CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2022-1498

    Last Modified: 21 Nov 2024

    Inappropriate implementation in HTML Parser in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 26 Jul 2022
    6.5
    Medium

    CVE-2022-1497

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Input in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to spoof the contents of cross-origin websites via a crafted HTML page.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-1496

    Last Modified: 21 Nov 2024

    Use after free in File Manager in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific and direct user interaction.

    Published: 26 Jul 2022
    4.3
    Medium

    CVE-2022-1495

    Last Modified: 21 Nov 2024

    Incorrect security UI in Downloads in Google Chrome on Android prior to 101.0.4951.41 allowed a remote attacker to spoof the APK downloads dialog via a crafted HTML page.

    Published: 26 Jul 2022
    6.1
    Medium

    CVE-2022-1494

    Last Modified: 21 Nov 2024

    Insufficient data validation in Trusted Types in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass trusted types policy via a crafted HTML page.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-1493

    Last Modified: 21 Nov 2024

    Use after free in Dev Tools in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific and direct user interaction.

    Published: 26 Jul 2022
    6.1
    Medium

    CVE-2022-1492

    Last Modified: 21 Nov 2024

    Insufficient data validation in Blink Editing in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to inject arbitrary scripts or HTML via a crafted HTML page.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-1491

    Last Modified: 21 Nov 2024

    Use after free in Bookmarks in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific and direct user interaction.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-1490

    Last Modified: 21 Nov 2024

    Use after free in Browser Switcher in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-1489

    Last Modified: 21 Nov 2024

    Out of bounds memory access in UI Shelf in Google Chrome on Chrome OS, Lacros prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific user interactions.

    Published: 26 Jul 2022
    4.3
    Medium

    CVE-2022-1488

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Extensions API in Google Chrome prior to 101.0.4951.41 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension.

    Published: 26 Jul 2022
    7.5
    High

    CVE-2022-1487

    Last Modified: 21 Nov 2024

    Use after free in Ozone in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via running a Wayland test.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-1486

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 26 Jul 2022
    7.5
    High

    CVE-2022-1485

    Last Modified: 21 Nov 2024

    Use after free in File System API in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-1484

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Web UI Settings in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-1483

    Last Modified: 21 Nov 2024

    Heap buffer overflow in WebGPU in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Jul 2022
    6.5
    Medium

    CVE-2022-1482

    Last Modified: 21 Nov 2024

    Inappropriate implementation in WebGL in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-1481

    Last Modified: 21 Nov 2024

    Use after free in Sharing in Google Chrome on Mac prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-1479

    Last Modified: 21 Nov 2024

    Use after free in ANGLE in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-1478

    Last Modified: 21 Nov 2024

    Use after free in SwiftShader in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-1477

    Last Modified: 21 Nov 2024

    Use after free in Vulkan in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-1364

    Last Modified: 24 Oct 2025

    Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Jul 2022
    9.8
    Critical

    CVE-2022-31207

    Last Modified: 21 Nov 2024

    The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic authentication. They utilize the Omron FINS (9600/TCP) protocol for engineering purposes, including downloading projects and control logic to the PLC. This protocol has authentication flaws as reported in FSCT-2022-0057. Control logic is downloaded to PLC volatile memory using the FINS Program Area Read and Program Area Write commands or to non-volatile memory using other commands from where it can be loaded into volatile memory for execution. The logic that is loaded into and executed from the user program area exists in compiled object code form. Upon execution, these object codes are first passed to a dedicated ASIC that determines whether the object code is to be executed by the ASIC or the microprocessor. In the former case, the object code is interpreted by the ASIC whereas in the latter case the object code is passed to the microprocessor for object code interpretation by a ROM interpreter. In the abnormal case where the object code cannot be handled by either, an abnormal condition is triggered and the PLC is halted. The logic that is downloaded to the PLC does not seem to be cryptographically authenticated, thus allowing an attacker to manipulate transmitted object code to the PLC and either execute arbitrary object code commands on the ASIC or on the microprocessor interpreter.

