CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-25441

    Last Modified: 21 Nov 2024

    Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the vlanid parameter in the SetIPTVCfg function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25440

    Last Modified: 21 Nov 2024

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25438

    Last Modified: 21 Nov 2024

    Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the SetIPTVCfg function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25439

    Last Modified: 21 Nov 2024

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25437

    Last Modified: 21 Nov 2024

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25435

    Last Modified: 21 Nov 2024

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetStaticRoutecfg function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25434

    Last Modified: 21 Nov 2024

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the firewallen parameter in the SetFirewallCfg function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25433

    Last Modified: 21 Nov 2024

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the urls parameter in the saveparentcontrolinfo function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25428

    Last Modified: 21 Nov 2024

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the deviceId parameter in the saveparentcontrolinfo function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25431

    Last Modified: 21 Nov 2024

    Tenda AC9 v15.03.2.21 was discovered to contain multiple stack overflows via the NPTR, V12, V10 and V11 parameter in the Formsetqosband function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25429

    Last Modified: 21 Nov 2024

    Tenda AC9 v15.03.2.21 was discovered to contain a buffer overflow via the time parameter in the saveparentcontrolinfo function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25427

    Last Modified: 21 Nov 2024

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-27250

    Last Modified: 21 Nov 2024

    The UNISOC chipset through 2022-03-15 allows attackers to obtain remote control of a mobile phone, e.g., to obtain sensitive information from text messages or the device's screen, record video of the device's physical environment, or modify data.

    Published: 18 Mar 2022
    —
    Unknown

    CVE-2022-26502

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 18 Mar 2022
    5.3
    Medium

    CVE-2020-25193

    Last Modified: 16 Apr 2025

    By having access to the hard-coded cryptographic key for GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06, attackers would be able to intercept and decrypt encrypted traffic through an HTTPS connection.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2020-25197

    Last Modified: 16 Apr 2025

    A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06 that could allow an authenticated remote attacker to execute arbitrary code on the system.

    Published: 18 Mar 2022
    5.3
    Medium

    CVE-2020-25180

    Last Modified: 16 Apr 2025

    Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of encryption performed with a fixed key value using the tiny encryption algorithm (TEA) on an entered or saved password. A remote, unauthenticated attacker could pass their own encrypted password to the ISaGRAF 5 Runtime, which may result in information disclosure on the device.

    Published: 18 Mar 2022
    7.8
    High

    CVE-2020-25184

    Last Modified: 16 Apr 2025

    Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable without any additional modification. A local, unauthenticated attacker could compromise the user passwords, resulting in information disclosure.

    Published: 18 Mar 2022
    9.1
    Critical

    CVE-2020-25176

    Last Modified: 16 Apr 2025

    Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not checked for reserved characters, it is possible for a remote, unauthenticated attacker to traverse an application’s directory, which could lead to remote code execution.

    Published: 18 Mar 2022
    7.5
    High

    CVE-2020-25178

    Last Modified: 16 Apr 2025

    ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Data is transferred over this protocol unencrypted, which could allow a remote unauthenticated attacker to upload, read, and delete files.

    Published: 18 Mar 2022
    6.7
    Medium

    CVE-2020-25182

    Last Modified: 16 Apr 2025

    Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries could allow a local, unauthenticated attacker to execute arbitrary code. This vulnerability only affects ISaGRAF Runtime when running on Microsoft Windows systems.

    Published: 18 Mar 2022
    2.8
    Low

    CVE-2020-16232

    Last Modified: 16 Apr 2025

    In Yokogawa WideField3 R1.01 - R4.03, a buffer overflow could be caused when a user loads a maliciously crafted project file.

    Published: 18 Mar 2022
    6.6
    Medium

    CVE-2022-25607

    Last Modified: 20 Feb 2025

    Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727).

    Published: 18 Mar 2022
    4.8
    Medium

    CVE-2022-25605

    Last Modified: 20 Feb 2025

    Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vvulnerable parameters &download_path, &download_path_url, &download_page_url.

    Published: 18 Mar 2022
    8.3
    High

    CVE-2022-25602

    Last Modified: 20 Feb 2025

    Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugin (versions <= 4.1.7).

    Published: 18 Mar 2022
    4.1
    Medium

    CVE-2022-25604

    Last Modified: 20 Feb 2025

    Authenticated (contributor of higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Price Table plugin (versions <= 0.2.2).

    Published: 18 Mar 2022
    4.8
    Medium

    CVE-2021-23209

    Last Modified: 23 Apr 2025

    Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP – Accelerated Mobile Pages WordPress plugin (versions <= 1.0.77.32).

    Published: 18 Mar 2022
    4.8
    Medium

    CVE-2021-23150

    Last Modified: 23 Apr 2025

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pages plugin <= 1.0.77.31 versions.

    Published: 18 Mar 2022
    4.8
    Medium

    CVE-2021-44760

    Last Modified: 23 Apr 2025

    Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability discovered in WP-DownloadManager plugin <= 1.68.6 versions.

    Published: 18 Mar 2022
    4.8
    Medium

    CVE-2022-25603

    Last Modified: 20 Feb 2025

    Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in MaxGalleria WordPress plugin (versions 6.2.5).

    Published: 18 Mar 2022
    2
    Low

    CVE-2022-1002

    Last Modified: 6 Dec 2024

    Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML content in the email invitations.

    Published: 18 Mar 2022
    3.3
    Low

    CVE-2022-1003

    Last Modified: 6 Dec 2024

    One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-0547

    Last Modified: 3 Nov 2025

    OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

    Published: 18 Mar 2022
    6.5
    Medium

    CVE-2022-22659

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in iOS 15.4 and iPadOS 15.4. An attacker in a privileged network position may be able to leak sensitive user information.

    Published: 18 Mar 2022
    3.3
    Low

    CVE-2022-22670

    Last Modified: 21 Nov 2024

    An access issue was addressed with improved access restrictions. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, watchOS 8.5. A malicious application may be able to identify what other applications a user has installed.

    Published: 18 Mar 2022
    7.8
    High

    CVE-2022-22667

    Last Modified: 21 Nov 2024

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.4 and iPadOS 15.4. An application may be able to execute arbitrary code with kernel privileges.

    Published: 18 Mar 2022
    7.8
    High

    CVE-2022-22661

    Last Modified: 21 Nov 2024

    A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. An application may be able to execute arbitrary code with kernel privileges.

    Published: 18 Mar 2022
    4.6
    Medium

    CVE-2022-22671

    Last Modified: 21 Nov 2024

    An authentication issue was addressed with improved state management. This issue is fixed in iOS 15.4 and iPadOS 15.4. A person with physical access to an iOS device may be able to access photos from the lock screen.

    Published: 18 Mar 2022
    7.8
    High

    CVE-2022-22669

    Last Modified: 21 Nov 2024

    A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3. An application may be able to execute arbitrary code with kernel privileges.

    Published: 18 Mar 2022
    7.8
    High

    CVE-2022-22665

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.3. A malicious application may be able to gain root privileges.

    Published: 18 Mar 2022
    7.5
    High

    CVE-2022-22651

    Last Modified: 21 Nov 2024

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.3. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

    Published: 18 Mar 2022
    7.8
    High

    CVE-2022-22666

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, watchOS 8.5. Processing a maliciously crafted image may lead to heap corruption.

    Published: 18 Mar 2022
    3.3
    Low

    CVE-2022-22656

    Last Modified: 21 Nov 2024

    An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. A local attacker may be able to view the previous logged in user’s desktop from the fast user switching screen.

    Published: 18 Mar 2022
    7.5
    High

    CVE-2022-22653

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.4 and iPadOS 15.4. A malicious website may be able to access information about the user and their devices.

    Published: 18 Mar 2022
    7.8
    High

    CVE-2022-22664

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Logic Pro 10.7.3, GarageBand 10.4.6, macOS Monterey 12.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.

    Published: 18 Mar 2022
    7.8
    High

    CVE-2022-22657

    Last Modified: 21 Nov 2024

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in Logic Pro 10.7.3, GarageBand 10.4.6, macOS Monterey 12.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.

    Published: 18 Mar 2022
    5.5
    Medium

    CVE-2022-22660

    Last Modified: 21 Nov 2024

    This issue was addressed with a new entitlement. This issue is fixed in macOS Monterey 12.3. An app may be able to spoof system notifications and UI.

    Published: 18 Mar 2022
    5.5
    Medium

    CVE-2022-22648

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. An application may be able to read restricted memory.

    Published: 18 Mar 2022
    4.3
    Medium

    CVE-2022-22654

    Last Modified: 21 Nov 2024

    A user interface issue was addressed. This issue is fixed in watchOS 8.5, Safari 15.4. Visiting a malicious website may lead to address bar spoofing.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-22642

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in iOS 15.4 and iPadOS 15.4. A user may be able to bypass the Emergency SOS passcode prompt.

    Published: 18 Mar 2022