Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-25078 1 Totolink 1 A3600r Firmware 2023-08-08 7.5 HIGH 9.8 CRITICAL
TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
CVE-2022-25077 1 Totolink 2 A3100r, A3100r Firmware 2023-08-08 7.5 HIGH 9.8 CRITICAL
TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
CVE-2022-25076 1 Totolink 2 A800r, A800r Firmware 2023-08-08 7.5 HIGH 9.8 CRITICAL
TOTOLink A800R V4.1.2cu.5137_B20200730 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
CVE-2022-25075 1 Totolink 2 A3000ru, A3000ru Firmware 2023-08-08 7.5 HIGH 9.8 CRITICAL
TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
CVE-2022-23176 1 Watchguard 1 Fireware 2023-08-08 9.0 HIGH 8.8 HIGH
WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. This vulnerability impacts Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U3, and 12.2.x through 12.5.x before 12.5.7_U3.
CVE-2022-24295 1 Okta 1 Advanced Server Access Client For Windows 2023-08-08 6.8 MEDIUM 8.8 HIGH
Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially crafted URL.
CVE-2022-25336 1 Ibexa 1 Ez Platform Kernel 2023-08-08 4.3 MEDIUM 5.3 MEDIUM
Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path and filename can be correctly deduced.
CVE-2021-45382 1 Dlink 12 Dir-810l, Dir-810l Firmware, Dir-820l and 9 more 2023-08-08 10.0 HIGH 9.8 CRITICAL
A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file. Note: DIR-810L, DIR-820L, DIR-830L, DIR-826L, DIR-836L, all hardware revisions, have reached their End of Life ("EOL") /End of Service Life ("EOS") Life-Cycle and as such this issue will not be patched.
CVE-2022-24985 1 Jqueryform 1 Jqueryform 2023-08-08 6.0 MEDIUM 8.8 HIGH
Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to bypass authentication and access the administrative section of other forms hosted on the same web server. This is relevant only when an organization hosts more than one of these forms on their server.
CVE-2021-42714 2 Microsoft, Splashtop 2 Windows, Splashtop 2023-08-08 7.2 HIGH 7.8 HIGH
Splashtop Remote Client (Business Edition) through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions.
CVE-2021-42713 2 Microsoft, Splashtop 2 Windows, Splashtop 2023-08-08 7.2 HIGH 7.8 HIGH
Splashtop Remote Client (Personal Edition) through 3.4.6.1 creates a Temporary File in a Directory with Insecure Permissions.
CVE-2022-23389 1 Publiccms 1 Publiccms 2023-08-08 7.5 HIGH 9.8 CRITICAL
PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.
CVE-2022-24988 1 Galois 2p8 Project 1 Galois 2p8 2023-08-08 7.5 HIGH 9.8 CRITICAL
In galois_2p8 before 0.1.2, PrimitivePolynomialField::new has an off-by-one buffer overflow for a vector.
CVE-2022-0305 1 Google 1 Chrome 2023-08-08 4.3 MEDIUM 6.5 MEDIUM
Inappropriate implementation in Service Worker API in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
CVE-2022-0301 1 Google 1 Chrome 2023-08-08 6.8 MEDIUM 7.8 HIGH
Heap buffer overflow in DevTools in Google Chrome prior to 97.0.4692.99 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-4100 1 Google 1 Chrome 2023-08-08 6.8 MEDIUM 8.8 HIGH
Object lifecycle issue in ANGLE in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-46362 1 Magnolia-cms 1 Magnolia Cms 2023-08-08 7.5 HIGH 9.8 CRITICAL
A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullname parameter.
CVE-2021-39688 1 Google 1 Android 2023-08-08 2.1 LOW 5.5 MEDIUM
In TBD of TBD, there is a possible out of bounds read due to TBD. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-206039140References: N/A
CVE-2022-21174 1 Intel 1 Quartus Prime 2023-08-08 4.6 MEDIUM 7.8 HIGH
Improper access control in a third-party component of Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2022-21157 1 Intel 1 Smart Campus 2023-08-08 2.1 LOW 5.5 MEDIUM
Improper access control in the Intel(R) Smart Campus Android application before version 6.1 may allow authenticated user to potentially enable information disclosure via local access.
CVE-2022-21153 1 Intel 1 Capital Global Summit 2023-08-08 2.1 LOW 5.5 MEDIUM
Improper access control in the Intel(R) Capital Global Summit Android application may allow an authenticated user to potentially enable information disclosure via local access.
CVE-2022-20038 2 Google, Mediatek 9 Android, Mt6833, Mt6853 and 6 more 2023-08-08 4.6 MEDIUM 6.7 MEDIUM
In ccu driver, there is a possible memory corruption due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06183335; Issue ID: ALPS06183335.
CVE-2022-20037 2 Google, Mediatek 57 Android, Mt6735, Mt6737 and 54 more 2023-08-08 2.1 LOW 5.5 MEDIUM
In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171705; Issue ID: ALPS06171705.
CVE-2022-20036 2 Google, Mediatek 56 Android, Mt6735, Mt6737 and 53 more 2023-08-08 2.1 LOW 5.5 MEDIUM
In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171689; Issue ID: ALPS06171689.
CVE-2022-20017 2 Google, Mediatek 26 Android, Mt6765, Mt6785 and 23 more 2023-08-08 2.1 LOW 5.5 MEDIUM
In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05862991; Issue ID: ALPS05862991.
