CVE Feed

    Dashboard / CVE

    3.3
    Low

    CVE-2022-40709

    Last Modified: 21 Nov 2024

    An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit these vulnerabilities. This vulnerability is similar to, but not identical to CVE-2022-40707 and 40708.

    Published: 28 Sept 2022
    3.3
    Low

    CVE-2022-40708

    Last Modified: 20 May 2025

    An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit these vulnerabilities. This vulnerability is similar to, but not identical to CVE-2022-40707.

    Published: 28 Sept 2022
    3.3
    Low

    CVE-2022-40707

    Last Modified: 21 Nov 2024

    An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit these vulnerabilities. This vulnerability is similar to, but not identical to CVE-2022-40708.

    Published: 28 Sept 2022
    6.8
    Medium

    CVE-2022-39263

    Last Modified: 23 Apr 2025

    `@next-auth/upstash-redis-adapter` is the Upstash Redis adapter for NextAuth.js, which provides authentication for Next.js. Applications that use `next-auth` Email Provider and `@next-auth/upstash-redis-adapter` before v3.0.2 are affected by this vulnerability. The Upstash Redis adapter implementation did not check for both the identifier (email) and the token, but only checking for the identifier when verifying the token in the email callback flow. An attacker who knows about the victim's email could easily sign in as the victim, given the attacker also knows about the verification token's expired duration. The vulnerability is patched in v3.0.2. A workaround is available. Using Advanced Initialization, developers can check the requests and compare the query's token and identifier before proceeding.

    Published: 28 Sept 2022
    7.5
    High

    CVE-2022-39257

    Last Modified: 23 Apr 2025

    Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in others. This attack is possible due to the matrix-ios-sdk implementing a too permissive key forwarding strategy. The default policy for accepting key forwards has been made more strict in the matrix-ios-sdk version 0.23.19. matrix-ios-sdk will now only accept forwarded keys in response to previously issued requests and only from own, verified devices. The SDK now sets a `trusted` flag on the decrypted message upon decryption, based on whether the key used to decrypt the message was received from a trusted source. Clients need to ensure that messages decrypted with a key with `trusted = false` are decorated appropriately (for example, by showing a warning for such messages). This attack requires coordination between a malicious home server and an attacker, so those who trust their home servers do not need a workaround.

    Published: 28 Sept 2022
    8.6
    High

    CVE-2022-39255

    Last Modified: 23 Apr 2025

    Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker cooperating with a malicious homeserver could employ this vulnerability to perform a targeted attack in order to send fake to-device messages appearing to originate from another user. This can allow, for example, to inject the key backup secret during a self-verification, to make a targeted device start using a malicious key backup spoofed by the homeserver. These attacks are possible due to a protocol confusion vulnerability that accepts to-device messages encrypted with Megolm instead of Olm. matrix-ios-sdk version 0.23.19 has been modified to only accept Olm-encrypted to-device messages. Out of caution, several other checks have been audited or added. This attack requires coordination between a malicious home server and an attacker, so those who trust their home servers do not need a workaround. To avoid malicious backup attacks, one should not verify one's new logins using emoji/QR verifications methods until patched.

    Published: 28 Sept 2022
    7.5
    High

    CVE-2022-34424

    Last Modified: 20 May 2025

    Networking OS10, versions 10.5.1.x, 10.5.2.x, and 10.5.3.x contain a vulnerability that could allow an attacker to cause a system crash by running particular security scans.

    Published: 28 Sept 2022
    3.7
    Low

    CVE-2022-34394

    Last Modified: 20 May 2025

    Dell OS10, version 10.5.3.4, contains an Improper Certificate Validation vulnerability in Support Assist. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to unauthorized access to limited switch configuration data. The vulnerability could be leveraged by attackers to conduct man-in-the-middle attacks to gain access to the Support Assist information.

    Published: 28 Sept 2022
    6.4
    Medium

    CVE-2022-29089

    Last Modified: 20 May 2025

    Dell Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an information disclosure vulnerability. A remote, unauthenticated attacker could potentially exploit this vulnerability by reverse engineering to retrieve sensitive information and access the REST API with admin privileges.

    Published: 28 Sept 2022
    4.6
    Medium

    CVE-2022-3292

    Last Modified: 21 May 2025

    Use of Cache Containing Sensitive Information in GitHub repository ikus060/rdiffweb prior to 2.4.8.

    Published: 28 Sept 2022
    8.6
    High

    CVE-2022-39248

    Last Modified: 23 Apr 2025

    matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker cooperating with a malicious homeserver could employ this vulnerability to perform a targeted attack in order to send fake to-device messages appearing to originate from another user. This can allow, for example, to inject the key backup secret during a self-verification, to make a targeted device start using a malicious key backup spoofed by the homeserver. matrix-android-sdk2 would then additionally sign such a key backup with its device key, spilling trust over to other devices trusting the matrix-android-sdk2 device. These attacks are possible due to a protocol confusion vulnerability that accepts to-device messages encrypted with Megolm instead of Olm. matrix-android-sdk2 version 1.5.1 has been modified to only accept Olm-encrypted to-device messages and to stop signing backups on a successful decryption. Out of caution, several other checks have been audited or added. This attack requires coordination between a malicious home server and an attacker, so those who trust their home servers do not need a workaround.

