CVE Feed

    Dashboard / CVE

    5.6
    Medium

    CVE-2022-33748

    Last Modified: 21 Nov 2024

    lock order inversion in transitive grant copy handling As part of XSA-226 a missing cleanup call was inserted on an error handling path. While doing so, locking requirements were not paid attention to. As a result two cooperating guests granting each other transitive grants can cause locks to be acquired nested within one another, but in respectively opposite order. With suitable timing between the involved grant copy operations this may result in the locking up of a CPU.

    Published: 11 Oct 2022
    5.3
    Medium

    CVE-2022-33749

    Last Modified: 21 Nov 2024

    XAPI open file limit DoS It is possible for an unauthenticated client on the network to cause XAPI to hit its file-descriptor limit. This causes XAPI to be unable to accept new requests for other (trusted) clients, and blocks XAPI from carrying out any tasks that require the opening of file descriptors.

    Published: 11 Oct 2022
    3.5
    Low

    CVE-2022-3453

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Book Store Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /transcation.php. The manipulation of the argument buyer_name leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-210437 was assigned to this vulnerability.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-35289

    Last Modified: 21 Nov 2024

    A write-what-where condition in hermes caused by an integer overflow, prior to commit 5b6255ae049fa4641791e47fad994e8e8c4da374 allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

    Published: 11 Oct 2022
    4.9
    Medium

    CVE-2022-35296

    Last Modified: 21 Nov 2024

    Under certain conditions, the application SAP BusinessObjects Business Intelligence Platform (Version Management System) exposes sensitive information to an actor over the network with high privileges that is not explicitly authorized to have access to that information, leading to a high impact on Confidentiality.

    Published: 11 Oct 2022
    5.4
    Medium

    CVE-2022-35297

    Last Modified: 21 Nov 2024

    The application SAP Enable Now does not sufficiently encode user-controlled inputs over the network before it is placed in the output being served to other users, thereby expanding the attack scope, resulting in Stored Cross-Site Scripting (XSS) vulnerability leading to limited impact on Confidentiality, Integrity and Availability.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-35299

    Last Modified: 21 Nov 2024

    SAP SQL Anywhere - version 17.0, and SAP IQ - version 16.1, allows an attacker to leverage logical errors in memory management to cause a memory corruption, such as Stack-based buffer overflow.

    Published: 11 Oct 2022
    6.5
    Medium

    CVE-2022-35770

    Last Modified: 2 Jan 2025

    Windows NTLM Spoofing Vulnerability

    Published: 11 Oct 2022
    6.2
    Medium

    CVE-2022-35829

    Last Modified: 2 Jan 2025

    Service Fabric Explorer Spoofing Vulnerability

    Published: 11 Oct 2022
    7.5
    High

    CVE-2022-36360

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Affected devices load firmware updates without checking the authenticity. Furthermore the integrity of the unencrypted firmware is only verified by a non-cryptographic method. This could allow an attacker to manipulate a firmware update and flash it to the device.

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-37616

    Last Modified: 21 Nov 2024

    A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."

    Published: 11 Oct 2022
    9.8
    Critical

    CVE-2022-37617

    Last Modified: 21 Nov 2024

    Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the k variable in resolve-shims.js.

    Published: 11 Oct 2022
    7.7
    High

    CVE-2022-37973

    Last Modified: 2 Jan 2025

    Windows Local Session Manager (LSM) Denial of Service Vulnerability

    Published: 11 Oct 2022
    6.5
    Medium

    CVE-2022-37974

    Last Modified: 2 Jan 2025

    Windows Mixed Reality Developer Tools Information Disclosure Vulnerability

    Published: 11 Oct 2022
    8.8
    High

    CVE-2022-37976

    Last Modified: 2 Jan 2025

    Active Directory Certificate Services Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-37980

    Last Modified: 2 Jan 2025

    Windows DHCP Client Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    4.3
    Medium

    CVE-2022-37981

    Last Modified: 2 Jan 2025

    Windows Event Logging Service Denial of Service Vulnerability

    Published: 11 Oct 2022
    8.8
    High

    CVE-2022-37982

    Last Modified: 2 Jan 2025

    Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-37983

    Last Modified: 2 Jan 2025

    Microsoft DWM Core Library Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-37986

    Last Modified: 2 Jan 2025

    Windows Win32k Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-37988

    Last Modified: 2 Jan 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-37989

    Last Modified: 2 Jan 2025

    Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-37991

    Last Modified: 2 Jan 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-37993

    Last Modified: 2 Jan 2025

    Windows Group Policy Preference Client Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-37994

    Last Modified: 2 Jan 2025

    Windows Group Policy Preference Client Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-37997

    Last Modified: 2 Jan 2025

    Windows Graphics Component Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    7.7
    High

    CVE-2022-37998

    Last Modified: 2 Jan 2025

    Windows Local Session Manager (LSM) Denial of Service Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-37999

    Last Modified: 2 Jan 2025

    Windows Group Policy Preference Client Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    8.1
    High

    CVE-2022-38000

    Last Modified: 2 Jan 2025

    Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

    Published: 11 Oct 2022
    8.8
    High

    CVE-2022-38016

    Last Modified: 2 Jan 2025

    Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    6.8
    Medium

    CVE-2022-38017

    Last Modified: 2 Jan 2025

    StorSimple 8000 Series Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    7
    High

    CVE-2022-38021

    Last Modified: 2 Jan 2025

    Connected User Experiences and Telemetry Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    3.3
    Low

    CVE-2022-38022

    Last Modified: 2 Jan 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-38025

    Last Modified: 2 Jan 2025

    Windows Distributed File System (DFS) Information Disclosure Vulnerability

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-38026

    Last Modified: 2 Jan 2025

    Windows DHCP Client Information Disclosure Vulnerability

    Published: 11 Oct 2022
    7
    High

    CVE-2022-38029

    Last Modified: 2 Jan 2025

    Windows ALPC Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    4.3
    Medium

    CVE-2022-38030

    Last Modified: 2 Jan 2025

    Windows USB Serial Driver Information Disclosure Vulnerability

    Published: 11 Oct 2022
    8.8
    High

    CVE-2022-38034

    Last Modified: 2 Jan 2025

    Windows Workstation Service Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    7.5
    High

    CVE-2022-38036

    Last Modified: 2 Jan 2025

    Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-38037

    Last Modified: 2 Jan 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-38038

    Last Modified: 2 Jan 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-38039

    Last Modified: 2 Jan 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    7.5
    High

    CVE-2022-38041

    Last Modified: 2 Jan 2025

    Windows Secure Channel Denial of Service Vulnerability

    Published: 11 Oct 2022
    7.1
    High

    CVE-2022-38042

    Last Modified: 2 Jan 2025

    Active Directory Domain Services Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    5.5
    Medium

    CVE-2022-38043

    Last Modified: 2 Jan 2025

    Windows Security Support Provider Interface Information Disclosure Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-38044

    Last Modified: 27 Aug 2025

    Windows CD-ROM File System Driver Remote Code Execution Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-38048

    Last Modified: 2 Jan 2025

    Microsoft Office Remote Code Execution Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-38049

    Last Modified: 2 Jan 2025

    Microsoft Office Graphics Remote Code Execution Vulnerability

    Published: 11 Oct 2022
    7.8
    High

    CVE-2022-38050

    Last Modified: 2 Jan 2025

    Win32k Elevation of Privilege Vulnerability

    Published: 11 Oct 2022
    8.8
    High

    CVE-2022-38053

    Last Modified: 2 Jan 2025

    Microsoft SharePoint Server Remote Code Execution Vulnerability

    Published: 11 Oct 2022