CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2022-30673

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    5.5
    Medium

    CVE-2022-30674

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    5.5
    Medium

    CVE-2022-30672

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    5.5
    Medium

    CVE-2022-28855

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    5.5
    Medium

    CVE-2022-28857

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    5.5
    Medium

    CVE-2022-30671

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    5.5
    Medium

    CVE-2022-28854

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    5.5
    Medium

    CVE-2022-28856

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-28852

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-28853

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-38434

    Last Modified: 21 Nov 2024

    Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-38432

    Last Modified: 23 Apr 2025

    Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-38433

    Last Modified: 23 Apr 2025

    Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.sue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-38426

    Last Modified: 23 Apr 2025

    Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    5.5
    Medium

    CVE-2022-38428

    Last Modified: 23 Apr 2025

    Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-38429

    Last Modified: 23 Apr 2025

    Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-38431

    Last Modified: 23 Apr 2025

    Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-35713

    Last Modified: 23 Apr 2025

    Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-38427

    Last Modified: 23 Apr 2025

    Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-38430

    Last Modified: 23 Apr 2025

    Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-38401

    Last Modified: 23 Apr 2025

    Adobe InCopy version 17.3 (and earlier) and 16.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    5.5
    Medium

    CVE-2022-38407

    Last Modified: 23 Apr 2025

    Adobe InCopy version 17.3 (and earlier) and 16.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-38405

    Last Modified: 23 Apr 2025

    Adobe InCopy version 17.3 (and earlier) and 16.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    5.5
    Medium

    CVE-2022-38406

    Last Modified: 23 Apr 2025

    Adobe InCopy version 17.3 (and earlier) and 16.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-38404

    Last Modified: 23 Apr 2025

    Adobe InCopy version 17.3 (and earlier) and 16.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-38402

    Last Modified: 23 Apr 2025

    Adobe InCopy version 17.3 (and earlier) and 16.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-38403

    Last Modified: 23 Apr 2025

    Adobe InCopy version 17.3 (and earlier) and 16.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    5.5
    Medium

    CVE-2022-38410

    Last Modified: 23 Apr 2025

    Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-38408

    Last Modified: 23 Apr 2025

    Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    5.5
    Medium

    CVE-2022-38409

    Last Modified: 23 Apr 2025

    Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-38411

    Last Modified: 23 Apr 2025

    Adobe Animate version 21.0.11 (and earlier) and 22.0.7 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    7.8
    High

    CVE-2022-38412

    Last Modified: 23 Apr 2025

    Adobe Animate version 21.0.11 (and earlier) and 22.0.7 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Sept 2022
    5.4
    Medium

    CVE-2021-42597

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Storage Unit Rental Management System PHP 8.0.10 , Apache 2.4.14, SURMS V 1.0 via the Add New Tenant List Rent List form.

    Published: 16 Sept 2022
    8.8
    High

    CVE-2022-3225

    Last Modified: 25 Feb 2026

    Improper Control of Dynamically-Managed Code Resources in GitHub repository budibase/budibase prior to 1.3.20.

    Published: 16 Sept 2022
    4.8
    Medium

    CVE-2021-41731

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS vulnerability exists in )Sourcecodester News247 News Magazine (CMS) PHP 5.6 or higher and MySQL 5.7 or higher via the blog category name field

    Published: 16 Sept 2022
    6.1
    Medium

    CVE-2022-37775

    Last Modified: 21 Nov 2024

    Genesys PureConnect Interaction Web Tools Chat Service (up to at least 26- September- 2019) allows XSS within the Printable Chat History via the participant -> name JSON POST parameter.

    Published: 16 Sept 2022
    7.2
    High

    CVE-2022-35193

    Last Modified: 21 Nov 2024

    TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php.

    Published: 16 Sept 2022
    7.2
    High

    CVE-2022-35195

    Last Modified: 21 Nov 2024

    TestLink 1.9.20 Raijin was discovered to contain a broken access control vulnerability at /lib/attachments/attachmentdownload.php

    Published: 16 Sept 2022
    8.8
    High

    CVE-2022-40337

    Last Modified: 21 Nov 2024

    OASES (aka Open Aviation Strategic Engineering System) 8.8.0.2 allows attackers to execute arbitrary code via the Open Print Folder menu.

    Published: 16 Sept 2022
    3.7
    Low

    CVE-2021-42948

    Last Modified: 21 Nov 2024

    HotelDruid Hotel Management Software v3.0.3 and below was discovered to have exposed session tokens in multiple links via GET parameters, allowing attackers to access user session id's.

    Published: 16 Sept 2022
    5.4
    Medium

    CVE-2022-37248

    Last Modified: 21 Nov 2024

    Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.

    Published: 16 Sept 2022
    7.2
    High

    CVE-2022-38877

    Last Modified: 3 Jun 2025

    Garage Management System v1.0 is vulnerable to Arbitrary code execution via ip/garage/php_action/editProductImage.php?id=1.

    Published: 16 Sept 2022
    7.2
    High

    CVE-2022-38878

    Last Modified: 3 Jun 2025

    School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/event/index.php?view=edit&id=.

    Published: 16 Sept 2022
    5.4
    Medium

    CVE-2022-37250

    Last Modified: 3 Jun 2025

    Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.

    Published: 16 Sept 2022
    7.2
    High

    CVE-2022-38832

    Last Modified: 3 Jun 2025

    School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/department/index.php?view=edit&id=.

    Published: 16 Sept 2022
    7.2
    High

    CVE-2022-38833

    Last Modified: 3 Jun 2025

    School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/modstudent/index.php?view=view&id=.

    Published: 16 Sept 2022
    9.8
    Critical

    CVE-2021-42949

    Last Modified: 3 Jun 2025

    The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.

    Published: 16 Sept 2022
    9.8
    Critical

    CVE-2022-38829

    Last Modified: 21 Nov 2024

    Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setMacFilterCfg.

    Published: 16 Sept 2022
    9.8
    Critical

    CVE-2022-38830

    Last Modified: 21 Nov 2024

    Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setIPv6Status.

    Published: 16 Sept 2022
    9.8
    Critical

    CVE-2022-38831

    Last Modified: 21 Nov 2024

    Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/SetNetControlList

    Published: 16 Sept 2022