Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
71,772 matching · page 1296/1436Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-40841(opens NVD record) | Medium | 6.1 | A cross-site scripting (XSS) vulnerability in NdkAdvancedCustomizationFields v3.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payloads injected into the "htmlNodes" parameter. | Dec 21, 2022 |
| CVE-2022-38065(opens NVD record) | High | 8.8 | A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileges. | Dec 21, 2022 |
| CVE-2022-46328(opens NVD record) | High | 7.5 | Some smartphones have the input validation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | Dec 20, 2022 |
| CVE-2022-46327(opens NVD record) | Critical | 9.8 | Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation, which results in system service exceptions. | Dec 20, 2022 |
| CVE-2022-46326(opens NVD record) | Critical | 9.8 | Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions. | Dec 20, 2022 |
| CVE-2022-46325(opens NVD record) | Critical | 9.8 | Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions. | Dec 20, 2022 |
| CVE-2022-46324(opens NVD record) | Critical | 9.8 | Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions. | Dec 20, 2022 |
| CVE-2022-46323(opens NVD record) | Critical | 9.8 | Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions. | Dec 20, 2022 |
| CVE-2022-46322(opens NVD record) | High | 7.5 | Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions. | Dec 20, 2022 |
| CVE-2022-46321(opens NVD record) | High | 7.5 | The Wi-Fi module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect data confidentiality. | Dec 20, 2022 |
| CVE-2022-46320(opens NVD record) | Critical | 9.8 | The kernel module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may cause memory overwriting. | Dec 20, 2022 |
| CVE-2022-46319(opens NVD record) | Critical | 9.8 | Fingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of this vulnerability may cause out-of-bounds write. | Dec 20, 2022 |
| CVE-2022-46318(opens NVD record) | Medium | 5.3 | The HAware module has a function logic error. Successful exploitation of this vulnerability will affect the account removal function in Settings. | Dec 20, 2022 |
| CVE-2022-46317(opens NVD record) | High | 7.5 | The power consumption module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability. | Dec 20, 2022 |
| CVE-2022-46316(opens NVD record) | Critical | 9.8 | A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability. | Dec 20, 2022 |
| CVE-2022-46315(opens NVD record) | High | 7.5 | The ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability. | Dec 20, 2022 |
| CVE-2022-46314(opens NVD record) | High | 7.5 | The IPC module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability. | Dec 20, 2022 |
| CVE-2022-46313(opens NVD record) | Medium | 5.3 | The sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause unavailability of the smartphone's camera and microphone. | Dec 20, 2022 |
| CVE-2022-46312(opens NVD record) | High | 7.5 | The application management module has a vulnerability in permission verification. Successful exploitation of this vulnerability causes unexpected clear of device applications. | Dec 20, 2022 |
| CVE-2022-46311(opens NVD record) | High | 7.5 | The contacts component has a free (undefined) provider vulnerability. Successful exploitation of this vulnerability may affect data integrity. | Dec 20, 2022 |
| CVE-2022-46310(opens NVD record) | High | 7.5 | The TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this vulnerability may affect data confidentiality. | Dec 20, 2022 |
| CVE-2022-43382(opens NVD record) | Medium | 6.2 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a local user with elevated privileges to exploit a vulnerability in the lpd daemon to cause a denial of service. IBM X-Force ID: 238641. | Dec 20, 2022 |
| CVE-2022-41599(opens NVD record) | High | 7.5 | The system service has a vulnerability that causes incorrect return values. Successful exploitation of this vulnerability may affect data confidentiality. | Dec 20, 2022 |
| CVE-2022-41596(opens NVD record) | High | 7.5 | The system tool has inconsistent serialization and deserialization. Successful exploitation of this vulnerability will cause unauthorized startup of components. | Dec 20, 2022 |
| CVE-2022-41591(opens NVD record) | High | 7.5 | The backup module has a path traversal vulnerability. Successful exploitation of this vulnerability causes unauthorized access to other system files. | Dec 20, 2022 |
| CVE-2022-41590(opens NVD record) | Medium | 5.5 | Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypassed. Successful exploitation of this vulnerability affects the smartphone availability. | Dec 20, 2022 |
| CVE-2022-39166(opens NVD record) | Medium | 4.4 | IBM Security Guardium 11.4 could allow a privileged user to obtain sensitive information inside of an HTTP response. IBM X-Force ID: 235405. | Dec 20, 2022 |
| CVE-2022-38733(opens NVD record) | High | 8.6 | OnCommand Insight versions 7.3.1 through 7.3.14 are susceptible to an authentication bypass vulnerability in the Data Warehouse component. | Dec 20, 2022 |
| CVE-2022-38391(opens NVD record) | Medium | 5.1 | IBM Spectrum Control 5.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 233982. | Dec 20, 2022 |
| CVE-2021-46856(opens NVD record) | High | 7.5 | The multi-screen collaboration module has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | Dec 20, 2022 |
| CVE-2022-46771(opens NVD record) | Medium | 4.6 | IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.18, 7.0.5.0 through 7.0.5.13, 7.1.0.0 through 7.1.2.9, 7.2.0.0 through 7.2.3.2 and 7.3.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 242273. | Dec 20, 2022 |
| CVE-2022-43875(opens NVD record) | Medium | 6.2 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an authenticated user to lock additional RM authorizations, resulting in a denial of service on displaying or managing these authorizations. IBM X-Force ID: 240034. | Dec 20, 2022 |
| CVE-2022-43872(opens NVD record) | Medium | 5.3 | IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows getting unauthorized technical information (e.g. event log entries) about the FTM SWIFT system. IBM X-Force ID: 239708. | Dec 20, 2022 |
| CVE-2022-47578(opens NVD record) | High | 7.1 | An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrictions on USB pendrives, USB HDD devices, memory cards, USB connections to mobile devices, etc., it is still possible to bypass the USB restrictions by booting into Safe Mode. This allows a file to be exchanged outside the laptop/system. Safe Mode can be launched by any user (even without admin rights). Data exfiltration can occur, and also malware might be introduced onto the system. NOTE: the vendor's position is "it's not a vulnerability in our product." | Dec 20, 2022 |
| CVE-2022-47577(opens NVD record) | High | 7.1 | An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrictions on USB pendrives, USB HDD devices, memory cards, USB connections to mobile devices, etc., it is still possible to bypass the USB restrictions by making use of a virtual machine (VM). This allows a file to be exchanged outside the laptop/system. VMs can be created by any user (even without admin rights). The data exfiltration can occur without any record in the audit trail of Windows events on the host machine. NOTE: the vendor's position is "it's not a vulnerability in our product." | Dec 20, 2022 |
| CVE-2022-40434(opens NVD record) | Critical | 9.8 | Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page. | Dec 19, 2022 |
| CVE-2022-43887(opens NVD record) | Medium | 5.3 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API keys to log files. If these keys contain sensitive information, it could lead to further attacks. IBM X-Force ID: 240450. | Dec 19, 2022 |
| CVE-2022-43883(opens NVD record) | Medium | 6.5 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 240266. | Dec 19, 2022 |
| CVE-2022-39160(opens NVD record) | Medium | 6.1 | IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 235064. | Dec 19, 2022 |
| CVE-2022-38708(opens NVD record) | Medium | 6.5 | IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 234180. | Dec 19, 2022 |
| CVE-2022-40607(opens NVD record) | Medium | 6.8 | IBM Spectrum Scale 5.1 could allow users with permissions to create pod, persistent volume and persistent volume claim to access files and directories outside of the volume, including on the host filesystem. IBM X-Force ID: 235740. | Dec 19, 2022 |
| CVE-2022-3775(opens NVD record) | High | 7.1 | When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bitmap size. As consequence an attacker can craft an input which will lead to a out-of-bounds write into grub2's heap, leading to memory corruption and availability issues. Although complex, arbitrary code execution could not be discarded. | Dec 19, 2022 |
| CVE-2022-40435(opens NVD record) | Medium | 4.8 | Employee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via adding new entries under the Departments and Designations module. | Dec 19, 2022 |
| CVE-2022-47512(opens NVD record) | Medium | 5.5 | Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Cloud Observability (HCO)/ SolarWinds Platform 2022.4. No other versions are affected | Dec 19, 2022 |
| CVE-2022-38659(opens NVD record) | Medium | 6.0 | In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent. | Dec 19, 2022 |
| CVE-2022-47521(opens NVD record) | High | 7.8 | An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_CHANNEL_LIST in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when parsing the operating channel attribute from Wi-Fi management frames. | Dec 18, 2022 |
| CVE-2022-47520(opens NVD record) | High | 7.1 | An issue was discovered in the Linux kernel before 6.0.11. Missing offset validation in drivers/net/wireless/microchip/wilc1000/hif.c in the WILC1000 wireless driver can trigger an out-of-bounds read when parsing a Robust Security Network (RSN) information element from a Netlink packet. | Dec 18, 2022 |
| CVE-2022-47519(opens NVD record) | High | 7.8 | An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_OPER_CHANNEL in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger an out-of-bounds write when parsing the channel list attribute from Wi-Fi management frames. | Dec 18, 2022 |
| CVE-2022-47518(opens NVD record) | High | 7.8 | An issue was discovered in the Linux kernel before 6.0.11. Missing validation of the number of channels in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when copying the list of operating channels from Wi-Fi management frames. | Dec 18, 2022 |
| CVE-2022-38756(opens NVD record) | Medium | 4.3 | A vulnerability has been identified in Micro Focus GroupWise Web in versions prior to 18.4.2. The GW Web component makes a request to the Post Office Agent that contains sensitive information in the query parameters that could be logged by any intervening HTTP proxies. | Dec 16, 2022 |