CVE-2022-29818

CVSS v3 Score
7.1
High
CVSS v2 Score
3.6
Low

Vulnerability Description

In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed

CVSS:7.1(High)

An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database.

CVSS:7.2(High)

AVEVA System Platform versions 2017 through 2020 R2 P01 does not properly verify that the source of data or communication is valid.

CVSS:7.3(High)

An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, aka MMSA-2020-0006.

CVSS:7.3(High)

Yandex Browser for Android 20.8.4 allows remote attackers to perform SOP bypass and addresss bar spoofing

CVSS:6.8(Medium)

For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox. This may result in esc...

CVSS:6.8(Medium)

An Insufficient Firmware Update Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras adjacent network to make unsupported changes to the camera sy...