Medium · CVSS 6.7
The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is a security bug that allows a limited user to get escalated admin privileges on their system.
Published Sep 23, 2022 · Updated May 22, 2025
Critical · CVSS 9.8
Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function setSmartPowerManagement with the request /goform/PowerSaveSet
Published Sep 23, 2022 · Updated May 22, 2025
Critical · CVSS 9.8
Tenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulnerability in the function fromNatStaticSetting with the request /goform/NatStaticSetting
Published Sep 23, 2022 · Updated May 22, 2025
High · CVSS 7.2
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_packages.php.
Published Sep 23, 2022 · Updated May 22, 2025
High · CVSS 7.2
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_payment.php.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 5.5
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via FoFiTrueType::writeTTF at /xpdf/FoFiTrueType.cc.
Published Sep 23, 2022 · Updated May 22, 2025
High · CVSS 7.2
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_tax.php.
Published Sep 23, 2022 · Updated May 22, 2025
Critical · CVSS 9.8
Tenda AC15 router V15.03.05.19 contains a stack overflow vulnerability in the function formSetQosBand->FUN_0007dd20 with request /goform/SetNetControlList
Published Sep 23, 2022 · Updated May 22, 2025
Critical · CVSS 9.8
Tenda AC15 router V15.03.05.19 contains a stack overflow via the list parameter at /goform/fast_setting_wifi_set
Published Sep 23, 2022 · Updated May 22, 2025
Critical · CVSS 9.8
Tenda AC15 V15.03.05.19 contained a stack overflow via the function fromAddressNat.
Published Sep 23, 2022 · Updated May 22, 2025
Critical · CVSS 9.8
Tenda AC18 router contained a stack overflow vulnerability in /goform/fast_setting_wifi_set
Published Sep 23, 2022 · Updated May 22, 2025
Critical · CVSS 9.8
Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formDelDhcpRule with the request /goform/delDhcpRules/
Published Sep 23, 2022 · Updated May 22, 2025
Critical · CVSS 9.8
Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formIPMacBindDel with the request /goform/delIpMacBind/
Published Sep 23, 2022 · Updated May 22, 2025
Critical · CVSS 9.8
Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formSetDebugCfg with request /goform/setDebugCfg/
Published Sep 23, 2022 · Updated May 22, 2025
Critical · CVSS 9.8
Tenda W20E router V15.11.0.6 contains a stack overflow in the function formSetPortMapping with post request 'goform/setPortMapping/'. This vulnerability allows attackers to cause a Denial of Service (DoS) or Remote Code Execution (RCE) via the portMappingServer, portMappingProtocol, portMappingWan, porMappingtInternal, and portMappingExternal parameters.
Published Sep 23, 2022 · Updated May 22, 2025
High · CVSS 7.2
Tenda AC18 router V15.03.05.19 contains a stack overflow vulnerability in the formSetQosBand->FUN_0007db78 function with the request /goform/SetNetControlList/
Published Sep 23, 2022 · Updated May 22, 2025
Critical · CVSS 9.8
an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction. The explotation of this vulnerability may lead an attacker to execute a shell with full access.
Published Sep 23, 2022 · Updated May 22, 2025
Critical · CVSS 9.8
This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper control of code generation in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted device. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary commands on the targeted device.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 5.5
SWFTools commit 772e55a2 was discovered to contain a floating point exception (FPE) via DCTStream::readMCURow() at /xpdf/Stream.cc.ow()
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 5.5
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via convert_gfxline at /gfxpoly/convert.c.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 6.5
IBM Common Cryptographic Architecture (CCA 5.x MTM for 4767 and CCA 7.x MTM for 4769) could allow a local user to cause a denial of service due to improper input validation. IBM X-Force ID: 223596.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 5.5
A null pointer dereference was addressed with improved validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing an image may lead to a denial-of-service.
Published Sep 23, 2022 · Updated May 22, 2025
High · CVSS 7.1
IBM Sterling Partner Engagement Manager 6.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 230017.
Published Sep 23, 2022 · Updated May 22, 2025
High · CVSS 7.8
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.
Published Sep 23, 2022 · Updated May 22, 2025
High · CVSS 8.8
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing maliciously crafted web content may lead to arbitrary code execution.
Published Sep 23, 2022 · Updated May 22, 2025
High · CVSS 7.1
This issue was addressed with improved checks. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary may result in unexpected termination or disclosure of process memory.
Published Sep 23, 2022 · Updated May 22, 2025
High · CVSS 7.8
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app with root privileges may be able to execute arbitrary code with kernel privileges.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 6.5
The issue was addressed with improved UI handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. Visiting a website that frames malicious content may lead to UI spoofing.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 4.3
A NoSQL-Injection information disclosure vulnerability vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 in the getS3FileUrl Meteor server method that can disclose arbitrary file upload URLs to users that should not be able to access.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 5.5
An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to disclose kernel memory.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 5.5
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4. An app may gain unauthorized access to Bluetooth.
Published Sep 23, 2022 · Updated May 22, 2025
High · CVSS 7.1
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary may result in unexpected termination or disclosure of process memory.
Published Sep 23, 2022 · Updated May 22, 2025
High · CVSS 8.8
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. Processing maliciously crafted web content may lead to arbitrary code execution.
Published Sep 23, 2022 · Updated May 22, 2025
High · CVSS 7.5
This issue was addressed with improved checks. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, macOS Big Sur 11.6.6, Security Update 2022-004 Catalina. A remote user may be able to cause a denial-of-service.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 5.5
An issue in the handling of environment variables was addressed with improved validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to modify protected parts of the file system.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 5.5
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5. An app may be able to bypass Privacy preferences.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 5.5
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via GfxICCBasedColorSpace::getDefaultColor(GfxColor*) at /xpdf/GfxState.cc.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 5.5
SWFTools commit 772e55a2 was discovered to contain a stack overflow via ImageStream::getPixel(unsigned char*) at /xpdf/Stream.cc.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 5.4
A cross-site scripting vulnerability exists in Rocket.chat <v5 due to style injection in the complete chat window, an adversary is able to manipulate not only the style of it, but will also be able to block functionality as well as hijacking the content of targeted users. Hence the payloads are stored in messages, it is a persistent attack vector, which will trigger as soon as the message gets viewed.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 4.3
A privilege escalation vulnerability exists in Rocket.chat <v5 which made it possible to elevate privileges for any authenticated user to view Direct messages without appropriate permissions.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 5.5
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5. An app may be able to leak sensitive kernel state.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 4.3
A information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.
Published Sep 23, 2022 · Updated May 22, 2025
High · CVSS 7.8
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to execute arbitrary code with kernel privileges.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 5.4
An issue was discovered in AjaXplorer 4.2.3, allows attackers to cause cross site scripting vulnerabilities via a crafted svg file upload.
Published Sep 23, 2022 · Updated May 22, 2025
Low · CVSS 3.7
Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows about the structure of the underlying domain model, they can craft HTTP requests that expose hidden entity attributes.
Published Sep 21, 2022 · Updated May 22, 2025
High · CVSS 8
The Web Server component of TIBCO Software Inc.'s TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 6.0.0 through 6.0.8.
Published Sep 21, 2022 · Updated May 22, 2025
High · CVSS 7.5
In Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as world-readable.
Published Sep 21, 2022 · Updated May 22, 2025
High · CVSS 7
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.7.
Published Sep 22, 2022 · Updated May 22, 2025
Medium · CVSS 6.8
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0552.
Published Sep 23, 2022 · Updated May 22, 2025
Medium · CVSS 6.4
Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7.
Published Sep 23, 2022 · Updated May 22, 2025