CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2022-35306

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none

    Published: 11 Jul 2022
    —
    Unknown

    CVE-2022-35305

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none

    Published: 11 Jul 2022
    —
    Unknown

    CVE-2022-35304

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none

    Published: 11 Jul 2022
    —
    Unknown

    CVE-2022-35303

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none

    Published: 11 Jul 2022
    —
    Unknown

    CVE-2022-35302

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none

    Published: 11 Jul 2022
    —
    Unknown

    CVE-2022-35301

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none

    Published: 11 Jul 2022
    —
    Unknown

    CVE-2022-35300

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none

    Published: 11 Jul 2022
    9.1
    Critical

    CVE-2020-35169

    Last Modified: 21 Nov 2024

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Improper Input Validation Vulnerability.

    Published: 11 Jul 2022
    4.7
    Medium

    CVE-2020-35168

    Last Modified: 21 Nov 2024

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.

    Published: 11 Jul 2022
    4.8
    Medium

    CVE-2020-35167

    Last Modified: 21 Nov 2024

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.

    Published: 11 Jul 2022
    5.1
    Medium

    CVE-2020-35166

    Last Modified: 21 Nov 2024

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.

    Published: 11 Jul 2022
    6.7
    Medium

    CVE-2020-35164

    Last Modified: 21 Nov 2024

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.

    Published: 11 Jul 2022
    5.3
    Medium

    CVE-2020-35163

    Last Modified: 21 Nov 2024

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain a Use of Insufficiently Random Values Vulnerability.

    Published: 11 Jul 2022
    5.3
    Medium

    CVE-2020-29508

    Last Modified: 21 Nov 2024

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Input Validation Vulnerability.

    Published: 11 Jul 2022
    5.3
    Medium

    CVE-2020-29507

    Last Modified: 21 Nov 2024

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.4, and Dell BSAFE Micro Edition Suite, versions before 4.4, contain an Improper Input Validation Vulnerability.

    Published: 11 Jul 2022
    6.8
    Medium

    CVE-2020-29506

    Last Modified: 21 Nov 2024

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.

    Published: 11 Jul 2022
    7.1
    High

    CVE-2020-29505

    Last Modified: 21 Nov 2024

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain a Key Management Error Vulnerability.

    Published: 11 Jul 2022
    —
    Unknown

    CVE-2022-32951

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 11 Jul 2022
    5.9
    Medium

    CVE-2022-31139

    Last Modified: 23 Apr 2025

    UnsafeAccessor (UA) is a bridge to access jdk.internal.misc.Unsafe & sun.misc.Unsafe. Normally, if UA is loaded as a named module, the internal data of UA is protected by JVM and others can only access UA via UA's standard API. The main application can set up `SecurityCheck.AccessLimiter` for UA to limit access to UA. Starting with version 1.4.0 and prior to version 1.7.0, when `SecurityCheck.AccessLimiter` is set up, untrusted code can access UA without limitation, even when UA is loaded as a named module. This issue does not affect those for whom `SecurityCheck.AccessLimiter` is not set up. Version 1.7.0 contains a patch.

    Published: 11 Jul 2022
    6.1
    Medium

    CVE-2022-31904

    Last Modified: 21 Nov 2024

    EGT-Kommunikationstechnik UG Mediacenter before v2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Online_Update.php.

    Published: 11 Jul 2022
    9.8
    Critical

    CVE-2020-4150

    Last Modified: 21 Nov 2024

    IBM SiteProtector Appliance 3.1.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174142.

    Published: 11 Jul 2022
    5.5
    Medium

    CVE-2020-4138

    Last Modified: 21 Nov 2024

    IBM SiteProtector Appliance 3.1.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 174049.

    Published: 11 Jul 2022
    7.8
    High

    CVE-2021-36668

    Last Modified: 21 Nov 2024

    URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App.

    Published: 11 Jul 2022
    7.8
    High

    CVE-2021-36667

    Last Modified: 21 Nov 2024

    Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library.

    Published: 11 Jul 2022
    7.8
    High

    CVE-2021-36666

    Last Modified: 21 Nov 2024

    An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.

    Published: 11 Jul 2022
    7.8
    High

    CVE-2021-36665

    Last Modified: 21 Nov 2024

    An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.

    Published: 11 Jul 2022
    5.6
    Medium

    CVE-2022-2366

    Last Modified: 6 Dec 2024

    Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass some of the rate limitations in place or use manipulated IPs for audit logging via manipulating the request headers.

    Published: 11 Jul 2022
    8.8
    High

    CVE-2022-31138

    Last Modified: 22 Apr 2025

    mailcow is a mailserver suite. Prior to mailcow-dockerized version 2022-06a, an extended privilege vulnerability can be exploited by manipulating the custom parameters regexmess, skipmess, regexflag, delete2foldersonly, delete2foldersbutnot, regextrans2, pipemess, or maxlinelengthcmd to execute arbitrary code. Users should update their mailcow instances with the `update.sh` script in the mailcow root directory to 2022-06a or newer to receive a patch for this issue. As a temporary workaround, the Syncjob ACL can be removed from all mailbox users, preventing changes to those settings.

