CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-29730

    Last Modified: 21 Nov 2024

    USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 was discovered to contain hard-coded credentials for its highest privileged account. The credentials cannot be altered through normal operation of the device.

    Published: 27 May 2022
    7.5
    High

    CVE-2022-29729

    Last Modified: 21 Nov 2024

    Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.

    Published: 27 May 2022
    9.8
    Critical

    CVE-2022-30510

    Last Modified: 21 Nov 2024

    School Dormitory Management System 1.0 is vulnerable to SQL Injection via reports/daily_collection_report.php:59.

    Published: 27 May 2022
    8.1
    High

    CVE-2022-1908

    Last Modified: 21 Nov 2024

    Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.

    Published: 27 May 2022
    5.4
    Medium

    CVE-2022-1909

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository causefx/organizr prior to 2.1.2200.

    Published: 27 May 2022
    8.1
    High

    CVE-2022-1907

    Last Modified: 21 Nov 2024

    Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.

    Published: 27 May 2022
    5.5
    Medium

    CVE-2022-2806

    Last Modified: 21 Nov 2024

    It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev

    Published: 27 May 2022
    8.2
    High

    CVE-2022-25878

    Last Modified: 21 Nov 2024

    The package protobufjs before 6.11.3 are vulnerable to Prototype Pollution which can allow an attacker to add/modify properties of the Object.prototype. This vulnerability can occur in multiple ways: 1. by providing untrusted user input to util.setProperty or to ReflectionObject.setParsedOption functions 2. by parsing/loading .proto files

    Published: 27 May 2022
    7
    High

    CVE-2022-2959

    Last Modified: 21 Nov 2024

    A race condition was found in the Linux kernel's watch queue due to a missing lock in pipe_resize_ring(). The specific flaw exists within the handling of pipe buffers. The issue results from the lack of proper locking when performing operations on an object. This flaw allows a local user to crash the system or escalate their privileges on the system.

    Published: 27 May 2022
    10
    Critical

    CVE-2022-30123

    Last Modified: 21 Nov 2024

    A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.

    Published: 27 May 2022
    5.5
    Medium

    CVE-2022-31783

    Last Modified: 21 Nov 2024

    Liblouis 3.21.0 has an out-of-bounds write in compileRule in compileTranslationTable.c, as demonstrated by lou_trace.

    Published: 27 May 2022
    6.5
    Medium

    CVE-2022-2805

    Last Modified: 9 May 2025

    A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allows an attacker with sufficient privileges to read the log file, leading to confidentiality loss.

    Published: 27 May 2022
    7.5
    High

    CVE-2022-30122

    Last Modified: 21 Nov 2024

    A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack.

    Published: 27 May 2022
    9.8
    Critical

    CVE-2022-30521

    Last Modified: 21 Nov 2024

    The LAN-side Web-Configuration Interface has Stack-based Buffer Overflow vulnerability in the D-Link Wi-Fi router firmware DIR-890L DIR890LA1_FW107b09.bin and previous versions. The function created at 0x17958 of /htdocs/cgibin will call sprintf without checking the length of strings in parameters given by HTTP header and can be controlled by users easily. The attackers can exploit the vulnerability to carry out arbitrary code by means of sending a specially constructed payload to port 49152.

    Published: 27 May 2022
    7.8
    High

    CVE-2022-30701

    Last Modified: 21 Nov 2024

    An uncontrolled search path element vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to craft a special configuration file to load an untrusted library with escalated privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-30700

    Last Modified: 21 Nov 2024

    An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to load a DLL with escalated privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 26 May 2022
    7.1
    High

    CVE-2022-30687

    Last Modified: 21 Nov 2024

    Trend Micro Maximum Security 2022 is vulnerable to a link following vulnerability that could allow a low privileged local user to manipulate the product's secure erase feature to delete arbitrary files.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-28394

    Last Modified: 21 Nov 2024

    EOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 3.7.0.1223 and below provided by Trend Micro Incorporated contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427). Please note that this was reported on an EOL version of the product, and users are advised to upgrade to the latest supported version (5.x).

    Published: 26 May 2022
    7.8
    High

    CVE-2022-29637

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in Mindoc v2.1-beta.5 allows attackers to execute arbitrary commands via a crafted Zip file.

    Published: 26 May 2022
    9.8
    Critical

    CVE-2022-29633

    Last Modified: 21 Nov 2024

    An access control issue in Linglong v1.0 allows attackers to access the background of the application via a crafted cookie.

    Published: 26 May 2022
    9.8
    Critical

    CVE-2022-29632

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in the component /course/api/upload/pic of Roncoo Education v9.0.0 allows attackers to execute arbitrary code via a crafted file.

    Published: 26 May 2022
    6.1
    Medium

    CVE-2021-28509

    Last Modified: 21 Nov 2024

    This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAttr might leak MACsec sensitive data in clear text in CVP to other authorized users, which could cause MACsec traffic to be decrypted or modified by other authorized users on the device.

