Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
71,857 matching · page 1322/1438Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-37348(opens NVD record) | Medium | 5.5 | Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure Vulnerability that could allow an attacker to read sensitive information from other memory locations and cause a crash on an affected machine. This vulnerability is similar to, but not the same as CVE-2022-37347. | Sep 19, 2022 |
| CVE-2022-37347(opens NVD record) | Medium | 5.5 | Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure Vulnerability that could allow an attacker to read sensitive information from other memory locations and cause a crash on an affected machine. This vulnerability is similar to, but not the same as CVE-2022-35234. | Sep 19, 2022 |
| CVE-2022-34893(opens NVD record) | High | 7.8 | Trend Micro Security 2022 (consumer) has a link following vulnerability where an attacker with lower privileges could manipulate a mountpoint which could lead to escalation of privilege on an affected machine. | Sep 19, 2022 |
| CVE-2022-40715(opens NVD record) | Medium | 6.5 | An issue was discovered in NOKIA 1350OMS R14.2. An Absolute Path Traversal vulnerability exists for a specific endpoint via the logfile parameter, allowing a remote authenticated attacker to read files on the filesystem arbitrarily. | Sep 19, 2022 |
| CVE-2022-40714(opens NVD record) | Medium | 6.1 | An issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under different /oms1350/* endpoints. | Sep 19, 2022 |
| CVE-2022-40713(opens NVD record) | Medium | 6.5 | An issue was discovered in NOKIA 1350OMS R14.2. Multiple Relative Path Traversal issues exist in different specific endpoints via the file parameter, allowing a remote authenticated attacker to read files on the filesystem arbitrarily. | Sep 19, 2022 |
| CVE-2022-40712(opens NVD record) | Medium | 6.1 | An issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under different /cgi-bin/R14.2* endpoints. | Sep 19, 2022 |
| CVE-2022-38618(opens NVD record) | High | 8.8 | SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/country_group.jsf. | Sep 19, 2022 |
| CVE-2022-38577(opens NVD record) | High | 8.8 | ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators. | Sep 19, 2022 |
| CVE-2022-38425(opens NVD record) | Medium | 5.5 | Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Sep 19, 2022 |
| CVE-2022-37700(opens NVD record) | High | 7.5 | Zentao Demo15 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: URL : view-source:https://demo15.zentao.pm/user-login.html/zentao/index.php?mode=getconfig. | Sep 19, 2022 |
| CVE-2022-35709(opens NVD record) | Medium | 5.5 | Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Sep 19, 2022 |
| CVE-2022-35708(opens NVD record) | High | 7.8 | Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Sep 19, 2022 |
| CVE-2022-35707(opens NVD record) | High | 7.8 | Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Sep 19, 2022 |
| CVE-2022-35706(opens NVD record) | High | 7.8 | Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Sep 19, 2022 |
| CVE-2022-35705(opens NVD record) | High | 7.8 | Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Sep 19, 2022 |
| CVE-2022-35704(opens NVD record) | High | 7.8 | Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Sep 19, 2022 |
| CVE-2022-35703(opens NVD record) | High | 7.8 | Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Sep 19, 2022 |
| CVE-2022-35702(opens NVD record) | High | 7.8 | Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Sep 19, 2022 |
| CVE-2022-35701(opens NVD record) | High | 7.8 | Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Sep 19, 2022 |
| CVE-2022-35700(opens NVD record) | High | 7.8 | Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Sep 19, 2022 |
| CVE-2022-35699(opens NVD record) | High | 7.8 | Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Sep 19, 2022 |
| CVE-2022-38617(opens NVD record) | High | 8.8 | SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at /SVFE2/pages/audit/voiceaudit.jsf. | Sep 19, 2022 |
| CVE-2022-40300(opens NVD record) | Critical | 9.8 | Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities. | Sep 16, 2022 |
| CVE-2022-37251(opens NVD record) | Medium | 5.4 | Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts. | Sep 16, 2022 |
| CVE-2022-39010(opens NVD record) | High | 7.5 | The HwChrService module has a vulnerability in permission control. Successful exploitation of this vulnerability may cause disclosure of user network information. | Sep 16, 2022 |
| CVE-2022-39009(opens NVD record) | Critical | 9.8 | The WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause third-party apps to affect WLAN functions. | Sep 16, 2022 |
| CVE-2022-39008(opens NVD record) | Critical | 9.1 | The NFC module has bundle serialization/deserialization vulnerabilities. Successful exploitation of this vulnerability may cause third-party apps to read and write files that are accessible only to system apps. | Sep 16, 2022 |
| CVE-2022-39007(opens NVD record) | Critical | 9.8 | The location module has a vulnerability of bypassing permission verification.Successful exploitation of this vulnerability may cause privilege escalation. | Sep 16, 2022 |
| CVE-2022-39006(opens NVD record) | Medium | 5.9 | The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability may cause the device to restart. | Sep 16, 2022 |
| CVE-2022-39005(opens NVD record) | High | 7.5 | The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks. | Sep 16, 2022 |
| CVE-2022-39004(opens NVD record) | High | 7.5 | The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks. | Sep 16, 2022 |
| CVE-2022-39003(opens NVD record) | Critical | 9.1 | Buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability will affect the confidentiality and integrity of trusted components. | Sep 16, 2022 |
| CVE-2022-39002(opens NVD record) | Critical | 9.8 | Double free vulnerability in the storage module. Successful exploitation of this vulnerability will cause the memory to be freed twice. | Sep 16, 2022 |
| CVE-2022-39001(opens NVD record) | High | 7.5 | The number identification module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause data disclosure. | Sep 16, 2022 |
| CVE-2022-39000(opens NVD record) | Critical | 9.8 | The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vulnerability will cause malicious apps to automatically start upon system startup. | Sep 16, 2022 |
| CVE-2022-38999(opens NVD record) | Critical | 9.8 | The AOD module has the improper update of reference count vulnerability. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability. | Sep 16, 2022 |
| CVE-2022-38997(opens NVD record) | High | 7.5 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | Sep 16, 2022 |
| CVE-2022-38996(opens NVD record) | High | 7.5 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. | Sep 16, 2022 |
| CVE-2022-38995(opens NVD record) | High | 7.5 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. | Sep 16, 2022 |
| CVE-2022-38994(opens NVD record) | High | 7.5 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | Sep 16, 2022 |
| CVE-2022-38993(opens NVD record) | High | 7.5 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. | Sep 16, 2022 |
| CVE-2022-38992(opens NVD record) | High | 7.5 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | Sep 16, 2022 |
| CVE-2022-38991(opens NVD record) | High | 7.5 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | Sep 16, 2022 |
| CVE-2022-38990(opens NVD record) | High | 7.5 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. | Sep 16, 2022 |
| CVE-2022-38989(opens NVD record) | High | 7.5 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. | Sep 16, 2022 |
| CVE-2022-38988(opens NVD record) | High | 7.5 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | Sep 16, 2022 |
| CVE-2022-38987(opens NVD record) | High | 7.5 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. | Sep 16, 2022 |
| CVE-2022-38979(opens NVD record) | High | 7.5 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | Sep 16, 2022 |
| CVE-2022-38978(opens NVD record) | High | 7.5 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | Sep 16, 2022 |