    Published: 11 Jul 2022
    7.5
    High

    CVE-2021-39999

    Last Modified: 21 Nov 2024

    There is a buffer overflow vulnerability in eSE620X vESS V100R001C10SPC200 and V100R001C20SPC200. An attacker can exploit this vulnerability by sending a specific message to the target device due to insufficient validation of packets. Successful exploit could cause a denial of service condition.

    Published: 11 Jul 2022
    6.5
    Medium

    CVE-2021-40016

    Last Modified: 21 Nov 2024

    Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will affect confidentiality.

    Published: 11 Jul 2022
    6.5
    Medium

    CVE-2021-40013

    Last Modified: 21 Nov 2024

    Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will affect integrity.

    Published: 11 Jul 2022
    7.5
    High

    CVE-2021-40012

    Last Modified: 21 Nov 2024

    Vulnerability of pointers being incorrectly used during data transmission in the video framework. Successful exploitation of this vulnerability may affect confidentiality.

    Published: 11 Jul 2022
    7.5
    High

    CVE-2022-34738

    Last Modified: 21 Nov 2024

    The SystemUI module has a vulnerability in permission control. If this vulnerability is successfully exploited, users are unaware of the service running in the background.

    Published: 11 Jul 2022
    9.1
    Critical

    CVE-2022-34737

    Last Modified: 21 Nov 2024

    The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may affect data integrity and confidentiality.

    Published: 11 Jul 2022
    7.5
    High

    CVE-2022-34742

    Last Modified: 21 Nov 2024

    The system module has a read/write vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 11 Jul 2022
    7.5
    High

    CVE-2022-34739

    Last Modified: 21 Nov 2024

    The fingerprint module has a vulnerability of overflow in arithmetic addition. Successful exploitation of this vulnerability may result in the acquisition of data from unknown addresses in address mappings.

    Published: 11 Jul 2022
    6.5
    Medium

    CVE-2022-34741

    Last Modified: 21 Nov 2024

    The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability may cause exceptions in NFC card registration, deletion, and activation.

    Published: 11 Jul 2022
    6.5
    Medium

    CVE-2022-34740

    Last Modified: 21 Nov 2024

    The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability may cause exceptions in NFC card registration, deletion, and activation.

    Published: 11 Jul 2022
    7.5
    High

    CVE-2022-34743

    Last Modified: 21 Nov 2024

    The AT commands of the USB port have an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability.

    Published: 11 Jul 2022
    7.5
    High

    CVE-2022-34736

    Last Modified: 21 Nov 2024

    The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.

    Published: 11 Jul 2022
    7.5
    High

    CVE-2022-34735

    Last Modified: 21 Nov 2024

    The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.

    Published: 11 Jul 2022
    7.5
    High

    CVE-2021-46741

    Last Modified: 21 Nov 2024

    The basic framework and setting module have defects, which were introduced during the design. Successful exploitation of this vulnerability may affect system integrity.

    Published: 11 Jul 2022
    5.3
    Medium

    CVE-2022-33707

    Last Modified: 21 Nov 2024

    Improper identifier creation logic in Find My Mobile prior to version 7.2.24.12 allows attacker to identify the device.

    Published: 11 Jul 2022
    3.3
    Low

    CVE-2022-33705

    Last Modified: 21 Nov 2024

    Information exposure in Calendar prior to version 12.3.05.10000 allows attacker to access calendar schedule without READ_CALENDAR permission.

    Published: 11 Jul 2022
    7.5
    High

    CVE-2022-33713

    Last Modified: 21 Nov 2024

    Implicit Intent hijacking vulnerability in Samsung Cloud prior to version 5.2.0 allows attacker to get sensitive information.

    Published: 11 Jul 2022
    2.4
    Low

    CVE-2022-33706

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Samsung Gallery prior to version 13.1.05.8 allows physical attackers to access the pictures using S Pen air gesture.

    Published: 11 Jul 2022
    5.5
    Medium

    CVE-2022-33711

    Last Modified: 21 Nov 2024

    Improper validation of integrity check vulnerability in Samsung USB Driver Windows Installer for Mobile Phones prior to version 1.7.56.0 allows local attackers to delete arbitrary directory using directory junction.

    Published: 11 Jul 2022
    5.3
    Medium

    CVE-2022-33712

    Last Modified: 21 Nov 2024

    Intent redirection vulnerability using implict intent in Camera prior to versions 12.0.01.64 ,12.0.3.23, 12.0.0.98, 12.0.6.11, 12.0.3.19 in Android S(12) allows attacker to get sensitive information.

    Published: 11 Jul 2022
    7.8
    High

    CVE-2022-33710

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in BillingPackageInsraller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.

    Published: 11 Jul 2022
    7.8
    High

    CVE-2022-33709

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.

    Published: 11 Jul 2022