CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2022-2785

    Last Modified: 14 Apr 2026

    There exists an arbitrary memory read within the Linux Kernel BPF - Constants provided to fill pointers in structs passed in to bpf_sys_bpf are not verified and can point anywhere, including memory not owned by BPF. An attacker with CAP_BPF can arbitrarily read memory from anywhere on the system. We recommend upgrading past commit 86f44fcec22c

    Published: 10 Aug 2022
    7.5
    High

    CVE-2021-37150

    Last Modified: 8 Sept 2025

    Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

    Published: 10 Aug 2022
    7.5
    High

    CVE-2022-28129

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

    Published: 10 Aug 2022
    7.5
    High

    CVE-2022-31778

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 8.0.0 to 9.0.2.

    Published: 10 Aug 2022
    7.5
    High

    CVE-2022-31780

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

    Published: 10 Aug 2022
    5.5
    Medium

    CVE-2022-4129

    Last Modified: 14 Apr 2025

    A flaw was found in the Linux kernel's Layer 2 Tunneling Protocol (L2TP). A missing lock when clearing sk_user_data can lead to a race condition and NULL pointer dereference. A local user could use this flaw to potentially crash the system causing a denial of service.

    Published: 10 Aug 2022
    9.8
    Critical

    CVE-2022-20361

    Last Modified: 27 Aug 2025

    In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth Standard. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-231161832

    Published: 9 Aug 2022
    7.8
    High

    CVE-2022-20360

    Last Modified: 20 Oct 2025

    In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228314987

    Published: 9 Aug 2022
    —
    Unknown

    CVE-2022-20359

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 9 Aug 2022
    3.3
    Low

    CVE-2022-20358

    Last Modified: 3 Sept 2025

    In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content providers due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-203229608

    Published: 9 Aug 2022
    5.5
    Medium

    CVE-2022-20357

    Last Modified: 21 Nov 2024

    In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-214999987

    Published: 9 Aug 2022
    7.8
    High

    CVE-2022-20356

    Last Modified: 8 Sept 2025

    In shouldAllowFgsWhileInUsePermissionLocked of ActiveServices.java, there is a possible way to start foreground service from background due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-215003903

    Published: 9 Aug 2022
    5.5
    Medium

    CVE-2022-20355

    Last Modified: 21 Nov 2024

    In get of PacProxyService.java, there is a possible system service crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-219498290

    Published: 9 Aug 2022
    7.8
    High

    CVE-2022-20354

    Last Modified: 21 Nov 2024

    In onDefaultNetworkChanged of Vpn.java, there is a possible way to disable VPN due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-219546241

    Published: 9 Aug 2022
    5.5
    Medium

    CVE-2022-20353

    Last Modified: 21 Nov 2024

    In onSaveRingtone of DefaultRingtonePreference.java, there is a possible inappropriate file read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-221041256

    Published: 9 Aug 2022
    5.5
    Medium

    CVE-2022-20352

    Last Modified: 21 Nov 2024

    In addProviderRequestListener of LocationManagerService.java, there is a possible way to learn which packages request location information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-222473855

    Published: 9 Aug 2022
    5.5
    Medium

    CVE-2022-20350

    Last Modified: 20 Oct 2025

    In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notification access to the wrong app due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228178437

    Published: 9 Aug 2022
    7.8
    High

    CVE-2022-20349

    Last Modified: 21 Nov 2024

    In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228315522

    Published: 9 Aug 2022
    7.8
    High

    CVE-2022-20348

    Last Modified: 21 Nov 2024

    In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228315529

    Published: 9 Aug 2022
    8.8
    High

    CVE-2022-20347

    Last Modified: 20 Oct 2025

    In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228450811

    Published: 9 Aug 2022
    6.5
    Medium

    CVE-2022-20346

    Last Modified: 20 Oct 2025

    In updateAudioTrackInfoFromESDS_MPEG4Audio of MPEG4Extractor.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-230493653

    Published: 9 Aug 2022
    8.8
    High

    CVE-2022-20345

    Last Modified: 20 Oct 2025

    In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-230494481

    Published: 9 Aug 2022
    7
    High

    CVE-2022-20344

    Last Modified: 21 Nov 2024

    In stealReceiveChannel of EventThread.cpp, there is a possible way to interfere with process communication due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-232541124

    Published: 9 Aug 2022
    9.8
    Critical

    CVE-2022-20239

    Last Modified: 20 Oct 2025

    remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also be controlled by userspace, so userspace may map the kernel area to be writable, which is easy to be exploitedProduct: AndroidVersions: Android SoCAndroid ID: A-233972091

    Published: 9 Aug 2022
    7.8
    High

    CVE-2021-39696

    Last Modified: 21 Nov 2024

    In Task.java, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-185810717

    Published: 9 Aug 2022
    5.9
    Medium

    CVE-2022-22983

    Last Modified: 21 Nov 2024

    VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious actor with local user privileges to the victim machine may exploit this vulnerability leading to the disclosure of user passwords of the remote server connected through VMware Workstation.

