| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-46117 | Hig | 0.47 | 7.2 | 0.01 | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=view_product&id=. | ||
| CVE-2022-46074 | Hig | 0.57 | 8.8 | 0.00 | Dec 14, 2022 | Helmet Store Showroom 1.0 is vulnerable to Cross Site Request Forgery (CSRF). An unauthenticated user can add an admin account due to missing CSRF protection. | ||
| CVE-2022-23519 | Hig | 0.47 | 7.2 | 0.01 | Dec 14, 2022 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer may allow an attacker to inject content if the application developer has overridden… | ||
| CVE-2022-23517 | Hig | 0.42 | 7.5 | 0.01 | Dec 14, 2022 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails-html-sanitizer < 1.4.4 use an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes.… | ||
| CVE-2022-44898 | Hig | 0.51 | 7.8 | 0.00 | Dec 14, 2022 | The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, and 0x80102054, allowing attackers to trigger a memory corruption and cause a Denial of Service (DoS) or escalate privileges via crafted… | ||
| CVE-2022-23516 | Hig | 0.42 | 7.5 | 0.01 | Dec 14, 2022 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.2.0, < 2.19.1 uses recursion for sanitizing CDATA sections, making it susceptible to stack exhaustion and raising a SystemStackError exception. … | ||
| CVE-2022-23514 | Hig | 0.42 | 7.5 | 0.02 | Dec 14, 2022 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah < 2.19.1 contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes.… | ||
| CVE-2022-23512 | Hig | 0.50 | 7.7 | 0.01 | Dec 14, 2022 | MeterSphere is a one-stop open source continuous testing platform. Versions prior to 2.4.1 are vulnerable to Path Injection in ApiTestCaseService::deleteBodyFiles which takes a user-controlled string id and passes it to ApiTestCaseService, which uses the user-provided value… | ||
| CVE-2022-34271 | Hig | 0.50 | 8.8 | 0.01 | Dec 14, 2022 | A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0. | ||
| CVE-2022-23503 | Hig | 0.42 | 7.5 | 0.01 | Dec 14, 2022 | TYPO3 is an open source PHP based web content management system. Versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are vulnerable to Code Injection. Due to the lack of separating user-submitted data from the internal configuration in the Form Designer backend… | ||
| CVE-2022-4440 | Hig | 0.57 | 8.8 | 0.01 | Dec 14, 2022 | Use after free in Profiles in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2022-4439 | Hig | 0.57 | 8.8 | 0.01 | Dec 14, 2022 | Use after free in Aura in Google Chrome on Windows prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chromium security severity: High) | ||
| CVE-2022-4438 | Hig | 0.57 | 8.8 | 0.01 | Dec 14, 2022 | Use after free in Blink Frames in Google Chrome prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2022-4437 | Hig | 0.57 | 8.8 | 0.01 | Dec 14, 2022 | Use after free in Mojo IPC in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2022-4436 | Hig | 0.57 | 8.8 | 0.01 | Dec 14, 2022 | Use after free in Blink Media in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2022-24377 | Hig | 0.41 | 7.4 | 0.02 | Dec 14, 2022 | The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization. | ||
| CVE-2022-42140 | Hig | 0.47 | 7.2 | 0.02 | Dec 14, 2022 | Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose. | ||
| CVE-2022-42139 | Hig | 0.59 | 8.8 | 0.18 | Dec 14, 2022 | Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL. | ||
| CVE-2022-37155 | Hig | 0.60 | 8.8 | 0.40 | Dec 14, 2022 | RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter. | ||
| CVE-2022-38355 | Hig | 0.49 | 7.5 | 0.00 | Dec 13, 2022 | Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to attackers with access to the local area network (LAN) to disclose sensitive information stored by the affected product without requiring authentication. | ||
| CVE-2022-2951 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to improper validation of array index vulnerability during processing of H3D files. A DWORD value from a PoC file is extracted and used as an index to write to a buffer, leading to memory corruption. … | ||
| CVE-2022-2950 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerability during parsing of H3D files. A DWORD is extracted from an uninitialized buffer and, after sign extension, is used as an index into a stack variable to… | ||
| CVE-2022-2949 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerability during parsing of H3D files. A DWORD is extracted from an uninitialized buffer and, after sign extension, is used as an index into a stack variable to… | ||
| CVE-2022-2947 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | Altair HyperView Player versions 2021.1.0.27 and prior perform operations on a memory buffer but can read from or write to a memory location outside of the intended boundary of the buffer. This hits initially as a read access violation, leading to a memory corruption… | ||
| CVE-2022-47213 | Hig | 0.51 | 7.8 | 0.01 | Dec 13, 2022 | Microsoft Office Graphics Remote Code Execution Vulnerability | ||
| CVE-2022-47212 | Hig | 0.51 | 7.8 | 0.01 | Dec 13, 2022 | Microsoft Office Graphics Remote Code Execution Vulnerability | ||
| CVE-2022-47211 | Hig | 0.51 | 7.8 | 0.01 | Dec 13, 2022 | Microsoft Office Graphics Remote Code Execution Vulnerability | ||
| CVE-2022-44713 | Hig | 0.49 | 7.5 | 0.01 | Dec 13, 2022 | Microsoft Outlook for Mac Spoofing Vulnerability | ||
| CVE-2022-44710 | Hig | 0.51 | 7.8 | 0.01 | Dec 13, 2022 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | ||
| CVE-2022-44708 | Hig | 0.54 | 8.3 | 0.02 | Dec 13, 2022 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | ||
| CVE-2022-44704 | Hig | 0.51 | 7.8 | 0.01 | Dec 13, 2022 | Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability | ||
| CVE-2022-44702 | Hig | 0.51 | 7.8 | 0.01 | Dec 13, 2022 | Windows Terminal Remote Code Execution Vulnerability | ||
| CVE-2022-44697 | Hig | 0.51 | 7.8 | 0.01 | Dec 13, 2022 | Windows Graphics Component Elevation of Privilege Vulnerability | ||
| CVE-2022-44696 | Hig | 0.51 | 7.8 | 0.01 | Dec 13, 2022 | Microsoft Office Visio Remote Code Execution Vulnerability | ||
| CVE-2022-44695 | Hig | 0.51 | 7.8 | 0.01 | Dec 13, 2022 | Microsoft Office Visio Remote Code Execution Vulnerability | ||
| CVE-2022-44694 | Hig | 0.51 | 7.8 | 0.01 | Dec 13, 2022 | Microsoft Office Visio Remote Code Execution Vulnerability | ||
| CVE-2022-44693 | Hig | 0.57 | 8.8 | 0.02 | Dec 13, 2022 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2022-44692 | Hig | 0.51 | 7.8 | 0.01 | Dec 13, 2022 | Microsoft Office Graphics Remote Code Execution Vulnerability | ||
| CVE-2022-44691 | Hig | 0.51 | 7.8 | 0.01 | Dec 13, 2022 | Microsoft Office OneNote Remote Code Execution Vulnerability | ||
| CVE-2022-44690 | Hig | 0.64 | 8.8 | 0.82 | Dec 13, 2022 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2022-44689 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability | ||
| CVE-2022-44687 | Hig | 0.51 | 7.8 | 0.01 | Dec 13, 2022 | Raw Image Extension Remote Code Execution Vulnerability | ||
| CVE-2022-44683 | Hig | 0.51 | 7.8 | 0.08 | Dec 13, 2022 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2022-44681 | Hig | 0.51 | 7.8 | 0.01 | Dec 13, 2022 | Windows Print Spooler Elevation of Privilege Vulnerability | ||
| CVE-2022-44680 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | Windows Graphics Component Elevation of Privilege Vulnerability | ||
| CVE-2022-44678 | Hig | 0.51 | 7.8 | 0.01 | Dec 13, 2022 | Windows Print Spooler Elevation of Privilege Vulnerability | ||
| CVE-2022-44677 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | Windows Projected File System Elevation of Privilege Vulnerability | ||
| CVE-2022-44676 | Hig | 0.53 | 8.1 | 0.01 | Dec 13, 2022 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | ||
| CVE-2022-44675 | Hig | 0.51 | 7.8 | 0.05 | Dec 13, 2022 | Windows Bluetooth Driver Elevation of Privilege Vulnerability | ||
| CVE-2022-44673 | Hig | 0.46 | 7.0 | 0.05 | Dec 13, 2022 | Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability |
- risk 0.47cvss 7.2epss 0.01
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=view_product&id=.
