CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-2816

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0212.

    Published: 12 Aug 2022
    6.5
    Medium

    CVE-2022-38183

    Last Modified: 21 Nov 2024

    In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any issue to any project in Gitea (there was no permission check for fetching the issue). As a result, the attacker would get access to private issue titles.

    Published: 12 Aug 2022
    6.9
    Medium

    CVE-2022-2503

    Last Modified: 21 Apr 2025

    Dm-verity is used for extending root-of-trust to root filesystems. LoadPin builds on this property to restrict module/firmware loads to just the trusted root filesystem. Device-mapper table reloads currently allow users with root privileges to switch out the target with an equivalent dm-linear target and bypass verification till reboot. This allows root to bypass LoadPin and can be used to load untrusted and unverified kernel modules and firmware, which implies arbitrary kernel execution and persistence for peripherals that do not verify firmware updates. We recommend upgrading past commit 4caae58406f8ceb741603eee460d79bacca9b1b5

    Published: 12 Aug 2022
    7.8
    High

    CVE-2022-2817

    Last Modified: 21 Nov 2024

    Use After Free in GitHub repository vim/vim prior to 9.0.0213.

    Published: 12 Aug 2022
    6.1
    Medium

    CVE-2022-37044

    Last Modified: 21 Nov 2024

    In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/search?action accepts parameters called extra, title, and onload that are partially sanitised and lead to reflected XSS that allows executing arbitrary JavaScript on the victim's machine.

    Published: 11 Aug 2022
    5.7
    Medium

    CVE-2022-37043

    Last Modified: 21 Nov 2024

    An issue was discovered in the webmail component in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. When using preauth, CSRF tokens are not checked on some POST endpoints. Thus, when an authenticated user views an attacker-controlled page, a request will be sent to the application that appears to be intended. The CSRF token is omitted from the request, but the request still succeeds.

    Published: 11 Aug 2022
    9.8
    Critical

    CVE-2022-37042

    Last Modified: 4 Nov 2025

    Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.

    Published: 11 Aug 2022
    7.5
    High

    CVE-2022-37041

    Last Modified: 21 Nov 2024

    An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. The value of the X-Forwarded-Host header overwrites the value of the Host header in proxied requests. The value of X-Forwarded-Host header is not checked against the whitelist of hosts that ZCS is allowed to proxy to (the zimbraProxyAllowedDomains setting).

    Published: 11 Aug 2022
    6.7
    Medium

    CVE-2022-28634

    Last Modified: 21 Nov 2024

    A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. A highly privileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality, integrity, and availability. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).

    Published: 11 Aug 2022
    7.3
    High

    CVE-2022-28633

    Last Modified: 21 Nov 2024

    A local disclosure of sensitive information and a local unauthorized data modification vulnerability were discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could locally exploit this vulnerability to read and write to the iLO 5 firmware file system resulting in a complete loss of confidentiality and a partial loss of integrity and availability. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).

    Published: 11 Aug 2022
    7.4
    High

    CVE-2022-28635

    Last Modified: 21 Nov 2024

    A potential local arbitrary code execution and a local denial of service (DoS) vulnerability within an isolated process were discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could locally exploit this vulnerability to potentially execute arbitrary code in an isolated process resulting in a complete loss of confidentiality, integrity, and availability within that process. In addition, an unprivileged user could exploit a denial of service (DoS) vulnerability in an isolated process resulting in a complete loss of availability within that process. A successful attack depends on conditions beyond the attackers control. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).

    Published: 11 Aug 2022
    7.4
    High

    CVE-2022-28636

    Last Modified: 21 Nov 2024

    A potential local arbitrary code execution and a local denial of service (DoS) vulnerability within an isolated process were discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could locally exploit this vulnerability to potentially execute arbitrary code in an isolated process resulting in a complete loss of confidentiality, integrity, and availability within that process. In addition, an unprivileged user could exploit a denial of service (DoS) vulnerability in an isolated process resulting in a complete loss of availability within that process. A successful attack depends on conditions beyond the attackers control. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).

