Vulnerabilites CVE
Base de donnees CVE enrichie avec CISA KEV et NVD
| CVE ID | CVSS | Severite | KEV | Observations |
|---|---|---|---|---|
| CVE-2022-42164 Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetClientState. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-41305 A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with... | 7.8 | HIGH | — | 0 |
| CVE-2022-41306 A maliciously crafted PCT file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other ... | 7.8 | HIGH | — | 0 |
| CVE-2022-41307 A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with ... | 7.8 | HIGH | — | 0 |
| CVE-2022-41308 A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with ... | 7.8 | HIGH | — | 0 |
| CVE-2022-42234 There is a file inclusion vulnerability in the template management module in UCMS 1.6 | 8.8 | HIGH | — | 0 |
| CVE-2022-2963 A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault. | 7.5 | HIGH | — | 0 |
| CVE-2022-2984 In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-2985 In music service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed. | 7.8 | HIGH | — | 0 |
| CVE-2022-38669 In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed. | 7.8 | HIGH | — | 0 |
| CVE-2022-38670 In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed. | 7.8 | HIGH | — | 0 |
| CVE-2022-42165 Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetDeviceName. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-38672 In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-38673 In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-38676 In gpu driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-38677 In cell service, there is a missing permission check. This could lead to local denial of service in cell service with no additional execution privileges needed. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-41471 74cmsSE v3.12.0 allows authenticated attackers with low-level privileges to arbitrarily change the rights and credentials of the Super Administrator account. | 6.5 | MEDIUM | — | 0 |
| CVE-2022-38679 In music service, there is a missing permission check. This could lead to local denial of service in music service with no additional execution privileges needed. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-38687 In messaging service, there is a missing permission check. This could lead to local denial of service in messaging service with no additional execution privileges needed. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-38688 In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-38689 In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-2762 The AdminPad WordPress plugin before 2.2 does not have CSRF check when updating admin's note, allowing attackers to make a logged in admin update their notes via a CSRF attack | 6.5 | MEDIUM | — | 0 |
| CVE-2022-38690 In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-38697 In messaging service, there is a missing permission check. This could lead to access unexpected provider in contacts service with no additional execution privileges needed. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-38698 In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed. | 7.8 | HIGH | — | 0 |
| CVE-2022-39080 In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed. | 7.8 | HIGH | — | 0 |
| CVE-2022-41472 74cmsSE v3.12.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /apiadmin/notice/add. This vulnerability allows attackers to execute arbitrary web scripts or HTM... | 5.4 | MEDIUM | — | 0 |
| CVE-2022-39103 In Gallery service, there is a missing permission check. This could lead to local denial of service in Gallery service with no additional execution privileges needed. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-39105 In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-39107 In Soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in Soundrecorder service with no additional execution privileges needed. | 7.8 | HIGH | — | 0 |
| CVE-2022-39108 In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed. | 7.8 | HIGH | — | 0 |
| CVE-2022-41498 Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editbrand.php. | 7.2 | HIGH | — | 0 |
| CVE-2022-39109 In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed. | 7.8 | HIGH | — | 0 |
| CVE-2022-39110 In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed. | 7.8 | HIGH | — | 0 |
| CVE-2022-39111 In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed. | 7.8 | HIGH | — | 0 |
| CVE-2022-39112 In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-2834 The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensiti... | 5.3 | MEDIUM | — | 0 |
| CVE-2022-39113 In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-39114 In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-39115 In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-39117 In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-3082 The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logged in users, such as subscriber to call them, and di... | 6.5 | MEDIUM | — | 0 |
| CVE-2022-39120 In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-39121 In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-39122 In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-39123 In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-3126 The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could allow attackers to make logged in users upload files on their behalf | 4.3 | MEDIUM | — | 0 |
| CVE-2022-39124 In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-39125 In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | 5.5 | MEDIUM | — | 0 |
| CVE-2022-39126 In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel. | 5.5 | MEDIUM | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.