    Published: 26 Jul 2022
    7.5
    High

    CVE-2022-31205

    Last Modified: 21 Nov 2024

    In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further authentication.

    Published: 26 Jul 2022
    9.8
    Critical

    CVE-2022-31206

    Last Modified: 21 Nov 2024

    The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryptographic authentication. These PLCs are programmed using the SYMAC Studio engineering software (which compiles IEC 61131-3 conformant POU code to native machine code for execution by the PLC's runtime). The resulting machine code is executed by a runtime, typically controlled by a real-time operating system. The logic that is downloaded to the PLC does not seem to be cryptographically authenticated, allowing an attacker to manipulate transmitted object code to the PLC and execute arbitrary machine code on the processor of the PLC's CPU module in the context of the runtime. In the case of at least the NJ series, an RTOS and hardware combination is used that would potentially allow for memory protection and privilege separation and thus limit the impact of code execution. However, it was not confirmed whether these sufficiently segment the runtime from the rest of the RTOS.

    Published: 26 Jul 2022
    7.5
    High

    CVE-2022-31204

    Last Modified: 21 Nov 2024

    Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection setting that allows users or system integrators to configure a password in order to restrict sensitive engineering operations (such as project/logic uploads and downloads). This password is set using the OMRON FINS command Program Area Protect and unset using the command Program Area Protect Clear, both of which are transmitted in cleartext.

    Published: 26 Jul 2022
    7.5
    High

    CVE-2022-30275

    Last Modified: 21 Nov 2024

    The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext password. It utilizes an MDLC driver to communicate with MOSCAD/ACE RTUs for engineering purposes. Access to these communications is protected by a password stored in cleartext in the wmdlcdrv.ini driver configuration file. In addition, this password is used for access control to MOSCAD/STS projects protected with the Legacy Password feature. In this case, an insecure CRC of the password is present in the project file: this CRC is validated against the password in the driver configuration file.

    Published: 26 Jul 2022
    9.8
    Critical

    CVE-2022-30273

    Last Modified: 21 Nov 2024

    The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Legacy Encryption, and New Encryption. In Legacy Encryption mode, traffic is encrypted via the Tiny Encryption Algorithm (TEA) block-cipher in ECB mode. This mode of operation does not offer message integrity and offers reduced confidentiality above the block level, as demonstrated by an ECB Penguin attack against any block ciphers.

    Published: 26 Jul 2022
    7.8
    High

    CVE-2022-29957

    Last Modified: 21 Nov 2024

    The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wide variety of functionality. These protocols include Firmware upgrade (18508/TCP, 18518/TCP); Plug-and-Play (18510/UDP); Hawk services (18507/UDP); Management (18519/TCP); Cold restart (18512/UDP); SIS communications (12345/TCP); and Wireless Gateway Protocol (18515/UDP). None of these protocols have any authentication features, allowing any attacker capable of communicating with the ports in question to invoke (a subset of) desired functionality.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2022-29960

    Last Modified: 21 Nov 2024

    Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES with hardcoded cryptographic keys is used for protection of certain system credentials, engineering files, and sensitive utilities.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2022-29962

    Last Modified: 21 Nov 2024

    The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2022-29964

    Last Modified: 21 Nov 2024

    The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell as root, DeltaV, or backup via hardcoded credentials. NOTE: this is different from CVE-2014-2350.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2022-29963

    Last Modified: 21 Nov 2024

    The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides access to a root shell via hardcoded credentials. This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2022-29965

    Last Modified: 21 Nov 2024

    The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on the maintenance port TELNET interface (23/TCP) on M-series and SIS (CSLS/LSNB/LSNG) nodes is controlled by means of utility passwords. These passwords are generated using a deterministic, insecure algorithm using a single seed value composed of a day/hour/minute timestamp with less than 16 bits of entropy. The seed value is fed through a lookup table and a series of permutation operations resulting in three different four-character passwords corresponding to different privilege levels. An attacker can easily reconstruct these passwords and thus gain access to privileged maintenance operations. NOTE: this is different from CVE-2014-2350.

