Medium · CVSS 4.6
Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application in the notifications. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known workarounds for this issue.
Published Nov 25, 2022 · Updated Nov 3, 2025
High · CVSS 7
sysstat is a set of system performance tools for the Linux operating system. On 32 bit systems, in versions 9.1.16 and newer but prior to 12.7.1, allocate_structures contains a size_t overflow in sa_common.c. The allocate_structures function insufficiently checks bounds before arithmetic multiplication, allowing for an overflow in the size allocated for the buffer representing system activities. This issue may lead to Remote Code Execution (RCE). This issue has been patched in version 12.7.1.
Published Nov 8, 2022 · Updated Nov 3, 2025
High · CVSS 8.8 · CISA KEV
Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published Nov 1, 2022 · Updated Oct 21, 2025
High · CVSS 7.8 · CISA KEV
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
Published Nov 1, 2022 · Updated Oct 21, 2025
Critical · CVSS 9.8 · CISA KEV
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors.
Published Nov 8, 2022 · Updated Oct 21, 2025
Medium · CVSS 5.4 · CISA KEV
Windows Mark of the Web Security Feature Bypass Vulnerability
Published Nov 9, 2022 · Updated Oct 21, 2025
High · CVSS 7.8 · CISA KEV
Windows Print Spooler Elevation of Privilege Vulnerability
Published Nov 9, 2022 · Updated Oct 21, 2025
High · CVSS 8.8 · CISA KEV
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published Nov 9, 2022 · Updated Oct 21, 2025
Medium · CVSS 5.4 · CISA KEV
Windows Mark of the Web Security Feature Bypass Vulnerability
Published Nov 9, 2022 · Updated Oct 21, 2025
High · CVSS 7.8 · CISA KEV
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
Published Nov 9, 2022 · Updated Oct 21, 2025
High · CVSS 7.8 · CISA KEV
mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files.
Published Nov 17, 2022 · Updated Oct 21, 2025
Medium · CVSS 6.8 · CISA KEV
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters.
Published Nov 22, 2022 · Updated Oct 21, 2025
Medium · CVSS 6.8 · CISA KEV
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.
Published Nov 22, 2022 · Updated Oct 21, 2025
Critical · CVSS 9.6 · CISA KEV
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published Nov 25, 2022 · Updated Oct 21, 2025
High · CVSS 8.8 · CISA KEV
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device.
Published Nov 29, 2022 · Updated Oct 21, 2025
High · CVSS 7.1
A vulnerability exists in the Intelligent Electronic Device (IED) Connectivity Package (ConnPack) credential storage function in Hitachi Energy’s PCM600 product included in the versions listed below, where IEDs credentials are stored in a cleartext format in the PCM600 database and logs files. An attacker having get access to the exported backup file can exploit the vulnerability and obtain user credentials of the IEDs. Additionally, an attacker with administrator access to the PCM600 host machine can obtain other user credentials by analyzing database log files. The credentials may be used to perform unauthorized modifications such as loading incorrect configurations, reboot the IEDs or cause a denial-of-service on the IEDs.
Published Nov 22, 2022 · Updated Aug 27, 2025
Critical · CVSS 9.8
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: 236687.
Published Nov 16, 2022 · Updated Jul 23, 2025
High · CVSS 8.8
An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA
Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role.
Published Nov 21, 2022 · Updated Jul 23, 2025
Critical · CVSS 9.8
A cleverly devised username might bypass LDAP authentication checks. In
LDAP-authenticated Derby installations, this could let an attacker fill
up the disk by creating junk Derby databases. In LDAP-authenticated
Derby installations, this could also allow the attacker to execute
malware which was visible to and executable by the account which booted
the Derby server. In LDAP-protected databases which weren't also
protected by SQL GRANT/REVOKE authorization, this vulnerability could
also let an attacker view and corrupt sensitive data and run sensitive
database functions and procedures.
Mitigation:
Users should upgrade to Java 21 and Derby 10.17.1.0.
Alternatively, users who wish to remain on older Java versions should
build their own Derby distribution from one of the release families to
which the fix was backported: 10.16, 10.15, and 10.14. Those are the
releases which correspond, respectively, with Java LTS versions 17, 11,
and 8.
Published Nov 20, 2023 · Updated Jun 10, 2025
Critical · CVSS 9.8
Remote code execution
Published Nov 29, 2023 · Updated Jun 5, 2025
Medium · CVSS 5.4
In Tenda (Shenzhen Tenda Technology Co., Ltd) AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) issue exists allowing an attacker to execute JavaScript code via the applications website filtering tab, specifically the URL body.
Published Nov 15, 2022 · Updated May 14, 2025
Medium · CVSS 6.5
The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined with the improper authorization/improper session management vulnerability, an attacker with access to the router may be able to expose sensitive information which they're not explicitly authorized to have.
Published Nov 15, 2022 · Updated May 13, 2025
High · CVSS 7.5
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setWanPpoe function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.
Published Nov 15, 2022 · Updated May 13, 2025
Medium · CVSS 6.1
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the dashboard icons due to un-sanitized output. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.
Published Nov 14, 2022 · Updated May 13, 2025
Medium · CVSS 6.1
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the multilingual report due to un-sanitized output. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.
Published Nov 14, 2022 · Updated May 13, 2025
Medium · CVSS 4.8
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting (XSS) in dashboard/system/express/entities/associations because Concrete CMS allows association with an entity name that doesn’t exist or, if it does exist, contains XSS since it was not properly sanitized. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.
Published Nov 14, 2022 · Updated May 13, 2025
Medium · CVSS 5.5
XPDF v4.04 was discovered to contain a stack overflow via the function FileStream::copy() at xpdf/Stream.cc:795.
Published Nov 14, 2022 · Updated May 13, 2025
Medium · CVSS 6.5
Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak directory controls in the logs directory. This can lead to a denial-of-service attack on the DXL Broker.
Published Nov 7, 2022 · Updated May 8, 2025
Medium · CVSS 5.4
Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with user privileges to alter current user session. On successful exploitation, the attacker can view or modify information, causing a limited impact on confidentiality and integrity of the application.
Published Nov 8, 2022 · Updated May 8, 2025
High · CVSS 7.8
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. An app may be able to gain elevated privileges.
Published Nov 1, 2022 · Updated May 6, 2025
Medium · CVSS 5.5
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to cause a denial-of-service.
Published Nov 1, 2022 · Updated May 6, 2025
Low · CVSS 3.3
This issue was addressed with improved entitlements. This issue is fixed in iOS 16, watchOS 9. An app may be able to read a persistent device identifier.
Published Nov 1, 2022 · Updated May 6, 2025
Medium · CVSS 5.5
The issue was addressed with improved memory handling. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. An app may be able to leak sensitive kernel state.
Published Nov 1, 2022 · Updated May 6, 2025
High · CVSS 7.5
The package muhammara before 2.6.1, from 3.0.0 and before 3.1.1; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed.
Published Nov 1, 2022 · Updated May 6, 2025
Medium · CVSS 5.3
A logic issue was addressed with improved state management. This issue is fixed in iOS 16. Deleted contacts may still appear in spotlight search results.
Published Nov 1, 2022 · Updated May 6, 2025
Medium · CVSS 5.5
This issue was addressed with improved data protection. This issue is fixed in macOS Big Sur 11.7.1, macOS Ventura 13, macOS Monterey 12.6.1. An app with root privileges may be able to access private information.
Published Nov 1, 2022 · Updated May 6, 2025
High · CVSS 7.8
The issue was addressed with improved memory handling. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to execute arbitrary code with kernel privileges.
Published Nov 1, 2022 · Updated May 6, 2025
High · CVSS 7.8
The issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, watchOS 9, macOS Monterey 12.6, tvOS 16. An app may be able to execute arbitrary code with kernel privileges.
Published Nov 1, 2022 · Updated May 6, 2025
Low · CVSS 2.4
This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. A user with physical access to an iOS device may be able to read past diagnostic logs.
Published Nov 1, 2022 · Updated May 6, 2025
Medium · CVSS 5.5
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, macOS Monterey 12.6. An app may be able to access user-sensitive data.
Published Nov 1, 2022 · Updated May 6, 2025
High · CVSS 7.8
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13. Processing a maliciously crafted DMG file may lead to arbitrary code execution with system privileges.
Published Nov 1, 2022 · Updated May 6, 2025
Low · CVSS 3.3
The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Monterey 12.6, tvOS 16. A sandboxed app may be able to determine which app is currently using the camera.
Published Nov 1, 2022 · Updated May 6, 2025
High · CVSS 7.8
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Monterey 12.6, tvOS 16. An app may be able to execute arbitrary code with kernel privileges.
Published Nov 1, 2022 · Updated May 6, 2025
High · CVSS 7.8
A type confusion issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to execute arbitrary code with kernel privileges.
Published Nov 1, 2022 · Updated May 6, 2025
Medium · CVSS 5.5
This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to bypass Privacy preferences.
Published Nov 1, 2022 · Updated May 6, 2025
High · CVSS 8.8
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13. Processing maliciously crafted web content may lead to arbitrary code execution.
Published Nov 1, 2022 · Updated May 6, 2025
High · CVSS 7.1
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able to cause unexpected system termination or write kernel memory.
Published Nov 1, 2022 · Updated May 6, 2025
Medium · CVSS 6.7
The issue was addressed with improved bounds checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16. An app with root privileges may be able to execute arbitrary code with kernel privileges.
Published Nov 1, 2022 · Updated May 6, 2025
Medium · CVSS 4.3
A logic issue in the handling of concurrent media was addressed with improved state handling. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. Video self-preview in a webRTC call may be interrupted if the user answers a phone call.
Published Nov 1, 2022 · Updated May 6, 2025
High · CVSS 7.5
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. Joining a malicious Wi-Fi network may result in a denial-of-service of the Settings app.
Published Nov 1, 2022 · Updated May 6, 2025