CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2022-34165

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP header injection, caused by improper validation. This could allow an attacker to conduct various attacks against the vulnerable system, including cache poisoning and cross-site scripting. IBM X-Force ID: 229429.

    Published: 9 Sept 2022
    7.5
    High

    CVE-2022-28740

    Last Modified: 21 Nov 2024

    aEnrich eHRD Learning Management Key Performance Indicator System 5+ exposes Sensitive Information to an Unauthorized Actor.

    Published: 9 Sept 2022
    7.5
    High

    CVE-2022-28742

    Last Modified: 21 Nov 2024

    aEnrich eHRD Learning Management Key Performance Indicator System 5+ has Improper Access Control. The web application does not validate user session when accessing many application pages. This can allow an attacker to gain unauthenticated access to sensitive functionalities in the application

    Published: 9 Sept 2022
    8.1
    High

    CVE-2022-28741

    Last Modified: 21 Nov 2024

    aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability that occurs due to missing input validation in v5.x

    Published: 9 Sept 2022
    6.5
    Medium

    CVE-2022-38613

    Last Modified: 21 Nov 2024

    A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system.

    Published: 9 Sept 2022
    4.9
    Medium

    CVE-2022-36617

    Last Modified: 21 Nov 2024

    Arq Backup 7.19.5.0 and below stores backup encryption passwords using reversible encryption. This issue allows attackers with administrative privileges to recover cleartext passwords.

    Published: 9 Sept 2022
    4.8
    Medium

    CVE-2022-37335

    Last Modified: 20 Feb 2025

    Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in WHA's Word Search Puzzles game plugin <= 2.0.1 at WordPress.

    Published: 9 Sept 2022
    4.1
    Medium

    CVE-2022-37407

    Last Modified: 20 Feb 2025

    Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress.

    Published: 9 Sept 2022
    5
    Medium

    CVE-2022-26393

    Last Modified: 21 Nov 2024

    The Baxter Spectrum WBM is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information or cause a Denial of Service (DoS) on the WBM.

    Published: 9 Sept 2022
    4.2
    Medium

    CVE-2022-26390

    Last Modified: 21 Nov 2024

    The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to extract sensitive information.

    Published: 9 Sept 2022
    3.1
    Low

    CVE-2022-26392

    Last Modified: 21 Nov 2024

    The Baxter Spectrum WBM (v16, v16D38) and Baxter Spectrum WBM (v17, v17D19, v20D29 to v20D32) when in superuser mode is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information.

    Published: 9 Sept 2022
    5.5
    Medium

    CVE-2022-26394

    Last Modified: 21 Nov 2024

    The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker to perform a man in the middle attack that modifies parameters making the network connection fail.

    Published: 9 Sept 2022
    3.9
    Low

    CVE-2022-36851

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data of Samsung pass on a certain state of an unlocked device.

    Published: 9 Sept 2022
    4.4
    Medium

    CVE-2022-36855

    Last Modified: 21 Nov 2024

    A use after free vulnerability in iva_ctl driver prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

    Published: 9 Sept 2022
    4
    Medium

    CVE-2022-36864

    Last Modified: 21 Nov 2024

    Improper access control and intent redirection in Samsung Email prior to 6.1.70.20 allows attacker to access specific formatted file and execute privileged behavior.

    Published: 9 Sept 2022
    6.6
    Medium

    CVE-2022-36869

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in ContactsDumpActivity of?Contacts Provider prior to version 12.7.59 allows attacker to access the file without permission.

    Published: 9 Sept 2022
    4
    Medium

    CVE-2022-36866

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Broadcaster in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.

    Published: 9 Sept 2022
    4
    Medium

    CVE-2022-36850

    Last Modified: 21 Nov 2024

    Path traversal vulnerability in CallBGProvider prior to SMR Sep-2022 Release 1 allows attacker to overwrite arbitrary file with phone uid.

    Published: 9 Sept 2022
    4
    Medium

    CVE-2022-36865

    Last Modified: 21 Nov 2024

    Improper access control in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to access device information.

    Published: 9 Sept 2022
    5.9
    Medium

    CVE-2022-36867

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Editor Lite prior to version 4.0.40.14 allows attackers to access sensitive information.

    Published: 9 Sept 2022
    1.9
    Low

    CVE-2022-36857

    Last Modified: 21 Nov 2024

    Improper Authorization vulnerability in Photo Editor prior to SMR Sep-2022 Release 1 allows physical attackers to read internal application data.

    Published: 9 Sept 2022
    1.9
    Low

    CVE-2022-36852

    Last Modified: 21 Nov 2024

    Improper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local attacker to access internal application data.

    Published: 9 Sept 2022
    3.3
    Low

    CVE-2022-36853

    Last Modified: 21 Nov 2024

    Intent redirection in Photo Editor prior to SMR Sep-2022 Release 1 allows attacker to get sensitive information.

    Published: 9 Sept 2022
    4
    Medium

    CVE-2022-36856

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Telecom application prior to SMR Sep-2022 Release 1 allows attacker to start emergency calls via undefined permission.

    Published: 9 Sept 2022
    5.9
    Medium

    CVE-2022-36861

    Last Modified: 21 Nov 2024

    Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystemUI privilege.

    Published: 9 Sept 2022
    5.1
    Medium

    CVE-2022-36848

    Last Modified: 21 Nov 2024

    Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of service.

    Published: 9 Sept 2022
    5
    Medium

    CVE-2022-36872

    Last Modified: 21 Nov 2024

    Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.

    Published: 9 Sept 2022
    5
    Medium

    CVE-2022-36871

    Last Modified: 21 Nov 2024

    Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.

    Published: 9 Sept 2022
    5
    Medium

    CVE-2022-36870

    Last Modified: 21 Nov 2024

    Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.

    Published: 9 Sept 2022
    5.9
    Medium

    CVE-2022-36873

    Last Modified: 21 Nov 2024

    Improper restriction of broadcasting Intent in GalaxyStoreBridgePageLinker of?Waterplugin prior to version 2.2.11.22081151 leaks MAC address of the connected Bluetooth device.

    Published: 9 Sept 2022
    4
    Medium

    CVE-2022-36854

    Last Modified: 21 Nov 2024

    Out of bound read in libapexjni.media.samsung.so prior to SMR Sep-2022 Release 1 allows attacker access unauthorized information.

    Published: 9 Sept 2022
    4.4
    Medium

    CVE-2022-36858

    Last Modified: 21 Nov 2024

    A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc() function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

    Published: 9 Sept 2022
    5.9
    Medium

    CVE-2022-36874

    Last Modified: 21 Nov 2024

    Improper Handling of Insufficient Permissions or Privileges vulnerability in Waterplugin prior to 2.2.11.22040751 allows attacker to access device IMEI and Serial number.

    Published: 9 Sept 2022
    6.6
    Medium

    CVE-2022-36875

    Last Modified: 21 Nov 2024

    Improper restriction of broadcasting Intent in SaWebViewRelayActivity of?Waterplugin prior to version 2.2.11.22081151 allows attacker to access the file without permission.

    Published: 9 Sept 2022
    4.4
    Medium

    CVE-2022-36842

    Last Modified: 21 Nov 2024

    A heap-based overflow vulnerability in prepareRecogLibrary function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

    Published: 9 Sept 2022
    4.4
    Medium

    CVE-2022-36843

    Last Modified: 21 Nov 2024

    A heap-based overflow vulnerability in MHW_RECOG_LIB_INFO function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

    Published: 9 Sept 2022
    4.4
    Medium

    CVE-2022-36844

    Last Modified: 21 Nov 2024

    A heap-based overflow vulnerability in HWR::EngJudgeModel::Construct() in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

    Published: 9 Sept 2022
    4.4
    Medium

    CVE-2022-36846

    Last Modified: 21 Nov 2024

    A heap-based overflow vulnerability in ConstructDictionary function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

    Published: 9 Sept 2022
    4.4
    Medium

    CVE-2022-36860

    Last Modified: 21 Nov 2024

    A heap-based overflow vulnerability in LoadEnvironment function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

    Published: 9 Sept 2022
    4.4
    Medium

    CVE-2022-36862

    Last Modified: 21 Nov 2024

    A heap-based overflow vulnerability in HWR::EngineCJK::Impl::Construct() in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

    Published: 9 Sept 2022
    4.4
    Medium

    CVE-2022-36863

    Last Modified: 21 Nov 2024

    A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

    Published: 9 Sept 2022
    4.4
    Medium

    CVE-2022-36841

    Last Modified: 21 Nov 2024

    A heap-based overflow vulnerability in PrepareRecogLibrary_Part function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

    Published: 9 Sept 2022
    4.4
    Medium

    CVE-2022-36845

    Last Modified: 21 Nov 2024

    A heap-based overflow vulnerability in MHW_RECOG_LIB_INFO function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

    Published: 9 Sept 2022
    4.9
    Medium

    CVE-2022-36847

    Last Modified: 21 Nov 2024

    Use after free vulnerability in mtp_send_signal function of MTP driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions.

    Published: 9 Sept 2022
    4.9
    Medium

    CVE-2022-36849

    Last Modified: 21 Nov 2024

    Use after free vulnerability in sdp_mm_set_process_sensitive function of sdpmm driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions.

    Published: 9 Sept 2022
    5.7
    Medium

    CVE-2022-36859

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in SmartTagPlugin prior to version 1.2.21-6 allows privileged attackers to trigger a XSS on a victim&#39;s devices.

    Published: 9 Sept 2022
    1.8
    Low

    CVE-2022-36876

    Last Modified: 21 Nov 2024

    Improper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical attackers to access account list without authentication.

    Published: 9 Sept 2022
    6.2
    Medium

    CVE-2022-38701

    Last Modified: 21 Nov 2024

    OpenHarmony-v3.1.2 and prior versions have a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information.

    Published: 9 Sept 2022
    5.5
    Medium

    CVE-2022-39845

    Last Modified: 21 Nov 2024

    Improper validation of integrity check vulnerability in Samsung Kies prior to version 2.6.4.22074 allows local attackers to delete arbitrary directory using directory junction.

    Published: 9 Sept 2022
    2.8
    Low

    CVE-2022-36877

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information in FaqSymptomCardViewModel in Samsung Members prior to versions 4.3.00.11 in Global and 14.0.02.4 in China allows local attackers to access device identification via log.

    Published: 9 Sept 2022