    Published: 26 Jul 2022
    —
    Unknown

    CVE-2022-36827

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Jul 2022
    —
    Unknown

    CVE-2022-36816

    Last Modified: 15 Nov 2023

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 26 Jul 2022
    5.4
    Medium

    CVE-2022-27105

    Last Modified: 21 Nov 2024

    InMailX Outlook Plugin < 3.22.0101 is vulnerable to Cross Site Scripting (XSS). InMailX Connection names are not sanitzed in the Outlook tab, which allows a local user or network administrator to execute HTML / Javascript in the Outlook of users.

    Published: 26 Jul 2022
    9.1
    Critical

    CVE-2022-29951

    Last Modified: 21 Nov 2024

    JTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication. They utilize the CMPLink/TCP protocol (configurable on ports 1024-65534 on either TCP or UDP) for a wide variety of engineering purposes such as starting and stopping the PLC, downloading and uploading projects, and changing configuration settings. This protocol does not have any authentication features, allowing any attacker capable of communicating with the port in question to invoke (a subset of) desired functionality.

    Published: 26 Jul 2022
    9.8
    Critical

    CVE-2022-29958

    Last Modified: 21 Nov 2024

    JTEKT TOYOPUC PLCs through 2022-04-29 do not ensure data integrity. They utilize the unauthenticated CMPLink/TCP protocol for engineering purposes, including downloading projects and control logic to the PLC. Control logic is downloaded to the PLC on a block-by-block basis with a given memory address and a blob of machine code. The logic that is downloaded to the PLC is not cryptographically authenticated, allowing an attacker to execute arbitrary machine code on the PLC's CPU module in the context of the runtime. In the case of the PC10G-CPU, and likely for other CPU modules of the TOYOPUC family, a processor without MPU or MMU is used and this no memory protection or privilege-separation capabilities are available, giving an attacker full control over the CPU.

    Published: 26 Jul 2022
    7.5
    High

    CVE-2022-35639

    Last Modified: 21 Nov 2024

    IBM Sterling Partner Engagement Manager 6.1, 6.2, and Cloud 22.2 do not limit the length of a connection which could cause the server to become unresponsive. IBM X-Force ID: 230932.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-35286

    Last Modified: 21 Nov 2024

    IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230814.

    Published: 26 Jul 2022
    4.6
    Medium

    CVE-2022-22412

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user with access to the local host (client machine) to obtain a login access token. IBM X-Force ID: 223019.

    Published: 26 Jul 2022
    5.7
    Medium

    CVE-2022-1648

    Last Modified: 21 Nov 2024

    Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. The impact could lead to a Remote Code Execution with running application privilege.

    Published: 26 Jul 2022
    9.8
    Critical

    CVE-2022-36412

    Last Modified: 21 Nov 2024

    In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)

    Published: 26 Jul 2022
    5.4
    Medium

    CVE-2022-34988

    Last Modified: 21 Nov 2024

    Inout Blockchain AltExchanger v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/js.

    Published: 26 Jul 2022
    5.4
    Medium

    CVE-2022-34991

    Last Modified: 21 Nov 2024

    Paymoney v3.3 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the first_name and last_name parameters.

    Published: 26 Jul 2022
    9.8
    Critical

    CVE-2022-34989

    Last Modified: 21 Nov 2024

    Fruits Bazar v1.0 was discovered to contain a SQL injection vulnerability via the recover_email parameter at user_password_recover.php.

    Published: 26 Jul 2022
    9.8
    Critical

    CVE-2022-36161

    Last Modified: 21 Nov 2024

    Orange Station 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.

    Published: 26 Jul 2022
    7.5
    High

    CVE-2022-34067

    Last Modified: 24 Feb 2025

    Warehouse Management System v1.0 was discovered to contain a SQL injection vulnerability via the cari parameter.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-31879

    Last Modified: 21 Nov 2024

    Online Fire Reporting System 1.0 is vulnerable to SQL Injection via the date parameter.

    Published: 26 Jul 2022