| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-30661 | Hig | 0.51 | 7.8 | 0.06 | Jun 16, 2022 | Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a… | ||
| CVE-2022-30660 | Hig | 0.51 | 7.8 | 0.02 | Jun 16, 2022 | Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must… | ||
| CVE-2022-30659 | Hig | 0.51 | 7.8 | 0.02 | Jun 16, 2022 | Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must… | ||
| CVE-2022-30658 | Hig | 0.51 | 7.8 | 0.06 | Jun 16, 2022 | Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a… | ||
| CVE-2022-29865 | — | Hig | 0.49 | 7.5 | 0.01 | Jun 16, 2022 | OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials. | |
| CVE-2022-29862 | Hig | 0.49 | 7.5 | 0.01 | Jun 16, 2022 | An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message. | ||
| CVE-2022-1642 | Hig | 0.42 | 7.5 | 0.01 | Jun 16, 2022 | A program using swift-corelibs-foundation is vulnerable to a denial of service attack caused by a potentially malicious source producing a JSON document containing a type mismatch. This vulnerability is caused by the interaction between a deserialization mechanism offered by the… | ||
| CVE-2022-31291 | Hig | 0.00 | 7.5 | 0.01 | Jun 16, 2022 | An issue in dlt_config_file_parser.c of dlt-daemon v2.18.8 allows attackers to cause a double free via crafted TCP packets. | ||
| CVE-2022-27532 | Hig | 0.51 | 7.8 | 0.01 | Jun 16, 2022 | A maliciously crafted TIF file in Autodesk 3ds Max 2022 and 2021 can be used to write beyond the allocated buffer while parsing TIF files. This vulnerability in conjunction with other vulnerabilities could lead to arbitrary code execution. | ||
| CVE-2022-27531 | Hig | 0.51 | 7.8 | 0.01 | Jun 16, 2022 | A maliciously crafted TIF file can be forced to read beyond allocated boundaries in Autodesk 3ds Max 2022, and 2021 when parsing the TIF files. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | ||
| CVE-2022-31912 | Hig | 0.47 | 7.2 | 0.01 | Jun 16, 2022 | Online Tutor Portal Site v1.0 is vulnerable to SQL Injection via /otps/classes/Master.php?f=delete_team. | ||
| CVE-2022-31911 | Hig | 0.47 | 7.2 | 0.01 | Jun 16, 2022 | Online Discussion Forum Site v1.0 is vulnerable to SQL Injection via /odfs/classes/Master.php?f=delete_team. | ||
| CVE-2022-31908 | — | Hig | 0.47 | 7.2 | 0.01 | Jun 16, 2022 | Student Registration and Fee Payment System v1.0 is vulnerable to SQL Injection via /scms/student.php. | |
| CVE-2022-31849 | Hig | 0.57 | 8.8 | 0.02 | Jun 16, 2022 | MERCURY MIPC451-4 1.0.22 Build 220105 Rel.55642n was discovered to contain a remote code execution (RCE) vulnerability which is exploitable via a crafted POST request. | ||
| CVE-2022-31277 | Hig | 0.57 | 8.8 | 0.01 | Jun 16, 2022 | Xiaomi Lamp 1 v2.0.4_0066 was discovered to be vulnerable to replay attacks. This allows attackers to to bypass the expected access restrictions and gain control of the switch and other functions via a crafted POST request. | ||
| CVE-2022-30023 | Hig | 0.61 | 8.8 | 0.42 | Jun 16, 2022 | Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function. | ||
| CVE-2022-31372 | Hig | 0.00 | 7.5 | 0.01 | Jun 16, 2022 | Wiris Mathtype v7.28.0 was discovered to contain a path traversal vulnerability in the resourceFile parameter. This vulnerability is exploited via a crafted request to the resource handler. | ||
| CVE-2021-41402 | Hig | 0.57 | 8.8 | 0.01 | Jun 16, 2022 | flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP code. | ||
| CVE-2022-31626 | Hig | 0.53 | 7.5 | 0.58 | Jun 16, 2022 | In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow… | ||
| CVE-2022-31625 | Hig | 0.53 | 8.1 | 0.03 | Jun 16, 2022 | In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized data as pointers. This could lead to RCE… | ||
| CVE-2022-30549 | Hig | 0.51 | 7.8 | 0.01 | Jun 16, 2022 | Out-of-bounds read vulnerability exists in V-Server v4.0.11.0 and earlier and V-Server Lite v4.0.13.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file. | ||
| CVE-2022-30546 | Hig | 0.51 | 7.8 | 0.01 | Jun 16, 2022 | Out-of-bounds read vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file. | ||
| CVE-2022-30538 | Hig | 0.51 | 7.8 | 0.01 | Jun 16, 2022 | Out-of-bounds write vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file. | ||
| CVE-2022-30193 | Hig | 0.51 | 7.8 | 0.02 | Jun 15, 2022 | AV1 Video Extension Remote Code Execution Vulnerability | ||
| CVE-2022-30188 | Hig | 0.51 | 7.8 | 0.03 | Jun 15, 2022 | HEVC Video Extensions Remote Code Execution Vulnerability | ||
| CVE-2022-30180 | Hig | 0.51 | 7.8 | 0.02 | Jun 15, 2022 | Azure RTOS GUIX Studio Information Disclosure Vulnerability | ||
| CVE-2022-30179 | Hig | 0.51 | 7.8 | 0.02 | Jun 15, 2022 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | ||
| CVE-2022-30178 | Hig | 0.51 | 7.8 | 0.02 | Jun 15, 2022 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | ||
| CVE-2022-30177 | Hig | 0.51 | 7.8 | 0.02 | Jun 15, 2022 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | ||
| CVE-2022-30174 | Hig | 0.51 | 7.8 | 0.03 | Jun 15, 2022 | Microsoft Office Remote Code Execution Vulnerability | ||
| CVE-2022-30173 | Hig | 0.51 | 7.8 | 0.02 | Jun 15, 2022 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2022-30168 | Hig | 0.51 | 7.8 | 0.02 | Jun 15, 2022 | Microsoft Photos App Remote Code Execution Vulnerability | ||
| CVE-2022-30167 | Hig | 0.51 | 7.8 | 0.02 | Jun 15, 2022 | AV1 Video Extension Remote Code Execution Vulnerability | ||
| CVE-2022-30166 | Hig | 0.51 | 7.8 | 0.01 | Jun 15, 2022 | Local Security Authority Subsystem Service Elevation of Privilege Vulnerability | ||
| CVE-2022-30165 | Hig | 0.58 | 8.8 | 0.04 | Jun 15, 2022 | Windows Kerberos Elevation of Privilege Vulnerability | ||
| CVE-2022-30164 | Hig | 0.51 | 7.8 | 0.01 | Jun 15, 2022 | Kerberos AppContainer Security Feature Bypass Vulnerability | ||
| CVE-2022-30163 | Hig | 0.55 | 8.5 | 0.02 | Jun 15, 2022 | Windows Hyper-V Remote Code Execution Vulnerability | ||
| CVE-2022-30161 | Hig | 0.57 | 8.8 | 0.02 | Jun 15, 2022 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2022-30160 | Hig | 0.51 | 7.8 | 0.06 | Jun 15, 2022 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | ||
| CVE-2022-30158 | Hig | 0.57 | 8.8 | 0.03 | Jun 15, 2022 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2022-30157 | Hig | 0.58 | 8.8 | 0.07 | Jun 15, 2022 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2022-30153 | Hig | 0.57 | 8.8 | 0.02 | Jun 15, 2022 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2022-30152 | Hig | 0.49 | 7.5 | 0.03 | Jun 15, 2022 | Windows Network Address Translation (NAT) Denial of Service Vulnerability | ||
| CVE-2022-30151 | Hig | 0.46 | 7.0 | 0.01 | Jun 15, 2022 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | ||
| CVE-2022-30150 | Hig | 0.49 | 7.5 | 0.03 | Jun 15, 2022 | Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability | ||
| CVE-2022-30149 | Hig | 0.49 | 7.5 | 0.02 | Jun 15, 2022 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2022-30147 | Hig | 0.51 | 7.8 | 0.05 | Jun 15, 2022 | Windows Installer Elevation of Privilege Vulnerability | ||
| CVE-2022-30146 | Hig | 0.49 | 7.5 | 0.02 | Jun 15, 2022 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2022-30145 | Hig | 0.49 | 7.5 | 0.02 | Jun 15, 2022 | Windows Encrypting File System (EFS) Remote Code Execution Vulnerability | ||
| CVE-2022-30143 | Hig | 0.49 | 7.5 | 0.02 | Jun 15, 2022 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability |
- risk 0.51cvss 7.8epss 0.06
Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…
- risk 0.51cvss 7.8epss 0.02
Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…
- risk 0.51cvss 7.8epss 0.02
Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…
- risk 0.51cvss 7.8epss 0.06
Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…
- risk 0.49cvss 7.5epss 0.01
OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials.
