Updated CVEs

IDDescriptionSeverityUpdated
CVE-2022-23925Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.
high
2026-10-08
CVE-2022-23924Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.
high
2026-10-08
CVE-2022-23456Potential arbitrary file deletion vulnerability has been identified in HP Support Assistant software.
medium
2026-10-08
CVE-2022-2345Use After Free in GitHub repository vim/vim prior to 9.0.0046.
high
2026-10-08
CVE-2022-2344Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0045.
high
2026-10-08
CVE-2022-23437There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
medium
2026-10-08
CVE-2022-2343Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0044.
high
2026-10-08
CVE-2022-2304Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
high
2026-10-08
CVE-2022-22971In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
medium
2026-10-08
CVE-2022-22970In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
medium
2026-10-08
CVE-2022-22968In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.
medium
2026-10-08
CVE-2022-22950n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.
medium
2026-10-08
CVE-2022-2287Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
high
2026-10-08
CVE-2022-2286Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
high
2026-10-08
CVE-2022-2285Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.
high
2026-10-08
CVE-2022-2284Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
high
2026-10-08
CVE-2022-2257Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
high
2026-10-08
CVE-2022-2210Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
high
2026-10-08
CVE-2022-2208NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.5163.
medium
2026-10-08
CVE-2022-2207Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
high
2026-10-08
CVE-2022-2206Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
high
2026-10-08
CVE-2022-21991Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability
high
2026-10-08
CVE-2022-21986.NET Denial of Service Vulnerability
high
2026-10-08
CVE-2022-2183Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
high
2026-10-08
CVE-2022-2182Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
high
2026-10-08
CVE-2022-2175Buffer Over-read in GitHub repository vim/vim prior to 8.2.
high
2026-10-08
CVE-2022-2129Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
high
2026-10-08
CVE-2022-2126Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
high
2026-10-08
CVE-2022-2125Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
high
2026-10-08
CVE-2022-2124Buffer Over-read in GitHub repository vim/vim prior to 8.2.
high
2026-10-08
CVE-2022-2042Use After Free in GitHub repository vim/vim prior to 8.2.
high
2026-10-08
CVE-2022-20154In lock_sock_nested of sock.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-174846563References: Upstream kernel
medium
2026-10-08
CVE-2022-20153In rcu_cblist_dequeue of rcu_segcblist.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-222091980References: Upstream kernel
medium
2026-10-08
CVE-2022-1674NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in GitHub repository vim/vim prior to 8.2.4938. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 allows attackers to cause a denial of service (application crash) via a crafted input.
medium
2026-10-08
CVE-2022-1665A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even though it shouldn't. These kernel builds don't have the secure boot lockdown patches applied to it and can bypass the secure boot validations, allowing the attacker to load another non-trusted code.
high
2026-10-08
CVE-2022-1620NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 in GitHub repository vim/vim prior to 8.2.4901. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 allows attackers to cause a denial of service (application crash) via a crafted input.
high
2026-10-08
CVE-2022-1619Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2.4899. This vulnerabilities are capable of crashing software, modify memory, and possible remote execution
high
2026-10-08
CVE-2022-1616Use after free in append_command in GitHub repository vim/vim prior to 8.2.4895. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
high
2026-10-08
CVE-2022-0987A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This issue allows a local user to measure the time the methods take to execute and know whether a file owned by root or other users exists.
low
2026-10-08
CVE-2022-0530A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
medium
2026-10-08
CVE-2022-0529A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
medium
2026-10-08
CVE-2022-0500A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows a local user to crash or escalate their privileges on the system.
high
2026-10-08
CVE-2022-0351Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2.
high
2026-10-08
CVE-2022-0264A vulnerability was found in the Linux kernel's eBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak internal kernel memory details defeating some of the exploit mitigations in place for the kernel. This flaws affects kernel versions < v5.16-rc6
medium
2026-10-08
CVE-2022-0213vim is vulnerable to Heap-based Buffer Overflow
medium
2026-10-08
CVE-2022-0144shelljs is vulnerable to Improper Privilege Management
high
2026-10-08
CVE-2021-48007PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packets with invalid floating-point values to crash servers through unhandled mathematical operations or prevent clients from rendering other players.
high
2026-10-08
CVE-2021-48006PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but only removes an exactly matching entry, so an operator name stored with non-lowercase letters cannot be revoked using the deop command, leaving the player as an operator until the entry is removed from ops.txt manually.
medium
2026-10-08
CVE-2021-47935Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary commands by injecting malicious pickle-serialized objects through the audit log entry data parameter. Attackers can submit crafted POST requests to the admin audit log endpoint with base64-encoded compressed pickle payloads in the data field to achieve code execution with application privileges.
high
2026-10-08
CVE-2021-47776Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl parameters in multiple dashboard and help controller endpoints. Attackers can craft malicious requests to the GetContextHelpForPage, GetRemoteDashboardContent, and GetRemoteDashboardCss endpoints to trigger unauthorized server-side requests to external hosts.
medium
2026-10-08