Common Vulnerabilities and Exposures (CVE) is a critical tool for maintaining software security, providing a standardized way to track and manage vulnerabilities across systems. Organizations should regularly monitor CVE databases, assess the impact of vulnerabilities, and apply patches promptly to reduce the risk of exploitation.
CVE (Common Vulnerabilities and Exposures) is a public database that provides a standardized method for identifying, tracking, and referencing publicly disclosed security vulnerabilities in software and hardware.
Each vulnerability receives a unique identifier called a CVE ID (e.g., CVE-2023-12345), making it easier to reference specific vulnerabilities across different tools and databases.
Total Search Results: 158437
CVE ID | Description | Severity | Published Date | Affected Vendor | Action |
---|---|---|---|---|---|
CVE-2022-30752 | Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_STATE_CHANGED action. | Unknown | N/A | Samsung Mobile | |
CVE-2022-30753 | Improper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers to get the device ID without permission. | Unknown | N/A | Samsung Mobile | |
CVE-2022-30754 | Implicit Intent hijacking vulnerability in AppLinker prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of AppLinker. | Unknown | N/A | Samsung Mobile | |
CVE-2022-30755 | Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijacking the implicit intent. | Unknown | N/A | Samsung Mobile | |
CVE-2022-30756 | Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of Finder. | Unknown | N/A | Samsung Mobile | |
CVE-2022-30757 | Improper authorization in isemtelephony prior to SMR Jul-2022 Release 1 allows attacker to obtain CID without ACCESS_FINE_LOCATION permission. | Unknown | N/A | Samsung Mobile | |
CVE-2022-30758 | Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to access some protected information with privilege of Finder. | Unknown | N/A | Samsung Mobile | |
CVE-2022-30759 | In Nokia One-NDS (aka Network Directory Server) through 20.9, some Sudo permissions can be exploited by some users to escalate to root privileges and execute arbitrary commands. | Unknown | N/A | n/a | |
CVE-2022-3076 | The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example. | Unknown | N/A | Unknown | |
CVE-2022-30760 | An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authenticated attackers to obtain sensitive student information (final grades, study courses, degrees) by changing the student ID parameter in the HTTP POST request to the FrontControllerSS endpoint. | Unknown | N/A | n/a | |
CVE-2022-30763 | Janet before 1.22.0 mishandles arrays. | Unknown | N/A | n/a | |
CVE-2022-30765 | Calibre-Web before 0.6.18 allows user table SQL Injection. | Unknown | N/A | n/a | |
CVE-2022-30767 | nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196. | Unknown | N/A | n/a | |
CVE-2022-30768 | A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: this exists in later versions than CVE-2019-7348 and requires a different attack method. | Unknown | N/A | n/a | |
CVE-2022-30769 | Session fixation exists in ZoneMinder through 1.36.12 as an attacker can poison a session cookie to the next logged-in user. | Unknown | N/A | n/a | |
CVE-2022-3077 | A buffer overflow vulnerability was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way it handled the I2C_SMBUS_BLOCK_PROC_CALL case (via the ioctl I2C_SMBUS) with malicious input data. This flaw could allow a local user to crash the system. | Unknown | N/A | n/a | |
CVE-2022-30770 | Terminalfour versions 8.3.7, 8.3.x versions prior to version 8.3.8 and r 8.2.x versions prior to version 8.2.18.5 or 8.2.18.2.1 are vulnerable to (XSS) vulnerability that could be exploited by an attacker to mislead an administrator and steal their credentials. | Unknown | N/A | n/a | |
CVE-2022-30771 | Initialization function in PnpSmm could lead to SMRAM corruption when using subsequent PNP SMI functions Initialization function in PnpSmm could lead to SMRAM corruption when using subsequent PNP SMI functions. This issue was discovered by Insyde engineering during a security review. Fixed in: Kernel 5.1: Version 05.17.25 Kernel 5.2: Version 05.27.25 Kernel 5.3: Version 05.36.25 Kernel 5.4: Version 05.44.25 Kernel 5.5: Version 05.52.25 https://www.insyde.com/security-pledge/SA-2022064 | Unknown | N/A | n/a | |
CVE-2022-30772 | Manipulation of the input address in PnpSmm function 0x52 could be used by malware to overwrite SMRAM or OS kernel memory. Function 0x52 of the PnpSmm driver is passed the address and size of data to write into the SMBIOS table, but manipulation of the address could be used by malware to overwrite SMRAM or OS kernel memory. This issue was discovered by Insyde engineering during a security review. This issue is fixed in: Kernel 5.0: 05.09.41 Kernel 5.1: 05.17.43 Kernel 5.2: 05.27.30 Kernel 5.3: 05.36.30 Kernel 5.4: 05.44.30 Kernel 5.5: 05.52.30 https://www.insyde.com/security-pledge/SA-2022065 | Unknown | N/A | n/a | |
