CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-25790

    Last Modified: 21 Nov 2024

    A maliciously crafted DWF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated boundaries when parsing the DWF files. Exploitation of this vulnerability may lead to code execution.

    Published: 11 Apr 2022
    7.8
    High

    CVE-2022-25791

    Last Modified: 21 Nov 2024

    A Memory Corruption vulnerability for DWF and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 may lead to code execution through maliciously crafted DLL files.

    Published: 11 Apr 2022
    7.8
    High

    CVE-2022-25789

    Last Modified: 21 Nov 2024

    A maliciously crafted DWF, 3DS and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.

    Published: 11 Apr 2022
    9.8
    Critical

    CVE-2021-38125

    Last Modified: 21 Nov 2024

    Unauthenticated remote code execution in Micro Focus Operations Bridge containerized, affecting versions 2021.05, 2021.08, and newer versions of Micro Focus Operations Bridge containerized if the deployment was upgraded from 2021.05 or 2021.08. The vulnerability could be exploited to unauthenticated remote code execution.

    Published: 11 Apr 2022
    4.8
    Medium

    CVE-2021-36893

    Last Modified: 20 Feb 2025

    Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Responsive Tabs (WordPress plugin) <= 4.0.5

    Published: 11 Apr 2022
    9.1
    Critical

    CVE-2022-27577

    Last Modified: 21 Nov 2024

    The vulnerability in the MSC800 in all versions before 4.15 allows for an attacker to predict the TCP initial sequence number. When the TCP sequence is predictable, an attacker can send packets that are forged to appear to come from a trusted computer. These forged packets could compromise services on the MSC800. SICK has released a new firmware version of the SICK MSC800 and recommends updating to the newest version.

    Published: 11 Apr 2022
    7.8
    High

    CVE-2022-27578

    Last Modified: 21 Nov 2024

    An attacker can perform a privilege escalation through the SICK OEE if the application is installed in a directory where non authenticated or low privilege users can modify its content.

    Published: 11 Apr 2022
    4.4
    Medium

    CVE-2022-28778

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Samsung Security Supporter prior to version 1.2.40.0 allows attacker to set the arbitrary folder as Secret Folder without Samsung Security Supporter permission

    Published: 11 Apr 2022
    5.3
    Medium

    CVE-2022-28779

    Last Modified: 21 Nov 2024

    Uncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version 1.7.50 allows attacker to execute arbitrary code.

    Published: 11 Apr 2022
    4.3
    Medium

    CVE-2022-28777

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Samsung Members prior to version 13.6.08.5 allows local attacker to execute call function without CALL_PHONE permission.

    Published: 11 Apr 2022
    5.9
    Medium

    CVE-2022-28776

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications from Galaxy Store without user interactions.

    Published: 11 Apr 2022
    5.1
    Medium

    CVE-2022-28775

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Samsung Flow prior to version 4.8.06.5 allows attacker to write the file without Samsung Flow permission.

    Published: 11 Apr 2022
    4.8
    Medium

    CVE-2021-36846

    Last Modified: 20 Feb 2025

    Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Premio Chaty (WordPress plugin) <= 2.8.3

    Published: 11 Apr 2022
    5.3
    Medium

    CVE-2021-43177

    Last Modified: 21 Nov 2024

    As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)

    Published: 11 Apr 2022
    9.8
    Critical

    CVE-2022-22954

    Last Modified: 30 Oct 2025

    VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

    Published: 11 Apr 2022
    5.3
    Medium

    CVE-2021-22055

    Last Modified: 21 Nov 2024

    The SchedulerServer in Vmware photon allows remote attackers to inject logs through \r in the package parameter. Attackers can also insert malicious data and fake entries.

    Published: 11 Apr 2022
    6.2
    Medium

    CVE-2022-28544

    Last Modified: 21 Nov 2024

    Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allows attacker to access the file of Galaxy store.

    Published: 11 Apr 2022
    6.8
    Medium

    CVE-2022-28542

    Last Modified: 21 Nov 2024

    Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access privileged content providers as Galaxy Store permission.

    Published: 11 Apr 2022
    4
    Medium

    CVE-2022-28543

    Last Modified: 21 Nov 2024

    Path traversal vulnerability in Samsung Flow prior to version 4.8.07.4 allows local attackers to read arbitrary files as Samsung Flow permission.

    Published: 11 Apr 2022
    5.9
    Medium

    CVE-2022-28541

    Last Modified: 21 Nov 2024

    Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as Samsung Update permission.

    Published: 11 Apr 2022
    6.2
    Medium

    CVE-2022-27843

    Last Modified: 21 Nov 2024

    DLL hijacking vulnerability in Kies prior to version 2.6.4.22014_2 allows attacker to execute abitrary code.

    Published: 11 Apr 2022
    4.3
    Medium

    CVE-2022-27841

    Last Modified: 21 Nov 2024

    Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication

    Published: 11 Apr 2022
    6.2
    Medium

    CVE-2022-27842

    Last Modified: 21 Nov 2024

    DLL hijacking vulnerability in Smart Switch PC prior to version 4.2.22022_4 allows attacker to execute abitrary code.

    Published: 11 Apr 2022
    4.4
    Medium

    CVE-2022-27840

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in SamsungRecovery prior to version 8.1.43.0 allows local attckers to delete arbitrary files as SamsungRecovery permission.

    Published: 11 Apr 2022
    3.3
    Low

    CVE-2022-27839

    Last Modified: 21 Nov 2024

    Improper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to access bookmark tab without proper credentials.

    Published: 11 Apr 2022
    7.7
    High

    CVE-2022-27838

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in FactoryCamera prior to version 2.1.96 allows attacker to access the file with system privilege.

    Published: 11 Apr 2022
    4.4
    Medium

    CVE-2022-27837

    Last Modified: 21 Nov 2024

    A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Android S(12.0) allows attacker to access the file with system privilege.

    Published: 11 Apr 2022
    8.4
    High

    CVE-2022-27836

    Last Modified: 21 Nov 2024

    Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local attackers to access arbitrary system files without a proper permission. The patch adds proper validation logic to prevent arbitrary files access.

    Published: 11 Apr 2022
    7.6
    High

    CVE-2022-27835

    Last Modified: 21 Nov 2024

    Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write.

    Published: 11 Apr 2022
    2.9
    Low

    CVE-2022-27834

    Last Modified: 21 Nov 2024

    Use after free vulnerability in dsp_context_unload_graph function of DSP driver prior to SMR Apr-2022 Release 1 allows attackers to perform malicious actions.

    Published: 11 Apr 2022
    4
    Medium

    CVE-2022-27832

    Last Modified: 21 Nov 2024

    Improper boundary check in media.extractor library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via a crafted media file.

    Published: 11 Apr 2022
    4.4
    Medium

    CVE-2022-27833

    Last Modified: 21 Nov 2024

    Improper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write by integer overflow.

    Published: 11 Apr 2022
    2.9
    Low

    CVE-2022-27831

    Last Modified: 21 Nov 2024

    Improper boundary check in sflvd_rdbuf_bits of libsflvextractor prior to SMR Apr-2022 Release 1 allows attackers to read out of bounds memory.

    Published: 11 Apr 2022
    8.5
    High

    CVE-2022-27830

    Last Modified: 21 Nov 2024

    Improper validation vulnerability in SemBlurInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

    Published: 11 Apr 2022
    8.5
    High

    CVE-2022-27829

    Last Modified: 21 Nov 2024

    Improper validation vulnerability in VerifyCredentialResponse prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

    Published: 11 Apr 2022
    8.5
    High

    CVE-2022-27828

    Last Modified: 21 Nov 2024

    Improper validation vulnerability in MediaMonitorEvent prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

    Published: 11 Apr 2022
    8.5
    High

    CVE-2022-27826

    Last Modified: 21 Nov 2024

    Improper validation vulnerability in SemSuspendDialogInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

    Published: 11 Apr 2022
    8.5
    High

    CVE-2022-27827

    Last Modified: 21 Nov 2024

    Improper validation vulnerability in MediaMonitorDimension prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

    Published: 11 Apr 2022
    4
    Medium

    CVE-2022-27825

    Last Modified: 21 Nov 2024

    Improper size check in sapefd_parse_meta_HEADER function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.

    Published: 11 Apr 2022
    4
    Medium

    CVE-2022-27824

    Last Modified: 21 Nov 2024

    Improper size check of in sapefd_parse_meta_DESCRIPTION function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file

    Published: 11 Apr 2022
    4
    Medium

    CVE-2022-27823

    Last Modified: 21 Nov 2024

    Improper size check in sapefd_parse_meta_HEADER_old function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.

    Published: 11 Apr 2022
    6.6
    Medium

    CVE-2022-27822

    Last Modified: 21 Nov 2024

    Information exposure vulnerability in ril property setting prior to SMR April-2022 Release 1 allows access to EF_RUIMID value without permission.

    Published: 11 Apr 2022
    4
    Medium

    CVE-2022-27821

    Last Modified: 21 Nov 2024

    Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via crafted image file.

    Published: 11 Apr 2022
    3.3
    Low

    CVE-2022-27576

    Last Modified: 21 Nov 2024

    Information exposure vulnerability in Samsung DeX Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission

    Published: 11 Apr 2022
    3.3
    Low

    CVE-2022-27575

    Last Modified: 21 Nov 2024

    Information exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission.

    Published: 11 Apr 2022
    4.4
    Medium

    CVE-2022-27573

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in parser_infe and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by privileged attackers.

    Published: 11 Apr 2022
    4.4
    Medium

    CVE-2022-27574

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in parser_iloc and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by privileged attacker.

    Published: 11 Apr 2022
    8.1
    High

    CVE-2022-27572

    Last Modified: 21 Nov 2024

    Heap-based buffer overflow vulnerability in parser_ipma function of libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attackers.

    Published: 11 Apr 2022
    8.1
    High

    CVE-2022-27571

    Last Modified: 21 Nov 2024

    Heap-based buffer overflow vulnerability in sheifd_get_info_image function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.

    Published: 11 Apr 2022
    8.1
    High

    CVE-2022-27570

    Last Modified: 21 Nov 2024

    Heap-based buffer overflow vulnerability in parser_single_iref function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.

    Published: 11 Apr 2022