CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-21148

    Last Modified: 5 May 2025

    Improper access control in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2022-25966

    Last Modified: 5 May 2025

    Improper access control in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-22730

    Last Modified: 5 May 2025

    Improper authentication in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

    Published: 18 Aug 2022
    5.5
    Medium

    CVE-2022-21793

    Last Modified: 5 May 2025

    Insufficient control flow management in the Intel(R) Ethernet 500 Series Controller drivers for VMWare before version 1.11.4.0 and in the Intel(R) Ethernet 700 Series Controller drivers for VMWare before version 2.1.5.0 may allow an authenticated user to potentially enable a denial of service via local access.

    Published: 18 Aug 2022
    7.1
    High

    CVE-2021-23179

    Last Modified: 5 May 2025

    Out of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow a privileged user to potentially enable information disclosure via local access.

    Published: 18 Aug 2022
    5.5
    Medium

    CVE-2021-26950

    Last Modified: 5 May 2025

    Out of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 18 Aug 2022
    5.5
    Medium

    CVE-2021-26257

    Last Modified: 5 May 2025

    Improper buffer restrictions in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2021-33847

    Last Modified: 5 May 2025

    Improper buffer restrictions in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 18 Aug 2022
    5.5
    Medium

    CVE-2022-21140

    Last Modified: 5 May 2025

    Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable information disclosure via local access.

    Published: 18 Aug 2022
    6.5
    Medium

    CVE-2022-21212

    Last Modified: 5 May 2025

    Improper input validation for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 18 Aug 2022
    3.3
    Low

    CVE-2021-23188

    Last Modified: 5 May 2025

    Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 18 Aug 2022
    7.5
    High

    CVE-2022-21160

    Last Modified: 5 May 2025

    Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable denial of service via network access.

    Published: 18 Aug 2022
    7.5
    High

    CVE-2022-21197

    Last Modified: 5 May 2025

    Improper input validation for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable denial of service via network access.

    Published: 18 Aug 2022
    8.8
    High

    CVE-2022-21139

    Last Modified: 5 May 2025

    Inadequate encryption strength for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 18 Aug 2022
    4.4
    Medium

    CVE-2022-21240

    Last Modified: 5 May 2025

    Out of bounds read for some Intel(R) PROSet/Wireless WiFi products may allow a privileged user to potentially enable information disclosure via local access.

    Published: 18 Aug 2022
    6.7
    Medium

    CVE-2022-21172

    Last Modified: 5 May 2025

    Out of bounds write for some Intel(R) PROSet/Wireless WiFi products may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 18 Aug 2022
    5.5
    Medium

    CVE-2021-26254

    Last Modified: 5 May 2025

    Out of bounds read for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable denial of service via local access.

    Published: 18 Aug 2022
    5.5
    Medium

    CVE-2021-44470

    Last Modified: 5 May 2025

    Incorrect default permissions for the Intel(R) Connect M Android application before version 1.7.4 may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 18 Aug 2022
    4.4
    Medium

    CVE-2022-28709

    Last Modified: 5 May 2025

    Improper access control in the firmware for some Intel(R) E810 Ethernet Controllers before version 1.6.1.9 may allow a privileged user to potentially enable denial of service via local access.

    Published: 18 Aug 2022
    4.4
    Medium

    CVE-2021-33128

    Last Modified: 5 May 2025

    Improper access control in the firmware for some Intel(R) E810 Ethernet Controllers before version 1.6.0.6 may allow a privileged user to potentially enable denial of service via local access.

    Published: 18 Aug 2022
    4.4
    Medium

    CVE-2021-33126

    Last Modified: 5 May 2025

    Improper access control in the firmware for some Intel(R) 700 and 722 Series Ethernet Controllers and Adapters before versions 8.5 and 1.5.5 may allow a privileged user to potentially enable denial of service via local access.

    Published: 18 Aug 2022
    8.8
    High

    CVE-2022-28757

    Last Modified: 21 Nov 2024

    The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.6 contains a vulnerability in the auto update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

    Published: 18 Aug 2022
    6.5
    Medium

    CVE-2022-37770

    Last Modified: 21 Nov 2024

    libjpeg commit 281daa9 was discovered to contain a segmentation fault via LineMerger::GetNextLowpassLine at linemerger.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.

