Latest CVE Feed
-
8.2
HIGHCVE-2022-35893
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM memory corruption vulnerability in the FvbServicesRuntimeDxe driver allows an attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalat... Read more
Affected Products : insydeh2o- Published: Sep. 23, 2022
- Modified: May. 05, 2025
-
3.7
LOWCVE-2022-35252
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to a... Read more
Affected Products : debian_linux curl hci_management_node solidfire macos element_software h300s_firmware h500s_firmware h700s_firmware h410s_firmware +8 more products- Published: Sep. 23, 2022
- Modified: May. 05, 2025
-
6.1
MEDIUMCVE-2022-35155
Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the searchdata parameter.... Read more
- Published: Sep. 30, 2022
- Modified: May. 05, 2025
-
3.3
LOWCVE-2022-33981
drivers/block/floppy.c in the Linux kernel before 5.17.6 is vulnerable to a denial of service, because of a concurrency use-after-free flaw after deallocating raw_cmd in the raw_cmd_ioctl function.... Read more
- Published: Jun. 18, 2022
- Modified: May. 05, 2025
-
7.0
HIGHCVE-2022-32953
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the SdHostDriver buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges. This... Read more
Affected Products : insydeh2o- Published: Feb. 15, 2023
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2022-32899
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7 and iPadOS 15.7, iOS 16, macOS Ventura 13, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.... Read more
- Published: Nov. 01, 2022
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2022-32898
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7 and iPadOS 15.7, iOS 16, macOS Ventura 13, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.... Read more
- Published: Nov. 01, 2022
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2022-32889
The issue was addressed with improved memory handling. This issue is fixed in iOS 16, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.... Read more
- Published: Nov. 01, 2022
- Modified: May. 05, 2025
-
7.0
HIGHCVE-2022-32477
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the FvbServicesRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of ... Read more
Affected Products : insydeh2o- Published: Feb. 15, 2023
- Modified: May. 05, 2025
-
7.0
HIGHCVE-2022-32475
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the VariableRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of pri... Read more
Affected Products : insydeh2o- Published: Feb. 15, 2023
- Modified: May. 05, 2025
-
7.0
HIGHCVE-2022-32471
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. The IhisiDxe driver uses the command buffer to pass input and output data. By modifying the command buffer contents with DMA after the input parameters have been checked ... Read more
Affected Products : insydeh2o- Published: Feb. 15, 2023
- Modified: May. 05, 2025
-
7.0
HIGHCVE-2022-32470
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the FwBlockServiceSmm shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of priv... Read more
Affected Products : insydeh2o- Published: Feb. 15, 2023
- Modified: May. 05, 2025
-
7.0
HIGHCVE-2022-32469
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the PnpSmm shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges. Thi... Read more
Affected Products : insydeh2o- Published: Feb. 15, 2023
- Modified: May. 05, 2025
-
5.9
MEDIUMCVE-2022-32208
When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.... Read more
Affected Products : fedora debian_linux curl hci_management_node solidfire macos element_software h300s_firmware h500s_firmware h700s_firmware +9 more products- Published: Jul. 07, 2022
- Modified: May. 05, 2025
-
6.5
MEDIUMCVE-2022-32206
curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing ... Read more
Affected Products : fedora debian_linux curl hci_management_node solidfire element_software h300s_firmware h500s_firmware h700s_firmware h410s_firmware +20 more products- Published: Jul. 07, 2022
- Modified: May. 05, 2025
-
4.3
MEDIUMCVE-2022-32205
A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the cook... Read more
Affected Products : fedora debian_linux curl hci_management_node solidfire macos element_software h300s_firmware h500s_firmware h700s_firmware +19 more products- Published: Jul. 07, 2022
- Modified: May. 05, 2025
-
5.5
MEDIUMCVE-2022-30944
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via local access.... Read more
- Published: Aug. 18, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-30601
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable information disclosure and escalation of privilege via network access.... Read more
- Published: Aug. 18, 2022
- Modified: May. 05, 2025
-
4.9
MEDIUMCVE-2022-2943
The WordPress Infinite Scroll – Ajax Load More plugin for Wordpress is vulnerable to arbitrary file reading in versions up to, and including, 5.5.3 due to insufficient file path validation on the alm_repeaters_export() function. This makes it possible for... Read more
Affected Products : ajax_load_more- Published: Sep. 06, 2022
- Modified: May. 05, 2025
-
5.5
MEDIUMCVE-2022-2941
The WP-UserOnline plugin for WordPress has multiple Stored Cross-Site Scripting vulnerabilities in versions up to, and including 2.88.0. This is due to the fact that all fields in the "Naming Conventions" section do not properly sanitize user input, nor e... Read more
Affected Products : wp-useronline- Published: Sep. 06, 2022
- Modified: May. 05, 2025