CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2022-41218

    Last Modified: 28 May 2025

    In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting dvb_demux_open and dvb_dmxdev_release.

    Published: 21 Sept 2022
    7.5
    High

    CVE-2022-4743

    Last Modified: 25 Nov 2025

    A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerability allows an attacker to cause a denial of service attack. The vulnerability affects SDL2 v2.0.4 and above. SDL-1.x are not affected.

    Published: 21 Sept 2022
    5.5
    Medium

    CVE-2023-38667

    Last Modified: 21 Nov 2024

    Stack-based buffer over-read in function disasm in nasm 2.16 allows attackers to cause a denial of service.

    Published: 21 Sept 2022
    5.5
    Medium

    CVE-2023-38668

    Last Modified: 21 Nov 2024

    Stack-based buffer over-read in disasm in nasm 2.16 allows attackers to cause a denial of service (crash).

    Published: 21 Sept 2022
    5.3
    Medium

    CVE-2022-2795

    Last Modified: 1 Sept 2026

    By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

    Published: 21 Sept 2022
    5.5
    Medium

    CVE-2022-2881

    Last Modified: 28 May 2025

    The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.

    Published: 21 Sept 2022
    7.5
    High

    CVE-2022-2906

    Last Modified: 28 May 2025

    An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.

    Published: 21 Sept 2022
    8.1
    High

    CVE-2022-3262

    Last Modified: 23 Apr 2025

    A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.

    Published: 21 Sept 2022
    5.4
    Medium

    CVE-2022-41224

    Last Modified: 28 May 2025

    Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control tooltips for this component.

    Published: 21 Sept 2022
    7.5
    High

    CVE-2022-3080

    Last Modified: 21 Nov 2024

    By sending specific queries to the resolver, an attacker can cause named to crash.

    Published: 21 Sept 2022
    7.5
    High

    CVE-2022-3204

    Last Modified: 5 May 2025

    A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The NRDelegation Attack works by having a malicious delegation with a considerable number of non responsive nameservers. The attack starts by querying a resolver for a record that relies on those unresponsive nameservers. The attack can cause a resolver to spend a lot of time/resources resolving records under a malicious delegation point where a considerable number of unresponsive NS records reside. It can trigger high CPU usage in some resolver implementations that continually look in the cache for resolved NS records in that delegation. This can lead to degraded performance and eventually denial of service in orchestrated attacks. Unbound does not suffer from high CPU usage, but resources are still needed for resolving the malicious delegation. Unbound will keep trying to resolve the record until hard limits are reached. Based on the nature of the attack and the replies, different limits could be reached. From version 1.16.3 on, Unbound introduces fixes for better performance when under load, by cutting opportunistic queries for nameserver discovery and DNSKEY prefetching and limiting the number of times a delegation point can issue a cache lookup for missing records.

    Published: 21 Sept 2022
    9.8
    Critical

    CVE-2022-37026

    Last Modified: 27 May 2025

    In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.

    Published: 21 Sept 2022
    9.8
    Critical

    CVE-2022-38619

    Last Modified: 28 May 2025

    SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf.

    Published: 20 Sept 2022
    5.5
    Medium

    CVE-2022-35085

    Last Modified: 27 May 2025

    SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c.

    Published: 20 Sept 2022
    5.5
    Medium

    CVE-2022-35086

    Last Modified: 28 May 2025

    SWFTools commit 772e55a2 was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S.

    Published: 20 Sept 2022
    5.5
    Medium

    CVE-2022-35087

    Last Modified: 28 May 2025

    SWFTools commit 772e55a2 was discovered to contain a segmentation violation via MovieAddFrame at /src/gif2swf.c.

    Published: 20 Sept 2022
    5.5
    Medium

    CVE-2022-35088

    Last Modified: 28 May 2025

    SWFTools commit 772e55a2 was discovered to contain a heap buffer-overflow via getGifDelayTime at /home/bupt/Desktop/swftools/src/src/gif2swf.c.

    Published: 20 Sept 2022
    5.5
    Medium

    CVE-2022-35089

    Last Modified: 28 May 2025

    SWFTools commit 772e55a2 was discovered to contain a heap-buffer-overflow via getTransparentColor at /home/bupt/Desktop/swftools/src/gif2swf.

    Published: 20 Sept 2022
    5.5
    Medium

    CVE-2022-35090

    Last Modified: 28 May 2025

    SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via __asan_memcpy at /asan/asan_interceptors_memintrinsics.cpp:.

    Published: 20 Sept 2022
    7.5
    High

    CVE-2022-39221

    Last Modified: 23 Apr 2025

    McWebserver mod runs a simple HTTP server alongside the Minecraft server in seperate threads. Path traversal in McWebserver Minecraft Mod for Fabric and Quilt up to and including 0.1.2.1 and McWebserver Minecraft Mod for Forge up to and including 0.1.1 allows all files, accessible by the program, to be read by anyone via HTTP request. Version 0.2.0 with patches are released to both platforms (Fabric and Quilt, Forge). As a workaround, the McWebserver mod can be disabled by removing the file from the `mods` directory.

    Published: 20 Sept 2022
    6.1
    Medium

    CVE-2022-39220

    Last Modified: 23 Apr 2025

    SFTPGo is an SFTP server written in Go. Versions prior to 2.3.5 are subject to Cross-site scripting (XSS) vulnerabilities in the SFTPGo WebClient, allowing remote attackers to inject malicious code. This issue is patched in version 2.3.5. No known workarounds exist.

    Published: 20 Sept 2022
    7.8
    High

    CVE-2022-32802

    Last Modified: 28 May 2025

    A logic issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, tvOS 15.6, macOS Monterey 12.5. Processing a maliciously crafted file may lead to arbitrary code execution.

    Published: 20 Sept 2022
    6.5
    Medium

    CVE-2022-32880

    Last Modified: 28 May 2025

    This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.5. An app may be able to access user-sensitive data.

    Published: 20 Sept 2022
    9.8
    Critical

    CVE-2022-32882

    Last Modified: 27 May 2025

    This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. An app may be able to bypass Privacy preferences.

    Published: 20 Sept 2022
    8.8
    High

    CVE-2022-26696

    Last Modified: 28 May 2025

    This issue was addressed with improved environment sanitization. This issue is fixed in macOS Monterey 12.4. A sandboxed process may be able to circumvent sandbox restrictions.

    Published: 20 Sept 2022
    5.3
    Medium

    CVE-2022-32861

    Last Modified: 27 May 2025

    A logic issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monterey 12.5. A user may be tracked through their IP address.

    Published: 20 Sept 2022
    9.8
    Critical

    CVE-2022-32788

    Last Modified: 28 May 2025

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. A remote user may be able to cause kernel code execution.

    Published: 20 Sept 2022
    8.8
    High

    CVE-2022-23685

    Last Modified: 27 May 2025

    A vulnerability in the ClearPass Policy Manager web-based management interface exists which exposes some endpoints to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against these endpoints if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address this security vulnerability.

    Published: 20 Sept 2022
    8.8
    High

    CVE-2022-23692

    Last Modified: 28 May 2025

    Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address these security vulnerabilities.

    Published: 20 Sept 2022
    8.8
    High

    CVE-2022-23693

    Last Modified: 28 May 2025

    Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address these security vulnerabilities.

    Published: 20 Sept 2022
    8.8
    High

    CVE-2022-23695

    Last Modified: 29 May 2025

    Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address these security vulnerabilities.

    Published: 20 Sept 2022
    8.8
    High

    CVE-2022-23694

    Last Modified: 29 May 2025

    Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address these security vulnerabilities.

    Published: 20 Sept 2022
    7.8
    High

    CVE-2022-28637

    Last Modified: 27 May 2025

    A local Denial of Service (DoS) and local arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability were discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated firmware for HPE Integrated Lights-Out 5 (iLO 5) that addresses these security vulnerabilities.

    Published: 20 Sept 2022
    8.8
    High

    CVE-2022-28639

    Last Modified: 29 May 2025

    A remote potential adjacent denial of service (DoS) and potential adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability were discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated firmware for HPE Integrated Lights-Out 5 (iLO 5) that addresses these security vulnerabilities.

