Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
70,050 matching · page 1247/1401Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-34451(opens NVD record) | Medium | 4.8 | PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains a Stored Cross-site Scripting Vulnerability. An authenticated admin user could potentially exploit this vulnerability, to hijack user sessions or trick a victim application user into unknowingly send arbitrary requests to the server. | Feb 11, 2023 |
| CVE-2022-34450(opens NVD record) | Medium | 6.7 | PowerPath Management Appliance with version 3.3 contains Privilege Escalation vulnerability. An authenticated admin user could potentially exploit this issue and gain unrestricted control/code execution on the system as root. | Feb 11, 2023 |
| CVE-2022-34449(opens NVD record) | Medium | 6.0 | PowerPath Management Appliance with versions 3.3 & 3.2* contains a Hardcoded Cryptographic Keys vulnerability. Authenticated admin users can exploit the issue that leads to view and modifying sensitive information stored in the application. | Feb 11, 2023 |
| CVE-2022-34448(opens NVD record) | High | 8.8 | PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains a Cross-site Request Forgery vulnerability. An unauthenticated non-privileged user could potentially exploit the issue and perform any privileged state-changing actions. | Feb 11, 2023 |
| CVE-2022-34447(opens NVD record) | High | 7.2 | PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains OS Command Injection vulnerability. An authenticated remote attacker with administrative privileges could potentially exploit the issue and execute commands on the system as the root user. | Feb 11, 2023 |
| CVE-2022-34446(opens NVD record) | High | 8.8 | PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass vulnerability. An authenticated remote user with limited privileges (e.g., of role Monitoring) can exploit this issue and gain access to sensitive information, and modify the configuration. | Feb 11, 2023 |
| CVE-2022-34445(opens NVD record) | Medium | 6.0 | Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A malicious local privileged attacker may potentially exploit this vulnerability, leading to information disclosure. | Feb 11, 2023 |
| CVE-2022-34444(opens NVD record) | Medium | 5.9 | Dell PowerScale OneFS, versions 9.2.0.x through 9.4.0.x contain an information vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to cause data leak. | Feb 11, 2023 |
| CVE-2022-34404(opens NVD record) | Medium | 6.5 | Dell System Update, version 2.0.0 and earlier, contains an Improper Certificate Validation in data parser module. A local attacker with high privileges could potentially exploit this vulnerability, leading to credential theft and/or denial of service. | Feb 11, 2023 |
| CVE-2022-34392(opens NVD record) | Medium | 5.5 | SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability. An authenticated non-admin user can be able to obtain the refresh token and that leads to reuse the access token and fetch sensitive information. | Feb 11, 2023 |
| CVE-2022-34389(opens NVD record) | Low | 3.7 | Dell SupportAssist contains a rate limit bypass issues in screenmeet API third party component. An unauthenticated attacker could potentially exploit this vulnerability and impersonate a legitimate dell customer to a dell support technician. | Feb 11, 2023 |
| CVE-2022-34388(opens NVD record) | High | 7.1 | Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain information disclosure vulnerability. A local malicious user with low privileges could exploit this vulnerability to view and modify sensitive information in the database of the affected application. | Feb 11, 2023 |
| CVE-2022-34387(opens NVD record) | Medium | 6.4 | Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this vulnerability to elevate privileges and gain total control of the system. | Feb 11, 2023 |
| CVE-2022-34386(opens NVD record) | Medium | 5.5 | Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information. | Feb 11, 2023 |
| CVE-2022-34385(opens NVD record) | Medium | 5.5 | SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information. | Feb 11, 2023 |
| CVE-2022-34384(opens NVD record) | High | 7.8 | Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | Update, Dell Update, and Alienware Update versions before 4.5 contain a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user may potentially exploit this vulnerability, leading to privilege escalation. | Feb 11, 2023 |
| CVE-2023-24816(opens NVD record) | Medium | 4.5 | IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Versions prior to 8.1.0 are subject to a command injection vulnerability with very specific prerequisites. This vulnerability requires that the function `IPython.utils.terminal.set_term_title` be called on Windows in a Python environment where ctypes is not available. The dependency on `ctypes` in `IPython.utils._process_win32` prevents the vulnerable code from ever being reached in the ipython binary. However, as a library that could be used by another tool `set_term_title` could be called and hence introduce a vulnerability. Should an attacker get untrusted input to an instance of this function they would be able to inject shell commands as current process and limited to the scope of the current process. Users of ipython as a library are advised to upgrade. Users unable to upgrade should ensure that any calls to the `IPython.utils.terminal.set_term_title` function are done with trusted or filtered input. | Feb 10, 2023 |
| CVE-2022-34377(opens NVD record) | Low | 1.9 | Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service. | Feb 10, 2023 |
| CVE-2022-34376(opens NVD record) | Low | 3.9 | Dell PowerEdge BIOS and Dell Precision BIOS contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by manipulating an SMI to cause a denial of service during SMM. | Feb 10, 2023 |
| CVE-2022-34366(opens NVD record) | Medium | 6.5 | Dell SupportAssist for Home PCs (version 3.11.2 and prior) contain Overly Permissive Cross-domain Whitelist vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information. | Feb 10, 2023 |
| CVE-2022-34364(opens NVD record) | Medium | 4.4 | Dell BSAFE SSL-J, versions before 6.5 and version 7.0 contain a debug message revealing unnecessary information vulnerability. This may lead to disclosing sensitive information to a locally privileged user. . | Feb 10, 2023 |
| CVE-2022-33934(opens NVD record) | High | 7.7 | Dell PowerScale OneFS, versions 8.2.x through 9.4.x contain multiple stored cross-site scripting vulnerabilities. A remote authenticated malicious user with high privileges may potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple affected fields. | Feb 10, 2023 |
| CVE-2023-24573(opens NVD record) | Medium | 4.7 | Dell Command | Monitor versions prior to 10.9 contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion. | Feb 10, 2023 |
| CVE-2023-24569(opens NVD record) | High | 7.8 | Dell Alienware Command Center versions 5.5.37.0 and prior contain an Improper Input validation vulnerability. A local authenticated malicious user could potentially send malicious input to a named pipe in order to elevate privileges on the system. | Feb 10, 2023 |
| CVE-2023-23698(opens NVD record) | Medium | 5.5 | Dell Command | Update, Dell Update, and Alienware Update versions before 4.6.0 and 4.7.1 contain Insecure Operation on Windows Junction in the installer component. A local malicious user may potentially exploit this vulnerability leading to arbitrary file delete. | Feb 10, 2023 |
| CVE-2018-7935(opens NVD record) | Medium | 5.3 | There is a vulnerability in 21.328.01.00.00 version of the E5573Cs-322. Remote attackers could exploit this vulnerability to make the network where the E5573Cs-322 is running temporarily unavailable. | Feb 10, 2023 |
| CVE-2022-24410(opens NVD record) | Medium | 6.8 | Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the system and knowledge of the system configuration could potentially exploit this vulnerability to read system information via debug interfaces. | Feb 10, 2023 |
| CVE-2022-34454(opens NVD record) | Medium | 6.7 | Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a heap-based buffer overflow. A local privileged malicious user could potentially exploit this vulnerability, leading to system takeover. This impacts compliance mode clusters. | Feb 10, 2023 |
| CVE-2022-34452(opens NVD record) | Low | 2.7 | PowerPath Management Appliance with versions 3.3, 3.2*, 3.1 & 3.0* contains sensitive information disclosure vulnerability. An Authenticated admin user can able to exploit the issue and view sensitive information stored in the logs. | Feb 10, 2023 |
| CVE-2023-23592(opens NVD record) | High | 7.5 | WALLIX Access Manager 3.x through 4.0.x allows a remote attacker to access sensitive information. | Feb 9, 2023 |
| CVE-2023-23912(opens NVD record) | High | 8.8 | A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with their DHCPv6 prefix delegation set to dhcpv6-stateless or dhcpv6-stateful, allows a malicious actor directly connected to the WAN interface of an affected device to create a remote code execution vulnerability. | Feb 9, 2023 |
| CVE-2022-43550(opens NVD record) | Critical | 9.8 | A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows which could allow an attacker to insert an arbitrary URL which opens up the opportunity to remote execution. | Feb 9, 2023 |
| CVE-2023-0575(opens NVD record) | High | 7.2 | External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege Abuse. This vulnerability is associated with program files backup.Py. This issue affects Yugabyte DB: Lesser then 2.2.0.0 | Feb 9, 2023 |
| CVE-2022-48302(opens NVD record) | High | 7.5 | The AMS module has a vulnerability of lacking permission verification in APIs.Successful exploitation of this vulnerability may affect data confidentiality. | Feb 9, 2023 |
| CVE-2022-48301(opens NVD record) | High | 7.5 | The bundle management module lacks permission verification in some APIs. Successful exploitation of this vulnerability may restore the pre-installed apps that have been uninstalled. | Feb 9, 2023 |
| CVE-2022-48300(opens NVD record) | High | 7.5 | The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality. | Feb 9, 2023 |
| CVE-2022-48299(opens NVD record) | High | 7.5 | The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality. | Feb 9, 2023 |
| CVE-2022-48298(opens NVD record) | High | 7.5 | The geofencing kernel code does not verify the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access. | Feb 9, 2023 |
| CVE-2022-48297(opens NVD record) | High | 7.5 | The geofencing kernel code has a vulnerability of not verifying the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access. | Feb 9, 2023 |
| CVE-2022-48296(opens NVD record) | Medium | 5.3 | The SystemUI has a vulnerability in permission management. Successful exploitation of this vulnerability may cause users to receive broadcasts from malicious apps, conveying false alarm information about external storage devices. | Feb 9, 2023 |
| CVE-2022-48295(opens NVD record) | High | 7.5 | The IHwAntiMalPlugin interface lacks permission verification. Successful exploitation of this vulnerability can lead to filling problems (batch installation of applications). | Feb 9, 2023 |
| CVE-2022-48294(opens NVD record) | High | 7.5 | The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiality. | Feb 9, 2023 |
| CVE-2022-48293(opens NVD record) | Medium | 6.5 | The Bluetooth module has an OOM vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | Feb 9, 2023 |
| CVE-2022-48292(opens NVD record) | Medium | 6.5 | The Bluetooth module has an out-of-memory (OOM) vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | Feb 9, 2023 |
| CVE-2022-48290(opens NVD record) | Critical | 9.1 | The phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality and integrity. | Feb 9, 2023 |
| CVE-2022-48289(opens NVD record) | High | 7.5 | The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality. | Feb 9, 2023 |
| CVE-2022-48288(opens NVD record) | High | 7.5 | The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality. | Feb 9, 2023 |
| CVE-2022-48287(opens NVD record) | High | 7.5 | The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data integrity. | Feb 9, 2023 |
| CVE-2022-48286(opens NVD record) | High | 7.5 | The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | Feb 9, 2023 |
| CVE-2022-38777(opens NVD record) | High | 7.8 | An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account. | Feb 8, 2023 |