    Published: 26 May 2022
    6.8
    Medium

    CVE-2021-28508

    Last Modified: 21 Nov 2024

    This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAttr might leak IPsec sensitive data in clear text in CVP to other authorized users, which could cause IPsec traffic to be decrypted or modified by other authorized users on the device.

    Published: 26 May 2022
    9.8
    Critical

    CVE-2022-26776

    Last Modified: 30 May 2025

    This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. An attacker may be able to cause unexpected application termination or arbitrary code execution.

    Published: 26 May 2022
    9.8
    Critical

    CVE-2022-26775

    Last Modified: 30 May 2025

    An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4. An attacker may be able to cause unexpected application termination or arbitrary code execution.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-26774

    Last Modified: 30 May 2025

    A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.12.4 for Windows. A local attacker may be able to elevate their privileges.

    Published: 26 May 2022
    7.1
    High

    CVE-2022-26773

    Last Modified: 30 May 2025

    A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.12.4 for Windows. An application may be able to delete files for which it does not have permission.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-26772

    Last Modified: 30 May 2025

    A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.4. An application may be able to execute arbitrary code with kernel privileges.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-26771

    Last Modified: 30 May 2025

    A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 8.6, tvOS 15.5, iOS 15.5 and iPadOS 15.5. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-26770

    Last Modified: 30 May 2025

    An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-26769

    Last Modified: 30 May 2025

    A memory corruption issue was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-26768

    Last Modified: 30 May 2025

    A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.4, watchOS 8.6, tvOS 15.5, macOS Big Sur 11.6.6. An application may be able to execute arbitrary code with kernel privileges.

    Published: 26 May 2022
    5.5
    Medium

    CVE-2022-26767

    Last Modified: 30 May 2025

    The issue was addressed with additional permissions checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to bypass Privacy preferences.

    Published: 26 May 2022
    5.5
    Medium

    CVE-2022-26766

    Last Modified: 30 May 2025

    A certificate parsing issue was addressed with improved checks. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A malicious app may be able to bypass signature validation.

    Published: 26 May 2022
    4.7
    Medium

    CVE-2022-26765

    Last Modified: 30 May 2025

    A race condition was addressed with improved state handling. This issue is fixed in watchOS 8.6, tvOS 15.5, macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.

    Published: 26 May 2022
    4.7
    Medium

    CVE-2022-26764

    Last Modified: 30 May 2025

    A memory corruption issue was addressed with improved validation. This issue is fixed in watchOS 8.6, tvOS 15.5, macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-26763

    Last Modified: 30 May 2025

    An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A malicious application may be able to execute arbitrary code with system privileges.

    Published: 26 May 2022
    9.6
    Critical

    CVE-2022-30584

    Last Modified: 21 Nov 2024

    Archer Platform 6.3 before 6.11 (6.11.0.0) contains an Improper Access Control Vulnerability within SSO ADFS functionality that could potentially be exploited by malicious users to compromise the affected system. 6.10 P3 (6.10.0.3) and 6.9 SP3 P4 (6.9.3.4) are also fixed releases.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-26761

    Last Modified: 30 May 2025

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. An application may be able to execute arbitrary code with kernel privileges.

    Published: 26 May 2022
    6.5
    Medium

    CVE-2022-30585

    Last Modified: 21 Nov 2024

    The REST API in Archer Platform 6.x before 6.11 (6.11.0.0) contains an Authorization Bypass Vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to view sensitive information. 6.10 P3 (6.10.0.3) and 6.9 SP3 P4 (6.9.3.4) are also fixed releases.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-26757

    Last Modified: 21 Nov 2024

    A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. An application may be able to execute arbitrary code with kernel privileges.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-26756

    Last Modified: 21 Nov 2024

    An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. An application may be able to execute arbitrary code with kernel privileges.

    Published: 26 May 2022
    6.3
    Medium

    CVE-2022-26755

    Last Modified: 21 Nov 2024

    This issue was addressed with improved environment sanitization. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to break out of its sandbox.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-26754

    Last Modified: 21 Nov 2024

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.4. An application may be able to execute arbitrary code with kernel privileges.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-26753

    Last Modified: 21 Nov 2024

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.4. An application may be able to execute arbitrary code with kernel privileges.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-26752

    Last Modified: 21 Nov 2024

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.4. An application may be able to execute arbitrary code with kernel privileges.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-26751

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved input validation. This issue is fixed in iTunes 12.12.4 for Windows, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6, macOS Monterey 12.4. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-26750

    Last Modified: 21 Nov 2024

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.4. An application may be able to execute arbitrary code with kernel privileges.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-26749

    Last Modified: 21 Nov 2024

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.4. An application may be able to execute arbitrary code with kernel privileges.

    Published: 26 May 2022
    8.8
    High

    CVE-2022-26748

    Last Modified: 21 Nov 2024

    An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 26 May 2022