Vulnerabilites CVE
Base de donnees CVE enrichie avec CISA KEV et NVD
| CVE ID | CVSS | Severite | KEV | Observations |
|---|---|---|---|---|
| CVE-2022-26427 In camera isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not ... | 6.7 | MEDIUM | — | 0 |
| CVE-2022-21789 In audio ipi, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed fo... | 6.4 | MEDIUM | — | 0 |
| CVE-2022-21790 In camera isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not ne... | 4.4 | MEDIUM | — | 0 |
| CVE-2022-21791 In camera isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not ne... | 4.4 | MEDIUM | — | 0 |
| CVE-2022-21792 In camera isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not ... | 6.7 | MEDIUM | — | 0 |
| CVE-2022-26426 In camera isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not ... | 6.7 | MEDIUM | — | 0 |
| CVE-2022-26428 In video codec, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed ... | 6.4 | MEDIUM | — | 0 |
| CVE-2022-26429 In cta, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges ... | 7.8 | HIGH | — | 0 |
| CVE-2022-26430 In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for ... | 6.7 | MEDIUM | — | 0 |
| CVE-2022-26431 In mailbox, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not nee... | 6.7 | MEDIUM | — | 0 |
| CVE-2022-26432 In mailbox, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not nee... | 6.7 | MEDIUM | — | 0 |
| CVE-2022-26433 In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for ... | 6.7 | MEDIUM | — | 0 |
| CVE-2022-26434 In mailbox, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not nee... | 6.7 | MEDIUM | — | 0 |
| CVE-2022-26436 In emi mpu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not neede... | 4.4 | MEDIUM | — | 0 |
| CVE-2022-26437 In httpclient, there is a possible out of bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is ... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-26438 In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not... | 6.7 | MEDIUM | — | 0 |
| CVE-2022-26439 In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not... | 6.7 | MEDIUM | — | 0 |
| CVE-2022-26440 In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not... | 6.7 | MEDIUM | — | 0 |
| CVE-2022-26441 In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not... | 6.7 | MEDIUM | — | 0 |
| CVE-2022-26442 In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not... | 6.7 | MEDIUM | — | 0 |
| CVE-2022-26443 In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not... | 6.7 | MEDIUM | — | 0 |
| CVE-2022-26444 In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not... | 6.7 | MEDIUM | — | 0 |
| CVE-2022-26445 In wifi driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not... | 6.7 | MEDIUM | — | 0 |
| CVE-2022-34567 An issue in \Roaming\Mango\Plugins of University of Texas Multi-image Analysis GUI (Mango) 4.1 allows attackers to escalate privileges via crafted plugins. | 8.8 | HIGH | — | 0 |
| CVE-2022-36301 BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device password. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-36302 File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access different resources, which may contain sensitive information. | 8.8 | HIGH | — | 0 |
| CVE-2022-36343 Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin <= 1.0.1 at WordPress. | 3.4 | LOW | — | 0 |
| CVE-2022-2571 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0101. | 7.8 | HIGH | — | 0 |
| CVE-2022-35785 Azure Site Recovery Elevation of Privilege Vulnerability | 6.5 | MEDIUM | — | 0 |
| CVE-2022-2580 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0102. | 7.8 | HIGH | — | 0 |
| CVE-2022-2581 Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0104. | 7.8 | HIGH | — | 0 |
| CVE-2022-2589 Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.3. | 6.1 | MEDIUM | — | 0 |
| CVE-2022-2595 Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1. | 10.0 | CRITICAL | — | 0 |
| CVE-2022-30698 NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried fo... | 6.5 | MEDIUM | — | 0 |
| CVE-2022-30699 NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried f... | 6.5 | MEDIUM | — | 0 |
| CVE-2022-33955 IBM CICS TX 11.1 could allow allow an attacker with physical access to the system to execute code due using a back and refresh attack. IBM X-Force ID: 229312. | 6.8 | MEDIUM | — | 0 |
| CVE-2022-34161 IBM CICS TX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID... | 8.8 | HIGH | — | 0 |
| CVE-2022-34162 IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to ... | 6.1 | MEDIUM | — | 0 |
| CVE-2022-34163 IBM CICS TX 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable syst... | 6.1 | MEDIUM | — | 0 |
| CVE-2022-34164 IBM CICS TX 11.1 could allow a local user to impersonate another legitimate user due to improper input validation. IBM X-Force ID: 229338. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-27619 Cleartext transmission of sensitive information vulnerability in authentication management in Synology Note Station Client before 2.2.2-609 allows man-in-the-middle attackers to obtain sensitive infor... | 6.8 | MEDIUM | — | 0 |
| CVE-2022-34307 IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this li... | 4.3 | MEDIUM | — | 0 |
| CVE-2022-31109 laminas-diactoros is a PHP package containing implementations of the PSR-7 HTTP message interfaces and PSR-17 HTTP message factory interfaces. Applications that use Diactoros, and are either not behin... | 7.2 | HIGH | — | 0 |
| CVE-2022-31128 Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions Tuleap does not properly verify permissions when creating branches with the ... | 5.4 | MEDIUM | — | 0 |
| CVE-2022-31148 Shopware is an open source e-commerce software. In versions from 5.7.0 a persistent cross site scripting (XSS) vulnerability exists in the customer module. Users are recommend to update to the current... | 5.4 | MEDIUM | — | 0 |
| CVE-2022-34530 An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames. | 5.3 | MEDIUM | — | 0 |
| CVE-2022-31154 Sourcegraph is an opensource code search and navigation engine. It is possible for an authenticated Sourcegraph user to edit the Code Monitors owned by any other Sourcegraph user. This includes being ... | 6.4 | MEDIUM | — | 0 |
| CVE-2022-31155 Sourcegraph is an opensource code search and navigation engine. In Sourcegraph versions before 3.41.0, it is possible for an attacker to delete other users’ saved searches due to a bug in the authoriz... | 4.3 | MEDIUM | — | 0 |
| CVE-2022-31173 Juniper is a GraphQL server library for Rust. Affected versions of Juniper are vulnerable to uncontrolled recursion resulting in a program crash. This issue has been addressed in version 0.15.10. User... | 7.5 | HIGH | — | 0 |
| CVE-2022-31178 eLabFTW is an electronic lab notebook manager for research teams. A vulnerability was discovered which allows a logged in user to read a template without being authorized to do so. This vulnerability ... | 4.3 | MEDIUM | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.