SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

28 results for “kev-cve-2022-22954” · 2.31 s · cached

Facets · 1 entity types

28 CVE
CVE-2025-22954CVE

CVE-2025-22954

GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid or serialid parameter.

CVSS 10.0EPSS 25.6%
Match for kev-cve-2022-22954
CVE-2026-42914CVE

CVE-2026-42914

Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.

CVSS 5.3EPSS 0.8%microsoft
Match for kev-cve-2022-22954
CVE-2025-29922CVE

CVE-2025-29922

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.26.3, the identified vulnerability allows creating or deleting an object vi…

CVSS 9.6EPSS 0.4%
Match for kev-cve-2022-22954
CVE-2025-24956CVE

CVE-2025-24956

A vulnerability has been identified in OpenV2G (All versions < V0.9.6). The OpenV2G EXI parsing feature is missing a length check when parsing X509 serial numbers. Thus, an attacker could introduce a…

CVSS 9.8EPSS 0.4%
Match for kev-cve-2022-22954
CVE-2026-48556CVE

CVE-2026-48556

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2022-22954
CVE-2026-40527CVE

CVE-2026-40527

radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences as DWARF DW_TAG_formal_pa…

CVSS 7.8EPSS 1.5%radare
Match for kev-cve-2022-22954
CVE-2026-42799CVE

CVE-2026-42799

Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects …

CVSS 9.8EPSS 0.4%
Match for kev-cve-2022-22954
CVE-2026-31553CVE

CVE-2026-31553

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix the descriptor address in __kvm_at_swap_desc() Using "(u64 __user *)hva + offset" to get the virtual addresses of…

CVSS 8.8EPSS 0.2%
Match for kev-cve-2022-22954
CVE-2026-23112CVE

CVE-2026-23112

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk past cmd->req.sg when a PDU leng…

CVSS 9.8EPSS 0.4%linux
Match for kev-cve-2022-22954
CVE-2026-5434CVE

CVE-2026-5434

Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially…

CVSS 5.9EPSS 0.3%
Match for kev-cve-2022-22954
CVE-2026-29955CVE

CVE-2026-29955

The `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. The component uses `subprocess.Popen()` with `shell=True` parameter to execute sh…

CVSS 8.8EPSS 2.9%
Match for kev-cve-2022-22954
CVE-2026-25259CVE

CVE-2026-25259

Memory corruption while processing multiple IOCTL command for escape operations.

CVSS 7.8EPSS 0.1%qualcomm
Match for kev-cve-2022-22954
CVE-2026-27654CVE

CVE-2026-27654

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may r…

CVSS 8.2EPSS 25.1%f5
Match for kev-cve-2022-22954
CVE-2026-42984CVE

CVE-2026-42984

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVSS 7.0EPSS 0.3%microsoft
Match for kev-cve-2022-22954
CVE-2026-43452CVE

CVE-2026-43452

In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: guard option walkers against 1-byte tail reads When the last byte of options is a non-single-byte option kin…

CVSS 8.2EPSS 0.6%
Match for kev-cve-2022-22954
CVE-2026-25209CVE

CVE-2026-25209

Out-of-bounds read vulnerability in Samsung Open Source Escargot allows Resource Leak Exposure.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335.

CVSS 9.1EPSS 0.3%
Match for kev-cve-2022-22954
CVE-2025-24514CVE

CVE-2025-24514

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into nginx. This can lead to…

CVSS 8.8EPSS 30.5%
Match for kev-cve-2022-22954
CVE-2025-8654CVE

CVE-2025-8654

Kenwood DMX958XR ReadMVGImage Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Kenwoo…

CVSS 8.8EPSS 0.8%
Match for kev-cve-2022-22954
CVE-2026-40685CVE

CVE-2026-40685

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation…

CVSS 9.8EPSS 0.6%
Match for kev-cve-2022-22954
CVE-2024-56122CVE

CVE-2024-56122

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2022-22954
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.