Search Results (361517 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-22112 1 Daybydaycrm 1 Daybyday 2024-11-21 5.4 Medium
In DayByDay CRM, versions 1.1 through 2.2.1 (latest) suffer from an application-wide Client-Side Template Injection (CSTI). A low privileged attacker can input template injection payloads in the application at various locations to execute JavaScript on the client browser.
CVE-2022-22111 1 Daybydaycrm 1 Daybyday Crm 2024-11-21 8.8 High
In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled is able to change the password of other users, including the administrator’s. This allows the attacker to gain access to the highest privileged user in the application.
CVE-2022-22110 1 Daybydaycrm 1 Daybyday Crm 2024-11-21 7.5 High
In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user with privileges to update his password could change it to a weak password, such as those with a length of a single character. This may allow an attacker to brute-force users’ passwords with minimal to no computational effort.
CVE-2022-22109 1 Daybydaycrm 1 Daybyday Crm 2024-11-21 5.4 Medium
In Daybyday CRM, version 2.2.0 is vulnerable to Stored Cross-Site Scripting (XSS) vulnerability that allows low privileged application users to store malicious scripts in the title field of new tasks. These scripts are executed in a victim’s browser when they open the “/tasks” page to view all the tasks.
CVE-2022-22108 1 Daybydaycrm 1 Daybyday Crm 2024-11-21 4.3 Medium
In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the absences of all users in the system including administrators. This type of user is not authorized to view this kind of information.
CVE-2022-22107 1 Daybydaycrm 1 Daybyday Crm 2024-11-21 4.3 Medium
In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the appointments of all users in the system including administrators. However, this type of user is not authorized to view the calendar at all.
CVE-2022-22106 1 Qualcomm 4 Sa8540p, Sa8540p Firmware, Sa9000p and 1 more 2024-11-21 8.4 High
Memory corruption in multimedia due to improper length check while copying the data in Snapdragon Auto
CVE-2022-22105 1 Qualcomm 102 Apq8009, Apq8009 Firmware, Apq8017 and 99 more 2024-11-21 9.4 Critical
Memory corruption in bluetooth due to integer overflow while processing HFP-UNIT profile in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music
CVE-2022-22104 1 Qualcomm 38 Apq8096au, Apq8096au Firmware, Msm8996au and 35 more 2024-11-21 8.4 High
Memory corruption in multimedia due to improper check on the messages received. in Snapdragon Auto
CVE-2022-22103 1 Qualcomm 4 Sa8540p, Sa8540p Firmware, Sa9000p and 1 more 2024-11-21 7.8 High
Memory corruption in multimedia driver due to double free while processing data from user in Snapdragon Auto
CVE-2022-22102 1 Qualcomm 18 Qca6574au, Qca6574au Firmware, Qca6696 and 15 more 2024-11-21 8.4 High
Memory corruption in multimedia due to incorrect type conversion while adding data in Snapdragon Auto
CVE-2022-22101 1 Qualcomm 34 Apq8096au, Apq8096au Firmware, Qam8295p and 31 more 2024-11-21 6.2 Medium
Denial of service in multimedia due to uncontrolled resource consumption while parsing an incoming HAB message in Snapdragon Auto
CVE-2022-22100 1 Qualcomm 34 Apq8096au, Apq8096au Firmware, Qam8295p and 31 more 2024-11-21 8.4 High
Memory corruption in multimedia due to improper check on received export descriptors in Snapdragon Auto
CVE-2022-22099 1 Qualcomm 4 Sa8540p, Sa8540p Firmware, Sa9000p and 1 more 2024-11-21 8.4 High
Memory corruption in multimedia due to improper validation of array index in Snapdragon Auto
CVE-2022-22098 1 Qualcomm 2 Apq8096au, Apq8096au Firmware 2024-11-21 8.4 High
Memory corruption in multimedia driver due to untrusted pointer dereference while reading data from socket in Snapdragon Auto
CVE-2022-22097 1 Qualcomm 16 Qcs410, Qcs410 Firmware, Qcs610 and 13 more 2024-11-21 8.4 High
Memory corruption in graphic driver due to use after free while calling multiple threads application to driver. in Snapdragon Consumer IOT
CVE-2022-22096 1 Qualcomm 113 Aqt1000, Aqt1000 Firmware, Qca6390 and 110 more 2024-11-21 9.8 Critical
Memory corruption in Bluetooth HOST due to stack-based buffer overflow when when extracting data using command length parameter in Snapdragon Connectivity, Snapdragon Mobile
CVE-2022-22095 1 Qualcomm 98 Apq8053, Apq8053 Firmware, Msm8953 and 95 more 2024-11-21 8.4 High
Memory corruption in synx driver due to use-after-free condition in the synx driver due to accessing object handles without acquiring lock in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
CVE-2022-22094 1 Qualcomm 111 Aqt1000, Aqt1000 Firmware, Qca6390 and 108 more 2024-11-21 7.8 High
memory corruption in Kernel due to race condition while getting mapping reference in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
CVE-2022-22093 1 Qualcomm 111 Aqt1000, Aqt1000 Firmware, Qca6390 and 108 more 2024-11-21 7.8 High
Memory corruption or temporary denial of service due to improper handling of concurrent hypervisor operations to attach or detach IRQs from virtual interrupt sources in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile