CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2022-32868

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. A website may be able to track users through Safari web extensions.

    Published: 20 Sept 2022
    7.8
    High

    CVE-2022-32911

    Last Modified: 29 May 2025

    The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to execute arbitrary code with kernel privileges.

    Published: 20 Sept 2022
    7.5
    High

    CVE-2022-37972

    Last Modified: 11 Mar 2025

    Microsoft Endpoint Configuration Manager Spoofing Vulnerability

    Published: 20 Sept 2022
    6.1
    Medium

    CVE-2022-40956

    Last Modified: 15 Apr 2025

    When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

    Published: 20 Sept 2022
    7.8
    High

    CVE-2022-3155

    Last Modified: 15 Apr 2025

    When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an application and the user attempted to open it, then the application was started immediately without asking the user to confirm. This vulnerability affects Thunderbird < 102.3.

    Published: 20 Sept 2022
    6.6
    Medium

    CVE-2022-35957

    Last Modified: 28 Jan 2026

    Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to server admin when auth proxy is used, allowing an admin to take over the server admin account and gain full control of the grafana instance. All installations should be upgraded as soon as possible. As a workaround deactivate auth proxy following the instructions at: https://grafana.com/docs/grafana/latest/setup-grafana/configure-security/configure-authentication/auth-proxy/

    Published: 20 Sept 2022
    5.5
    Medium

    CVE-2022-3266

    Last Modified: 15 Apr 2025

    An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

    Published: 20 Sept 2022
    9.8
    Critical

    CVE-2022-32863

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monterey 12.5. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 20 Sept 2022
    7.8
    High

    CVE-2022-32908

    Last Modified: 29 May 2025

    A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. A user may be able to elevate privileges.

    Published: 20 Sept 2022
    9.1
    Critical

    CVE-2022-38340

    Last Modified: 29 May 2025

    Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a Path Traversal vulnerability via the component fmedataupload.

    Published: 20 Sept 2022
    6.5
    Medium

    CVE-2022-40957

    Last Modified: 15 Apr 2025

    Inconsistent data in instruction and data cache when creating wasm code could lead to a potentially exploitable crash.<br>*This bug only affects Firefox on ARM64 platforms.*. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

    Published: 20 Sept 2022
    7.8
    High

    CVE-2022-32917

    Last Modified: 23 Oct 2025

    The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

    Published: 20 Sept 2022
    5.4
    Medium

    CVE-2022-38550

    Last Modified: 27 May 2025

    A stored cross-site scripting (XSS) vulnerability in the /weibo/list component of Jeesns v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 19 Sept 2022
    9.6
    Critical

    CVE-2022-38545

    Last Modified: 21 Nov 2024

    Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.

    Published: 19 Sept 2022
    7.8
    High

    CVE-2022-38532

    Last Modified: 21 Nov 2024

    Micro-Star International Co., Ltd MSI Center 1.0.50.0 was discovered to contain a vulnerability in the component C_Features of MSI.CentralServer.exe. This vulnerability allows attackers to escalate privileges via running a crafted executable.

    Published: 19 Sept 2022
    6.5
    Medium

    CVE-2022-35070

    Last Modified: 21 Nov 2024

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x65fc97.

    Published: 19 Sept 2022
    6.5
    Medium

    CVE-2022-35069

    Last Modified: 21 Nov 2024

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b544e.

    Published: 19 Sept 2022
    6.5
    Medium

    CVE-2022-35068

    Last Modified: 29 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e420d.

    Published: 19 Sept 2022
    6.5
    Medium

    CVE-2022-35067

    Last Modified: 29 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e41b0.

    Published: 19 Sept 2022
    6.5
    Medium

    CVE-2022-35066

    Last Modified: 29 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e41b8.

    Published: 19 Sept 2022
    6.5
    Medium

    CVE-2022-35065

    Last Modified: 29 May 2025

    OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x65f724.

    Published: 19 Sept 2022
    6.5
    Medium

    CVE-2022-35064

    Last Modified: 29 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x4adcdb in __asan_memset.

    Published: 19 Sept 2022
    6.5
    Medium

    CVE-2022-35063

    Last Modified: 29 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e41a8.

    Published: 19 Sept 2022
    6.5
    Medium

    CVE-2022-35062

    Last Modified: 29 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c0bc3.

    Published: 19 Sept 2022
    6.5
    Medium

    CVE-2022-35061

    Last Modified: 29 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e412a.

    Published: 19 Sept 2022
    6.5
    Medium

    CVE-2022-35060

    Last Modified: 29 May 2025

    OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c0a32.

    Published: 19 Sept 2022
    6.1
    Medium

    CVE-2022-38527

    Last Modified: 29 May 2025

    UCMS v1.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Import function under the Site Management page.

    Published: 19 Sept 2022
    9.3
    Critical

    CVE-2022-0143

    Last Modified: 29 May 2025

    When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Server (RCS)

    Published: 19 Sept 2022
    9.8
    Critical

    CVE-2022-38509

    Last Modified: 29 May 2025

    Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budget.php.

    Published: 19 Sept 2022
    7.5
    High

    CVE-2022-28204

    Last Modified: 29 May 2025

    A denial-of-service issue was discovered in MediaWiki 1.37.x before 1.37.2. Rendering of w/index.php?title=Special%3AWhatLinksHere&target=Property%3AP31&namespace=1&invert=1 can take more than thirty seconds. There is a DDoS risk.

    Published: 19 Sept 2022
    8.8
    High

    CVE-2022-38351

    Last Modified: 29 May 2025

    A vulnerability in Suprema BioStar (aka Bio Star) 2 v2.8.16 allows attackers to escalate privileges to System Administrator via a crafted PUT request to the update profile page.

    Published: 19 Sept 2022
    7.8
    High

    CVE-2022-23766

    Last Modified: 29 May 2025

    An improper input validation vulnerability leading to arbitrary file execution was discovered in BigFileAgent. In order to cause arbitrary files to be executed, the attacker makes the victim access a web page d by them or inserts a script using XSS into a general website.

    Published: 19 Sept 2022
    8.8
    High

    CVE-2022-23767

    Last Modified: 3 Jun 2025

    This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform various attacks such as obtaining privileges and executing remote code, thereby taking over the victim’s system.

    Published: 19 Sept 2022
    8.8
    High

    CVE-2022-23768

    Last Modified: 3 Jun 2025

    This Vulnerability in NIS-HAP11AC is caused by an exposed external port for the telnet service. Remote attackers use this vulnerability to induce all attacks such as source code hijacking, remote control of the device.

    Published: 19 Sept 2022
    5.3
    Medium

    CVE-2022-29835

    Last Modified: 21 Nov 2024

    WD Discovery software executable files were signed with an unsafe SHA-1 hashing algorithm. An attacker could use this weakness to create forged certificate signatures due to the use of a hashing algorithm that is not collision-free. This could thereby impact the confidentiality of user content. This issue affects: Western Digital WD Discovery WD Discovery Desktop App versions prior to 4.4.396 on Mac; WD Discovery Desktop App versions prior to 4.4.396 on Windows.

    Published: 19 Sept 2022
    7.2
    High

    CVE-2022-38576

    Last Modified: 25 Nov 2025

    Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /interview/delete.php?action=deletecand&id=.

    Published: 19 Sept 2022
    9.1
    Critical

    CVE-2022-40980

    Last Modified: 21 Nov 2024

    A potential unathenticated file deletion vulnerabilty on Trend Micro Mobile Security for Enterprise 9.8 SP5 could allow an attacker with access to the Management Server to delete files. This issue was resolved in 9.8 SP5 Critical Patch 2.

    Published: 19 Sept 2022
    7.3
    High

    CVE-2022-40143

    Last Modified: 21 Nov 2024

    A link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service servers could allow a local attacker to abuse an insecure directory that could allow a low-privileged user to run arbitrary code with elevated privileges. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 19 Sept 2022
    7.8
    High

    CVE-2022-40142

    Last Modified: 21 Nov 2024

    A security link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service agents could allow a local attacker to create a writable folder in an arbitrary location and escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 19 Sept 2022
    7.5
    High

    CVE-2022-40141

    Last Modified: 21 Nov 2024

    A vulnerability in Trend Micro Apex One and Apex One as a Service could allow an attacker to intercept and decode certain communication strings that may contain some identification attributes of a particular Apex One server.

    Published: 19 Sept 2022
    5.5
    Medium

    CVE-2022-40140

    Last Modified: 21 Nov 2024

    An origin validation error vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to cause a denial-of-service on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 19 Sept 2022
    7.2
    High

    CVE-2022-40139

    Last Modified: 31 Oct 2025

    Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.

    Published: 19 Sept 2022
    7.8
    High

    CVE-2022-38764

    Last Modified: 21 Nov 2024

    A vulnerability on Trend Micro HouseCall version 1.62.1.1133 and below could allow a local attacker to escalate privlieges due to an overly permissive folder om the product installer.

    Published: 19 Sept 2022
    5.5
    Medium

    CVE-2022-37348

    Last Modified: 21 Nov 2024

    Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure Vulnerability that could allow an attacker to read sensitive information from other memory locations and cause a crash on an affected machine. This vulnerability is similar to, but not the same as CVE-2022-37347.

    Published: 19 Sept 2022
    5.5
    Medium

    CVE-2022-37347

    Last Modified: 29 May 2025

    Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure Vulnerability that could allow an attacker to read sensitive information from other memory locations and cause a crash on an affected machine. This vulnerability is similar to, but not the same as CVE-2022-35234.

    Published: 19 Sept 2022
    7.8
    High

    CVE-2022-34893

    Last Modified: 21 Nov 2024

    Trend Micro Security 2022 (consumer) has a link following vulnerability where an attacker with lower privileges could manipulate a mountpoint which could lead to escalation of privilege on an affected machine.

    Published: 19 Sept 2022
    7.5
    High

    CVE-2022-40608

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the target machine by manipulating the URL with a directory traversal attack. This results in the restore operation gaining access to files which the operator should not have access to. IBM X-Force ID: 235873.

    Published: 19 Sept 2022
    5.9
    Medium

    CVE-2022-40234

    Last Modified: 21 Nov 2024

    Versions of IBM Spectrum Protect Plus prior to 10.1.12 (excluding 10.1.12) include the private key information for a certificate inside the generated .crt file when uploading a TLS certificate to IBM Spectrum Protect Plus. If this generated .crt file is shared, an attacker can obtain the private key information for the uploaded certificate. IBM X-Force ID: 235718.

    Published: 19 Sept 2022
    9.8
    Critical

    CVE-2022-3218

    Last Modified: 21 Nov 2024

    Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which can result in remote code execution.

    Published: 19 Sept 2022
    7.5
    High

    CVE-2022-38333

    Last Modified: 21 Nov 2024

    Openwrt before v21.02.3 and Openwrt v22.03.0-rc6 were discovered to contain two skip loops in the function header_value(). This vulnerability allows attackers to access sensitive information via a crafted HTTP request.

    Published: 19 Sept 2022