CVE-2022-30773 | DMA attacks on the parameter buffer used by the IhisiSmm driver could change the contents after parameter values have been checked but before they are used (a TOCTOU attack). DMA attacks on the parameter buffer used by the IhisiSmm driver could change the contents after parameter values have been checked but before they are used (a TOCTOU attack). This issue was discovered by Insyde engineering. This issue is fixed in Kernel 5.4: 05.44.23 and Kernel 5.5: 05.52.23. CWE-367 | Unknown | N/A | n/a | |
CVE-2022-30774 | DMA attacks on the parameter buffer used by the PnpSmm driver could change the contents after parameter values have been checked but before they are used (a TOCTOU attack) DMA attacks on the parameter buffer used by the PnpSmm driver could change the contents after parameter values have been checked but before they are used (a TOCTOU attack) . This issue was discovered by Insyde engineering during a security review. This iss was fixed in Kernel 5.2: 05.27.29, Kernel 5.3: 05.36.25, Kernel 5.4: 05.44.25, Kernel 5.5: 05.52.25. CWE-367 https://www.insyde.com/security-pledge/SA-2022043 | Unknown | N/A | n/a | |
CVE-2022-30775 | xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafted PDF document to the pdftoppm binary. It is most easily reproduced with the DCMAKE_CXX_COMPILER=afl-clang-fast++ option. | Unknown | N/A | n/a | |
CVE-2022-30776 | atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter. | Unknown | N/A | n/a | |
CVE-2022-30777 | Parallels H-Sphere 3.6.1713 allows XSS via the index_en.php from parameter. | Unknown | N/A | n/a | |
CVE-2022-3078 | An issue was discovered in the Linux kernel through 5.16-rc6. There is a lack of check after calling vzalloc() and lack of free after allocation in drivers/media/test-drivers/vidtv/vidtv_s302m.c. | Unknown | N/A | n/a | |
CVE-2022-30780 | Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read_header_more in connections.c has a typo that disrupts use of multiple read operations on large headers. | Unknown | N/A | n/a | |
CVE-2022-30781 | Gitea before 1.16.7 does not escape git fetch remote. | Unknown | N/A | n/a | |
CVE-2022-30782 | Openmoney API through 2020-06-29 uses the JavaScript Math.random function, which does not provide cryptographically secure random numbers. | Unknown | N/A | n/a | |
CVE-2022-30783 | An invalid return code in fuse_kern_mount enables intercepting of libfuse-lite protocol traffic between NTFS-3G and the kernel in NTFS-3G through 2021.8.22 when using libfuse-lite. | Unknown | N/A | n/a | |
CVE-2022-30784 | A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22. | Unknown | N/A | n/a | |
CVE-2022-30785 | A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite. | Unknown | N/A | n/a | |
CVE-2022-30786 | A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22. | Unknown | N/A | n/a | |
CVE-2022-30787 | An integer underflow in fuse_lib_readdir enables arbitrary memory read operations in NTFS-3G through 2021.8.22 when using libfuse-lite. | Unknown | N/A | n/a | |
CVE-2022-30788 | A crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc in NTFS-3G through 2021.8.22. | Unknown | N/A | n/a | |
CVE-2022-30789 | A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3G through 2021.8.22. | Unknown | N/A | n/a | |
CVE-2022-3079 | Festo control block CPX-CEC-C1 and CPX-CMXX in multiple versions allow unauthenticated, remote access to critical webpage functions which may cause a denial of service. | Unknown | N/A | FESTO | |
CVE-2022-30790 | Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552. | Unknown | N/A | n/a | |
CVE-2022-30791 | In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected. | Unknown | N/A | CODESYS | |
CVE-2022-30792 | In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected. | Unknown | N/A | CODESYS | |
CVE-2022-30794 | Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php. | Unknown | N/A | n/a | |
CVE-2022-30795 | Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php. | Unknown | N/A | n/a | |
CVE-2022-30797 | Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php. | Unknown | N/A | n/a | |
CVE-2022-30798 | Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php. | Unknown | N/A | n/a | |
CVE-2022-30799 | Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php. | Unknown | N/A | n/a | |
CVE-2022-3080 | By sending specific queries to the resolver, an attacker can cause named to crash. | Unknown | N/A | ISC | |
