LiveActive security incident?Get immediate response
CVE archive

September 2022

Browse CVE records published in September 2022, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2323 matching CVEs · Page 18 of 47.

Medium · CVSS 5.3

CVE-2022-39835: An issue was discovered in Gajim through 1.4.7.

An issue was discovered in Gajim through 1.4.7. The vulnerability allows attackers, via crafted XML stanzas, to correct messages that were not sent by them. The attacker needs to be part of the group chat or single chat. The fixed version is 1.5.0.

Published Sep 27, 2022 · Updated May 21, 2025

High · CVSS 8.4

CVE-2022-22058: Memory corruption due to use after free issue in kernel while processing ION handles in Snapdragon Auto, Sn...

Memory corruption due to use after free issue in kernel while processing ION handles in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

Published Sep 26, 2022 · Updated May 21, 2025

High · CVSS 7.5

CVE-2022-3323: An SQL injection vulnerability in Advantech iView 5.7.04.6469.

An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet endpoint, which listens on TCP port 8080 by default. An unauthenticated remote attacker can craft a special column_value parameter in the setConfiguration action to bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform SQL injection. For example, the attacker can exploit the vulnerability to retrieve the iView admin password.

Published Sep 27, 2022 · Updated May 21, 2025

Low · CVSS 1.8

CVE-2022-23006: Buffer Overflow Vulnerability in Western Digital My Cloud Home Products and SanDisk ibi

A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk ibi that could allow an attacker accessing the system locally to read information from /etc/version file. This vulnerability can only be exploited by chaining it with another issue. If an attacker is able to carry out a remote code execution attack, they can gain access to the vulnerable file, due to the presence of insecure functions in code. User interaction is required for exploitation. Exploiting the vulnerability could result in exposure of information, ability to modify files, memory access errors, or system crashes.

Published Sep 27, 2022 · Updated May 21, 2025

Medium · CVSS 6.5

CVE-2022-40816: Zammad 5.2.1 is vulnerable to Incorrect Access Control.

Zammad 5.2.1 is vulnerable to Incorrect Access Control. Zammad's asset handling mechanism has logic to ensure that customer users are not able to see personal information of other users. This logic was not effective when used through a web socket connection, so that a logged-in attacker would be able to fetch personal data of other users by querying the Zammad API. This issue is fixed in , 5.2.2.

Published Sep 27, 2022 · Updated May 21, 2025

High · CVSS 8.8

CVE-2022-39032: Smart eVision - Improper Privilege Management

Smart eVision has an improper privilege management vulnerability. A remote attacker with general user privilege can exploit this vulnerability to escalate to administrator privilege, and then perform arbitrary system command or disrupt service.

Published Sep 28, 2022 · Updated May 21, 2025

Critical · CVSS 9.8

CVE-2022-39033: Smart eVision - Path Traversal -1

Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication, access restricted paths to download and delete arbitrary system files to disrupt service.

Published Sep 28, 2022 · Updated May 21, 2025

Medium · CVSS 6.5

CVE-2022-39034: Smart eVision - Path Traversal -2

Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special characters in URLs. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication, access restricted paths and download system files.

Published Sep 28, 2022 · Updated May 21, 2025

Medium · CVSS 6.1

CVE-2022-39035: Smart eVision - Stored XSS

Smart eVision has insufficient filtering for special characters in the POST Data parameter in the specific function. An unauthenticated remote attacker can inject JavaScript to perform XSS (Stored Cross-Site Scripting) attack.

Published Sep 28, 2022 · Updated May 21, 2025

High · CVSS 7.5

CVE-2022-22523: Carlo Gavazzi UWP 3.0 WebApp allows for authentication bypass

An improper authentication vulnerability exists in the Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 Web-App which allows an authentication bypass to the context of an unauthorised user if free-access is disabled.

Published Sep 28, 2022 · Updated May 21, 2025