    Published: 11 Aug 2022
    8.8
    High

    CVE-2022-28632

    Last Modified: 21 Nov 2024

    A potential arbitrary code execution and a denial of service (DoS) vulnerability within an isolated process were discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could exploit this vulnerability in an adjacent network to potentially execute arbitrary code in an isolated process resulting in a complete loss of confidentiality, integrity, and availability within that process. In addition, an unprivileged user could exploit a denial of service (DoS) vulnerability in an isolated process resulting in a complete loss of availability within that process. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).

    Published: 11 Aug 2022
    8.8
    High

    CVE-2022-28631

    Last Modified: 21 Nov 2024

    A potential arbitrary code execution and a denial of service (DoS) vulnerability within an isolated process were discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could exploit this vulnerability in an adjacent network to potentially execute arbitrary code in an isolated process resulting in a complete loss of confidentiality, integrity, and availability within that process. In addition, an unprivileged user could exploit a denial of service (DoS) vulnerability in an isolated process resulting in a complete loss of availability within that process. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).

    Published: 11 Aug 2022
    7.3
    High

    CVE-2022-28630

    Last Modified: 21 Nov 2024

    A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality and integrity, and a partial loss of availability. User interaction is required to exploit this vulnerability. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).

    Published: 11 Aug 2022
    7.8
    High

    CVE-2022-28629

    Last Modified: 21 Nov 2024

    A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. A low privileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality, integrity, and availability. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).

    Published: 11 Aug 2022
    8.4
    High

    CVE-2022-28627

    Last Modified: 21 Nov 2024

    A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality, integrity, and availability. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).

    Published: 11 Aug 2022
    8.4
    High

    CVE-2022-28628

    Last Modified: 21 Nov 2024

    A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality, integrity, and availability. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).

    Published: 11 Aug 2022
    6.7
    Medium

    CVE-2022-28626

    Last Modified: 21 Nov 2024

    A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. A highly privileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality, integrity, and availability. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).

    Published: 11 Aug 2022
    7.5
    High

    CVE-2022-35561

    Last Modified: 21 Nov 2024

    A stack overflow vulnerability exists in /goform/WifiMacFilterSet in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter.

    Published: 11 Aug 2022
    7.5
    High

    CVE-2022-35560

    Last Modified: 21 Nov 2024

    A stack overflow vulnerability exists in /goform/wifiSSIDset in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter.

    Published: 11 Aug 2022
    9.8
    Critical

    CVE-2022-35559

    Last Modified: 21 Nov 2024

    A stack overflow vulnerability exists in /goform/setAutoPing in Tenda W6 V1.0.0.9(4122), which allows an attacker to construct ping1 parameters and ping2 parameters for a stack overflow attack. An attacker can use this vulnerability to execute arbitrary code execution.

    Published: 11 Aug 2022
    7.5
    High

    CVE-2022-35558

    Last Modified: 21 Nov 2024

    A stack overflow vulnerability exists in /goform/WifiMacFilterGet in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter.

    Published: 11 Aug 2022
    7.5
    High

    CVE-2022-35557

    Last Modified: 21 Nov 2024

    A stack overflow vulnerability exists in /goform/wifiSSIDget in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter.

    Published: 11 Aug 2022
    9.8
    Critical

    CVE-2022-35555

    Last Modified: 21 Nov 2024

    A command injection vulnerability exists in /goform/exeCommand in Tenda W6 V1.0.0.9(4122), which allows attackers to construct cmdinput parameters for arbitrary command execution.

    Published: 11 Aug 2022
    7.2
    High

    CVE-2021-44720

    Last Modified: 21 Nov 2024

    In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targets.cgi screen. A read-only administrative user can escalate to a read-write administrative role.

