CVE-2022-33748
Last Modified: 21 Nov 2024lock order inversion in transitive grant copy handling As part of XSA-226 a missing cleanup call was inserted on an error handling path. While doing so, locking requirements were not paid attention to. As a result two cooperating guests granting each other transitive grants can cause locks to be acquired nested within one another, but in respectively opposite order. With suitable timing between the involved grant copy operations this may result in the locking up of a CPU.
CVE-2022-33749
Last Modified: 21 Nov 2024XAPI open file limit DoS It is possible for an unauthenticated client on the network to cause XAPI to hit its file-descriptor limit. This causes XAPI to be unable to accept new requests for other (trusted) clients, and blocks XAPI from carrying out any tasks that require the opening of file descriptors.
CVE-2022-3453
Last Modified: 15 Apr 2025A vulnerability was found in SourceCodester Book Store Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /transcation.php. The manipulation of the argument buyer_name leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-210437 was assigned to this vulnerability.
CVE-2022-35289
Last Modified: 21 Nov 2024A write-what-where condition in hermes caused by an integer overflow, prior to commit 5b6255ae049fa4641791e47fad994e8e8c4da374 allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.
CVE-2022-35296
Last Modified: 21 Nov 2024Under certain conditions, the application SAP BusinessObjects Business Intelligence Platform (Version Management System) exposes sensitive information to an actor over the network with high privileges that is not explicitly authorized to have access to that information, leading to a high impact on Confidentiality.
CVE-2022-35297
Last Modified: 21 Nov 2024The application SAP Enable Now does not sufficiently encode user-controlled inputs over the network before it is placed in the output being served to other users, thereby expanding the attack scope, resulting in Stored Cross-Site Scripting (XSS) vulnerability leading to limited impact on Confidentiality, Integrity and Availability.
CVE-2022-35299
Last Modified: 21 Nov 2024SAP SQL Anywhere - version 17.0, and SAP IQ - version 16.1, allows an attacker to leverage logical errors in memory management to cause a memory corruption, such as Stack-based buffer overflow.
CVE-2022-35770
Last Modified: 2 Jan 2025Windows NTLM Spoofing Vulnerability
CVE-2022-35829
Last Modified: 2 Jan 2025Service Fabric Explorer Spoofing Vulnerability
CVE-2022-36360
Last Modified: 21 Nov 2024A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Affected devices load firmware updates without checking the authenticity. Furthermore the integrity of the unencrypted firmware is only verified by a non-cryptographic method. This could allow an attacker to manipulate a firmware update and flash it to the device.
CVE-2022-37616
Last Modified: 21 Nov 2024A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."
CVE-2022-37617
Last Modified: 21 Nov 2024Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the k variable in resolve-shims.js.
CVE-2022-37973
Last Modified: 2 Jan 2025Windows Local Session Manager (LSM) Denial of Service Vulnerability
CVE-2022-37974
Last Modified: 2 Jan 2025Windows Mixed Reality Developer Tools Information Disclosure Vulnerability
CVE-2022-37976
Last Modified: 2 Jan 2025Active Directory Certificate Services Elevation of Privilege Vulnerability
CVE-2022-37980
Last Modified: 2 Jan 2025Windows DHCP Client Elevation of Privilege Vulnerability
CVE-2022-37981
Last Modified: 2 Jan 2025Windows Event Logging Service Denial of Service Vulnerability
CVE-2022-37982
Last Modified: 2 Jan 2025Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2022-37983
Last Modified: 2 Jan 2025Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2022-37986
Last Modified: 2 Jan 2025Windows Win32k Elevation of Privilege Vulnerability
CVE-2022-37988
Last Modified: 2 Jan 2025Windows Kernel Elevation of Privilege Vulnerability
CVE-2022-37989
Last Modified: 2 Jan 2025Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
CVE-2022-37991
Last Modified: 2 Jan 2025Windows Kernel Elevation of Privilege Vulnerability
CVE-2022-37993
Last Modified: 2 Jan 2025Windows Group Policy Preference Client Elevation of Privilege Vulnerability
CVE-2022-37994
Last Modified: 2 Jan 2025Windows Group Policy Preference Client Elevation of Privilege Vulnerability
CVE-2022-37997
Last Modified: 2 Jan 2025Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2022-37998
Last Modified: 2 Jan 2025Windows Local Session Manager (LSM) Denial of Service Vulnerability
CVE-2022-37999
Last Modified: 2 Jan 2025Windows Group Policy Preference Client Elevation of Privilege Vulnerability
CVE-2022-38000
Last Modified: 2 Jan 2025Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
CVE-2022-38016
Last Modified: 2 Jan 2025Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
CVE-2022-38017
Last Modified: 2 Jan 2025StorSimple 8000 Series Elevation of Privilege Vulnerability
CVE-2022-38021
Last Modified: 2 Jan 2025Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
CVE-2022-38022
Last Modified: 2 Jan 2025Windows Kernel Elevation of Privilege Vulnerability
CVE-2022-38025
Last Modified: 2 Jan 2025Windows Distributed File System (DFS) Information Disclosure Vulnerability
CVE-2022-38026
Last Modified: 2 Jan 2025Windows DHCP Client Information Disclosure Vulnerability
CVE-2022-38029
Last Modified: 2 Jan 2025Windows ALPC Elevation of Privilege Vulnerability
CVE-2022-38030
Last Modified: 2 Jan 2025Windows USB Serial Driver Information Disclosure Vulnerability
CVE-2022-38034
Last Modified: 2 Jan 2025Windows Workstation Service Elevation of Privilege Vulnerability
CVE-2022-38036
Last Modified: 2 Jan 2025Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability
CVE-2022-38037
Last Modified: 2 Jan 2025Windows Kernel Elevation of Privilege Vulnerability
CVE-2022-38038
Last Modified: 2 Jan 2025Windows Kernel Elevation of Privilege Vulnerability
CVE-2022-38039
Last Modified: 2 Jan 2025Windows Kernel Elevation of Privilege Vulnerability
CVE-2022-38041
Last Modified: 2 Jan 2025Windows Secure Channel Denial of Service Vulnerability
CVE-2022-38042
Last Modified: 2 Jan 2025Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2022-38043
Last Modified: 2 Jan 2025Windows Security Support Provider Interface Information Disclosure Vulnerability
CVE-2022-38044
Last Modified: 27 Aug 2025Windows CD-ROM File System Driver Remote Code Execution Vulnerability
CVE-2022-38048
Last Modified: 2 Jan 2025Microsoft Office Remote Code Execution Vulnerability
CVE-2022-38049
Last Modified: 2 Jan 2025Microsoft Office Graphics Remote Code Execution Vulnerability
CVE-2022-38050
Last Modified: 2 Jan 2025Win32k Elevation of Privilege Vulnerability
CVE-2022-38053
Last Modified: 2 Jan 2025Microsoft SharePoint Server Remote Code Execution Vulnerability