    Published: 20 Sept 2022
    7.8
    High

    CVE-2022-28638

    Last Modified: 29 May 2025

    An isolated local disclosure of information and potential isolated local arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability were discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated firmware for HPE Integrated Lights-Out 5 (iLO 5) that addresses these security vulnerabilities.

    Published: 20 Sept 2022
    8.8
    High

    CVE-2022-23696

    Last Modified: 28 May 2025

    Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address these security vulnerabilities.

    Published: 20 Sept 2022
    8.8
    High

    CVE-2022-28640

    Last Modified: 28 May 2025

    A potential local adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability was discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated firmware for HPE Integrated Lights-Out 5 (iLO 5) that addresses this security vulnerability.

    Published: 20 Sept 2022
    9.8
    Critical

    CVE-2022-40357

    Last Modified: 28 May 2025

    A security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the zb_users/plugin/UEditor/php/action_crawler.php file allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the source parameter.

    Published: 20 Sept 2022
    7.8
    High

    CVE-2022-37877

    Last Modified: 27 May 2025

    A vulnerability in the ClearPass OnGuard macOS agent could allow malicious users on a macOS instance to elevate their user privileges. A successful exploit could allow these users to execute arbitrary code with root level privileges on the macOS instance in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address this security vulnerability.

    Published: 20 Sept 2022
    7.2
    High

    CVE-2022-37880

    Last Modified: 28 May 2025

    Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address these security vulnerabilities.

    Published: 20 Sept 2022
    8.8
    High

    CVE-2022-38931

    Last Modified: 28 May 2025

    A Server-Side Request Forgery (SSRF) in fetch_net_file_upload function of baijiacmsV4 v4.1.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the url parameter.

    Published: 20 Sept 2022
    7.2
    High

    CVE-2022-37878

    Last Modified: 28 May 2025

    Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address these security vulnerabilities.

    Published: 20 Sept 2022
    7.2
    High

    CVE-2022-37879

    Last Modified: 28 May 2025

    Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address these security vulnerabilities.

    Published: 20 Sept 2022
    7.5
    High

    CVE-2022-37884

    Last Modified: 28 May 2025

    A vulnerability exists in the ClearPass Policy Manager Guest User Interface that can allow an unauthenticated attacker to send specific operations which result in a Denial-of-Service condition. A successful exploitation of this vulnerability results in the unavailability of the guest interface in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address this security vulnerability.

    Published: 20 Sept 2022
    7.2
    High

    CVE-2022-37881

    Last Modified: 28 May 2025

    Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address these security vulnerabilities.

    Published: 20 Sept 2022
    7.2
    High

    CVE-2022-37882

    Last Modified: 28 May 2025

    Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address these security vulnerabilities.

    Published: 20 Sept 2022
    7.2
    High

    CVE-2022-37883

    Last Modified: 29 May 2025

    Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address these security vulnerabilities.

    Published: 20 Sept 2022
    7.5
    High

    CVE-2022-39218

    Last Modified: 23 Apr 2025

    The JS Compute Runtime for Fastly's Compute@Edge platform provides the environment JavaScript is executed in when using the Compute@Edge JavaScript SDK. In versions prior to 0.5.3, the `Math.random` and `crypto.getRandomValues` methods fail to use sufficiently random values. The initial value to seed the PRNG (pseudorandom number generator) is baked-in to the final WebAssembly module, making the sequence of random values for that specific WebAssembly module predictable. An attacker can use the fixed seed to predict random numbers generated by these functions and bypass cryptographic security controls, for example to disclose sensitive data encrypted by functions that use these generators. The problem has been patched in version 0.5.3. No known workarounds exist.

    Published: 20 Sept 2022
    4.3
    Medium

    CVE-2021-46835

    Last Modified: 28 May 2025

    There is a traffic hijacking vulnerability in WS7200-10 11.0.2.13. Successful exploitation of this vulnerability can cause packets to be hijacked by attackers.

    Published: 20 Sept 2022
    7.5
    High

    CVE-2022-37395

    Last Modified: 28 May 2025

    A Huawei device has an input verification vulnerability. Successful exploitation of this vulnerability may lead to DoS attacks.Affected product versions include:CV81-WDM FW versions 01.70.49.29.46.

    Published: 20 Sept 2022