CVE-2021-33061 1 Intel 6 82599eb, 82599eb Firmware, 82599en and 3 more 2023-08-08 2.1 LOW 5.5 MEDIUM
Insufficient control flow management for the Intel(R) 82599 Ethernet Controllers and Adapters may allow an authenticated user to potentially enable denial of service via local access.
CVE-2021-0147 1 Intel 1 Power Management Controller 2023-08-08 2.1 LOW 4.4 MEDIUM
Improper locking in the Power Management Controller (PMC) for some Intel Chipset firmware before versions pmc_fw_lbg_c1-21ww02a and pmc_fw_lbg_b0-21ww02a may allow a privileged user to potentially enable denial of service via local access.
CVE-2021-0127 2 Intel, Netapp 755 Celeron G1610, Celeron G1610t, Celeron G1620 and 752 more 2023-08-08 2.1 LOW 5.5 MEDIUM
Insufficient control flow management in some Intel(R) Processors may allow an authenticated user to potentially enable a denial of service via local access.
CVE-2022-23276 2 Linux, Microsoft 2 Linux Kernel, Sql Server 2023-08-08 4.6 MEDIUM 7.8 HIGH
SQL Server for Linux Containers Elevation of Privilege Vulnerability
CVE-2022-23273 1 Microsoft 1 Dynamics Gp 2023-08-08 9.0 HIGH 7.1 HIGH
Microsoft Dynamics GP Elevation Of Privilege Vulnerability
CVE-2022-23272 1 Microsoft 1 Dynamics Gp 2023-08-08 9.0 HIGH 8.1 HIGH
Microsoft Dynamics GP Elevation Of Privilege Vulnerability
CVE-2022-23271 1 Microsoft 1 Dynamics Gp 2023-08-08 9.0 HIGH 6.5 MEDIUM
Microsoft Dynamics GP Elevation Of Privilege Vulnerability
CVE-2022-22717 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-08-08 6.9 MEDIUM 7.0 HIGH
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2022-22715 1 Microsoft 4 Windows 10, Windows 11, Windows Server and 1 more 2023-08-08 7.2 HIGH 7.8 HIGH
Named Pipe File System Elevation of Privilege Vulnerability
CVE-2022-22001 1 Microsoft 9 Windows 10, Windows 11, Windows 7 and 6 more 2023-08-08 7.2 HIGH 7.8 HIGH
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVE-2022-22000 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-08-08 7.2 HIGH 7.8 HIGH
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2022-21997 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-08-08 3.6 LOW 7.1 HIGH
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2022-21996 1 Microsoft 1 Windows 11 2023-08-08 7.2 HIGH 7.8 HIGH
Win32k Elevation of Privilege Vulnerability
CVE-2022-21994 1 Microsoft 4 Windows 10, Windows 11, Windows Server and 1 more 2023-08-08 7.2 HIGH 7.8 HIGH
Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2022-21989 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-08-08 6.9 MEDIUM 7.8 HIGH
Windows Kernel Elevation of Privilege Vulnerability
CVE-2022-21981 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-08-08 4.6 MEDIUM 7.8 HIGH
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2022-21971 1 Microsoft 4 Windows 10, Windows 11, Windows Server and 1 more 2023-08-08 9.3 HIGH 7.8 HIGH
Windows Runtime Remote Code Execution Vulnerability
CVE-2022-24682 1 Zimbra 1 Collaboration 2023-08-08 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.
CVE-2021-45327 1 Gitea 1 Gitea 2023-08-08 7.5 HIGH 9.8 CRITICAL
Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. which could let a remote malisious user execute arbitrary code.
CVE-2022-21173 1 Elecom 16 Wrh-300bk3, Wrh-300bk3-s, Wrh-300bk3-s Firmware and 13 more 2023-08-08 8.3 HIGH 8.8 HIGH
Hidden functionality vulnerability in ELECOM LAN routers (WRH-300BK3 firmware v1.05 and earlier, WRH-300WH3 firmware v1.05 and earlier, WRH-300BK3-S firmware v1.05 and earlier, WRH-300DR3-S firmware v1.05 and earlier, WRH-300LB3-S firmware v1.05 and earlier, WRH-300PN3-S firmware v1.05 and earlier, WRH-300WH3-S firmware v1.05 and earlier, and WRH-300YG3-S firmware v1.05 and earlier) allows an attacker on the adjacent network to execute an arbitrary OS command via unspecified vectors.
CVE-2022-23263 1 Microsoft 1 Edge Chromium 2023-08-08 4.4 MEDIUM 7.7 HIGH
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2022-23262 1 Microsoft 1 Edge Chromium 2023-08-08 6.8 MEDIUM 6.3 MEDIUM
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2022-24552 1 Starwindsoftware 2 Nas, San 2023-08-08 10.0 HIGH 9.8 CRITICAL
A flaw was found in the REST API in StarWind Stack. REST command, which manipulates a virtual disk, doesn’t check input parameters. Some of them go directly to bash as part of a script. An attacker with non-root user access can inject arbitrary data into the command that will be executed with root privileges. This affects StarWind SAN and NAS v0.2 build 1633.
CVE-2022-22832 1 Servisnet 1 Tessa 2023-08-08 10.0 HIGH 9.8 CRITICAL
An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/users/ request.
CVE-2021-45741 1 Totolink 2 X5000r, X5000r Firmware 2023-08-08 7.8 HIGH 7.5 HIGH
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setIpv6Cfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the relay6to4 parameters.