CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-41189

    Last Modified: 20 May 2025

    Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dwg, TeighaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41201

    Last Modified: 5 Jun 2025

    Due to lack of proper memory management, when a victim opens a manipulated Right Hemisphere Binary (.rh, rh.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-41380

    Last Modified: 20 May 2025

    The d8s-yaml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-41386

    Last Modified: 20 May 2025

    The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.

    Published: 11 Oct 2022
    7.2
    High

    CVE-2022-41532

    Last Modified: 20 May 2025

    Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_plan.

    Published: 11 Oct 2022
    6.5
    Medium

    CVE-2022-41550

    Last Modified: 20 May 2025

    GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component osip_body_parse_header.

    Published: 11 Oct 2022
    —
    Unknown

    CVE-2022-42794

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 11 Oct 2022
    —
    Unknown

    CVE-2022-42804

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 11 Oct 2022
    —
    Unknown

    CVE-2022-42822

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 11 Oct 2022
    —
    Unknown

    CVE-2022-42835

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 11 Oct 2022
    —
    Unknown

    CVE-2022-42857

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 11 Oct 2022
    7
    High

    CVE-2021-0696

    Last Modified: 21 Nov 2024

    In dllist_remove_node of TBD, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-242344778

    Published: 11 Oct 2022
    8.8
    High

    CVE-2022-42034

    Last Modified: 20 May 2025

    Wedding Planner v1.0 is vulnerable to arbitrary code execution via users_profile.php.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-42036

    Last Modified: 21 Nov 2024

    The d8s-urls package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-csv package. The affected version is 0.1.0.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-42037

    Last Modified: 20 May 2025

    The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-csv package. The affected version is 0.1.0.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-42038

    Last Modified: 19 May 2025

    The d8s-ip-addresses package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-csv package. The affected version is 0.1.0.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-42039

    Last Modified: 19 May 2025

    The d8s-lists package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-dicts package. The affected version is 0.1.0.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-42040

    Last Modified: 19 May 2025

    The d8s-algorithms package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-dicts package. The affected version is 0.1.0.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-42041

    Last Modified: 19 May 2025

    The d8s-file-system package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hashes package. The affected version is 0.1.0.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-42042

    Last Modified: 19 May 2025

    The d8s-networking package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hashes package. The affected version is 0.1.0.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-42044

    Last Modified: 19 May 2025

    The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-html package. The affected version is 0.1.0.

    Published: 11 Oct 2022
    5
    Medium

    CVE-2022-20394

    Last Modified: 21 Nov 2024

    In getInputMethodWindowVisibleHeight of InputMethodManagerService.java, there is a possible way to determine when another app is showing an IME due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-204906124

    Published: 11 Oct 2022
    7.5
    High

    CVE-2022-20410

    Last Modified: 21 Nov 2024

    In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-205570663

    Published: 11 Oct 2022
    6.7
    Medium

    CVE-2022-20412

    Last Modified: 21 Nov 2024

    In fdt_next_tag of fdt.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-230794395

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-20413

    Last Modified: 21 Nov 2024

    In start of Threads.cpp, there is a possible way to record audio during a phone call due to a logic error in the code. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-235850634

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-20415

    Last Modified: 21 Nov 2024

    In handleFullScreenIntent of StatusBarNotificationActivityStarter.java, there is a possible bypass of the restriction of starting activity from background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-231322873

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-20416

    Last Modified: 21 Nov 2024

    In audioTransportsToHal of HidlUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-237717857

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-20417

    Last Modified: 21 Nov 2024

    In audioTransportsToHal of HidlUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-237288416

    Published: 11 Oct 2022
    7.5
    High

    CVE-2022-20418

    Last Modified: 21 Nov 2024

    In pickStartSeq of AAVCAssembler.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-231986464

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-20419

    Last Modified: 21 Nov 2024

    In setOptions of ActivityRecord.java, there is a possible load any arbitrary Java code into launcher process due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-237290578

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-20420

    Last Modified: 21 Nov 2024

    In getBackgroundRestrictionExemptionReason of AppRestrictionController.java, there is a possible way to bypass device policy restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-238377411

