2022-38027

    Last Modified: 2 Jan 2025

    Windows Storage Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    6.6
    Medium

    CVE-2022-38032

    Last Modified: 2 Jan 2025

    Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability

    Published: 11 Oct 2022
    8.1
    High

    CVE-2022-38047

    Last Modified: 2 Jan 2025

    Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

    Published: 11 Oct 2022
    —
    Unknown

    CVE-2022-42802

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 11 Oct 2022
    7.5
    High

    CVE-2022-39271

    Last Modified: 23 Apr 2025

    Traefik (pronounced traffic) is a modern HTTP reverse proxy and load balancer that assists in deploying microservices. There is a potential vulnerability in Traefik managing HTTP/2 connections. A closing HTTP/2 server connection could hang forever because of a subsequent fatal error. This failure mode could be exploited to cause a denial of service. There has been a patch released in versions 2.8.8 and 2.9.0-rc5. There are currently no known workarounds.

    Published: 11 Oct 2022
    6.1
    Medium

    CVE-2022-39800

    Last Modified: 21 Nov 2024

    SAP BusinessObjects BI LaunchPad - versions 420, 430, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the network. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-39807

    Last Modified: 21 Nov 2024

    Due to lack of proper memory management, when a victim opens manipulated SolidWorks Drawing (.sldasm, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-40138

    Last Modified: 21 Nov 2024

    An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, could have been used to perform Out-Of-Bounds operations and subsequently execute arbitrary code. Note that this is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence, most React Native applications are not affected.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41032

    Last Modified: 28 Feb 2025

    NuGet Client Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    8.8
    High

    CVE-2022-41036

    Last Modified: 2 Jan 2025

    Microsoft SharePoint Server Remote Code Execution Vulnerability

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-41176

    Last Modified: 21 Nov 2024

    Due to lack of proper memory management, when a victim opens manipulated Enhanced Metafile (.emf, emf.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

    Published: 11 Oct 2022