CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-33708

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in AppsPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.

    Published: 11 Jul 2022
    8.5
    High

    CVE-2022-33704

    Last Modified: 21 Nov 2024

    Improper validation vulnerability in ucmRetParcelable of KnoxSDK prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.

    Published: 11 Jul 2022
    8.5
    High

    CVE-2022-33703

    Last Modified: 21 Nov 2024

    Improper validation vulnerability in CACertificateInfo prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.

    Published: 11 Jul 2022
    6.2
    Medium

    CVE-2022-33702

    Last Modified: 21 Nov 2024

    Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass Knoxguard lock by factory reset.

    Published: 11 Jul 2022
    3.3
    Low

    CVE-2022-33701

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in KnoxCustomManagerService prior to SMR Jul-2022 Release 1 allows attacker to call PowerManaer.goToSleep method which is protected by system permission by sending braodcast intent.

    Published: 11 Jul 2022
    2
    Low

    CVE-2022-33700

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information in putDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.

    Published: 11 Jul 2022
    2
    Low

    CVE-2022-33699

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.

    Published: 11 Jul 2022
    3.3
    Low

    CVE-2022-33698

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information in Telecom application prior to SMR Jul-2022 Release 1 allows local attackers to access ICCID via log.

    Published: 11 Jul 2022
    3.3
    Low

    CVE-2022-33697

    Last Modified: 21 Nov 2024

    Sensitive information exposure vulnerability in ImsServiceSwitchBase in ImsCore prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.

    Published: 11 Jul 2022
    4
    Medium

    CVE-2022-33696

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information in Telephony service prior to SMR Jul-2022 Release 1 allows local attacker to access imsi and iccid via log.

    Published: 11 Jul 2022
    5.1
    Medium

    CVE-2022-33695

    Last Modified: 21 Nov 2024

    Use of improper permission in InputManagerService prior to SMR Jul-2022 Release 1 allows unauthorized access to the service.

    Published: 11 Jul 2022
    4
    Medium

    CVE-2022-33694

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information in CSC application prior to SMR Jul-2022 Release 1 allows local attacker to access wifi information via unprotected intent broadcasting.

    Published: 11 Jul 2022
    2
    Low

    CVE-2022-33693

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information in CID Manager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.

    Published: 11 Jul 2022
    4
    Medium

    CVE-2022-33692

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information in Messaging application prior to SMR Jul-2022 Release 1 allows local attacker to access imsi and iccid via log.

    Published: 11 Jul 2022
    6.2
    Medium

    CVE-2022-33691

    Last Modified: 21 Nov 2024

    A possible race condition vulnerability in score driver prior to SMR Jul-2022 Release 1 can allow local attackers to interleave malicious operations.

    Published: 11 Jul 2022
    4
    Medium

    CVE-2022-33690

    Last Modified: 21 Nov 2024

    Improper input validation in Contacts Storage prior to SMR Jul-2022 Release 1 allows attacker to access arbitrary file.

    Published: 11 Jul 2022
    6.2
    Medium

    CVE-2022-33689

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferred network type by unprotected binder call.

    Published: 11 Jul 2022
    3.3
    Low

    CVE-2022-33688

    Last Modified: 21 Nov 2024

    Sensitive information exposure vulnerability in EventType in SecTelephonyProvider prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.

    Published: 11 Jul 2022
    3.3
    Low

    CVE-2022-33687

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to access IMSI via log.

    Published: 11 Jul 2022
    2.3
    Low

    CVE-2022-33686

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.

    Published: 11 Jul 2022
    4
    Medium

    CVE-2022-33685

    Last Modified: 21 Nov 2024

    Unprotected dynamic receiver in Wearable Manager Service prior to SMR Jul-2022 Release 1 allows attacker to launch arbitray activity and access senstive information.

    Published: 11 Jul 2022
    4
    Medium

    CVE-2022-30758

    Last Modified: 21 Nov 2024

    Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to access some protected information with privilege of Finder.

    Published: 11 Jul 2022
    4
    Medium

    CVE-2022-30757

    Last Modified: 21 Nov 2024

    Improper authorization in isemtelephony prior to SMR Jul-2022 Release 1 allows attacker to obtain CID without ACCESS_FINE_LOCATION permission.

    Published: 11 Jul 2022
    8.5
    High

    CVE-2022-30756

    Last Modified: 21 Nov 2024

    Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of Finder.

    Published: 11 Jul 2022
    7.3
    High

    CVE-2022-30755

    Last Modified: 21 Nov 2024

    Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijacking the implicit intent.

    Published: 11 Jul 2022
    8.5
    High

    CVE-2022-30754

    Last Modified: 21 Nov 2024

    Implicit Intent hijacking vulnerability in AppLinker prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of AppLinker.

    Published: 11 Jul 2022
    3.3
    Low

    CVE-2022-30753

    Last Modified: 21 Nov 2024

    Improper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers to get the device ID without permission.

    Published: 11 Jul 2022
    3.3
    Low

    CVE-2022-30752

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_STATE_CHANGED action.

