Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-21792 | 2 Google, Mediatek | 11 Android, Mt6833, Mt6853 and 8 more | 2022-08-04 | N/A | 6.7 MEDIUM |
In camera isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07085410; Issue ID: ALPS07085410. | |||||
CVE-2022-21791 | 2 Google, Mediatek | 7 Android, Mt6833, Mt6853 and 4 more | 2022-08-04 | N/A | 4.4 MEDIUM |
In camera isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06478059; Issue ID: ALPS06478059. | |||||
CVE-2022-21790 | 2 Google, Mediatek | 6 Android, Mt6833, Mt6853 and 3 more | 2022-08-04 | N/A | 4.4 MEDIUM |
In camera isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479306; Issue ID: ALPS06479306. | |||||
CVE-2022-21789 | 2 Google, Mediatek | 21 Android, Mt6779, Mt6781 and 18 more | 2022-08-04 | N/A | 6.4 MEDIUM |
In audio ipi, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06478101; Issue ID: ALPS06478101. | |||||
CVE-2022-21788 | 2 Google, Mediatek | 4 Android, Mt6879, Mt6895 and 1 more | 2022-08-04 | N/A | 6.7 MEDIUM |
In scp, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06988728; Issue ID: ALPS06988728. | |||||
CVE-2022-35716 | 1 Ibm | 1 Urbancode Deploy | 2022-08-04 | N/A | 6.5 MEDIUM |
IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.16, 7.0.0.0 through 7.0.5.11, 7.1.0.0 through 7.1.2.7, and 7.2.0.0 through 7.2.3.0 could allow an authenticated user to obtain sensitive information in some instances due to improper security checking. IBM X-Force ID: 231360. | |||||
CVE-2022-34338 | 1 Ibm | 1 Robotic Process Automation | 2022-08-04 | N/A | 6.5 MEDIUM |
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due to improper privilege management for storage provider types. IBM X-Force ID: 229962. | |||||
CVE-2022-34953 | 1 Phptpoint | 1 Pharmacy Management System | 2022-08-04 | N/A | 9.8 CRITICAL |
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getOrderReport.php. | |||||
CVE-2022-33169 | 1 Ibm | 1 Robotic Process Automation | 2022-08-04 | N/A | 6.5 MEDIUM |
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently protected credentials for users created via a bulk upload. IBM X-Force ID: 228888. | |||||
CVE-2022-32750 | 1 Ibm | 1 Datapower Gateway | 2022-08-04 | N/A | 5.4 MEDIUM |
IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 228435. | |||||
CVE-2022-34952 | 1 Phptpoint | 1 Pharmacy Management System | 2022-08-04 | N/A | 9.8 CRITICAL |
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edituser.php. | |||||
CVE-2022-34951 | 1 Phptpoint | 1 Pharmacy Management System | 2022-08-04 | N/A | 9.8 CRITICAL |
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getsalereport.php. | |||||
CVE-2022-1805 | 1 Teradici | 2 Tera2 Pcoip Zero Client, Tera2 Pcoip Zero Client Firmware | 2022-08-04 | N/A | 8.1 HIGH |
When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero Clients. The issue could be exploited by an adversary that places a MITM (Man in the Middle) between a zero client and AWS session provisioner in the network. This issue is only applicable when connecting to an Amazon Workspace from a PCoIP Zero Client. | |||||
CVE-2022-2571 | 1 Vim | 1 Vim | 2022-08-04 | N/A | 7.8 HIGH |
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0101. | |||||
CVE-2022-2581 | 1 Vim | 1 Vim | 2022-08-04 | N/A | 7.8 HIGH |
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0104. | |||||
CVE-2022-2580 | 1 Vim | 1 Vim | 2022-08-04 | N/A | 7.8 HIGH |
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0102. | |||||
CVE-2022-2589 | 1 Fava Project | 1 Fava | 2022-08-04 | N/A | 6.1 MEDIUM |
Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.3. | |||||
CVE-2022-34945 | 1 Pharmacy Management System Project | 1 Pharmacy Management System | 2022-08-04 | N/A | 9.8 CRITICAL |
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getproductreport.php. | |||||
CVE-2022-34948 | 1 Pharmacy Management System Project | 1 Pharmacy Management System | 2022-08-04 | N/A | 9.8 CRITICAL |
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editbrand.php. | |||||
CVE-2022-34947 | 1 Pharmacy Management System Project | 1 Pharmacy Management System | 2022-08-04 | N/A | 9.8 CRITICAL |
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editcategory.php. |