- risk 0.57cvss 8.8epss 0.00
Helmet Store Showroom 1.0 is vulnerable to Cross Site Request Forgery (CSRF). An unauthenticated user can add an admin account due to missing CSRF protection.
- risk 0.47cvss 7.2epss 0.01
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer may allow an attacker to inject content if the application developer has overridden…
- risk 0.42cvss 7.5epss 0.01
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails-html-sanitizer < 1.4.4 use an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes.…
- risk 0.51cvss 7.8epss 0.00
The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, and 0x80102054, allowing attackers to trigger a memory corruption and cause a Denial of Service (DoS) or escalate privileges via crafted…
- risk 0.42cvss 7.5epss 0.01
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.2.0, < 2.19.1 uses recursion for sanitizing CDATA sections, making it susceptible to stack exhaustion and raising a SystemStackError exception. …
- risk 0.42cvss 7.5epss 0.02
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah < 2.19.1 contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes.…
- risk 0.50cvss 7.7epss 0.01
MeterSphere is a one-stop open source continuous testing platform. Versions prior to 2.4.1 are vulnerable to Path Injection in ApiTestCaseService::deleteBodyFiles which takes a user-controlled string id and passes it to ApiTestCaseService, which uses the user-provided value…
- risk 0.50cvss 8.8epss 0.01
A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0.
- risk 0.42cvss 7.5epss 0.01
TYPO3 is an open source PHP based web content management system. Versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are vulnerable to Code Injection. Due to the lack of separating user-submitted data from the internal configuration in the Form Designer backend…
- risk 0.57cvss 8.8epss 0.01
Use after free in Profiles in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.57cvss 8.8epss 0.01
Use after free in Aura in Google Chrome on Windows prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chromium security severity: High)
- risk 0.57cvss 8.8epss 0.01
Use after free in Blink Frames in Google Chrome prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.57cvss 8.8epss 0.01
Use after free in Mojo IPC in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.57cvss 8.8epss 0.01
Use after free in Blink Media in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.41cvss 7.4epss 0.02
The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization.
- risk 0.47cvss 7.2epss 0.02
Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.
- risk 0.59cvss 8.8epss 0.18
Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL.
- risk 0.60cvss 8.8epss 0.40
RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.
- risk 0.49cvss 7.5epss 0.00
Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to attackers with access to the local area network (LAN) to disclose sensitive information stored by the affected product without requiring authentication.
- risk 0.51cvss 7.8epss 0.00
Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to improper validation of array index vulnerability during processing of H3D files. A DWORD value from a PoC file is extracted and used as an index to write to a buffer, leading to memory corruption. …
- risk 0.51cvss 7.8epss 0.00
Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerability during parsing of H3D files. A DWORD is extracted from an uninitialized buffer and, after sign extension, is used as an index into a stack variable to…
- risk 0.51cvss 7.8epss 0.00
Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerability during parsing of H3D files. A DWORD is extracted from an uninitialized buffer and, after sign extension, is used as an index into a stack variable to…
- risk 0.51cvss 7.8epss 0.00
Altair HyperView Player versions 2021.1.0.27 and prior perform operations on a memory buffer but can read from or write to a memory location outside of the intended boundary of the buffer. This hits initially as a read access violation, leading to a memory corruption…
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Graphics Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Graphics Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Graphics Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.01
Microsoft Outlook for Mac Spoofing Vulnerability
- risk 0.51cvss 7.8epss 0.01
DirectX Graphics Kernel Elevation of Privilege Vulnerability
- risk 0.54cvss 8.3epss 0.02
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Terminal Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Graphics Component Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Visio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Visio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Visio Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Graphics Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office OneNote Remote Code Execution Vulnerability
- risk 0.64cvss 8.8epss 0.82
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Raw Image Extension Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.08
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Print Spooler Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Graphics Component Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Print Spooler Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Projected File System Elevation of Privilege Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.05
Windows Bluetooth Driver Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.05
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability