CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2022-1316

    Last Modified: 24 Feb 2026

    Incorrect Permission Assignment for Critical Resource in GitHub repository zerotier/zerotierone prior to 1.8.8. Local Privilege Escalation

    Published: 11 Apr 2022
    8.1
    High

    CVE-2022-24829

    Last Modified: 23 Apr 2025

    Garden is an automation platform for Kubernetes development and testing. In versions prior to 0.12.39 multiple endpoints did not require authentication. In some operating modes this allows for an attacker to gain access to the application erroneously. The configuration is leaked through the /api endpoint on the local server that is responsible for serving the Garden dashboard. At the moment, this server is accessible to 0.0.0.0 which makes it accessible to anyone on the same network (or anyone on the internet if they are on a public, static IP). This may lead to the ability to compromise credentials, secrets or environment variables. Users are advised to upgrade to version 0.12.39 as soon as possible. Users unable to upgrade should use a firewall blocking access to port 9777 from all untrusted network machines.

    Published: 11 Apr 2022
    4.3
    Medium

    CVE-2022-25614

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) in StylemixThemes eRoom – Zoom Meetings & Webinar (WordPress plugin) <= 1.3.7 allows an attacker to Sync with Zoom Meetings.

    Published: 11 Apr 2022
    4.3
    Medium

    CVE-2022-25615

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) in StylemixThemes eRoom – Zoom Meetings & Webinar (WordPress plugin) <= 1.3.8 allows cache deletion.

    Published: 11 Apr 2022
    8.8
    High

    CVE-2022-0999

    Last Modified: 16 Apr 2025

    An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior.

    Published: 11 Apr 2022
    8.1
    High

    CVE-2022-0835

    Last Modified: 16 Apr 2025

    AVEVA System Platform 2020 stores sensitive information in cleartext, which may allow access to an attacker or a low-privileged user.

    Published: 11 Apr 2022
    7.8
    High

    CVE-2022-22964

    Last Modified: 21 Nov 2024

    VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to root due to a vulnerable configuration file.

    Published: 11 Apr 2022
    7.8
    High

    CVE-2022-22962

    Last Modified: 21 Nov 2024

    VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location due to a vulnerable symbolic link. Successful exploitation can result in linking to a root owned file.

    Published: 11 Apr 2022
    2.6
    Low

    CVE-2022-1157

    Last Modified: 21 Nov 2024

    Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged

    Published: 11 Apr 2022
    4.3
    Medium

    CVE-2022-1193

    Last Modified: 21 Nov 2024

    Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain circumstances

    Published: 11 Apr 2022
    7.5
    High

    CVE-2021-40065

    Last Modified: 21 Nov 2024

    The communication module has a service logic error vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 11 Apr 2022
    7.5
    High

    CVE-2021-46740

    Last Modified: 21 Nov 2024

    The device authentication service module has a defect vulnerability introduced in the design process.Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 11 Apr 2022
    7.5
    High

    CVE-2022-22253

    Last Modified: 21 Nov 2024

    The DFX module has a vulnerability of improper validation of integrity check values.Successful exploitation of this vulnerability may affect system stability.

    Published: 11 Apr 2022
    9.1
    Critical

    CVE-2021-46742

    Last Modified: 21 Nov 2024

    The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings.Secure data.Successful exploitation of this vulnerability may affect the availability.

    Published: 11 Apr 2022
    7.5
    High

    CVE-2022-22254

    Last Modified: 21 Nov 2024

    A permission bypass vulnerability exists when the NFC CAs access the TEE.Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 11 Apr 2022
    7.5
    High

    CVE-2022-22255

    Last Modified: 21 Nov 2024

    The application framework has a common DoS vulnerability.Successful exploitation of this vulnerability may affect the availability.

    Published: 11 Apr 2022
    7.5
    High

    CVE-2022-22256

    Last Modified: 21 Nov 2024

    The DFX module has an access control vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 11 Apr 2022
    9.8
    Critical

    CVE-2022-22258

    Last Modified: 21 Nov 2024

    The Wi-Fi module has an event notification vulnerability.Successful exploitation of this vulnerability may allow third-party applications to intercept event notifications and add information and result in elevation-of-privilege.

    Published: 11 Apr 2022
    7.5
    High

    CVE-2022-22257

    Last Modified: 21 Nov 2024

    The customization framework has a vulnerability of improper permission control.Successful exploitation of this vulnerability may affect data integrity.

    Published: 11 Apr 2022
    4.8
    Medium

    CVE-2022-27845

    Last Modified: 20 Feb 2025

    Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) in PlausibleHQ Plausible Analytics (WordPress plugin) <= 1.2.2

    Published: 11 Apr 2022
    2.7
    Low

    CVE-2022-27844

    Last Modified: 20 Feb 2025

    Arbitrary File Read vulnerability in WPvivid Team Migration, Backup, Staging – WPvivid (WordPress plugin) versions <= 0.9.70

    Published: 11 Apr 2022
    6.5
    Medium

    CVE-2022-1067

    Last Modified: 16 Apr 2025

    Navigating to a specific URL with a patient ID number will result in the server generating a PDF of a lab report without authentication and rate limiting.

    Published: 11 Apr 2022
    10
    Critical

    CVE-2022-1161

    Last Modified: 16 Apr 2025

    An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the other.

    Published: 11 Apr 2022
    7.8
    High

    CVE-2022-1262

    Last Modified: 21 Nov 2024

    A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary commands as root.

    Published: 11 Apr 2022
    8.8
    High

    CVE-2022-22572

    Last Modified: 21 Nov 2024

    A non-admin user with user management permission can escalate his privilege to admin user via password reset functionality. The vulnerability affects Incapptic Connect version < 1.40.1.

    Published: 11 Apr 2022
    4.8
    Medium

    CVE-2022-22571

    Last Modified: 21 Nov 2024

    An authenticated high privileged user can perform a stored XSS attack due to incorrect output encoding in Incapptic connect and affects all current versions.

    Published: 11 Apr 2022
    6.4
    Medium

    CVE-2022-20080

    Last Modified: 21 Nov 2024

    In SUB2AF, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05881290; Issue ID: ALPS05881290.

    Published: 11 Apr 2022
    4.4
    Medium

    CVE-2022-20079

    Last Modified: 21 Nov 2024

    In vow, there is a possible read of uninitialized data due to a improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05837742; Issue ID: ALPS05857289.

    Published: 11 Apr 2022
    6.4
    Medium

    CVE-2022-20078

    Last Modified: 21 Nov 2024

    In vow, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05852819; Issue ID: ALPS05852819.

    Published: 11 Apr 2022
    6.4
    Medium

    CVE-2022-20077

    Last Modified: 21 Nov 2024

    In vow, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05837742; Issue ID: ALPS05852812.

    Published: 11 Apr 2022
    6.7
    Medium

    CVE-2022-20075

    Last Modified: 21 Nov 2024

    In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05838808; Issue ID: ALPS05838808.

    Published: 11 Apr 2022
    4.4
    Medium

    CVE-2022-20076

    Last Modified: 21 Nov 2024

    In ged, there is a possible memory corruption due to an incorrect error handling. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05838808; Issue ID: ALPS05839556.

    Published: 11 Apr 2022
    6.6
    Medium

    CVE-2022-20074

    Last Modified: 21 Nov 2024

    In preloader (partition), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06183301; Issue ID: ALPS06183301.

    Published: 11 Apr 2022
    6.6
    Medium

    CVE-2022-20073

    Last Modified: 21 Nov 2024

    In preloader (usb), there is a possible out of bounds write due to a integer underflow. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160841; Issue ID: ALPS06160841.

    Published: 11 Apr 2022
    6.7
    Medium

    CVE-2022-20072

    Last Modified: 21 Nov 2024

    In search engine service, there is a possible way to change the default search engine due to an incorrect comparison. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS06219118; Issue ID: ALPS06219118.

    Published: 11 Apr 2022
    6.7
    Medium

    CVE-2022-20071

    Last Modified: 21 Nov 2024

    In ccu, there is a possible escalation of privilege due to a missing certificate validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS06183315; Issue ID: ALPS06183315.

    Published: 11 Apr 2022
    6.7
    Medium

    CVE-2022-20070

    Last Modified: 21 Nov 2024

    In ssmr, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS06362920; Issue ID: ALPS06362920.

    Published: 11 Apr 2022
    6.6
    Medium

    CVE-2022-20069

    Last Modified: 21 Nov 2024

    In preloader (usb), there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160425; Issue ID: ALPS06160425.

    Published: 11 Apr 2022
    6.7
    Medium

    CVE-2022-20068

    Last Modified: 21 Nov 2024

    In mobile_log_d, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06308907; Issue ID: ALPS06308907.

    Published: 11 Apr 2022
    6.5
    Medium

    CVE-2022-20052

    Last Modified: 21 Nov 2024

    In mdp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS05836642; Issue ID: ALPS05836642.

    Published: 11 Apr 2022
    6.7
    Medium

    CVE-2022-20067

    Last Modified: 21 Nov 2024

    In mdp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05836585; Issue ID: ALPS05836585.

    Published: 11 Apr 2022
    4.4
    Medium

    CVE-2022-20066

    Last Modified: 21 Nov 2024

    In atf (hwfde), there is a possible leak of sensitive information due to incorrect error handling. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171729; Issue ID: ALPS06171729.

    Published: 11 Apr 2022
    6.7
    Medium

    CVE-2022-20064

    Last Modified: 21 Nov 2024

    In ccci, there is a possible leak of kernel pointer due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06108617; Issue ID: ALPS06108617.

    Published: 11 Apr 2022
    6.7
    Medium

    CVE-2022-20065

    Last Modified: 21 Nov 2024

    In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06108658; Issue ID: ALPS06108658.

    Published: 11 Apr 2022
    6.5
    Medium

    CVE-2022-20063

    Last Modified: 21 Nov 2024

    In atf (spm), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06171715; Issue ID: ALPS06171715.

    Published: 11 Apr 2022
    6.7
    Medium

    CVE-2022-20062

    Last Modified: 21 Nov 2024

    In mdp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05836418; Issue ID: ALPS05836418.

    Published: 11 Apr 2022
    5.9
    Medium

    CVE-2022-20081

    Last Modified: 21 Nov 2024

    In A-GPS, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06461919; Issue ID: ALPS06461919.

    Published: 11 Apr 2022
    7.8
    High

    CVE-2022-27528

    Last Modified: 21 Nov 2024

    A maliciously crafted DWFX and SKP files in Autodesk Navisworks 2022 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.

    Published: 11 Apr 2022
    7.8
    High

    CVE-2022-25796

    Last Modified: 21 Nov 2024

    A Double Free vulnerability allows remote malicious actors to execute arbitrary code on DWF file in Autodesk Navisworks 2022 within affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

    Published: 11 Apr 2022
    7.8
    High

    CVE-2022-25792

    Last Modified: 21 Nov 2024

    A maliciously crafted DXF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated buffer through Buffer overflow vulnerability. This vulnerability can be exploited to execute arbitrary code.

    Published: 11 Apr 2022