CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-3214

    Last Modified: 25 Feb 2026

    Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to  1.9.03.009 have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer authorization, allowing remote code execution.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-39063

    Last Modified: 21 Nov 2024

    When Open5GS UPF receives a PFCP Session Establishment Request, it stores related values for building the PFCP Session Establishment Response. Once UPF receives a request, it gets the f_teid_len from incoming message, and then uses it to copy data from incoming message to struct f_teid without checking the maximum length. If the pdi.local_f_teid.len exceeds the maximum length of the struct of f_teid, the memcpy() overwrites the fields (e.g., f_teid_len) after f_teid in the pdr struct. After parsing the request, the UPF starts to build a response. The f_teid_len with its overwritten value is used as a length for memcpy(). A segmentation fault occurs, as a result of a memcpy(), if this overwritten value is large enough.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2020-36601

    Last Modified: 21 Nov 2024

    Out-of-bounds write vulnerability in the kernel modules. Successful exploitation of this vulnerability may cause a panic reboot.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2020-36600

    Last Modified: 21 Nov 2024

    Out-of-bounds write vulnerability in the power consumption module. Successful exploitation of this vulnerability may cause the system to restart.

    Published: 16 Sept 2022
    9.1
    Critical

    CVE-2022-39003

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability will affect the confidentiality and integrity of trusted components.

    Published: 16 Sept 2022
    9.1
    Critical

    CVE-2021-40019

    Last Modified: 21 Nov 2024

    Out-of-bounds heap read vulnerability in the HW_KEYMASTER module. Successful exploitation of this vulnerability may cause out-of-bounds access.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2021-40023

    Last Modified: 21 Nov 2024

    Configuration defects in the secure OS module. Successful exploitation of this vulnerability will affect confidentiality.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-39010

    Last Modified: 21 Nov 2024

    The HwChrService module has a vulnerability in permission control. Successful exploitation of this vulnerability may cause disclosure of user network information.

    Published: 16 Sept 2022
    9.8
    Critical

    CVE-2022-39009

    Last Modified: 3 Jun 2025

    The WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause third-party apps to affect WLAN functions.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-39001

    Last Modified: 3 Jun 2025

    The number identification module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause data disclosure.

    Published: 16 Sept 2022
    9.8
    Critical

    CVE-2022-39007

    Last Modified: 3 Jun 2025

    The location module has a vulnerability of bypassing permission verification.Successful exploitation of this vulnerability may cause privilege escalation.

    Published: 16 Sept 2022
    9.8
    Critical

    CVE-2022-38999

    Last Modified: 21 Nov 2024

    The AOD module has the improper update of reference count vulnerability. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-38997

    Last Modified: 21 Nov 2024

    The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-38996

    Last Modified: 21 Nov 2024

    The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-38995

    Last Modified: 21 Nov 2024

    The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-38994

    Last Modified: 21 Nov 2024

    The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-38992

    Last Modified: 21 Nov 2024

    The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-38991

    Last Modified: 21 Nov 2024

    The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-38979

    Last Modified: 21 Nov 2024

    The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-38978

    Last Modified: 21 Nov 2024

    The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-38989

    Last Modified: 21 Nov 2024

    The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-38988

    Last Modified: 21 Nov 2024

    The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-39005

    Last Modified: 21 Nov 2024

    The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-39004

    Last Modified: 21 Nov 2024

    The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-38987

    Last Modified: 21 Nov 2024

    The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.

    Published: 16 Sept 2022
    5.9
    Medium

    CVE-2022-39006

    Last Modified: 21 Nov 2024

    The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability may cause the device to restart.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-38993

    Last Modified: 21 Nov 2024

    The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2022-38990

    Last Modified: 21 Nov 2024

    The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.

    Published: 16 Sept 2022
    9.8
    Critical

    CVE-2022-39000

    Last Modified: 21 Nov 2024

    The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vulnerability will cause malicious apps to automatically start upon system startup.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2021-46836

    Last Modified: 21 Nov 2024

    Implementation of the WLAN module interfaces has the information disclosure vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 16 Sept 2022
    7.5
    High

    CVE-2021-40024

    Last Modified: 21 Nov 2024

    Implementation of the WLAN module interfaces has the information disclosure vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 16 Sept 2022
    9.1
    Critical

    CVE-2022-39008

    Last Modified: 3 Jun 2025

    The NFC module has bundle serialization/deserialization vulnerabilities. Successful exploitation of this vulnerability may cause third-party apps to read and write files that are accessible only to system apps.

    Published: 16 Sept 2022
    5.4
    Medium

    CVE-2022-35664

    Last Modified: 19 Sept 2025

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privilege access to AEM.

    Published: 16 Sept 2022
    5.4
    Medium

    CVE-2022-30681

    Last Modified: 19 Sept 2025

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privilege access to AEM.

    Published: 16 Sept 2022
    5.4
    Medium

    CVE-2022-30684

    Last Modified: 19 Sept 2025

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privilege access to AEM.

    Published: 16 Sept 2022
    5.4
    Medium

    CVE-2022-34218

    Last Modified: 19 Sept 2025

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privilege access to AEM.

    Published: 16 Sept 2022
    5.4
    Medium

    CVE-2022-30686

    Last Modified: 19 Sept 2025

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privilege access to AEM.

    Published: 16 Sept 2022
    5.4
    Medium

    CVE-2022-30682

    Last Modified: 19 Sept 2025

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privilege access to AEM.

    Published: 16 Sept 2022
    5.4
    Medium

    CVE-2022-30680

    Last Modified: 19 Sept 2025

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privilege access to AEM.

    Published: 16 Sept 2022
    5.4
    Medium

    CVE-2022-30685

    Last Modified: 19 Sept 2025

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privilege access to AEM.

    Published: 16 Sept 2022
    5.4
    Medium

    CVE-2022-30678

    Last Modified: 19 Sept 2025

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privilege access to AEM.

    Published: 16 Sept 2022
    5.3
    Medium

    CVE-2022-30683

    Last Modified: 19 Sept 2025

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a Violation of Secure Design Principles vulnerability that could lead to bypass the security feature of the encryption mechanism in the backend . An attacker could leverage this vulnerability to decrypt secrets, however, this is a high-complexity attack as the threat actor needs to already possess those secrets. Exploitation of this issue requires low-privilege access to AEM.

    Published: 16 Sept 2022
    5.4
    Medium

    CVE-2022-30677

    Last Modified: 19 Sept 2025

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privilege access to AEM.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-38417

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-38416

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    5.5
    Medium

    CVE-2022-30676

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-38413

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-38415

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    5.5
    Medium

    CVE-2022-30675

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-38414

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022