    Published: 18 Aug 2022
    6.5
    Medium

    CVE-2022-37769

    Last Modified: 21 Nov 2024

    libjpeg commit 281daa9 was discovered to contain a segmentation fault via HuffmanDecoder::Get at huffmandecoder.hpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.

    Published: 18 Aug 2022
    7.5
    High

    CVE-2022-37768

    Last Modified: 21 Nov 2024

    libjpeg commit 281daa9 was discovered to contain an infinite loop via the component Frame::ParseTrailer.

    Published: 18 Aug 2022
    6.1
    Medium

    CVE-2022-35213

    Last Modified: 21 Nov 2024

    Ecommerce-CodeIgniter-Bootstrap before commit 56465f was discovered to contain a cross-site scripting (XSS) vulnerability via the function base_url() at /blog/blogpublish.php.

    Published: 18 Aug 2022
    6.1
    Medium

    CVE-2022-35212

    Last Modified: 21 Nov 2024

    osCommerce2 before v2.3.4.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the function tep_db_error().

    Published: 18 Aug 2022
    6.5
    Medium

    CVE-2022-25228

    Last Modified: 21 Nov 2024

    CandidATS Version 3.0.0 Beta allows an authenticated user to inject SQL queries in '/index.php?m=settings&a=show' via the 'userID' parameter, in '/index.php?m=candidates&a=show' via the 'candidateID', in '/index.php?m=joborders&a=show' via the 'jobOrderID' and '/index.php?m=companies&a=show' via the 'companyID' parameter

    Published: 18 Aug 2022
    —
    Unknown

    CVE-2020-27791

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 18 Aug 2022
    —
    Unknown

    CVE-2020-27789

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 18 Aug 2022
    5.5
    Medium

    CVE-2020-27788

    Last Modified: 11 Apr 2025

    An out-of-bounds read access vulnerability was discovered in UPX in PackLinuxElf64::canPack() function of p_lx_elf.cpp file. An attacker with a crafted input file could trigger this issue that could cause a crash leading to a denial of service.

    Published: 18 Aug 2022
    5.5
    Medium

    CVE-2020-27790

    Last Modified: 11 Apr 2025

    A floating point exception issue was discovered in UPX in PackLinuxElf64::invert_pt_dynamic() function of p_lx_elf.cpp file. An attacker with a crafted input file could trigger this issue that could cause a crash leading to a denial of service. The highest impact is to Availability.

    Published: 18 Aug 2022
    5.2
    Medium

    CVE-2022-35976

    Last Modified: 23 Apr 2025

    The GitOps Tools Extension for VSCode relies on kubeconfigs in order to communicate with Kubernetes clusters. A specially crafted kubeconfig leads to arbitrary code execution on behalf of the user running VSCode. Users relying on kubeconfigs that are generated or altered by other processes or users are affected by this issue. Please note that the vulnerability is specific to this extension, and the same kubeconfig would not result in arbitrary code execution when used with kubectl. Using only trust-worthy kubeconfigs is a safe mitigation. However, updating to the latest version of the extension is still highly recommended.

    Published: 18 Aug 2022
    5.5
    Medium

    CVE-2020-27787

    Last Modified: 11 Apr 2025

    A Segmentaation fault was found in UPX in invert_pt_dynamic() function in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service.

    Published: 18 Aug 2022
    4.3
    Medium

    CVE-2022-35204

    Last Modified: 21 Nov 2024

    Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service.

    Published: 18 Aug 2022
    9
    Critical

    CVE-2022-35975

    Last Modified: 23 Apr 2025

    The GitOps Tools Extension for VSCode can make it easier to manage Flux objects. A specially crafted Flux object may allow for remote code execution in the machine running the extension, in the context of the user that is running VSCode. Users using the VSCode extension to manage clusters that are shared amongst other users are affected by this issue. The only safe mitigation is to update to the latest version of the extension.

    Published: 18 Aug 2022
    9.8
    Critical

    CVE-2022-35175

    Last Modified: 21 Nov 2024

    Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /blotter/blotter.php.

    Published: 18 Aug 2022
    5.4
    Medium

    CVE-2022-35174

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in Kirby's Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tags field.