CVE-2022-30804 | elitecms v1.01 is vulnerable to Delete any file via /admin/delete_image.php?file=. | Unknown | N/A | n/a | |
CVE-2022-30808 | elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php. | Unknown | N/A | n/a | |
CVE-2022-30809 | elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_page.php?page=. | Unknown | N/A | n/a | |
CVE-2022-30810 | elitecms v1.01 is vulnerable to SQL Injection via admin/edit_post.php. | Unknown | N/A | n/a | |
CVE-2022-30813 | elitecms 1.01 is vulnerable to SQL Injection via /admin/add_post.php. | Unknown | N/A | n/a | |
CVE-2022-30814 | elitecms v1.01 is vulnerable to SQL Injection via /admin/add_sidebar.php. | Unknown | N/A | n/a | |
CVE-2022-30815 | elitecms 1.01 is vulnerable to SQL Injection via admin/edit_sidebar.php?page=2&sidebar= | Unknown | N/A | n/a | |
CVE-2022-30816 | elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_sidebar.php. | Unknown | N/A | n/a | |
CVE-2022-30817 | Simple Bus Ticket Booking System 1.0 is vulnerable to SQL Injection via /SimpleBusTicket/index.php. | Unknown | N/A | n/a | |
CVE-2022-30818 | Wedding Management System v1.0 is vulnerable to SQL injection via /Wedding-Management/admin/blog_events_edit.php?id=31. | Unknown | N/A | n/a | |
CVE-2022-30819 | In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "photos_edit.php" file. | Unknown | N/A | n/a | |
CVE-2022-3082 | The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logged in users, such as subscriber to call them, and disable the app for example | Unknown | N/A | Unknown | |
CVE-2022-30820 | In Wedding Management v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_edit.php" file. | Unknown | N/A | n/a | |
CVE-2022-30821 | In Wedding Management System v1.0, the editing function of the "Services" module in the background management system has an arbitrary file upload vulnerability in the picture upload point of "package_edit.php" file. | Unknown | N/A | n/a | |
CVE-2022-30822 | In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_profile.php" file. | Unknown | N/A | n/a | |
CVE-2022-30823 | Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\blog_events_edit.php. | Unknown | N/A | n/a | |
CVE-2022-30825 | Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\client_edit.php. | Unknown | N/A | n/a | |
CVE-2022-30826 | Wedding Management System v1.0 is vulnerable to SQL Injection via admin\client_assign.php. | Unknown | N/A | n/a | |
CVE-2022-30827 | Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\package_edit.php. | Unknown | N/A | n/a | |
CVE-2022-30828 | Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\photos_edit.php. | Unknown | N/A | n/a | |
CVE-2022-30829 | Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\users_edit.php. | Unknown | N/A | n/a | |
CVE-2022-3083 | All versions of Landis+Gyr E850 (ZMQ200) are vulnerable to CWE-784: Reliance on Cookies Without Validation and Integrity. The device's web application navigation depends on the value of the session cookie. The web application could become inaccessible for the user if an attacker changes the cookie values. | Unknown | N/A | Landis+Gyr | |
CVE-2022-30830 | Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\feature_edit.php. | Unknown | N/A | n/a | |
CVE-2022-30831 | Wedding Management System v1.0 is vulnerable to SQL Injection via Wedding-Management/wedding_details.php. | Unknown | N/A | n/a | |
CVE-2022-30832 | Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_assign.php?booking=31&user_id=. | Unknown | N/A | n/a | |
CVE-2022-30833 | Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_edit.php?booking=31&user_id=. | Unknown | N/A | n/a | |
CVE-2022-30834 | Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_manage_account_details.php?booking_id=31&user_id= | Unknown | N/A | n/a | |
CVE-2022-30835 | Wedding Management System v1.0 is vulnerable to SQL Injection. via /Wedding-Management/admin/budget.php?booking_id=. | Unknown | N/A | n/a | |
CVE-2022-30836 | Wedding Management System v1.0 is vulnerable to SQL Injection. via Wedding-Management/admin/select.php. | Unknown | N/A | n/a | |
CVE-2022-30837 | Toll-tax-management-system v1.0 is vulnerable to Cross Site Scripting (XSS) via /ttms/classes/Master.php?f=save_recipient, vehicle_name. | Unknown | N/A | n/a | |
CVE-2022-30838 | Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=update_application_status | Unknown | N/A | n/a | |
CVE-2022-30839 | Room-rent-portal-site v1.0 is vulnerable to Cross Site Scripting (XSS) via /rrps/classes/Master.php?f=save_category, vehicle_name. | Unknown | N/A | n/a | |
