CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2022-30743

    Last Modified: 21 Nov 2024

    Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.

    Published: 7 Jun 2022
    3.3
    Low

    CVE-2022-30742

    Last Modified: 21 Nov 2024

    Sensitive information exposure vulnerability in FmmExtraOperation of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permissio to get sim card information through device log.

    Published: 7 Jun 2022
    3.3
    Low

    CVE-2022-30741

    Last Modified: 21 Nov 2024

    Sensitive information exposure vulnerability in SimChangeAlertManger of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permission to get sim card information through device log.

    Published: 7 Jun 2022
    4.1
    Medium

    CVE-2022-30740

    Last Modified: 21 Nov 2024

    Improper auto-fill algorithm in Samsung Internet prior to version 17.0.1.69 allows physical attackers to guess stored credit card numbers.

    Published: 7 Jun 2022
    4
    Medium

    CVE-2022-30739

    Last Modified: 21 Nov 2024

    Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email or phone number with a normal level permission.

    Published: 7 Jun 2022
    4.3
    Medium

    CVE-2022-30738

    Last Modified: 21 Nov 2024

    Improper check in Loader in Samsung Internet prior to 17.0.1.69 allows attackers to spoof address bar via executing script.

    Published: 7 Jun 2022
    4
    Medium

    CVE-2022-30737

    Last Modified: 21 Nov 2024

    Implicit Intent hijacking vulnerability in Samsung Account prior to version 13.2.00.6 allows attackers to get email ID.

    Published: 7 Jun 2022
    5.3
    Medium

    CVE-2022-30736

    Last Modified: 21 Nov 2024

    Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.

    Published: 7 Jun 2022
    5.9
    Medium

    CVE-2022-30735

    Last Modified: 21 Nov 2024

    Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_token without permission.

    Published: 7 Jun 2022
    4
    Medium

    CVE-2022-30734

    Last Modified: 21 Nov 2024

    Sensitive information exposure in Sign-out log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number without permission.

    Published: 7 Jun 2022
    4
    Medium

    CVE-2022-30733

    Last Modified: 21 Nov 2024

    Sensitive information exposure in Sign-in log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number without permission.

    Published: 7 Jun 2022
    5.5
    Medium

    CVE-2022-30732

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information vulnerability in Samsung Account prior to version 13.2.00.6 allows attacker to access sensitive information via onActivityResult.

    Published: 7 Jun 2022
    5.1
    Medium

    CVE-2022-30731

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in My Files prior to version 13.1.00.193 allows attackers to access arbitrary private files in My Files application.

    Published: 7 Jun 2022
    4.6
    Medium

    CVE-2022-30730

    Last Modified: 21 Nov 2024

    Improper authorization in Samsung Pass prior to 1.0.00.33 allows physical attackers to acess account list without authentication.

    Published: 7 Jun 2022
    1.9
    Low

    CVE-2022-30728

    Last Modified: 21 Nov 2024

    Information exposure vulnerability in ScanPool prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.

    Published: 7 Jun 2022
    6.2
    Medium

    CVE-2022-30727

    Last Modified: 21 Nov 2024

    Improper handling of insufficient permissions vulnerability in addAppPackageNameToAllowList in PersonaManagerService prior to SMR Jun-2022 Release 1 allows local attackers to set some setting value in work space.

    Published: 7 Jun 2022
    6.2
    Medium

    CVE-2022-30726

    Last Modified: 21 Nov 2024

    Unprotected component vulnerability in DeviceSearchTrampoline in SecSettingsIntelligence prior to SMR Jun-2022 Release 1 allows local attackers to launch activities of SecSettingsIntelligence.

    Published: 7 Jun 2022
    4
    Medium

    CVE-2022-30725

    Last Modified: 21 Nov 2024

    Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionError function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.

    Published: 7 Jun 2022
    4
    Medium

    CVE-2022-30724

    Last Modified: 21 Nov 2024

    Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionCompleted function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.

    Published: 7 Jun 2022
    4
    Medium

    CVE-2022-30723

    Last Modified: 21 Nov 2024

    Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in activateVoiceRecognitionWithDevice function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.

    Published: 7 Jun 2022
    6.2
    Medium

    CVE-2022-30722

    Last Modified: 21 Nov 2024

    Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Account.

    Published: 7 Jun 2022
    3.3
    Low

    CVE-2022-30729

    Last Modified: 21 Nov 2024

    Implicit Intent hijacking vulnerability in Settings prior to SMR Jun-2022 Release 1 allows attackers to get Wi-Fi SSID and password via a malicious QR code scanner.

    Published: 7 Jun 2022
    2.5
    Low

    CVE-2022-30721

    Last Modified: 21 Nov 2024

    Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.

    Published: 7 Jun 2022
    2.5
    Low

    CVE-2022-30720

    Last Modified: 21 Nov 2024

    Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.

    Published: 7 Jun 2022
    2.5
    Low

    CVE-2022-30719

    Last Modified: 21 Nov 2024

    Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.

    Published: 7 Jun 2022
    8.8
    High

    CVE-2019-9972

    Last Modified: 21 Nov 2024

    PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands with the phonesystem user privileges because of "<space><space> followed by <shift><enter>" mishandling.

    Published: 7 Jun 2022
    8.8
    High

    CVE-2019-9971

    Last Modified: 21 Nov 2024

    PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo with the tcpdump command, without a password. This occurs because the -z (aka postrotate-command) option to tcpdump can be unsafe when used in conjunction with sudo.

    Published: 7 Jun 2022
    4
    Medium

    CVE-2022-30717

    Last Modified: 21 Nov 2024

    Improper caller check in AR Emoji prior to SMR Jun-2022 Release 1 allows untrusted applications to use some camera functions via deeplink.

    Published: 7 Jun 2022
    4
    Medium

    CVE-2022-30716

    Last Modified: 21 Nov 2024

    Unprotected broadcast in sendIntentForToastDumpLog in DisplayToast prior to SMR Jun-2022 Release 1 allows untrusted applications to access toast message information from device.

    Published: 7 Jun 2022
    4
    Medium

    CVE-2022-30715

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in DofViewer prior to SMR Jun-2022 Release 1 allows attackers to control floating system alert window.

    Published: 7 Jun 2022
    1.9
    Low

    CVE-2022-30714

    Last Modified: 21 Nov 2024

    Information exposure vulnerability in SemIWCMonitor prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.

    Published: 7 Jun 2022
    8.5
    High

    CVE-2022-30713

    Last Modified: 21 Nov 2024

    Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

    Published: 7 Jun 2022
    8.5
    High

    CVE-2022-30712

    Last Modified: 21 Nov 2024

    Improper validation vulnerability in KfaOptions prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

    Published: 7 Jun 2022
    8.5
    High

    CVE-2022-30711

    Last Modified: 21 Nov 2024

    Improper validation vulnerability in FeedsInfo prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

    Published: 7 Jun 2022
    8.5
    High

    CVE-2022-30710

    Last Modified: 21 Nov 2024

    Improper validation vulnerability in RemoteViews prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

    Published: 7 Jun 2022
    2.5
    Low

    CVE-2022-30709

    Last Modified: 21 Nov 2024

    Improper input validation check logic vulnerability in SECRIL prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.

    Published: 7 Jun 2022
    2.2
    Low

    CVE-2022-28794

    Last Modified: 21 Nov 2024

    Sensitive information exposure in low-battery dumpstate log prior to SMR Jun-2022 Release 1 allows local attackers to get SIM card information.

    Published: 7 Jun 2022
    4.6
    Medium

    CVE-2021-27786

    Last Modified: 21 Nov 2024

    Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between a browser and server to see if the request is allowed. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information when the Access-Control-Allow-Credentials is enabled.

    Published: 7 Jun 2022
    5.4
    Medium

    CVE-2022-2022

    Last Modified: 26 Aug 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository nocodb/nocodb prior to 0.91.7.

    Published: 7 Jun 2022
    6.4
    Medium

    CVE-2022-28736

    Last Modified: 13 Feb 2025

    There's a use-after-free vulnerability in grub_cmd_chainloader() function; The chainloader command is used to boot up operating systems that doesn't support multiboot and do not have direct support from GRUB2. When executing chainloader more than once a use-after-free vulnerability is triggered. If an attacker can control the GRUB2's memory allocation pattern sensitive data may be exposed and arbitrary code execution can be achieved.

    Published: 7 Jun 2022
    6.5
    Medium

    CVE-2022-28737

    Last Modified: 21 Nov 2024

    There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not discarded in such scenario.

    Published: 7 Jun 2022
    6.7
    Medium

    CVE-2022-28735

    Last Modified: 13 Feb 2025

    The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.

    Published: 7 Jun 2022
    8.1
    High

    CVE-2022-28734

    Last Modified: 13 Feb 2025

    Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by one position. This can lead to a out-of-bound write further when parsing the HTTP request, writing a NULL byte past the buffer. It's conceivable that an attacker controlled set of packets can lead to corruption of the GRUB2's internal memory metadata.

    Published: 7 Jun 2022
    —
    Unknown

    CVE-2022-31279

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Jun 2022
    6.1
    Medium

    CVE-2022-31495

    Last Modified: 21 Nov 2024

    LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS.

    Published: 7 Jun 2022
    7.5
    High

    CVE-2021-37589

    Last Modified: 21 Nov 2024

    Virtua Cobranca before 12R allows SQL Injection on the login page.

    Published: 7 Jun 2022
    9.1
    Critical

    CVE-2022-25361

    Last Modified: 21 Nov 2024

    WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to delete arbitrary files from a limited set of directories on the system. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.

    Published: 7 Jun 2022
    7.5
    High

    CVE-2022-29564

    Last Modified: 21 Nov 2024

    Jamf Private Access before 2022-05-16 has Incorrect Access Control, in which an unauthorized user can reach a system in the internal infrastructure, aka WND-44801.

    Published: 7 Jun 2022
    2.4
    Low

    CVE-2022-2020

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/?page=system_info of the component System Name Handler. The manipulation with the input <img src="" onerror="alert(1)"> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Jun 2022
    7.3
    High

    CVE-2022-2019

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical was found in SourceCodester Prison Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Users.php?f=save of the component New User Creation. The manipulation leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Jun 2022