Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
71,857 matching · page 1306/1438Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-42129(opens NVD record) | Medium | 4.3 | An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before update 4, and 7.4 GA allows remote authenticated users to view and access form entries via the `formInstanceRecordId` parameter. | Nov 15, 2022 |
| CVE-2022-42128(opens NVD record) | Medium | 5.3 | The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which allows remote attackers to obtain a WikiNode object via the WikiNodeResource.getSiteWikiNodeByExternalReferenceCode API. | Nov 15, 2022 |
| CVE-2022-42127(opens NVD record) | Medium | 5.3 | The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check user permissions, which allows remote attackers to obtain the history of all friendly URLs that was assigned to a page. | Nov 15, 2022 |
| CVE-2022-42126(opens NVD record) | Medium | 4.3 | The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset libraries via the UI. | Nov 15, 2022 |
| CVE-2022-42125(opens NVD record) | High | 7.5 | Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows attackers to create or overwrite existing files on the filesystem via the deployment of a malicious plugin/module. | Nov 15, 2022 |
| CVE-2022-42124(opens NVD record) | High | 7.5 | ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 through 7.4.3.4 and Liferay DXP 7.2 fix pack 9 through fix pack 18, 7.3 before update 4, and DXP 7.4 GA allows remote attackers to consume an excessive amount of server resources via a crafted payload injected into the 'name' field of a layout prototype. | Nov 15, 2022 |
| CVE-2022-42123(opens NVD record) | High | 7.5 | A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin. | Nov 15, 2022 |
| CVE-2022-42122(opens NVD record) | Critical | 9.8 | A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL. | Nov 15, 2022 |
| CVE-2022-42121(opens NVD record) | High | 8.8 | A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template's 'Name' field. | Nov 15, 2022 |
| CVE-2022-42120(opens NVD record) | Critical | 9.8 | A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute. | Nov 15, 2022 |
| CVE-2022-42119(opens NVD record) | Medium | 5.4 | Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8. | Nov 15, 2022 |
| CVE-2022-42118(opens NVD record) | Medium | 6.1 | A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the `tag` parameter. | Nov 15, 2022 |
| CVE-2022-34320(opens NVD record) | Medium | 5.9 | IBM CICS TX 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 229464. | Nov 14, 2022 |
| CVE-2022-34317(opens NVD record) | Medium | 5.4 | IBM CICS TX 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229459. | Nov 14, 2022 |
| CVE-2022-34316(opens NVD record) | Low | 3.7 | IBM CICS TX 11.1 does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers. IBM X-Force ID: 229452. | Nov 14, 2022 |
| CVE-2022-34315(opens NVD record) | Medium | 5.4 | IBM CICS TX 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229451. | Nov 14, 2022 |
| CVE-2022-34314(opens NVD record) | Medium | 4.0 | IBM CICS TX 11.1 could disclose sensitive information to a local user due to insecure permission settings. IBM X-Force ID: 229450. | Nov 14, 2022 |
| CVE-2022-38705(opens NVD record) | Medium | 5.3 | IBM CICS TX 11.1 Standard and Advanced could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a victim to a phishing site. IBM X-Force ID: 234172. | Nov 14, 2022 |
| CVE-2022-34329(opens NVD record) | Medium | 5.3 | IBM CICS TX 11.7 could allow an attacker to obtain sensitive information from HTTP response headers. IBM X-Force ID: 229467. | Nov 14, 2022 |
| CVE-2022-34319(opens NVD record) | Medium | 5.9 | IBM CICS TX 11.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 229463. | Nov 14, 2022 |
| CVE-2022-34313(opens NVD record) | Medium | 4.3 | IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. X-Force ID: 229449. | Nov 14, 2022 |
| CVE-2022-34312(opens NVD record) | Medium | 4.0 | IBM CICS TX 11.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 229447. | Nov 14, 2022 |
| CVE-2022-35719(opens NVD record) | Medium | 5.1 | IBM MQ Internet Pass-Thru 2.1, 9.2 LTS and 9.2 CD stores potentially sensitive information in trace files that could be read by a local user. | Nov 14, 2022 |
| CVE-2022-3970(opens NVD record) | Medium | 6.3 | A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f7aa570050e62617e3be. It is recommended to apply a patch to fix this issue. The identifier VDB-213549 was assigned to this vulnerability. | Nov 13, 2022 |
| CVE-2022-38652(opens NVD record) | Critical | 9.9 | A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authenticated user to run arbitrary code or malware within a Hyperic Agent instance and its host operating system with the privileges of the Hyperic Agent process (often SYSTEM on Windows platforms). NOTE: prior exploitation of CVE-2022-38650 results in the disclosure of the authentication material required to exploit this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | Nov 12, 2022 |
| CVE-2022-38651(opens NVD record) | Critical | 9.8 | A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some authentication requirements when issuing requests to Hyperic Server. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | Nov 12, 2022 |
| CVE-2022-38650(opens NVD record) | Critical | 10.0 | A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to run arbitrary code or malware within Hyperic Server and the host operating system with the privileges of the Hyperic server process. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | Nov 12, 2022 |
| CVE-2022-43672(opens NVD record) | Critical | 9.8 | Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671. | Nov 12, 2022 |
| CVE-2022-43671(opens NVD record) | Critical | 9.8 | Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection. | Nov 12, 2022 |
| CVE-2022-41339(opens NVD record) | High | 7.8 | In Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege escalation. | Nov 12, 2022 |
| CVE-2022-40773(opens NVD record) | High | 8.8 | Zoho ManageEngine ServiceDesk Plus MSP before 10609 and SupportCenter Plus before 11025 are vulnerable to privilege escalation. This allows users to obtain sensitive data during an exportMickeyList export of requests from the list view. | Nov 12, 2022 |
| CVE-2022-40750(opens NVD record) | Medium | 5.4 | IBM WebSphere Application Server 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 236588. | Nov 11, 2022 |
| CVE-2022-38387(opens NVD record) | High | 7.1 | IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 233786. | Nov 11, 2022 |
| CVE-2022-36776(opens NVD record) | Medium | 5.4 | IBM Cloud Pak for Security (CP4S) 1.10.0.0 79and 1.10.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 233663. | Nov 11, 2022 |
| CVE-2022-31772(opens NVD record) | Medium | 5.3 | IBM MQ 8.0, 9.0 LTS, 9.1 CD, 9.1 LTS, 9.2 CD, and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service to the MQTT channels. IBM X-Force ID: 228335. | Nov 11, 2022 |
| CVE-2022-34331(opens NVD record) | Medium | 5.5 | After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly configured leading to desired VEPA configuration being disabled. IBM X-Force ID: 229695. | Nov 11, 2022 |
| CVE-2022-33973(opens NVD record) | Low | 3.3 | Improper access control in the Intel(R) WAPI Security software for Windows 10/11 before version 22.2150.0.1 may allow an authenticated user to potentially enable information disclosure via local access. | Nov 11, 2022 |
| CVE-2022-21198(opens NVD record) | High | 7.9 | Time-of-check time-of-use race condition in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | Nov 11, 2022 |
| CVE-2022-34666(opens NVD record) | Medium | 6.5 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a local user with basic capabilities can cause a null-pointer dereference, which may lead to denial of service. | Nov 10, 2022 |
| CVE-2022-44089(opens NVD record) | Critical | 9.8 | ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE. | Nov 10, 2022 |
| CVE-2022-44088(opens NVD record) | Critical | 9.8 | ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION. | Nov 10, 2022 |
| CVE-2022-44087(opens NVD record) | Critical | 9.8 | ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT. | Nov 10, 2022 |
| CVE-2022-41128(opens NVD record) | High | 8.8 | Windows Scripting Languages Remote Code Execution Vulnerability | Nov 9, 2022 |
| CVE-2022-41125(opens NVD record) | High | 7.8 | Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | Nov 9, 2022 |
| CVE-2022-41123(opens NVD record) | High | 7.8 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Nov 9, 2022 |
| CVE-2022-41122(opens NVD record) | Medium | 6.5 | Microsoft SharePoint Server Spoofing Vulnerability | Nov 9, 2022 |
| CVE-2022-41120(opens NVD record) | High | 7.8 | Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability | Nov 9, 2022 |
| CVE-2022-41119(opens NVD record) | High | 7.8 | Visual Studio Remote Code Execution Vulnerability | Nov 9, 2022 |
| CVE-2022-41118(opens NVD record) | High | 7.5 | Windows Scripting Languages Remote Code Execution Vulnerability | Nov 9, 2022 |
| CVE-2022-41116(opens NVD record) | Medium | 5.9 | Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability | Nov 9, 2022 |