CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2022-21772

    Last Modified: 21 Nov 2024

    In TEEI driver, there is a possible type confusion due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06493842; Issue ID: ALPS06493842.

    Published: 6 Jul 2022
    6.7
    Medium

    CVE-2022-21771

    Last Modified: 21 Nov 2024

    In GED driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641585; Issue ID: ALPS06641585.

    Published: 6 Jul 2022
    6.7
    Medium

    CVE-2022-21770

    Last Modified: 21 Nov 2024

    In sound driver, there is a possible information disclosure due to symlink following. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558663; Issue ID: ALPS06558663.

    Published: 6 Jul 2022
    4.4
    Medium

    CVE-2022-21769

    Last Modified: 21 Nov 2024

    In CCCI, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641673; Issue ID: ALPS06641687.

    Published: 6 Jul 2022
    6.7
    Medium

    CVE-2022-21766

    Last Modified: 21 Nov 2024

    In CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641673; Issue ID: ALPS06641653.

    Published: 6 Jul 2022
    6.7
    Medium

    CVE-2022-21765

    Last Modified: 21 Nov 2024

    In CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641673; Issue ID: ALPS06641673.

    Published: 6 Jul 2022
    8.8
    High

    CVE-2022-21768

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06784351; Issue ID: ALPS06784351.

    Published: 6 Jul 2022
    8.8
    High

    CVE-2022-21767

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06784430; Issue ID: ALPS06784430.

    Published: 6 Jul 2022
    9.8
    Critical

    CVE-2022-20083

    Last Modified: 21 Nov 2024

    In Modem 2G/3G CC, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding combined FACILITY with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00803883; Issue ID: MOLY00803883.

    Published: 6 Jul 2022
    9.8
    Critical

    CVE-2022-21744

    Last Modified: 21 Nov 2024

    In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding GPRS Packet Neighbour Cell Data (PNCD) improper neighbouring cell size with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00810064; Issue ID: ALPS06641626.

    Published: 6 Jul 2022
    5.5
    Medium

    CVE-2022-21764

    Last Modified: 21 Nov 2024

    In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07044717; Issue ID: ALPS07044717.

    Published: 6 Jul 2022
    5.5
    Medium

    CVE-2022-21763

    Last Modified: 21 Nov 2024

    In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07044717; Issue ID: ALPS07044708.

    Published: 6 Jul 2022
    7
    High

    CVE-2022-20082

    Last Modified: 21 Nov 2024

    In GPU, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07044730; Issue ID: ALPS07044730.

    Published: 6 Jul 2022
    5.4
    Medium

    CVE-2022-24141

    Last Modified: 21 Nov 2024

    The iTopVPNmini.exe component of iTop VPN 3.2 will try to connect to datastate_iTopVPN_Pipe_Server on a loop. An attacker that opened a named pipe with the same name can use it to gain the token of another user by listening for connections and abusing ImpersonateNamedPipeClient().

    Published: 6 Jul 2022
    6.6
    Medium

    CVE-2022-24140

    Last Modified: 21 Nov 2024

    IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP requests in their update procedure in order to download a config file. After downloading the config file, the products will parse the HTTP location of the update from the file and will try to install the update automatically with ADMIN privileges. An attacker Intercepting this communication can supply the product a fake config file with malicious locations for the updates thus gaining a remote code execution on an endpoint.

    Published: 6 Jul 2022
    7.8
    High

    CVE-2022-24139

    Last Modified: 21 Nov 2024

    In IOBit Advanced System Care (AscService.exe) 15, an attacker with SEImpersonatePrivilege can create a named pipe with the same name as one of ASCService's named pipes. ASCService first tries to connect before trying to create the named pipes, because of that during login the service will try to connect to the attacker which will lead to either escalation of privileges (through token manipulation and ImpersonateNamedPipeClient() ) from ADMIN -> SYSTEM or from Local ADMIN-> Domain ADMIN depending on the user and named pipe that is used.

    Published: 6 Jul 2022
    7.8
    High

    CVE-2022-24138

    Last Modified: 21 Nov 2024

    IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramData folder, ProgramData folder has "rwx" permissions for unprivileged users. Low privilege users can use SetOpLock to wait for CreateProcess and switch the genuine component with a malicious executable thus gaining code execution as a high privilege user (Low Privilege -> high integrity ADMIN).

    Published: 6 Jul 2022
    4.3
    Medium

    CVE-2021-37839

    Last Modified: 21 Nov 2024

    Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.

    Published: 6 Jul 2022
    7.2
    High

    CVE-2022-28935

    Last Modified: 21 Nov 2024

    Totolink A830R V5.9c.4729_B20191112, Totolink A3100R V4.1.2cu.5050_B20200504, Totolink A950RG V4.1.2cu.5161_B20200903, Totolink A800R V4.1.2cu.5137_B20200730, Totolink A3000RU V5.9c.5185_B20201128, Totolink A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability.

    Published: 6 Jul 2022
    6.5
    Medium

    CVE-2021-31678

    Last Modified: 21 Nov 2024

    An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can delete import information about a user's company.

    Published: 6 Jul 2022
    6.5
    Medium

    CVE-2021-31679

    Last Modified: 21 Nov 2024

    An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that allows attackers to delete admin and other members' account numbers.

    Published: 6 Jul 2022
    6.5
    Medium

    CVE-2021-31677

    Last Modified: 21 Nov 2024

    An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can modify admin and other members' passwords.

    Published: 6 Jul 2022
    6.1
    Medium

    CVE-2021-31676

    Last Modified: 21 Nov 2024

    A reflected XSS was discovered in PESCMS-V2.3.3. When combined with CSRF in the same file, they can cause bigger destruction.

    Published: 6 Jul 2022
    9.8
    Critical

    CVE-2022-32383

    Last Modified: 21 Nov 2024

    Tenda AC23 v16.03.07.44 was discovered to contain a stack overflow via the AdvSetMacMtuWan function.

    Published: 6 Jul 2022
    9.8
    Critical

    CVE-2022-32385

    Last Modified: 21 Nov 2024

    Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the execution of arbitrary code (remote).

    Published: 6 Jul 2022
    9.8
    Critical

    CVE-2022-32386

    Last Modified: 21 Nov 2024

    Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan.

    Published: 6 Jul 2022
    7.5
    High

    CVE-2022-30591

    Last Modified: 21 Nov 2024

    quic-go through 0.27.0 allows remote attackers to cause a denial of service (CPU consumption) via a Slowloris variant in which incomplete QUIC or HTTP/3 requests are sent. This occurs because mtu_discoverer.go misparses the MTU Discovery service and consequently overflows the probe timer. NOTE: the vendor's position is that this behavior should not be listed as a vulnerability on the CVE List

    Published: 6 Jul 2022
    4.3
    Medium

    CVE-2022-32290

    Last Modified: 21 Nov 2024

    The client in Northern.tech Mender 3.2.0, 3.2.1, and 3.2.2 has Incorrect Access Control. It listens on a random, unprivileged TCP port and exposes an HTTP proxy to facilitate API calls from additional client components running on the device. However, it listens on all network interfaces instead of only the localhost interface. Therefore, any client on the same network can connect to this TCP port and send HTTP requests. The Mender Client will forward these requests to the Mender Server. Additionally, if mTLS is set up, the Mender Client will connect to the Mender Server using the device's client certificate, making it possible for the attacker to bypass mTLS authentication and send requests to the Mender Server without direct access to the client certificate and related private key. Accessing the HTTP proxy from the local network doesn't represent a direct threat, because it doesn't expose any device or server-specific data. However, it increases the attack surface and can be a potential vector to exploit other vulnerabilities both on the Client and the Server.

    Published: 6 Jul 2022
    3.7
    Low

    CVE-2022-35230

    Last Modified: 3 Nov 2025

    An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.

    Published: 6 Jul 2022
    3.7
    Low

    CVE-2022-35229

    Last Modified: 3 Nov 2025

    An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.

    Published: 6 Jul 2022
    3.1
    Low

    CVE-2021-23163

    Last Modified: 21 Nov 2024

    JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.33.6 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.

    Published: 6 Jul 2022
    9.8
    Critical

    CVE-2022-32533

    Last Modified: 21 Nov 2024

    Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dormant project of Apache Portals and no updates will be provided for this issue

    Published: 6 Jul 2022
    4.9
    Medium

    CVE-2021-46687

    Last Modified: 21 Nov 2024

    JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.

    Published: 6 Jul 2022
    6.1
    Medium

    CVE-2021-45721

    Last Modified: 21 Nov 2024

    JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one of the XHR parameters in Users REST API endpoint. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.36.1 versions prior to 7.29.8; JFrog Artifactory versions before 6.23.41 versions prior to 6.23.38.

    Published: 6 Jul 2022
    8.1
    High

    CVE-2022-22681

    Last Modified: 21 Nov 2024

    Session fixation vulnerability in access control management in Synology Photo Station before 6.8.16-3506 allows remote attackers to bypass security constraint via unspecified vectors.

    Published: 6 Jul 2022
    7.8
    High

    CVE-2022-2344

    Last Modified: 21 Nov 2024

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0045.

    Published: 6 Jul 2022
    9.8
    Critical

    CVE-2022-33980

    Last Modified: 21 Nov 2024

    Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing through 2.7, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Configuration 2.8.0, which disables the problematic interpolators by default.

    Published: 6 Jul 2022
    —
    Unknown

    CVE-2022-2331

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 6 Jul 2022
    7.8
    High

    CVE-2022-2343

    Last Modified: 21 Nov 2024

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0044.

    Published: 6 Jul 2022
    6.1
    Medium

    CVE-2022-23713

    Last Modified: 21 Nov 2024

    A cross-site-scripting (XSS) vulnerability was discovered in the Vega Charts Kibana integration which could allow arbitrary JavaScript to be executed in a victim’s browser.

    Published: 6 Jul 2022
    10
    Critical

    CVE-2022-31125

    Last Modified: 23 Apr 2025

    Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to bypass authentication and access admin functionality by sending a specially crafted HTTP request. This affects Roxywi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 6 Jul 2022
    8.8
    High

    CVE-2022-30550

    Last Modified: 23 May 2025

    An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation in certain configurations. The documentation does not advise against the use of passdb definitions that have the same driver and args settings. One such configuration would be where an administrator wishes to use the same PAM configuration or passwd file for both normal and master users but use the username_filter setting to restrict which of the users is able to be a master user.

    Published: 6 Jul 2022
    7.5
    High

    CVE-2022-31129

    Last Modified: 3 Nov 2025

    moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment (more specifically rfc2822 parsing, which is tried by default) has quadratic (N^2) complexity on specific inputs. Users may notice a noticeable slowdown is observed with inputs above 10k characters. Users who pass user-provided strings without sanity length checks to moment constructor are vulnerable to (Re)DoS attacks. The problem is patched in 2.29.4, the patch can be applied to all affected versions with minimal tweaking. Users are advised to upgrade. Users unable to upgrade should consider limiting date lengths accepted from user input.

    Published: 6 Jul 2022
    9.8
    Critical

    CVE-2022-32413

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in Dice v4.2.0 allows attackers to execute arbitrary code via a crafted file.

    Published: 5 Jul 2022
    9.8
    Critical

    CVE-2022-34972

    Last Modified: 21 Nov 2024

    So Filter Shop v3.x was discovered to contain multiple blind SQL injection vulnerabilities via the att_value_id , manu_value_id , opt_value_id , and subcate_value_id parameters at /index.php?route=extension/module/so_filter_shop_by/filter_data.

    Published: 5 Jul 2022
    9.8
    Critical

    CVE-2022-32311

    Last Modified: 21 Nov 2024

    Ingredient Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /isms/admin/stocks/view_stock.php.

    Published: 5 Jul 2022
    9.8
    Critical

    CVE-2022-32310

    Last Modified: 21 Nov 2024

    An access control issue in Ingredient Stock Management System v1.0 allows attackers to take over user accounts via a crafted POST request to /isms/classes/Users.php.

    Published: 5 Jul 2022
    9.8
    Critical

    CVE-2022-31856

    Last Modified: 21 Nov 2024

    Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter at /index.php.

    Published: 5 Jul 2022
    9.8
    Critical

    CVE-2022-2321

    Last Modified: 21 Nov 2024

    Improper Restriction of Excessive Authentication Attempts in GitHub repository heroiclabs/nakama prior to 3.13.0. This results in login brute-force attacks.

    Published: 5 Jul 2022
    5.4
    Medium

    CVE-2022-33075

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the Add Classification function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via unspecified vectors.

    Published: 5 Jul 2022