    Published: 28 Sept 2022
    7.5
    High

    CVE-2022-39246

    Last Modified: 23 Apr 2025

    matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be missing in others. This attack is possible due to the key forwarding strategy implemented in the matrix-android-sdk2 that is too permissive. Starting with version 1.5.1, the default policy for accepting key forwards has been made more strict in the matrix-android-sdk2. The matrix-android-sdk2 will now only accept forwarded keys in response to previously issued requests and only from own, verified devices. The SDK now sets a `trusted` flag on the decrypted message upon decryption, based on whether the key used to decrypt the message was received from a trusted source. Clients need to ensure that messages decrypted with a key with `trusted = false` are decorated appropriately (for example, by showing a warning for such messages). As a workaroubnd, current users of the SDK can disable key forwarding in their forks using `CryptoService#enableKeyGossiping(enable: Boolean)`.

    Published: 28 Sept 2022
    5.3
    Medium

    CVE-2022-23716

    Last Modified: 21 May 2025

    A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monitoring cluster.

    Published: 28 Sept 2022
    7.5
    High

    CVE-2022-3215

    Last Modified: 20 May 2025

    NIOHTTP1 and projects using it for generating HTTP responses can be subject to a HTTP Response Injection attack. This occurs when a HTTP/1.1 server accepts user generated input from an incoming request and reflects it into a HTTP/1.1 response header in some form. A malicious user can add newlines to their input (usually in encoded form) and "inject" those newlines into the returned HTTP response. This capability allows users to work around security headers and HTTP/1.1 framing headers by injecting entirely false responses or other new headers. The injected false responses may also be treated as the response to subsequent requests, which can lead to XSS, cache poisoning, and a number of other flaws. This issue was resolved by adding validation to the HTTPHeaders type, ensuring that there's no whitespace incorrectly present in the HTTP headers provided by users. As the existing API surface is non-failable, all invalid characters are replaced by linear whitespace.

    Published: 28 Sept 2022
    5.3
    Medium

    CVE-2022-36781

    Last Modified: 21 Nov 2024

    ConnectWise ScreenConnect versions 22.6 and below contained a flaw allowing potential brute force attacks on custom access tokens due to inadequate rate-limiting controls in the default configuration. Attackers could exploit this vulnerability to gain unauthorized access by repeatedly attempting access code combinations. ConnectWise has addressed this issue in later versions by implementing rate-limiting controls as a preventive measure against brute force attacks.

    Published: 28 Sept 2022
    —
    Unknown

    CVE-2022-41730

    Last Modified: 2 Jul 2024

    reserved but not needed

    Published: 28 Sept 2022
    —
    Unknown

    CVE-2022-41729

    Last Modified: 2 Jul 2024

    reserved but not needed

    Published: 28 Sept 2022
    —
    Unknown

    CVE-2022-41728

    Last Modified: 2 Jul 2024

    reserved but not needed

    Published: 28 Sept 2022
    —
    Unknown

    CVE-2022-41726

    Last Modified: 2 Jul 2024

    reserved but not needed

    Published: 28 Sept 2022
    —
    Unknown

    CVE-2022-41718

    Last Modified: 2 Jul 2024

    reserved but not needed

    Published: 28 Sept 2022
    5.9
    Medium

    CVE-2022-3100

    Last Modified: 3 Apr 2025

    A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.

    Published: 28 Sept 2022
    5.4
    Medium

    CVE-2021-41434

    Last Modified: 20 May 2025

    A stored Cross-Site Scripting (XSS) vulnerability exists in version 1.0 of the Expense Management System application that allows for arbitrary execution of JavaScript commands through index.php.

    Published: 28 Sept 2022
    3.3
    Low

    CVE-2022-38934

    Last Modified: 21 May 2025

    readelf in ToaruOS 2.0.1 has some arbitrary address read vulnerabilities when parsing a crafted ELF file.

    Published: 28 Sept 2022
    6.5
    Medium

    CVE-2022-36771

    Last Modified: 21 May 2025

    IBM QRadar User Behavior Analytics could allow an authenticated user to obtain sensitive information from that they should not have access to. IBM X-Force ID: 232791.

    Published: 28 Sept 2022
    5.4
    Medium

    CVE-2022-35722

    Last Modified: 20 May 2025

    IBM Jazz for Service Management is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 231381.

    Published: 28 Sept 2022
    6.5
    Medium

    CVE-2022-35282

    Last Modified: 20 May 2025

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker with local network access could exploit this vulnerability to obtain sensitive data.

    Published: 28 Sept 2022
    5.4
    Medium

    CVE-2022-22387

    Last Modified: 20 May 2025

    IBM Application Gateway is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 221965.

    Published: 28 Sept 2022
    8.2
    High

    CVE-2022-36448

    Last Modified: 21 May 2025

    An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. There is an SMM memory corruption vulnerability in the Software SMI handler in the PnpSmm driver.

    Published: 28 Sept 2022
    3.5
    Low

    CVE-2022-3354

    Last Modified: 15 Apr 2025

    A vulnerability has been found in Open5GS up to 2.4.10 and classified as problematic. This vulnerability affects unknown code in the library lib/core/ogs-tlv-msg.c of the component UDP Packet Handler. The manipulation leads to denial of service. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-209686 is the identifier assigned to this vulnerability.

    Published: 28 Sept 2022
    —
    Unknown

    CVE-2022-41637

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 28 Sept 2022
    —
    Unknown

    CVE-2022-41626

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 28 Sept 2022
    —
    Unknown

    CVE-2022-40688

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 28 Sept 2022
    —
    Unknown

    CVE-2022-41341

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 28 Sept 2022
    —
    Unknown

    CVE-2022-40689

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 28 Sept 2022
    9.8
    Critical

    CVE-2022-40942

    Last Modified: 21 May 2025

    Tenda TX3 US_TX3V1.0br_V16.03.13.11 is vulnerable to stack overflow via compare_parentcontrol_time.

    Published: 28 Sept 2022
    6.1
    Medium

    CVE-2022-40912

    Last Modified: 20 May 2025

    ETAP Lighting International NV ETAP Safety Manager 1.0.0.32 is vulnerable to Cross Site Scripting (XSS). Input passed to the GET parameter 'action' is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML/JS code in a user's browser session in context of an affected site.

    Published: 28 Sept 2022
    6.1
    Medium

    CVE-2022-28816

    Last Modified: 20 May 2025

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy is prone to reflected XSS which only affects the Sentilo service.

    Published: 28 Sept 2022
    2.7
    Low

    CVE-2022-28815

    Last Modified: 20 May 2025

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy server was discovered to contain a SQL injection vulnerability allowing an attacker to query other tables of the Sentilo service.

    Published: 28 Sept 2022
    9.8
    Critical

    CVE-2022-28814

    Last Modified: 20 May 2025

    Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a relative path traversal vulnerability which enables remote attackers to read arbitrary files and gain full control of the device.

    Published: 28 Sept 2022
    9.8
    Critical

    CVE-2022-28812

    Last Modified: 20 May 2025

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain SuperUser access to the device.

    Published: 28 Sept 2022
    9.8
    Critical

    CVE-2022-28811

    Last Modified: 21 May 2025

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could utilize an improper input validation on an API-submitted parameter to execute arbitrary OS commands.

    Published: 28 Sept 2022
    9.8
    Critical

    CVE-2022-22526

    Last Modified: 21 May 2025

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a missing authentication allows for full access via API.

    Published: 28 Sept 2022
    9.4
    Critical

    CVE-2022-22524

    Last Modified: 21 May 2025

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an unauthenticated remote attacker could utilize a SQL-Injection vulnerability to gain full database access, modify users and stop services .

    Published: 28 Sept 2022
    7.2
    High

    CVE-2022-22525

    Last Modified: 21 May 2025

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin rights could execute arbitrary commands due to missing input sanitization in the backup restore function

    Published: 28 Sept 2022
    7.5
    High

    CVE-2022-22523

    Last Modified: 21 May 2025

    An improper authentication vulnerability exists in the Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 Web-App which allows an authentication bypass to the context of an unauthorised user if free-access is disabled.

    Published: 28 Sept 2022
    9.8
    Critical

    CVE-2022-22522

    Last Modified: 21 May 2025

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain full access to the device.

    Published: 28 Sept 2022
    9.6
    Critical

    CVE-2022-40083

    Last Modified: 21 May 2025

    Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vulnerability can be leveraged by attackers to cause a Server-Side Request Forgery (SSRF).

    Published: 28 Sept 2022
    7.5
    High

    CVE-2022-40082

    Last Modified: 21 May 2025

    Hertz v0.3.0 ws discovered to contain a path traversal vulnerability via the normalizePath function.

    Published: 28 Sept 2022
    8.8
    High

    CVE-2022-40486

    Last Modified: 21 May 2025

    TP Link Archer AX10 V1 Firmware Version 1.3.1 Build 20220401 Rel. 57450(5553) was discovered to allow authenticated attackers to execute arbitrary code via a crafted backup file.

    Published: 28 Sept 2022
    6.8
    Medium

    CVE-2022-3349

    Last Modified: 15 Apr 2025

    A vulnerability was found in Sony PS4 and PS5. It has been classified as critical. This affects the function UVFAT_readupcasetable of the component exFAT Handler. The manipulation of the argument dataLength leads to heap-based buffer overflow. It is possible to launch the attack on the physical device. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-209679.

    Published: 28 Sept 2022