CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2022-36364

    Last Modified: 21 Nov 2024

    Apache Calcite Avatica JDBC driver creates HTTP client instances based on class names provided via `httpclient_impl` connection property; however, the driver does not verify if the class implements the expected interface before instantiating it, which can lead to code execution loaded via arbitrary classes and in rare cases remote code execution. To exploit the vulnerability: 1) the attacker needs to have privileges to control JDBC connection parameters; 2) and there should be a vulnerable class (constructor with URL parameter and ability to execute code) in the classpath. From Apache Calcite Avatica 1.22.0 onwards, it will be verified that the class implements the expected interface before invoking its constructor.

    Published: 28 Jul 2022
    5.4
    Medium

    CVE-2022-27611

    Last Modified: 21 Nov 2024

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Audio Station before 6.5.4-3367 allows remote authenticated users to delete arbitrary files via unspecified vectors.

    Published: 28 Jul 2022
    7.3
    High

    CVE-2022-27612

    Last Modified: 21 Nov 2024

    Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Audio Station before 6.5.4-3367 allows remote attackers to execute arbitrary commands via unspecified vectors.

    Published: 28 Jul 2022
    10
    Critical

    CVE-2022-22683

    Last Modified: 14 Jan 2025

    Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 28 Jul 2022
    5.3
    Medium

    CVE-2022-27614

    Last Modified: 14 Jan 2025

    Exposure of sensitive information to an unauthorized actor vulnerability in web server in Synology Media Server before 1.8.1-2876 allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 28 Jul 2022
    8.7
    High

    CVE-2022-22685

    Last Modified: 21 Nov 2024

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology WebDAV Server before 2.4.0-0062 allows remote authenticated users to delete arbitrary files via unspecified vectors.

    Published: 28 Jul 2022
    8.3
    High

    CVE-2022-27613

    Last Modified: 21 Nov 2024

    Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in webapi component in Synology CardDAV Server before 6.0.10-0153 allows remote authenticated users to inject SQL commands via unspecified vectors.

    Published: 28 Jul 2022
    7.2
    High

    CVE-2022-22684

    Last Modified: 14 Jan 2025

    Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in task management component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows remote authenticated users to execute arbitrary commands via unspecified vectors.

    Published: 28 Jul 2022
    7.7
    High

    CVE-2022-27615

    Last Modified: 21 Nov 2024

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology DNS Server before 2.2.2-5027 allows remote authenticated users to delete arbitrary files via unspecified vectors.

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2022-36393

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2022-36421

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2022-34653

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2022-33145

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2022-36792

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 28 Jul 2022
    —
    Unknown

    CVE-2022-36366

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-2296

    Last Modified: 21 Nov 2024

    Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 103.0.5060.114 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via direct UI interactions.

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-2295

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-2163

    Last Modified: 21 Nov 2024

    Use after free in Cast UI and Toolbar in Google Chrome prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via UI interaction.

    Published: 28 Jul 2022
    7.7
    High

    CVE-2022-36984

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger a denial of service attack against a NetBackup Primary server.

    Published: 28 Jul 2022
    7.8
    High

    CVE-2022-36985

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with unprivileged local access to a Windows NetBackup Primary server could potentially escalate their privileges.

    Published: 28 Jul 2022
    8.6
    High

    CVE-2022-36986

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with unauthenticated access could remotely execute arbitrary commands on a NetBackup Primary server.

    Published: 28 Jul 2022
    8.5
    High

    CVE-2022-36987

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could arbitrarily write files to a NetBackup Primary server.

    Published: 28 Jul 2022
    8
    High

    CVE-2022-36988

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup OpsCenter server, NetBackup Primary server, or NetBackup Media server could remotely execute arbitrary commands on a NetBackup Primary server or NetBackup Media server.

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-36989

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely execute arbitrary commands on a NetBackup Primary server.

    Published: 28 Jul 2022
    9.6
    Critical

    CVE-2022-36990

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely write arbitrary files to arbitrary locations from any Client to any other Client via a Primary server.

    Published: 28 Jul 2022
    8.1
    High

    CVE-2022-36991

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could arbitrarily write content to a partially controlled path on a NetBackup Primary server.

    Published: 28 Jul 2022
    9.9
    Critical

    CVE-2022-36992

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely execute arbitrary commands on a NetBackup Primary server (in specific notify conditions).

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-36993

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely execute arbitrary commands on a NetBackup Primary server.

    Published: 28 Jul 2022
    6.3
    Medium

    CVE-2022-36994

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could arbitrarily read files from a NetBackup Primary server.

    Published: 28 Jul 2022
    4.3
    Medium

    CVE-2022-36995

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could arbitrarily create directories on a NetBackup Primary server.

    Published: 28 Jul 2022
    4.3
    Medium

    CVE-2022-36996

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with access to a NetBackup Client could remotely gather information about any host known to a NetBackup Primary server.

    Published: 28 Jul 2022
    7.1
    High

    CVE-2022-36997

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger impacts that include arbitrary file read, Server-Side Request Forgery (SSRF), and denial of service.

    Published: 28 Jul 2022
    6.3
    Medium

    CVE-2022-36998

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger a stack-based buffer overflow on the NetBackup Primary server, resulting in a denial of service.

    Published: 28 Jul 2022
    6.5
    Medium

    CVE-2022-36999

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). Under certain conditions, an attacker with authenticated access to a NetBackup Client could remotely read files on a NetBackup Primary server.

    Published: 28 Jul 2022
    6.5
    Medium

    CVE-2022-37000

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). Under certain conditions, an attacker with authenticated access to a NetBackup Client could remotely read files on a NetBackup Primary server.

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-2415

    Last Modified: 21 Nov 2024

    Heap buffer overflow in WebGL in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 28 Jul 2022
    4.3
    Medium

    CVE-2022-2165

    Last Modified: 21 Nov 2024

    Insufficient data validation in URL formatting in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

    Published: 28 Jul 2022
    6.3
    Medium

    CVE-2022-2164

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Extensions API in Google Chrome prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted HTML page.

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-2162

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 103.0.5060.53 allowed a remote attacker to bypass file system access via a crafted HTML page.

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-2161

    Last Modified: 21 Nov 2024

    Use after free in WebApp Provider in Google Chrome prior to 103.0.5060.53 allowed a remote attacker who convinced the user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.

    Published: 28 Jul 2022
    6.5
    Medium

    CVE-2022-2160

    Last Modified: 2 Jun 2026

    Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from a user's local files via a crafted HTML page.

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-2158

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-2157

    Last Modified: 21 Nov 2024

    Use after free in Interest groups in Google Chrome prior to 103.0.5060.53 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-2156

    Last Modified: 21 Nov 2024

    Use after free in Core in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-2011

    Last Modified: 21 Nov 2024

    Use after free in ANGLE in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 28 Jul 2022
    9.3
    Critical

    CVE-2022-2010

    Last Modified: 21 Nov 2024

    Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-2008

    Last Modified: 21 Nov 2024

    Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-2007

    Last Modified: 21 Nov 2024

    Use after free in WebGPU in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 28 Jul 2022
    6.5
    Medium

    CVE-2022-37052

    Last Modified: 3 Nov 2025

    A reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject.

    Published: 28 Jul 2022
    6.5
    Medium

    CVE-2022-37051

    Last Modified: 3 Nov 2025

    An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving an embedded file.

    Published: 28 Jul 2022