Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29483 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-36876 1 Samsung 1 Samsung Pass 2024-11-21 N/A 1.8 LOW
Improper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical attackers to access account list without authentication.
CVE-2022-36875 1 Samsung 1 Galaxy Watch Plugin 2024-11-21 N/A 6.6 MEDIUM
Improper restriction of broadcasting Intent in SaWebViewRelayActivity of?Waterplugin prior to version 2.2.11.22081151 allows attacker to access the file without permission.
CVE-2022-36869 1 Samsung 1 Contacts Provider 2024-11-21 N/A 6.6 MEDIUM
Improper access control vulnerability in ContactsDumpActivity of?Contacts Provider prior to version 12.7.59 allows attacker to access the file without permission.
CVE-2022-36868 1 Google 1 Android 2024-11-21 N/A 5.9 MEDIUM
Improper restriction of broadcasting Intent in MouseNKeyHidDevice prior to SMR Oct-2022 Release 1 leaks MAC address of the connected Bluetooth device.
CVE-2022-36867 1 Samsung 1 Editor Lite 2024-11-21 N/A 5.9 MEDIUM
Improper access control vulnerability in Editor Lite prior to version 4.0.40.14 allows attackers to access sensitive information.
CVE-2022-36866 2 Google, Samsung 2 Android, Group Sharing 2024-11-21 N/A 4.0 MEDIUM
Improper access control vulnerability in Broadcaster in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.
CVE-2022-36865 2 Google, Samsung 2 Android, Group Sharing 2024-11-21 N/A 4.0 MEDIUM
Improper access control in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to access device information.
CVE-2022-36864 1 Samsung 1 Samsung Email 2024-11-21 N/A 4.0 MEDIUM
Improper access control and intent redirection in Samsung Email prior to 6.1.70.20 allows attacker to access specific formatted file and execute privileged behavior.
CVE-2022-36857 2 Google, Samsung 2 Android, Photo Editor 2024-11-21 N/A 1.9 LOW
Improper Authorization vulnerability in Photo Editor prior to SMR Sep-2022 Release 1 allows physical attackers to read internal application data.
CVE-2022-36852 1 Google 1 Android 2024-11-21 N/A 1.9 LOW
Improper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local attacker to access internal application data.
CVE-2022-36851 1 Samsung 1 Samsung Pass 2024-11-21 N/A 3.9 LOW
Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data of Samsung pass on a certain state of an unlocked device.
CVE-2022-36848 1 Google 1 Android 2024-11-21 N/A 5.1 MEDIUM
Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of service.
CVE-2022-36832 1 Samsung 1 Cameralyzer 2024-11-21 N/A 4.0 MEDIUM
Improper access control vulnerability in WebApp in Cameralyzer prior to versions 3.2.22, 3.3.22, 3.4.22 and 3.5.51 allows attackers to access external storage as Cameralyzer privilege.
CVE-2022-36830 1 Samsung 2 Charm, Charm Firmware 2024-11-21 N/A 6.2 MEDIUM
PendingIntent hijacking vulnerability in cancelAlarmManager in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.
CVE-2022-36829 1 Samsung 2 Charm, Charm Firmware 2024-11-21 N/A 6.2 MEDIUM
PendingIntent hijacking vulnerability in releaseAlarm in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.
CVE-2022-36797 1 Vmware 1 Ixgben 2024-11-21 N/A 3.3 LOW
Protection mechanism failure in the Intel(R) Ethernet 500 Series Controller drivers for VMware before version 1.10.0.1 may allow an authenticated user to potentially enable denial of service via local access.
CVE-2022-36638 1 Garage Management System Project 1 Garage Management System 2024-11-21 N/A 5.3 MEDIUM
An access control issue in the component print.php of Garage Management System v1.0 allows unauthenticated attackers to access data for all existing orders.
CVE-2022-36603 1 Innosilicon 2 T3t\+, T3t\+ Firmware 2024-11-21 N/A 8.8 HIGH
InnoSilicon T3T+ t2t+_soc_20190911_151433.swu was discovered to contain a remote code execution (RCE) vulnerability in the checkUrl function.
CVE-2022-36601 1 Jinglemining 2 Jasminer X4 Server, Jasminer X4 Server Firmware 2024-11-21 N/A 9.8 CRITICAL
The Eclipse TCF debug interface in JasMiner-X4-Server-20220621-090907 and below is open on port 1534. This issue allows unauthenticated attackers to gain root privileges on the affected device and access sensitive data or execute arbitrary commands.
CVE-2022-36565 1 Wampserver 1 Wampserver 2024-11-21 N/A 8.8 HIGH
Incorrect access control in the install directory (C:\Wamp64) of Wamp v3.2.6 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.