Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
71,772 matching · page 1301/1436Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-44955(opens NVD record) | Medium | 5.4 | webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the Chat function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Messages field. | Dec 2, 2022 |
| CVE-2022-44954(opens NVD record) | Medium | 5.4 | webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /contacts/listcontacts.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name field after clicking "Add". | Dec 2, 2022 |
| CVE-2022-44953(opens NVD record) | Medium | 5.4 | webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /linkedcontent/listfiles.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field after clicking "Add". | Dec 2, 2022 |
| CVE-2022-44952(opens NVD record) | Medium | 5.4 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in /index.php?module=configuration/application. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Copyright Text field after clicking "Add". | Dec 2, 2022 |
| CVE-2022-44951(opens NVD record) | Medium | 5.4 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab function at /index.php?module=entities/forms&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field. | Dec 2, 2022 |
| CVE-2022-44950(opens NVD record) | Medium | 5.4 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field. | Dec 2, 2022 |
| CVE-2022-44949(opens NVD record) | Medium | 5.4 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Short Name field. | Dec 2, 2022 |
| CVE-2022-44948(opens NVD record) | Medium | 5.4 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group feature at/index.php?module=entities/entities_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field after clicking "Add". | Dec 2, 2022 |
| CVE-2022-44947(opens NVD record) | Medium | 5.4 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Highlight Row feature at /index.php?module=entities/listing_types&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Note field after clicking "Add". | Dec 2, 2022 |
| CVE-2022-44946(opens NVD record) | Medium | 5.4 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Page function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field. | Dec 2, 2022 |
| CVE-2022-44945(opens NVD record) | Critical | 9.8 | Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter. | Dec 2, 2022 |
| CVE-2022-44944(opens NVD record) | Medium | 5.4 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Announcement function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field. | Dec 2, 2022 |
| CVE-2022-44291(opens NVD record) | Critical | 9.8 | webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php. | Dec 2, 2022 |
| CVE-2022-44290(opens NVD record) | Critical | 9.8 | webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php. | Dec 2, 2022 |
| CVE-2022-43901(opens NVD record) | Medium | 5.7 | IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.3 could disclose sensitive information. An authenticated local attacker could exploit this vulnerability to possibly gain information to other IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps components. IBM X-Force ID: 240829. | Dec 1, 2022 |
| CVE-2022-43900(opens NVD record) | Medium | 5.3 | IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A local attacker can create an outbound network connection to another system. IBM X-Force ID: 240827. | Dec 1, 2022 |
| CVE-2022-41297(opens NVD record) | Medium | 4.3 | IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237212. | Dec 1, 2022 |
| CVE-2022-3713(opens NVD record) | High | 8.8 | A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 GA. | Dec 1, 2022 |
| CVE-2022-3711(opens NVD record) | Medium | 4.3 | A post-auth read-only SQL injection vulnerability allows users to read non-sensitive configuration database contents in the User Portal of Sophos Firewall releases older than version 19.5 GA. | Dec 1, 2022 |
| CVE-2022-3710(opens NVD record) | Low | 2.7 | A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database contents in the API controller of Sophos Firewall releases older than version 19.5 GA. | Dec 1, 2022 |
| CVE-2022-3709(opens NVD record) | Medium | 6.8 | A stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sophos Firewall releases older than version 19.5 GA. | Dec 1, 2022 |
| CVE-2022-3696(opens NVD record) | High | 7.2 | A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA. | Dec 1, 2022 |
| CVE-2022-3226(opens NVD record) | High | 7.2 | An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version 19.5 GA. | Dec 1, 2022 |
| CVE-2022-37017(opens NVD record) | High | 7.5 | Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing security controls. This CVE applies narrowly to the Client User Interface Password protection and Policy Import/Export Password protection, if it has been enabled. | Dec 1, 2022 |
| CVE-2022-37016(opens NVD record) | Critical | 9.8 | Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user. | Dec 1, 2022 |
| CVE-2022-23746(opens NVD record) | High | 7.5 | The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the portal is configured for username/password authentication, it is vulnerable to a brute-force attack on usernames and passwords. | Nov 30, 2022 |
| CVE-2022-3859(opens NVD record) | Medium | 6.7 | An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This allows an attacker with admin access, which is required to place the DLL in the restricted Windows System folder, to elevate their privileges to System by placing a malicious DLL there. | Nov 30, 2022 |
| CVE-2022-4187(opens NVD record) | Medium | 6.5 | Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 108.0.5359.71 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium) | Nov 30, 2022 |
| CVE-2022-36964(opens NVD record) | High | 8.8 | SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands. | Nov 29, 2022 |
| CVE-2022-36962(opens NVD record) | High | 7.2 | SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete control over the SolarWinds database to execute arbitrary commands. | Nov 29, 2022 |
| CVE-2022-36960(opens NVD record) | High | 8.8 | SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to escalate user privileges. | Nov 29, 2022 |
| CVE-2022-4144(opens NVD record) | Medium | 6.5 | An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structure pointed to by the guest physical address, potentially reading past the end of the bar space into adjacent pages. A malicious guest user could use this flaw to crash the QEMU process on the host causing a denial of service condition. | Nov 29, 2022 |
| CVE-2022-38753(opens NVD record) | Medium | 6.3 | This update resolves a multi-factor authentication bypass attack | Nov 28, 2022 |
| CVE-2022-41732(opens NVD record) | Medium | 6.2 | IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 237407. | Nov 28, 2022 |
| CVE-2022-31877(opens NVD record) | High | 8.8 | An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet. | Nov 28, 2022 |
| CVE-2022-45934(opens NVD record) | High | 7.8 | An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets. | Nov 27, 2022 |
| CVE-2022-45919(opens NVD record) | High | 7.0 | An issue was discovered in the Linux kernel through 6.0.10. In drivers/media/dvb-core/dvb_ca_en50221.c, a use-after-free can occur is there is a disconnect after an open, because of the lack of a wait_event. | Nov 27, 2022 |
| CVE-2022-41157(opens NVD record) | High | 8.1 | A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the SYSTEM authority. This vulnerability could allow attackers to leak or steal sensitive information or execute malicious commands. | Nov 25, 2022 |
| CVE-2022-41156(opens NVD record) | High | 7.8 | Remote code execution vulnerability due to insufficient verification of URLs, etc. in OndiskPlayerAgent. A remote attacker could exploit the vulnerability to cause remote code execution by causing an arbitrary user to download and execute malicious code. | Nov 25, 2022 |
| CVE-2022-45210(opens NVD record) | Medium | 4.3 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin. | Nov 25, 2022 |
| CVE-2022-45208(opens NVD record) | Medium | 4.3 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin. | Nov 25, 2022 |
| CVE-2022-45207(opens NVD record) | Critical | 9.8 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString. | Nov 25, 2022 |
| CVE-2022-45206(opens NVD record) | Critical | 9.8 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check. | Nov 25, 2022 |
| CVE-2022-45205(opens NVD record) | Medium | 5.3 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData. | Nov 25, 2022 |
| CVE-2022-37721(opens NVD record) | Critical | 9.0 | PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation. | Nov 25, 2022 |
| CVE-2022-38377(opens NVD record) | Medium | 4.3 | An improper access control vulnerability [CWE-284] in FortiManager 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11 and FortiAnalyzer 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.0 through 6.0.12 may allow a remote and authenticated admin user assigned to a specific ADOM to access other ADOMs information such as device information and dashboard information. | Nov 25, 2022 |
| CVE-2022-37720(opens NVD record) | Critical | 9.0 | Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation when the malicious blog post is loaded in the victim's browser. | Nov 25, 2022 |
| CVE-2022-38166(opens NVD record) | High | 7.5 | In F-Secure Endpoint Protection for Windows and macOS before channel with Capricorn database 2022-11-22_07, the aerdl.dll unpacker handler crashes. This can lead to a scanning engine crash, triggerable remotely by an attacker for denial of service. | Nov 25, 2022 |
| CVE-2022-45888(opens NVD record) | Medium | 6.4 | An issue was discovered in the Linux kernel through 6.0.9. drivers/char/xillybus/xillyusb.c has a race condition and use-after-free during physical removal of a USB device. | Nov 25, 2022 |
| CVE-2022-45887(opens NVD record) | Medium | 4.7 | An issue was discovered in the Linux kernel through 6.0.9. drivers/media/usb/ttusb-dec/ttusb_dec.c has a memory leak because of the lack of a dvb_frontend_detach call. | Nov 25, 2022 |