CVE-2022-3084 | GE CIMPICITY versions 2022 and prior is vulnerable when data from a faulting address controls code flow starting at gmmiObj!CGmmiRootOptionTable, which could allow an attacker to execute arbitrary code. | Unknown | N/A | GE | |
CVE-2022-30842 | Covid-19 Travel Pass Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /ctpms/classes/Users.php?f=save, firstname. | Unknown | N/A | n/a | |
CVE-2022-30843 | Room-rent-portal-site v1.0 is vulnerable to SQL Injection via /rrps/classes/Master.php?f=delete_category, id. | Unknown | N/A | n/a | |
CVE-2022-3085 | Fuji Electric Tellus Lite V-Simulator versions 4.0.12.0 and prior are vulnerable to a stack-based buffer overflow which may allow an attacker to execute arbitrary code. | Unknown | N/A | Fuji Electric | |
CVE-2022-30852 | Known v1.3.1 was discovered to contain an Insecure Direct Object Reference (IDOR). | Unknown | N/A | n/a | |
CVE-2022-30858 | An issue was discovered in ngiflib 0.4. There is SEGV in SDL_LoadAnimatedGif when use SDLaffgif. poc : ./SDLaffgif CA_file2_0 | Unknown | N/A | n/a | |
CVE-2022-3086 | Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable to shell escape, which enables local attackers with non-superuser credentials to gain full, unrestrictive shell access which may allow an attacker to execute arbitrary code. | Unknown | N/A | Cradlepoint | |
CVE-2022-30860 | FUDforum 3.1.2 is vulnerable to Remote Code Execution through Upload File feature of File Administration System in Admin Control Panel. | Unknown | N/A | n/a | |
CVE-2022-30861 | FUDforum 3.1.2 is vulnerable to Stored XSS via Forum Name field in Forum Manager Feature. | Unknown | N/A | n/a | |
CVE-2022-30863 | FUDForum 3.1.2 is vulnerable to Cross Site Scripting (XSS) via page_title param in Page Manager in the Admin Control Panel. | Unknown | N/A | n/a | |
CVE-2022-3087 | Fuji Electric Tellus Lite V-Simulator versions 4.0.12.0 and prior are vulnerable to an out-of-bounds write which may allow an attacker to execute arbitrary code. | Unknown | N/A | Fuji Electric | |
CVE-2022-30874 | There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02. | Unknown | N/A | n/a | |
CVE-2022-30875 | Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page. | Unknown | N/A | n/a | |
CVE-2022-30877 | The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2. | Unknown | N/A | n/a | |
CVE-2022-3088 | UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12, UC-2100-W System Image: Versions v1.0 to v 1.12, UC-3100 System Image: Versions v1.0 to v1.6, UC-5100 System Image: Versions v1.0 to v1.4, UC-8100 System Image: Versions v3.0 to v3.5, UC-8100-ME-T System Image: Versions v3.0 and v3.1, UC-8200 System Image: v1.0 to v1.5, AIG-300 System Image: v1.0 to v1.4, UC-8410A with Debian 9 System Image: Versions v4.0.2 and v4.1.2, UC-8580 with Debian 9 System Image: Versions v2.0 and v2.1, UC-8540 with Debian 9 System Image: Versions v2.0 and v2.1, and DA-662C-16-LX (GLB) System Image: Versions v1.0.2 to v1.1.2 of Moxa's ARM-based computers have an execution with unnecessary privileges vulnerability, which could allow an attacker with user-level privileges to gain root privileges. | Unknown | N/A | Moxa | |
CVE-2022-30882 | pyanxdns package in PyPI version 0.2 is vulnerable to code execution backdoor. The impact is: execute arbitrary code (remote). When installing the pyanxdns package of version 0.2, the request package will be installed. | Unknown | N/A | n/a | |
CVE-2022-30885 | The pyesasky for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2.0-1.4.2. | Unknown | N/A | n/a | |
CVE-2022-30886 | School Dormitory Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /dms/admin/reports/daily_collection_report.php. | Unknown | N/A | n/a | |
CVE-2022-30887 | Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file. | Unknown | N/A | n/a | |
CVE-2022-3089 | Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, then the credentials could be used to control the web user interface and file transfer protocol (FTP) server. | Unknown | N/A | EnOcean | |
CVE-2022-30898 | A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password. | Unknown | N/A | n/a | |
CVE-2022-30899 | A Cross Site Scripting vulnerabilty exists in PartKeepr 1.4.0 via the 'name' field in /api/part_categories. | Unknown | N/A | n/a | |
CVE-2022-3090 | Red Lion Controls Crimson 3.0 versions 707.000 and prior, Crimson 3.1 versions 3126.001 and prior, and Crimson 3.2 versions 3.2.0044.0 and prior are vulnerable to path traversal. When attempting to open a file using a specific path, the user's password hash is sent to an arbitrary host. This could allow an attacker to obtain user credential hashes. | Unknown | N/A | Red Lion Controls |
vunerability-insight.com © 2023 - 2025. All Rights Reserved.
Vulnerability Data Repositories v