- risk 0.49cvss 7.5epss 0.01
An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message.
- risk 0.42cvss 7.5epss 0.01
A program using swift-corelibs-foundation is vulnerable to a denial of service attack caused by a potentially malicious source producing a JSON document containing a type mismatch. This vulnerability is caused by the interaction between a deserialization mechanism offered by the…
- risk 0.00cvss 7.5epss 0.01
An issue in dlt_config_file_parser.c of dlt-daemon v2.18.8 allows attackers to cause a double free via crafted TCP packets.
- risk 0.51cvss 7.8epss 0.01
A maliciously crafted TIF file in Autodesk 3ds Max 2022 and 2021 can be used to write beyond the allocated buffer while parsing TIF files. This vulnerability in conjunction with other vulnerabilities could lead to arbitrary code execution.
- risk 0.51cvss 7.8epss 0.01
A maliciously crafted TIF file can be forced to read beyond allocated boundaries in Autodesk 3ds Max 2022, and 2021 when parsing the TIF files. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
- risk 0.47cvss 7.2epss 0.01
Online Tutor Portal Site v1.0 is vulnerable to SQL Injection via /otps/classes/Master.php?f=delete_team.
- risk 0.47cvss 7.2epss 0.01
Online Discussion Forum Site v1.0 is vulnerable to SQL Injection via /odfs/classes/Master.php?f=delete_team.
- risk 0.47cvss 7.2epss 0.01
Student Registration and Fee Payment System v1.0 is vulnerable to SQL Injection via /scms/student.php.
- risk 0.57cvss 8.8epss 0.02
MERCURY MIPC451-4 1.0.22 Build 220105 Rel.55642n was discovered to contain a remote code execution (RCE) vulnerability which is exploitable via a crafted POST request.
- risk 0.57cvss 8.8epss 0.01
Xiaomi Lamp 1 v2.0.4_0066 was discovered to be vulnerable to replay attacks. This allows attackers to to bypass the expected access restrictions and gain control of the switch and other functions via a crafted POST request.
- risk 0.61cvss 8.8epss 0.42
Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.
- risk 0.00cvss 7.5epss 0.01
Wiris Mathtype v7.28.0 was discovered to contain a path traversal vulnerability in the resourceFile parameter. This vulnerability is exploited via a crafted request to the resource handler.
- risk 0.57cvss 8.8epss 0.01
flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP code.
- risk 0.53cvss 7.5epss 0.58
In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow…
- risk 0.53cvss 8.1epss 0.03
In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized data as pointers. This could lead to RCE…
- risk 0.51cvss 7.8epss 0.01
Out-of-bounds read vulnerability exists in V-Server v4.0.11.0 and earlier and V-Server Lite v4.0.13.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.
- risk 0.51cvss 7.8epss 0.01
Out-of-bounds read vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.
- risk 0.51cvss 7.8epss 0.01
Out-of-bounds write vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.
- risk 0.51cvss 7.8epss 0.02
AV1 Video Extension Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.03
HEVC Video Extensions Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.02
Azure RTOS GUIX Studio Information Disclosure Vulnerability
- risk 0.51cvss 7.8epss 0.02
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.02
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.02
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.03
Microsoft Office Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.02
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.02
Microsoft Photos App Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.02
AV1 Video Extension Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
- risk 0.58cvss 8.8epss 0.04
Windows Kerberos Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Kerberos AppContainer Security Feature Bypass Vulnerability
- risk 0.55cvss 8.5epss 0.02
Windows Hyper-V Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.06
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.03
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.58cvss 8.8epss 0.07
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows Network Address Translation (NAT) Denial of Service Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.05
Windows Installer Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability