CVE Feed

    Dashboard / CVE

    6.2
    Medium

    CVE-2022-22101

    Last Modified: 21 Nov 2024

    Denial of service in multimedia due to uncontrolled resource consumption while parsing an incoming HAB message in Snapdragon Auto

    Published: 2 Sept 2022
    8.4
    High

    CVE-2022-22100

    Last Modified: 21 Nov 2024

    Memory corruption in multimedia due to improper check on received export descriptors in Snapdragon Auto

    Published: 2 Sept 2022
    8.4
    High

    CVE-2022-22099

    Last Modified: 21 Nov 2024

    Memory corruption in multimedia due to improper validation of array index in Snapdragon Auto

    Published: 2 Sept 2022
    8.4
    High

    CVE-2022-22098

    Last Modified: 21 Nov 2024

    Memory corruption in multimedia driver due to untrusted pointer dereference while reading data from socket in Snapdragon Auto

    Published: 2 Sept 2022
    8.4
    High

    CVE-2022-22097

    Last Modified: 21 Nov 2024

    Memory corruption in graphic driver due to use after free while calling multiple threads application to driver. in Snapdragon Consumer IOT

    Published: 2 Sept 2022
    9.8
    Critical

    CVE-2022-22096

    Last Modified: 21 Nov 2024

    Memory corruption in Bluetooth HOST due to stack-based buffer overflow when when extracting data using command length parameter in Snapdragon Connectivity, Snapdragon Mobile

    Published: 2 Sept 2022
    8.4
    High

    CVE-2022-22080

    Last Modified: 21 Nov 2024

    Improper validation of backend id in PCM routing process can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

    Published: 2 Sept 2022
    7.8
    High

    CVE-2022-22070

    Last Modified: 21 Nov 2024

    Memory corruption in audio due to lack of check of invalid routing address into APR Routing table in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 2 Sept 2022
    7.7
    High

    CVE-2022-22069

    Last Modified: 21 Nov 2024

    Devices with keyprotect off may store unencrypted keybox in RPMB and cause cryptographic issue in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 2 Sept 2022
    7.5
    High

    CVE-2022-22067

    Last Modified: 21 Nov 2024

    Potential memory leak in modem during the processing of NSA RRC Reconfiguration with invalid Radio Bearer Config in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile

    Published: 2 Sept 2022
    8.2
    High

    CVE-2022-22062

    Last Modified: 21 Nov 2024

    An out-of-bounds read can occur while parsing a server certificate due to improper length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 2 Sept 2022
    7.8
    High

    CVE-2022-22061

    Last Modified: 21 Nov 2024

    Out of bounds writing is possible while verifying device IDs due to improper length check before copying the data in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile

    Published: 2 Sept 2022
    8.4
    High

    CVE-2022-22059

    Last Modified: 21 Nov 2024

    Memory corruption due to out of bound read while parsing a video file in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 2 Sept 2022
    6.2
    Medium

    CVE-2021-35135

    Last Modified: 21 Nov 2024

    A null pointer dereference may potentially occur during RSA key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 2 Sept 2022
    8.4
    High

    CVE-2021-35134

    Last Modified: 21 Nov 2024

    Due to insufficient validation of ELF headers, an Incorrect Calculation of Buffer Size can occur in Boot leading to memory corruption in Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 2 Sept 2022
    6.7
    Medium

    CVE-2021-35133

    Last Modified: 21 Nov 2024

    Use after free in the synx driver issue while performing other functions during multiple invocation of synx release calls in Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 2 Sept 2022
    8.4
    High

    CVE-2021-35132

    Last Modified: 21 Nov 2024

    Out of bound write in DSP service due to improper bound check for response buffer size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 2 Sept 2022
    9.3
    Critical

    CVE-2021-35122

    Last Modified: 21 Nov 2024

    Non-secure region can try modifying RG permissions of IO space xPUs due to improper input validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 2 Sept 2022
    7.3
    High

    CVE-2021-35113

    Last Modified: 21 Nov 2024

    Possible authentication bypass due to improper order of signature verification and hashing in the signature verification call in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 2 Sept 2022
    6.8
    Medium

    CVE-2021-35109

    Last Modified: 21 Nov 2024

    Possible address manipulation from APP-NS while APP-S is configuring an RG where it tries to merge the address ranges in Snapdragon Connectivity, Snapdragon Mobile

    Published: 2 Sept 2022
    6.8
    Medium

    CVE-2021-35108

    Last Modified: 21 Nov 2024

    Improper checking of AP-S lock bit while verifying the secure resource group permissions can lead to non secure read and write access in Snapdragon Connectivity, Snapdragon Mobile

    Published: 2 Sept 2022
    7.2
    High

    CVE-2022-37458

    Last Modified: 21 Nov 2024

    Discourse through 2.8.7 allows admins to send invitations to arbitrary email addresses at an unlimited rate.

    Published: 2 Sept 2022
    5.9
    Medium

    CVE-2021-44718

    Last Modified: 21 Nov 2024

    wolfSSL through 5.0.0 allows an attacker to cause a denial of service and infinite loop in the client component by sending crafted traffic from a Machine-in-the-Middle (MITM) position. The root cause is that the client module accepts TLS messages that normally are only sent to TLS servers.

    Published: 2 Sept 2022
    9.8
    Critical

    CVE-2022-38054

    Last Modified: 21 Nov 2024

    In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.

    Published: 2 Sept 2022
    4.7
    Medium

    CVE-2022-38170

    Last Modified: 21 Nov 2024

    In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the `--daemon` flag which could result in a race condition giving world-writable files in the Airflow home directory and allowing local users to expose arbitrary file contents via the webserver.