    Published: 11 Aug 2022
    8.8
    High

    CVE-2022-20362

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-230756082

    Published: 11 Aug 2022
    3.3
    Low

    CVE-2022-20342

    Last Modified: 21 Nov 2024

    In WiFi, there is a possible disclosure of WiFi password to the end user due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-143534321

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20341

    Last Modified: 21 Nov 2024

    In ConnectivityService, there is a possible bypass of network permissions due to a missing permission check. This could lead to local information disclosure of tethering interfaces with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-162952629

    Published: 11 Aug 2022
    3.3
    Low

    CVE-2022-20340

    Last Modified: 21 Nov 2024

    In SELinux policy, there is a possible way of inferring which websites are being opened in the browser due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-166269532

    Published: 11 Aug 2022
    3.3
    Low

    CVE-2022-20339

    Last Modified: 21 Nov 2024

    In Android, there is a possible access of network neighbor table information due to an insecure SEpolicy configuration. This could lead to local information disclosure of network topography with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-171572148

    Published: 11 Aug 2022
    3.3
    Low

    CVE-2022-20336

    Last Modified: 21 Nov 2024

    In Settings, there is a possible installed application disclosure due to a missing permission check. This could lead to local information disclosure of applications allow-listed to use the network during VPN lockdown mode with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-177239688

    Published: 11 Aug 2022
    3.3
    Low

    CVE-2022-20335

    Last Modified: 21 Nov 2024

    In Wifi Slice, there is a possible way to adjust Wi-Fi settings even when the permission has been disabled due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-178014725

    Published: 11 Aug 2022
    6.5
    Medium

    CVE-2022-20334

    Last Modified: 21 Nov 2024

    In Bluetooth, there are possible process crashes due to dereferencing a null pointer. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-178800552

    Published: 11 Aug 2022
    6.5
    Medium

    CVE-2022-20333

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-179161657

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20332

    Last Modified: 21 Nov 2024

    In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-180019130

    Published: 11 Aug 2022
    7.8
    High

    CVE-2022-20331

    Last Modified: 21 Nov 2024

    In the Framework, there is a possible way to enable a work profile without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-181785557

    Published: 11 Aug 2022
    3.5
    Low

    CVE-2022-20330

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible way to connect or disconnect bluetooth devices without user awareness due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-181962588

    Published: 11 Aug 2022
    7.8
    High

    CVE-2022-20329

    Last Modified: 21 Nov 2024

    In Wifi, there is a possible way to enable Wifi without permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-183410556

    Published: 11 Aug 2022
    3.3
    Low

    CVE-2022-20328

    Last Modified: 21 Nov 2024

    In PackageManager, there is a possible way to determine whether an app is installed due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-184948501

    Published: 11 Aug 2022
    2.8
    Low

    CVE-2022-20327

    Last Modified: 21 Nov 2024

    In Wi-Fi, there is a possible way to retrieve the WiFi SSID without location permissions due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-185126813

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20326

    Last Modified: 21 Nov 2024

    In Telephony, there is a possible disclosure of SIM identifiers due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-185235527

    Published: 11 Aug 2022
    7.8
    High

    CVE-2022-20325

    Last Modified: 21 Nov 2024

    In Media, there is a possible code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-186473060

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20324

    Last Modified: 21 Nov 2024

    In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-187042120

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20323

    Last Modified: 21 Nov 2024

    In PackageManager, there is a possible package installation disclosure due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-187176203

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20322

    Last Modified: 21 Nov 2024

    In PackageManager, there is a possible installed package disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-187176993

    Published: 11 Aug 2022
    3.3
    Low

    CVE-2022-20321

    Last Modified: 21 Nov 2024

    In Settings, there is a possible way for an application without permissions to read content of WiFi QR codes due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-187176859

    Published: 11 Aug 2022
    3.3
    Low

    CVE-2022-20320

    Last Modified: 21 Nov 2024

    In ActivityManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-187956596

    Published: 11 Aug 2022
    7.8
    High

    CVE-2022-20319

    Last Modified: 21 Nov 2024

    In DreamServices, there is a possible way to launch arbitrary protected activities due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-189574230

    Published: 11 Aug 2022
    3.3
    Low

    CVE-2022-20318

    Last Modified: 21 Nov 2024

    In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-194694069

    Published: 11 Aug 2022