Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Total 36333 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-28283 1 Mozilla 1 Firefox 2026-06-17 N/A 6.5 MEDIUM
The sourceMapURL feature in devtools was missing security checks that would have allowed a webpage to attempt to include local files or other files that should have been inaccessible. This vulnerability affects Firefox < 99.
CVE-2022-28229 1 Userver 1 Userver 2026-06-17 N/A 7.5 HIGH
The hash functionality in userver before 42059b6319661583b3080cab9b595d4f8ac48128 allows attackers to cause a denial of service via crafted HTTP request, involving collisions.
CVE-2022-28209 1 Mediawiki 1 Mediawiki 2026-06-17 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Mediawiki through 1.37.1. The check for the override-antispoof permission in the AntiSpoof extension is incorrect.
CVE-2022-28206 1 Mediawiki 1 Mediawiki 2026-06-17 7.5 HIGH 9.8 CRITICAL
An issue was discovered in MediaWiki through 1.37.1. ImportPlanValidator.php in the FileImporter extension mishandles the check for edit rights.
CVE-2022-28205 1 Mediawiki 1 Mediawiki 2026-06-17 7.5 HIGH 9.8 CRITICAL
An issue was discovered in MediaWiki through 1.37.1. The CentralAuth extension mishandles a ttl issue for groups expiring in the future.
CVE-2022-28204 1 Mediawiki 1 Mediawiki 2026-06-17 N/A 7.5 HIGH
A denial-of-service issue was discovered in MediaWiki 1.37.x before 1.37.2. Rendering of w/index.php?title=Special%3AWhatLinksHere&target=Property%3AP31&namespace=1&invert=1 can take more than thirty seconds. There is a DDoS risk.
CVE-2022-28198 2 Microsoft, Nvidia 3 Windows, Omniverse Cache, Omniverse Nucleus 2026-06-17 4.6 MEDIUM 6.6 MEDIUM
NVIDIA Omniverse Nucleus and Cache contain a vulnerability in its configuration of OpenSSL, where an attacker with physical access to the system can cause arbitrary code execution which can impact confidentiality, integrity, and availability.
CVE-2022-28184 1 Nvidia 2 Gpu Display Driver, Virtual Gpu 2026-06-17 4.6 MEDIUM 7.1 HIGH
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can access administrator- privileged registers, which may lead to denial of service, information disclosure, and data tampering.
CVE-2022-28114 1 Dscms Project 1 Dscms 2026-06-17 6.4 MEDIUM 9.1 CRITICAL
DSCMS v3.0 was discovered to contain an arbitrary file deletion vulnerability via /controller/Adv.php.
CVE-2022-28076 1 Seacms 1 Seacms 2026-06-17 6.5 MEDIUM 7.2 HIGH
Seacms v11.6 was discovered to contain a remote command execution (RCE) vulnerability via the Mail Server Settings.
CVE-2022-28063 1 Simple Bakery Shop Management System Project 1 Simple Bakery Shop Management System 2026-06-17 4.0 MEDIUM 4.9 MEDIUM
Simple Bakery Shop Management System v1.0 contains a file disclosure via /bsms/?page=products.
CVE-2022-28056 1 Shopxo 1 Shopxo 2026-06-17 7.5 HIGH 9.8 CRITICAL
ShopXO v2.2.5 and below was discovered to contain a system re-install vulnerability via the Add function in app/install/controller/Index.php.
CVE-2022-27983 1 Ruijienetworks 2 Rg-nbr2100g-e, Rg-nbr2100g-e Firmware 2026-06-17 5.0 MEDIUM 7.5 HIGH
RG-NBR-E Enterprise Gateway RG-NBR2100G-E was discovered to contain an arbitrary file read vulnerability via the url parameter in check.php.
CVE-2022-27982 1 Ruijienetworks 2 Rg-nbr2100g-e, Rg-nbr2100g-e Firmware 2026-06-17 7.5 HIGH 9.8 CRITICAL
RG-NBR-E Enterprise Gateway RG-NBR2100G-E was discovered to contain a remote code execution (RCE) vulnerability via the fileName parameter at /guest_auth/cfg/upLoadCfg.php.
CVE-2022-27969 1 Cynet 1 Cynet 360 2026-06-17 N/A 5.3 MEDIUM
Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of decoy users via a crafted GET request sent to /WebApp/DeceptionUser/GetAllDeceptionUsers.
CVE-2022-27968 1 Cynet 1 Cynet 360 2026-06-17 N/A 5.3 MEDIUM
Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of monitored files and profiles via a crafted GET request sent to /WebApp/SettingsFileMonitor/GetFileMonitorProfiles.
CVE-2022-27967 1 Cynet 1 Cynet 360 2026-06-17 N/A 5.3 MEDIUM
Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of excluded files and profiles via a crafted GET request sent to /WebApp/SettingsExclusion/GetExclusionsProfiles.
CVE-2022-27948 1 Tesla 6 Model 3, Model 3 Firmware, Model S and 3 more 2026-06-17 3.3 LOW 7.2 HIGH
Certain Tesla vehicles through 2022-03-26 allow attackers to open the charging port via a 315 MHz RF signal containing a fixed sequence of approximately one hundred symbols. NOTE: the vendor's perspective is that the behavior is as intended
CVE-2022-27936 1 Pexip 1 Pexip Infinity 2026-06-17 5.0 MEDIUM 7.5 HIGH
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via H.323.
CVE-2022-27935 1 Pexip 1 Pexip Infinity 2026-06-17 5.0 MEDIUM 7.5 HIGH
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via Epic Telehealth.