    Published: 2 Sept 2022
    7.5
    High

    CVE-2022-29158

    Last Modified: 21 Nov 2024

    Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, unauthenticated users. Upgrade to 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12599

    Published: 2 Sept 2022
    9.8
    Critical

    CVE-2022-29063

    Last Modified: 21 Nov 2024

    The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or on a server restart, in order to run arbitrary code. Upgrade to at least 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12646.

    Published: 2 Sept 2022
    7.5
    High

    CVE-2022-25813

    Last Modified: 21 Nov 2024

    In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a party manager needs to list the communications in the party component to activate the SSTI. A RCE is then possible.

    Published: 2 Sept 2022
    9.8
    Critical

    CVE-2022-25371

    Last Modified: 21 Nov 2024

    Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142) it is possible to perform a remote code execution (RCE) attack in Apache OFBiz, release 18.12.05 and earlier.

    Published: 2 Sept 2022
    5.4
    Medium

    CVE-2022-25370

    Last Modified: 21 Nov 2024

    Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. In Apache OFBiz release 18.12.05, and earlier versions, by leveraging a vulnerability in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142), an unauthenticated malicious user could perform a stored XSS attack in order to inject a malicious payload and execute it using the stored XSS.

    Published: 2 Sept 2022
    5.4
    Medium

    CVE-2022-36637

    Last Modified: 21 Nov 2024

    Garage Management System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the brand_name parameter at /brand.php.

    Published: 2 Sept 2022
    8.8
    High

    CVE-2022-36636

    Last Modified: 21 Nov 2024

    Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php.

    Published: 2 Sept 2022
    9.8
    Critical

    CVE-2022-36609

    Last Modified: 21 Nov 2024

    Clinic's Patient Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pms/update_patient.php.

    Published: 2 Sept 2022
    4.8
    Medium

    CVE-2022-37679

    Last Modified: 21 Nov 2024

    Miniblog.Core v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blog/edit. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Excerpt field.

    Published: 2 Sept 2022
    4.8
    Medium

    CVE-2022-36600

    Last Modified: 21 Nov 2024

    BlogEngine v3.3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blogengine/api/posts. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.

    Published: 2 Sept 2022
    9.8
    Critical

    CVE-2022-36594

    Last Modified: 21 Nov 2024

    Mapper v4.0.0 to v4.2.0 was discovered to contain a SQL injection vulnerability via the ids parameter at the selectByIds function.

    Published: 2 Sept 2022
    6.5
    Medium

    CVE-2022-36593

    Last Modified: 21 Nov 2024

    kkFileView v4.0.0 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter at /controller/FileController.java.

    Published: 2 Sept 2022
    9.8
    Critical

    CVE-2022-36759

    Last Modified: 30 Mar 2026

    Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /dishes.php?res_id=.

    Published: 2 Sept 2022
    7.8
    High

    CVE-2021-25657

    Last Modified: 21 Nov 2024

    A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate privileges. This issue affects Admin Lite and USB Creator 11.1 Feature Pack 2 Service Pack 1 and earlier versions.

    Published: 2 Sept 2022
    7.5
    High

    CVE-2020-10735

    Last Modified: 7 Oct 2026

    A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability.

    Published: 2 Sept 2022
    5.5
    Medium

    CVE-2022-3146

    Last Modified: 25 Feb 2025

    A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important configuration details from the OpenStack deployment.

    Published: 2 Sept 2022
    8.3
    High

    CVE-2022-31176

    Last Modified: 23 Apr 2025

    Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). An internal security review identified an unauthorized file disclosure vulnerability. It is possible for a malicious user to retrieve unauthorized files under some network conditions or via a fake datasource (if user has admin permissions in Grafana). All Grafana installations should be upgraded to version 3.6.1 as soon as possible. As a workaround it is possible to [disable HTTP remote rendering](https://grafana.com/docs/grafana/latest/setup-grafana/configure-grafana/#plugingrafana-image-renderer).

    Published: 2 Sept 2022
    7.3
    High

    CVE-2021-35097

    Last Modified: 21 Nov 2024

    Possible authentication bypass due to improper order of signature verification and hashing in the signature verification call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 2 Sept 2022
    5.5
    Medium

    CVE-2022-3101

    Last Modified: 25 Feb 2025

    A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important configuration details from the OpenStack deployment.

    Published: 2 Sept 2022
    —
    Unknown

    CVE-2022-3117

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 2 Sept 2022
    8.8
    High

    CVE-2022-39170

    Last Modified: 21 Nov 2024

    libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.

    Published: 2 Sept 2022
    4.9
    Medium

    CVE-2022-39194

    Last Modified: 21 Nov 2024

    An issue was discovered in the MediaWiki through 1.38.2. The community configuration pages for the GrowthExperiments extension could cause a site to become unavailable due to insufficient validation when certain actions (including page moves) were performed.

    Published: 2 Sept 2022
    —
    Unknown

    CVE-2022-39390

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-36534. Reason: This candidate is a reservation duplicate of CVE-2020-36534. Notes: All CVE users should reference CVE-2020-36534 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 2 Sept 2022
    9.8
    Critical

    CVE-2020-22669

    Last Modified: 3 Nov 2025

    Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.

    Published: 2 Sept 2022
    8.8
    High

    CVE-2022-39177

    Last Modified: 15 Apr 2026

    BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in profiles/audio/avdtp.c.

    Published: 2 Sept 2022