    Published: 11 Jul 2022
    3.3
    Low

    CVE-2022-30751

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_DHCPACK_EVENT action.

    Published: 11 Jul 2022
    3.3
    Low

    CVE-2022-30750

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in updateLastConnectedClientInfo function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected.

    Published: 11 Jul 2022
    4.3
    Medium

    CVE-2022-2123

    Last Modified: 21 Nov 2024

    The WP Opt-in WordPress plugin through 1.4.1 is vulnerable to CSRF which allows changed plugin settings and can be used for sending spam emails.

    Published: 11 Jul 2022
    4.8
    Medium

    CVE-2022-2093

    Last Modified: 21 Nov 2024

    The WP Duplicate Page WordPress plugin before 1.3 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

    Published: 11 Jul 2022
    6.1
    Medium

    CVE-2022-2092

    Last Modified: 21 Nov 2024

    The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.16.0 doesn't escape a parameter on its setting page, making it possible for attackers to conduct reflected cross-site scripting attacks.

    Published: 11 Jul 2022
    6.5
    Medium

    CVE-2022-2091

    Last Modified: 21 Nov 2024

    The Cache Images WordPress plugin before 3.2.1 does not implement nonce checks, which could allow attackers to make any logged user upload images via a CSRF attack.

    Published: 11 Jul 2022
    4.8
    Medium

    CVE-2022-2089

    Last Modified: 21 Nov 2024

    The Bold Page Builder WordPress plugin before 4.3.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

    Published: 11 Jul 2022
    4.8
    Medium

    CVE-2022-2050

    Last Modified: 21 Nov 2024

    The WP-Paginate WordPress plugin before 2.1.9 does not escape one of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when unfiltered_html is disallowed

    Published: 11 Jul 2022
    4.3
    Medium

    CVE-2022-1957

    Last Modified: 21 Nov 2024

    The Comment License WordPress plugin before 1.4.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 11 Jul 2022
    4.3
    Medium

    CVE-2022-1956

    Last Modified: 21 Nov 2024

    The Shortcut Macros WordPress plugin through 1.3 does not have authorisation and CSRF checks in place when updating its settings, which could allow any authenticated users, such as subscriber, to update them.

    Published: 11 Jul 2022
    9.8
    Critical

    CVE-2022-1952

    Last Modified: 23 Jan 2026

    The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to arbitrary file upload and subsequently to remote code execution. An AJAX action accessible to unauthenticated users is affected by this issue. An allowlist of valid file extensions is defined but is not used during the validation steps.

    Published: 11 Jul 2022
    6.1
    Medium

    CVE-2022-1951

    Last Modified: 21 Nov 2024

    The core plugin for kitestudio WordPress plugin before 2.3.1 does not sanitise and escape some parameters before outputting them back in a response of an AJAX action, available to both unauthenticated and authenticated users when a premium theme from the vendor is active, leading to a Reflected Cross-Site Scripting.

    Published: 11 Jul 2022
    5.4
    Medium

    CVE-2022-1938

    Last Modified: 21 Nov 2024

    The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a header when processing request to generate analytics data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against a logged in admin viewing the plugin's settings

    Published: 11 Jul 2022
    6.1
    Medium

    CVE-2022-1937

    Last Modified: 21 Nov 2024

    The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a parameter before outputting it back via an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting

    Published: 11 Jul 2022
    6.1
    Medium

    CVE-2022-1910

    Last Modified: 21 Nov 2024

    The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting

    Published: 11 Jul 2022
    4.8
    Medium

    CVE-2022-1894

    Last Modified: 21 Nov 2024

    The Popup Builder WordPress plugin before 4.1.11 does not escape and sanitize some settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltred_html is disallowed

    Published: 11 Jul 2022
    5.4
    Medium

    CVE-2022-1757

    Last Modified: 21 Nov 2024

    The pagebar WordPress plugin before 2.70 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of sanitisation in some of them, it could also lead to Stored XSS issues

    Published: 11 Jul 2022
    6.5
    Medium

    CVE-2022-1732

    Last Modified: 21 Nov 2024

    The Rename wp-login.php WordPress plugin through 2.6.0 does not have CSRF check in place when updating the secret login URL, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 11 Jul 2022
    5.4
    Medium

    CVE-2022-1626

    Last Modified: 21 Nov 2024

    The Sharebar WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and also lead to Stored Cross-Site Scripting issue due to the lack of sanitisation and escaping in some of them

    Published: 11 Jul 2022
    6.5
    Medium

    CVE-2022-1599

    Last Modified: 21 Nov 2024

    The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post date, comment status (enabled, disabled) and more.

    Published: 11 Jul 2022
    6.5
    Medium

    CVE-2022-1576

    Last Modified: 21 Nov 2024

    The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attackers to make a logged in admin perform such action via a CSRF attack

    Published: 11 Jul 2022
    6.1
    Medium

    CVE-2022-1546

    Last Modified: 21 Nov 2024

    The WooCommerce - Product Importer WordPress plugin through 1.5.2 does not sanitise and escape the imported data before outputting it back in the page, leading to a Reflected Cross-Site Scripting

    Published: 11 Jul 2022