Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29682 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-36857 2 Google, Samsung 2 Android, Photo Editor 2024-11-21 N/A 1.9 LOW
Improper Authorization vulnerability in Photo Editor prior to SMR Sep-2022 Release 1 allows physical attackers to read internal application data.
CVE-2022-36852 1 Google 1 Android 2024-11-21 N/A 1.9 LOW
Improper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local attacker to access internal application data.
CVE-2022-36851 1 Samsung 1 Samsung Pass 2024-11-21 N/A 3.9 LOW
Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data of Samsung pass on a certain state of an unlocked device.
CVE-2022-36848 1 Google 1 Android 2024-11-21 N/A 5.1 MEDIUM
Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of service.
CVE-2022-36832 1 Samsung 1 Cameralyzer 2024-11-21 N/A 4.0 MEDIUM
Improper access control vulnerability in WebApp in Cameralyzer prior to versions 3.2.22, 3.3.22, 3.4.22 and 3.5.51 allows attackers to access external storage as Cameralyzer privilege.
CVE-2022-36830 1 Samsung 2 Charm, Charm Firmware 2024-11-21 N/A 6.2 MEDIUM
PendingIntent hijacking vulnerability in cancelAlarmManager in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.
CVE-2022-36829 1 Samsung 2 Charm, Charm Firmware 2024-11-21 N/A 6.2 MEDIUM
PendingIntent hijacking vulnerability in releaseAlarm in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.
CVE-2022-36797 1 Vmware 1 Ixgben 2024-11-21 N/A 3.3 LOW
Protection mechanism failure in the Intel(R) Ethernet 500 Series Controller drivers for VMware before version 1.10.0.1 may allow an authenticated user to potentially enable denial of service via local access.
CVE-2022-36638 1 Garage Management System Project 1 Garage Management System 2024-11-21 N/A 5.3 MEDIUM
An access control issue in the component print.php of Garage Management System v1.0 allows unauthenticated attackers to access data for all existing orders.
CVE-2022-36603 1 Innosilicon 2 T3t\+, T3t\+ Firmware 2024-11-21 N/A 8.8 HIGH
InnoSilicon T3T+ t2t+_soc_20190911_151433.swu was discovered to contain a remote code execution (RCE) vulnerability in the checkUrl function.
CVE-2022-36601 1 Jinglemining 2 Jasminer X4 Server, Jasminer X4 Server Firmware 2024-11-21 N/A 9.8 CRITICAL
The Eclipse TCF debug interface in JasMiner-X4-Server-20220621-090907 and below is open on port 1534. This issue allows unauthenticated attackers to gain root privileges on the affected device and access sensitive data or execute arbitrary commands.
CVE-2022-36565 1 Wampserver 1 Wampserver 2024-11-21 N/A 8.8 HIGH
Incorrect access control in the install directory (C:\Wamp64) of Wamp v3.2.6 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.
CVE-2022-36564 2 Microsoft, Strawberryperl 2 Windows, Strawberryperl 2024-11-21 N/A 8.8 HIGH
Incorrect access control in the install directory (C:\Strawberry) of StrawberryPerl v5.32.1.1 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.
CVE-2022-36563 1 Rubyinstaller 1 Rubyinstaller2 2024-11-21 N/A 8.8 HIGH
Incorrect access control in the install directory (C:\RailsInstaller) of Rubyinstaller2 v3.1.2 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.
CVE-2022-36562 1 Rubyinstaller 1 Rubyinstaller2 2024-11-21 N/A 8.8 HIGH
Incorrect access control in the install directory (C:\Ruby31-x64) of Rubyinstaller2 v3.1.2 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.
CVE-2022-36542 1 Edoc-doctor-appointment-system Project 1 Edoc-doctor-appointment-system 2024-11-21 N/A 6.5 MEDIUM
An access control issue in the component /ip/admin/ of Edoc-doctor-appointment-system v1.0.1 allows attackers to arbitrarily edit, read, and delete Administrator data.
CVE-2022-36429 1 Netgear 2 Rbs750, Rbs750 Firmware 2024-11-21 N/A 7.2 HIGH
A command execution vulnerability exists in the ubus backend communications functionality of Netgear Orbi Satellite RBS750 4.6.8.5. A specially-crafted JSON object can lead to arbitrary command execution. An attacker can send a sequence of malicious packets to trigger this vulnerability.
CVE-2022-36427 1 About-rentals Project 1 About-rentals 2024-11-21 N/A 7.3 HIGH
Missing Access Control vulnerability in About Rentals. Inc. About Rentals plugin <= 1.5 at WordPress.
CVE-2022-36425 1 Fastlinemedia 1 Beaver Builder 2024-11-21 N/A 5.4 MEDIUM
Broken Access Control vulnerability in Beaver Builder plugin <= 2.5.4.3 at WordPress.
CVE-2022-36416 1 Vmware 1 Ixgben 2024-11-21 N/A 4.4 MEDIUM
Protection mechanism failure in the Intel(R) Ethernet 500 Series Controller drivers for VMware before version 1.10.0.13 may allow an authenticated user to potentially enable escalation of privilege via local access.