CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2022-31367

    Last Modified: 22 May 2025

    Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.

    Published: 27 Sept 2022
    7.4
    High

    CVE-2022-37193

    Last Modified: 22 May 2025

    Chipolo ONE Bluetooth tracker (2020) Chipolo iOS app version 4.13.0 is vulnerable to Incorrect Access Control. Chipolo devices suffer from access revocation evasion attacks once the malicious sharee obtains the access credentials.

    Published: 27 Sept 2022
    4.7
    Medium

    CVE-2021-27861

    Last Modified: 4 Nov 2025

    Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length (and optionally VLAN0 headers)

    Published: 27 Sept 2022
    8.8
    High

    CVE-2022-41604

    Last Modified: 22 May 2025

    Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges. This occurs because of weak permissions for the %PROGRAMDATA%\CheckPoint\ZoneAlarm\Data\Updates directory, and a self-protection driver bypass that allows creation of a junction directory. This can be leveraged to perform an arbitrary file move as NT AUTHORITY\SYSTEM.

    Published: 27 Sept 2022
    2.7
    Low

    CVE-2022-40199

    Last Modified: 21 May 2025

    Directory traversal vulnerability in EC-CUBE 3 series (EC-CUBE 3.0.0 to 3.0.18-p4 ) and EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote authenticated attacker with an administrative privilege to obtain the product's directory structure information.

    Published: 27 Sept 2022
    5.4
    Medium

    CVE-2022-38975

    Last Modified: 21 May 2025

    DOM-based cross-site scripting vulnerability in EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote attacker to inject an arbitrary script by having an administrative user of the product to visit a specially crafted page.

    Published: 27 Sept 2022
    9.8
    Critical

    CVE-2022-37346

    Last Modified: 21 May 2025

    EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a remote unauthenticated attacker to upload arbitrary files other than image files. If a user with an administrative privilege of EC-CUBE where the vulnerable plugin is installed is led to upload a specially crafted file, an arbitrary script may be executed on the system.

    Published: 27 Sept 2022
    9.8
    Critical

    CVE-2022-41571

    Last Modified: 21 May 2025

    An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Local file inclusion can occur.

    Published: 27 Sept 2022
    9.8
    Critical

    CVE-2022-41570

    Last Modified: 21 May 2025

    An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Unauthenticated SQL injection can occur.

    Published: 27 Sept 2022
    —
    Unknown

    CVE-2022-40970

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 27 Sept 2022
    7.8
    High

    CVE-2022-3324

    Last Modified: 24 Sept 2026

    Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.

    Published: 27 Sept 2022
    6.5
    Medium

    CVE-2022-47015

    Last Modified: 3 Apr 2025

    MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer.

    Published: 27 Sept 2022
    7.5
    High

    CVE-2022-34326

    Last Modified: 21 May 2025

    In ambiot amb1_sdk (aka SDK for Ameba1) before 2022-06-20 on Realtek RTL8195AM devices before 284241d70308ff2519e40afd7b284ba892c730a3, the timer task and RX task would be locked when there are frequent and continuous Wi-Fi connection (with four-way handshake) failures in Soft AP mode.

    Published: 27 Sept 2022
    7.5
    High

    CVE-2022-3298

    Last Modified: 21 May 2025

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.

    Published: 26 Sept 2022
    7.2
    High

    CVE-2022-40099

    Last Modified: 21 May 2025

    Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_expense_category.php.

    Published: 26 Sept 2022
    7.2
    High

    CVE-2022-40098

    Last Modified: 21 May 2025

    Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_expense.php.

    Published: 26 Sept 2022
    7.2
    High

    CVE-2022-40097

    Last Modified: 21 May 2025

    Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_currency.php.

    Published: 26 Sept 2022
    9.8
    Critical

    CVE-2022-30004

    Last Modified: 21 May 2025

    Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing remote attackers to dump the SQL database via time-based SQL injection..

    Published: 26 Sept 2022
    9.8
    Critical

    CVE-2022-40050

    Last Modified: 21 May 2025

    ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1.

    Published: 26 Sept 2022
    7.5
    High

    CVE-2022-3290

    Last Modified: 21 May 2025

    Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8.

    Published: 26 Sept 2022
    5.4
    Medium

    CVE-2022-30003

    Last Modified: 21 May 2025

    Sourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register as a Seller then create new products containing XSS payloads in the 'Product Title' and 'Short Description' fields.

    Published: 26 Sept 2022
    7.5
    High

    CVE-2022-3272

    Last Modified: 21 May 2025

    Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8.

    Published: 26 Sept 2022
    8.4
    High

    CVE-2022-22058

    Last Modified: 21 May 2025

    Memory corruption due to use after free issue in kernel while processing ION handles in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 26 Sept 2022
    5.4
    Medium

    CVE-2022-40044

    Last Modified: 21 May 2025

    Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations. This vulnerability allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-40043

    Last Modified: 21 May 2025

    Centreon v20.10.18 was discovered to contain a SQL injection vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations.

    Published: 26 Sept 2022
    7.5
    High

    CVE-2021-28052

    Last Modified: 21 May 2025

    A tenant administrator Hitachi Content Platform (HCP) may modify the configuration in another tenant without authorization, potentially allowing unauthorized access to data in the other tenant. Also, a tenant user (non-administrator) may view configuration in another tenant without authorization. This issue affects: Hitachi Vantara Hitachi Content Platform versions prior to 8.3.7; 9.0.0 versions prior to 9.2.3.

    Published: 26 Sept 2022
    9.6
    Critical

    CVE-2022-3075

    Last Modified: 24 Oct 2025

    Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-3071

    Last Modified: 21 May 2025

    Use after free in Tab Strip in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interaction.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-3058

    Last Modified: 21 May 2025

    Use after free in Sign-In Flow in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interaction.

    Published: 26 Sept 2022
    6.5
    Medium

    CVE-2022-3056

    Last Modified: 21 May 2025

    Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to bypass content security policy via a crafted HTML page.

    Published: 26 Sept 2022
    6.5
    Medium

    CVE-2022-3057

    Last Modified: 21 May 2025

    Inappropriate implementation in iframe Sandbox in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-3055

    Last Modified: 21 May 2025

    Use after free in Passwords in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Sept 2022
    6.5
    Medium

    CVE-2022-3054

    Last Modified: 21 May 2025

    Insufficient policy enforcement in DevTools in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Sept 2022
    4.3
    Medium

    CVE-2022-3053

    Last Modified: 21 May 2025

    Inappropriate implementation in Pointer Lock in Google Chrome on Mac prior to 105.0.5195.52 allowed a remote attacker to restrict user navigation via a crafted HTML page.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-3052

    Last Modified: 21 May 2025

    Heap buffer overflow in Window Manager in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-3051

    Last Modified: 21 May 2025

    Heap buffer overflow in Exosphere in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-3050

    Last Modified: 21 May 2025

    Heap buffer overflow in WebUI in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-3049

    Last Modified: 21 May 2025

    Use after free in SplitScreen in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Sept 2022
    6.8
    Medium

    CVE-2022-3048

    Last Modified: 21 May 2025

    Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a local attacker to bypass lockscreen navigation restrictions via physical access to the device.

    Published: 26 Sept 2022
    6.5
    Medium

    CVE-2022-3047

    Last Modified: 22 May 2025

    Insufficient policy enforcement in Extensions API in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to install a malicious extension to bypass downloads policy via a crafted HTML page.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-3046

    Last Modified: 22 May 2025

    Use after free in Browser Tag in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-3045

    Last Modified: 22 May 2025

    Insufficient validation of untrusted input in V8 in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Sept 2022
    6.5
    Medium

    CVE-2022-3044

    Last Modified: 22 May 2025

    Inappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-3043

    Last Modified: 21 May 2025

    Heap buffer overflow in Screen Capture in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-3042

    Last Modified: 21 May 2025

    Use after free in PhoneHub in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-3041

    Last Modified: 21 May 2025

    Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-3039

    Last Modified: 21 May 2025

    Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-3040

    Last Modified: 21 May 2025

    Use after free in Layout in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-3038

    Last Modified: 24 Oct 2025

    Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Sept 2022
    8.8
    High

    CVE-2022-2998

    Last Modified: 21 May 2025

    Use after free in Browser Creation in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who had convinced a user to engage in a specific UI interaction to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Sept 2022