Total
36333 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-26330 | 1 Microfocus | 1 Arcsight Logger | 2026-06-17 | N/A | 6.5 MEDIUM |
| Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exploited resulting in Information Disclosure, or Self Cross-Site Scripting (XSS). This issue affects: Micro Focus ArcSight Logger versions prior to v7.2.2 version and prior versions. | |||||
| CVE-2022-26313 | 1 Mendix | 1 Forgot Password | 2026-06-17 | 6.8 MEDIUM | 9.8 CRITICAL |
| A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1). In certain configurations of the affected product, a threat actor could use the sign up flow to hijack arbitrary user accounts. | |||||
| CVE-2022-26311 | 1 Couchbase | 1 Cloud Native Operator | 2026-06-17 | 5.0 MEDIUM | 7.5 HIGH |
| Couchbase Operator 2.2.x before 2.2.3 exposes Sensitive Information to an Unauthorized Actor. Secrets are not redacted in logs collected from Kubernetes environments. | |||||
| CVE-2022-26296 | 1 Boom-core | 1 Risvc-boom | 2026-06-17 | 2.1 LOW | 5.5 MEDIUM |
| BOOM: The Berkeley Out-of-Order RISC-V Processor commit d77c2c3 was discovered to allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | |||||
| CVE-2022-26273 | 1 Eyoucms | 1 Eyoucms | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities. | |||||
| CVE-2022-26269 | 1 Globalsuzuki | 1 Suzuki Connect | 2026-06-17 | 2.1 LOW | 4.6 MEDIUM |
| Suzuki Connect v1.0.15 allows attackers to tamper with displayed messages via spoofed CAN messages. | |||||
| CVE-2022-26131 | 1 Hegemonelectronics | 2 Plc4trucks, Plc4trucks Firmware | 2026-06-17 | 7.5 HIGH | 9.3 CRITICAL |
| Power Line Communications PLC4TRUCKS J2497 trailer receivers are susceptible to remote RF induced signals. | |||||
| CVE-2022-26112 | 1 Apache | 1 Pinot | 2026-06-17 | N/A | 9.8 CRITICAL |
| In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support. In order to avoid this, we disabled the groovy function support by default from Pinot release 0.11.0. See https://docs.pinot.apache.org/basics/releases/0.11.0 | |||||
| CVE-2022-26110 | 2 Debian, Wisc | 2 Debian Linux, Htcondor | 2026-06-17 | 6.5 MEDIUM | 8.8 HIGH |
| An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands to that daemon. | |||||
| CVE-2022-26103 | 1 Sap | 1 Netweaver Application Server Java | 2026-06-17 | 4.3 MEDIUM | 5.3 MEDIUM |
| Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to information gathering for further exploits and attacks. | |||||
| CVE-2022-26078 | 1 Gallagher | 2 Controller 6000, Controller 6000 Firmware | 2026-06-17 | 7.8 HIGH | 7.5 HIGH |
| Gallagher Controller 6000 is vulnerable to a Denial of Service attack via conflicting ARP packets with a duplicate IP address. This issue affects: Gallagher Gallagher Controller 6000 vCR8.60 versions prior to 220303a; vCR8.50 versions prior to 220303a; vCR8.40 versions prior to 220303a; vCR8.30 versions prior to 220303a. | |||||
| CVE-2022-25967 | 1 Eta.js | 1 Eta | 2026-06-17 | N/A | 8.1 HIGH |
| Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data. | |||||
| CVE-2022-25932 | 1 Inhandnetworks | 2 Inrouter302, Inrouter302 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| The firmware of InHand Networks InRouter302 V3.5.45 introduces fixes for TALOS-2022-1472 and TALOS-2022-1474. The fixes are incomplete. An attacker can still perform, respectively, a privilege escalation and an information disclosure vulnerability. | |||||
| CVE-2022-25914 | 1 Jib Project | 1 Jib | 2026-06-17 | N/A | 5.6 MEDIUM |
| The package com.google.cloud.tools:jib-core before 0.22.0 are vulnerable to Remote Code Execution (RCE) via the isDockerInstalled function, due to attempting to execute input. | |||||
| CVE-2022-25899 | 1 Intel | 1 Open Active Management Technology Cloud Toolkit | 2026-06-17 | N/A | 9.8 CRITICAL |
| Authentication bypass for the Open AMT Cloud Toolkit software maintained by Intel(R) before versions 2.0.2 and 2.2.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access. | |||||
| CVE-2022-25893 | 1 Vm2 Project | 1 Vm2 | 2026-06-17 | N/A | 9.8 CRITICAL |
| The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the WeakMap.prototype.set method. Exploiting this vulnerability leads to access to a host object and a sandbox compromise. | |||||
| CVE-2022-25892 | 1 Muhammara Project | 1 Muhammara | 2026-06-17 | N/A | 7.5 HIGH |
| The package muhammara before 2.6.1, from 3.0.0 and before 3.1.1; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed. | |||||
| CVE-2022-25891 | 1 Containrrr | 1 Shoutrrr | 2026-06-17 | N/A | 7.5 HIGH |
| The package github.com/containrrr/shoutrrr/pkg/util before 0.6.0 are vulnerable to Denial of Service (DoS) via the util.PartitionMessage function. Exploiting this vulnerability is possible by sending exactly 2000, 4000, or 6000 characters messages. | |||||
| CVE-2022-25885 | 1 Muhammara Project | 1 Muhammara | 2026-06-17 | N/A | 7.5 HIGH |
| The package muhammara before 2.6.0; all versions of package hummus are vulnerable to Denial of Service (DoS) when PDFStreamForResponse() is used with invalid data. | |||||
| CVE-2022-25860 | 1 Simple-git Project | 1 Simple-git | 2026-06-17 | N/A | 8.1 HIGH |
| Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() methods, due to improper input sanitization. This vulnerability exists due to an incomplete fix of [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221). | |||||
