‼ CVE-2022-26393 ‼
📖 Read
via "National Vulnerability Database".
The Baxter Spectrum WBM is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information or cause a Denial of Service (DoS) on the WBM.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-38280 ‼
📖 Read
via "National Vulnerability Database".
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/image/list.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-36843 ‼
📖 Read
via "National Vulnerability Database".
A heap-based overflow vulnerability in MHW_RECOG_LIB_INFO function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-37299 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in Shirne CMS 1.2.0. There is a Path Traversal vulnerability which could cause arbitrary file read via /static/ueditor/php/controller.php📖 Read
via "National Vulnerability Database".
‼ CVE-2022-38700 ‼
📖 Read
via "National Vulnerability Database".
OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-38281 ‼
📖 Read
via "National Vulnerability Database".
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/site/list.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-39845 ‼
📖 Read
via "National Vulnerability Database".
Improper validation of integrity check vulnerability in Samsung Kies prior to version 2.6.4.22074 allows local attackers to delete arbitrary directory using directory junction.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-37412 ‼
📖 Read
via "National Vulnerability Database".
Authenticated (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Galerio & Urda's Better Delete Revision plugin <= 1.6.1 at WordPress.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-2905 ‼
📖 Read
via "National Vulnerability Database".
An out-of-bounds memory read flaw was found in the Linux kernel's BPF subsystem in how a user calls the bpf_tail_call function with a key larger than the max_entries of the map. This flaw allows a local user to gain unauthorized access to data.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-36849 ‼
📖 Read
via "National Vulnerability Database".
Use after free vulnerability in sdp_mm_set_process_sensitive function of sdpmm driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-37335 ‼
📖 Read
via "National Vulnerability Database".
Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in WHA's Word Search Puzzles game plugin <= 2.0.1 at WordPress.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-2526 ‼
📖 Read
via "National Vulnerability Database".
A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-36875 ‼
📖 Read
via "National Vulnerability Database".
Improper restriction of broadcasting Intent in SaWebViewRelayActivity of?Waterplugin prior to version 2.2.11.22081151 allows attacker to access the file without permission.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-36870 ‼
📖 Read
via "National Vulnerability Database".
Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-38064 ‼
📖 Read
via "National Vulnerability Database".
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-38701 ‼
📖 Read
via "National Vulnerability Database".
OpenHarmony-v3.1.2 and prior versions have a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-36376 ‼
📖 Read
via "National Vulnerability Database".
Server-Side Request Forgery (SSRF) vulnerability in Rank Math SEO plugin <= 1.0.95 at WordPress.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-40133 ‼
📖 Read
via "National Vulnerability Database".
A use-after-free(UAF) vulnerability was found in function 'vmw_execbuf_tie_context' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in Linux kernel's vmwgfx driver with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).📖 Read
via "National Vulnerability Database".
‼ CVE-2022-36876 ‼
📖 Read
via "National Vulnerability Database".
Improper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical attackers to access account list without authentication.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-36858 ‼
📖 Read
via "National Vulnerability Database".
A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc() function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-38059 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Alexey Trofimov's Access Code Feeder plugin <= 1.0.3 at WordPress.📖 Read
via "National Vulnerability Database".