    Published: 11 Oct 2022
    7
    High

    CVE-2022-20422

    Last Modified: 21 Nov 2024

    In emulation_proc_handler of armv8_deprecated.c, there is a possible way to corrupt memory due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-237540956References: Upstream kernel

    Published: 11 Oct 2022
    4.6
    Medium

    CVE-2022-20423

    Last Modified: 21 Nov 2024

    In rndis_set_response of rndis.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if a malicious USB device is attached with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239842288References: Upstream kernel

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-20425

    Last Modified: 21 Nov 2024

    In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent degradation of performance due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-235823407

    Published: 11 Oct 2022
    8.8
    High

    CVE-2022-20429

    Last Modified: 21 Nov 2024

    In CarSettings of app packages, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-220741473

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-20430

    Last Modified: 21 Nov 2024

    There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221233

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-20431

    Last Modified: 21 Nov 2024

    There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221238

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-20433

    Last Modified: 21 Nov 2024

    There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221901

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-20435

    Last Modified: 21 Nov 2024

    There is a Unauthorized service in the system service, may cause the system reboot. Since the component does not have permission check and permission protection, resulting in EoP problem.Product: AndroidVersions: Android SoCAndroid ID: A-242248367

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-20437

    Last Modified: 21 Nov 2024

    In Messaging, There has unauthorized broadcast, this could cause Local Deny of Service.Product: AndroidVersions: Android SoCAndroid ID: A-242258929

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-20438

    Last Modified: 21 Nov 2024

    In Messaging, There has unauthorized broadcast, this could cause Local Deny of Service.Product: AndroidVersions: Android SoCAndroid ID: A-242259920

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-20439

    Last Modified: 21 Nov 2024

    In Messaging, There has unauthorized provider, this could cause Local Deny of Service.Product: AndroidVersions: Android SoCAndroid ID: A-242266172

    Published: 11 Oct 2022
    8.8
    High

    CVE-2022-42229

    Last Modified: 19 May 2025

    Wedding Planner v1.0 is vulnerable to Arbitrary code execution via package_edit.php.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2020-14129

    Last Modified: 21 Nov 2024

    A logic vulnerability exists in a Xiaomi product. The vulnerability is caused by an identity verification failure, which can be exploited by an attacker who can obtain a brief elevation of privilege.

    Published: 11 Oct 2022
    7.8
    High

    CVE-2021-0951

    Last Modified: 21 Nov 2024

    In DevmemIntHeapAcquire of TBD, there is a possible arbitrary code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-242345085

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-41851

    Last Modified: 20 May 2025

    A vulnerability has been identified in JTTK (All versions < V11.1.1.0), Simcenter Femap V2022.1 (All versions < V2022.1.3), Simcenter Femap V2022.2 (All versions < V2022.2.2). The JTTK library is vulnerable to an uninitialized pointer reference vulnerability while parsing specially crafted JT files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-16973)

    Published: 11 Oct 2022
    7.5
    High

    CVE-2022-42731

    Last Modified: 20 May 2025

    mfa/FIDO2.py in django-mfa2 before 2.5.1 and 2.6.x before 2.6.1 allows a replay attack that could be used to register another device for a user. The device registration challenge is not invalidated after usage.

    Published: 11 Oct 2022
    8.1
    High

    CVE-2022-33634

    Last Modified: 2 Jan 2025

    Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-33635

    Last Modified: 2 Jan 2025

    Windows GDI+ Remote Code Execution Vulnerability

    Published: 11 Oct 2022
    3.8
    Low

    CVE-2022-33747

    Last Modified: 21 Nov 2024

    Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e.g. removing pages from a guest's P2M (Physical-to-Machine) mapping. When large pages are in use to map guest pages in the 2nd-stage page tables, such a removal operation may incur a memory allocation (to replace a large mapping with individual smaller ones). These memory allocations are taken from the global memory pool. A malicious guest might be able to cause the global memory pool to be exhausted by manipulating its own P2M mappings.

    Published: 11 Oct 2022