    Published: 9 Aug 2022
    8.8
    High

    CVE-2022-31673

    Last Modified: 8 Oct 2026

    VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can create and leak hex dumps, leading to information disclosure. Successful exploitation can lead to a remote code execution.

    Published: 9 Aug 2022
    4.3
    Medium

    CVE-2022-31674

    Last Modified: 27 Aug 2025

    VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can access log files that lead to information disclosure.

    Published: 9 Aug 2022
    7.5
    High

    CVE-2022-31675

    Last Modified: 21 Nov 2024

    VMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malicious actor with network access may be able to create a user with administrative privileges.

    Published: 9 Aug 2022
    7.2
    High

    CVE-2022-31672

    Last Modified: 27 Aug 2025

    VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network access can escalate privileges to root.

    Published: 9 Aug 2022
    6.5
    Medium

    CVE-2022-23238

    Last Modified: 21 Nov 2024

    Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less than 4.7.0 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to view limited metrics information and modify alert email recipients and content.

    Published: 9 Aug 2022
    10
    Critical

    CVE-2022-2634

    Last Modified: 16 Apr 2025

    An attacker may be able to execute malicious actions due to the lack of device access protections and device permissions when using the web application. This could lead to uploading python files which can be later executed.

    Published: 9 Aug 2022
    7.8
    High

    CVE-2022-30580

    Last Modified: 6 Mar 2026

    Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.

    Published: 9 Aug 2022
    6.8
    Medium

    CVE-2022-29083

    Last Modified: 14 Apr 2026

    Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain access to the system.

    Published: 9 Aug 2022
    8.2
    High

    CVE-2022-32245

    Last Modified: 21 Nov 2024

    SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attacker to retrieve sensitive information plain text over the network. On successful exploitation, the attacker can view any data available for a business user and put load on the application by an automated attack. Thus, completely compromising confidentiality but causing a limited impact on the availability of the application.

    Published: 9 Aug 2022
    9.1
    Critical

    CVE-2022-35293

    Last Modified: 23 Jun 2026

    Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, an attacker can view or modify user data causing limited impact on confidentiality and integrity of the application.

    Published: 9 Aug 2022
    8.8
    High

    CVE-2022-35827

    Last Modified: 2 Jan 2025

    Visual Studio Remote Code Execution Vulnerability

    Published: 9 Aug 2022
    7.5
    High

    CVE-2022-35290

    Last Modified: 9 Mar 2026

    Under certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be restricted.

    Published: 9 Aug 2022
    8.8
    High

    CVE-2022-35826

    Last Modified: 2 Jan 2025

    Visual Studio Remote Code Execution Vulnerability

    Published: 9 Aug 2022
    5.4
    Medium

    CVE-2022-35697

    Last Modified: 23 Apr 2025

    Adobe Experience Manager Core Components version 2.20.6 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires a low author privilege access.

    Published: 9 Aug 2022
    8.8
    High

    CVE-2022-35825

    Last Modified: 2 Jan 2025

    Visual Studio Remote Code Execution Vulnerability

    Published: 9 Aug 2022
    7.2
    High

    CVE-2022-35824

    Last Modified: 2 Jan 2025

    Azure Site Recovery Remote Code Execution Vulnerability

    Published: 9 Aug 2022
    4.4
    Medium

    CVE-2022-35821

    Last Modified: 2 Jan 2025

    Azure Sphere Information Disclosure Vulnerability

    Published: 9 Aug 2022
    7.8
    High

    CVE-2022-35820

    Last Modified: 2 Jan 2025

    Windows Bluetooth Driver Elevation of Privilege Vulnerability

    Published: 9 Aug 2022
    7.5
    High

    CVE-2022-37006

    Last Modified: 21 Nov 2024

    Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service availability.

    Published: 9 Aug 2022
    6.5
    Medium

    CVE-2022-35819

    Last Modified: 2 Jan 2025

    Azure Site Recovery Elevation of Privilege Vulnerability

    Published: 9 Aug 2022
    7.5
    High

    CVE-2021-40040

    Last Modified: 6 Mar 2026

    Vulnerability of writing data to an arbitrary address in the HW_KEYMASTER module. Successful exploitation of this vulnerability may affect confidentiality.

    Published: 9 Aug 2022
    6.5
    Medium

    CVE-2022-35818

    Last Modified: 2 Jan 2025

    Azure Site Recovery Elevation of Privilege Vulnerability

    Published: 9 Aug 2022
    7.5
    High

    CVE-2021-40030

    Last Modified: 6 Mar 2026

    The My HUAWEI app has a defect in the design. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 9 Aug 2022
    6.5
    Medium

    CVE-2022-35817

    Last Modified: 2 Jan 2025

    Azure Site Recovery Elevation of Privilege Vulnerability

    Published: 9 Aug 2022