CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-29805

    Last Modified: 21 Nov 2024

    A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code via a crafted XML payload.

    Published: 19 Aug 2022
    7.5
    High

    CVE-2022-2075

    Last Modified: 21 Nov 2024

    In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service targeting the build information request validation.

    Published: 19 Aug 2022
    7.5
    High

    CVE-2022-2074

    Last Modified: 21 Nov 2024

    In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service using the Variable Project Template.

    Published: 19 Aug 2022
    7.5
    High

    CVE-2022-2049

    Last Modified: 21 Nov 2024

    In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service via the package upload function.

    Published: 19 Aug 2022
    5.3
    Medium

    CVE-2022-1901

    Last Modified: 21 Nov 2024

    In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview.

    Published: 19 Aug 2022
    —
    Unknown

    CVE-2022-37408

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 19 Aug 2022
    —
    Unknown

    CVE-2022-38071

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 19 Aug 2022
    —
    Unknown

    CVE-2022-33310

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 19 Aug 2022
    —
    Unknown

    CVE-2022-36420

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 19 Aug 2022
    —
    Unknown

    CVE-2022-36419

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 19 Aug 2022
    —
    Unknown

    CVE-2022-38084

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 19 Aug 2022
    5.4
    Medium

    CVE-2020-23466

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in the phpgurukul Online Marriage Registration System 1.0 allows attackers to run arbitrary code via the wzipcode field.

    Published: 19 Aug 2022
    8.8
    High

    CVE-2022-35167

    Last Modified: 21 Nov 2024

    Printix Cloud Print Management v1.3.1149.0 for Windows was discovered to contain insecure permissions.

    Published: 19 Aug 2022
    5.3
    Medium

    CVE-2022-2739

    Last Modified: 21 Nov 2024

    The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:5056. This issue could possibly allow an attacker to gain access to sensitive information stored in environment variables.

    Published: 19 Aug 2022
    7.5
    High

    CVE-2022-2738

    Last Modified: 21 Nov 2024

    The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-8945, which was previously fixed via RHSA-2020:2117. This issue could possibly be used to crash or cause potential code execution in Go applications that use the Go GPGME wrapper library, under certain conditions, during GPG signature verification.

    Published: 19 Aug 2022
    6.5
    Medium

    CVE-2022-2308

    Last Modified: 21 Nov 2024

    A flaw was found in vDPA with VDUSE backend. There are currently no checks in VDUSE kernel driver to ensure the size of the device config space is in line with the features advertised by the VDUSE userspace application. In case of a mismatch, Virtio drivers config read helpers do not initialize the memory indirectly passed to vduse_vdpa_get_config() returning uninitialized memory from the stack. This could cause undefined behavior or data leaks in Virtio drivers.

    Published: 19 Aug 2022
    9.8
    Critical

    CVE-2022-2526

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later.

    Published: 19 Aug 2022
    9.8
    Critical

    CVE-2020-36599

    Last Modified: 21 Nov 2024

    lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-35540

    Last Modified: 21 Nov 2024

    Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access.

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-36947

    Last Modified: 21 Nov 2024

    Unsafe Parsing of a PNG tRNS chunk in FastStone Image Viewer through 7.5 results in a stack buffer overflow.

    Published: 18 Aug 2022
    6.2
    Medium

    CVE-2022-34345

    Last Modified: 5 Feb 2025

    Improper input validation in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable escalation of privilege via physical access.

    Published: 18 Aug 2022
    7.2
    High

    CVE-2022-32579

    Last Modified: 10 Feb 2025

    Improper initialization in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable escalation of privilege via physical access.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2022-34488

    Last Modified: 18 Feb 2025

    Improper buffer restrictions in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2022-27493

    Last Modified: 18 Feb 2025

    Improper initialization in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable an escalation of privilege via local access.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2022-33209

    Last Modified: 18 Feb 2025

    Improper input validation in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2022-28858

    Last Modified: 18 Feb 2025

    Improper buffer restriction in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 18 Aug 2022
    5.5
    Medium

    CVE-2022-29507

    Last Modified: 18 Feb 2025

    Insufficiently protected credentials in the Intel(R) Team Blue mobile application in all versions may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 18 Aug 2022
    7.5
    High

    CVE-2022-30296

    Last Modified: 25 Feb 2025

    Insufficiently protected credentials in the Intel(R) Datacenter Group Event iOS application, all versions, may allow an unauthenticated user to potentially enable information disclosure via network access.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2022-26374

    Last Modified: 25 Feb 2025

    Uncontrolled search path in the installation binaries for Intel(R) SEAPI all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2022-26344

    Last Modified: 25 Feb 2025

    Incorrect default permissions in the installation binaries for Intel(R) SEAPI all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2022-26844

    Last Modified: 25 Feb 2025

    Insufficiently protected credentials in the installation binaries for Intel(R) SEAPI in all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-25899

    Last Modified: 25 Feb 2025

    Authentication bypass for the Open AMT Cloud Toolkit software maintained by Intel(R) before versions 2.0.2 and 2.2.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2021-33060

    Last Modified: 5 May 2025

    Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2022-28696

    Last Modified: 5 May 2025

    Uncontrolled search path in the Intel(R) Distribution for Python before version 2022.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 18 Aug 2022
    8
    High

    CVE-2022-26017

    Last Modified: 5 May 2025

    Improper access control in the Intel(R) DSA software for before version 22.2.14 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2022-25841

    Last Modified: 5 May 2025

    Uncontrolled search path elements in the Intel(R) Datacenter Group Event Android application, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2022-25999

    Last Modified: 5 May 2025

    Uncontrolled search path element in the Intel(R) Enpirion(R) Digital Power Configurator GUI software, all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 18 Aug 2022
    4.4
    Medium

    CVE-2022-26074

    Last Modified: 5 May 2025

    Incomplete cleanup in a firmware subsystem for Intel(R) SPS before versions SPS_E3_04.08.04.330.0 and SPS_E3_04.01.04.530.0 may allow a privileged user to potentially enable denial of service via local access.

    Published: 18 Aug 2022
    5.5
    Medium

    CVE-2022-23403

    Last Modified: 5 May 2025

    Improper input validation in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-36727

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /staff/delete.php.

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-36722

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the title parameter at /librarian/history.php.

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-36728

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /staff/delstu.php.

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-36725

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /student/dele.php.

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-36729

    Last Modified: 21 Nov 2024

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /librarian/del.php.

    Published: 18 Aug 2022
    5.5
    Medium

    CVE-2022-24378

    Last Modified: 5 May 2025

    Improper initialization in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 18 Aug 2022
    8.8
    High

    CVE-2022-23182

    Last Modified: 5 May 2025

    Improper access control in the Intel(R) Data Center Manager software before version 4.1 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 18 Aug 2022
    5.5
    Medium

    CVE-2022-27500

    Last Modified: 5 May 2025

    Incorrect default permissions for the Intel(R) Support Android application before 21.07.40 may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2022-21807

    Last Modified: 5 May 2025

    Uncontrolled search path elements in the Intel(R) VTune(TM) Profiler software before version 2022.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2022-21812

    Last Modified: 5 May 2025

    Improper access control in the Intel(R) HAXM software before version 7.7.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 18 Aug 2022
    5.5
    Medium

    CVE-2022-21152

    Last Modified: 5 May 2025

    Improper access control in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 18 Aug 2022