    Published: 18 Aug 2022
    5.4
    Medium

    CVE-2022-37063

    Last Modified: 17 Oct 2025

    All FLIR AX8 thermal sensor cameras versions up to and including 1.46.16 are vulnerable to Cross Site Scripting (XSS) due to improper input sanitization. An authenticated remote attacker can execute arbitrary JavaScript code in the web management interface. A successful exploit could allow the attacker to insert malicious JavaScript code. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.

    Published: 18 Aug 2022
    7.5
    High

    CVE-2022-37062

    Last Modified: 17 Oct 2025

    All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are affected by an insecure design vulnerability due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this by sending a URI that contains the path of the SQLite users database and download it. A successful exploit could allow the attacker to extract usernames and hashed passwords. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.

    Published: 18 Aug 2022
    7.5
    High

    CVE-2022-36024

    Last Modified: 23 Apr 2025

    py-cord is a an API wrapper for Discord written in Python. Bots creating using py-cord version 2.0.0 are vulnerable to remote shutdown if they are added to the server with the `application.commands` scope without the `bot` scope. Currently, it appears that all public bots that use slash commands are affected. This issue has been patched in version 2.0.1. There are currently no recommended workarounds - please upgrade to a patched version.

    Published: 18 Aug 2022
    7.8
    High

    CVE-2022-37025

    Last Modified: 21 Nov 2024

    An improper privilege management vulnerability in McAfee Security Scan Plus (MSS+) before 4.1.262.1 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack. This could result in the user gaining elevated permissions and being able to execute arbitrary code due to lack of an integrity check of the configuration file.

    Published: 18 Aug 2022
    7.3
    High

    CVE-2022-29549

    Last Modified: 21 Nov 2024

    An issue was discovered in Qualys Cloud Agent 4.8.0-49. It executes programs at various full pathnames without first making ownership and permission checks (e.g., to help ensure that a program was installed by root) and without integrity checks (e.g., a checksum comparison against known legitimate programs). Also, the vendor recommendation is to install this agent software with root privileges. Thus, privilege escalation is possible on systems where any of these pathnames is controlled by a non-root user. An example is /opt/firebird/bin/isql, where the /opt/firebird directory is often owned by the firebird user.

    Published: 18 Aug 2022
    5.5
    Medium

    CVE-2022-29550

    Last Modified: 21 Nov 2024

    An issue was discovered in Qualys Cloud Agent 4.8.0-49. It writes "ps auxwwe" output to the /var/log/qualys/qualys-cloud-agent-scan.log file. This may, for example, unexpectedly write credentials (from environment variables) to disk in cleartext. NOTE: there are no common circumstances in which qualys-cloud-agent-scan.log can be read by a user other than root; however, the file contents could be exposed through site-specific operational practices. The vendor does NOT characterize this as a vulnerability because the ps data collection is intentional, and would only capture credentials on a machine that was already affected by the CWE-214 weakness

    Published: 18 Aug 2022
    6.3
    Medium

    CVE-2022-2876

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, was found in SourceCodester Student Management System. Affected is an unknown function of the file index.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-206634 is the identifier assigned to this vulnerability.

    Published: 18 Aug 2022
    4.3
    Medium

    CVE-2022-33311

    Last Modified: 21 Nov 2024

    Browse restriction bypass vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Address Book via unspecified vectors.

    Published: 18 Aug 2022
    6.1
    Medium

    CVE-2022-33151

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows remote attackers to inject an arbitrary script via unspecified vectors.

    Published: 18 Aug 2022
    4.3
    Medium

    CVE-2022-32583

    Last Modified: 21 Nov 2024

    Operation restriction bypass vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to alter the data of Scheduler via unspecified vectors.

    Published: 18 Aug 2022
    4.3
    Medium

    CVE-2022-32544

    Last Modified: 21 Nov 2024

    Operation restriction bypass vulnerability in Project of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to alter the data of Project via unspecified vectors.

    Published: 18 Aug 2022
    6.5
    Medium

    CVE-2022-32453

    Last Modified: 21 Nov 2024

    HTTP header injection vulnerability in Cybozu Office 10.0.0 to 10.8.5 may allow a remote attacker to obtain and/or alter the data of the product via unspecified vectors.

    Published: 18 Aug 2022