Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
71,857 matching · page 1324/1438Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-36532(opens NVD record) | High | 8.8 | Bolt CMS contains a vulnerability in version 5.1.12 and below that allows an authenticated user with the ROLE_EDITOR privileges to upload and rename a malicious file to achieve remote code execution. | Sep 16, 2022 |
| CVE-2022-38890(opens NVD record) | Medium | 5.5 | Nginx NJS v0.7.7 was discovered to contain a segmentation violation via njs_utf8_next at src/njs_utf8.h | Sep 15, 2022 |
| CVE-2022-29649(opens NVD record) | Medium | 6.1 | Qsmart Next v4.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability. | Sep 15, 2022 |
| CVE-2022-37257(opens NVD record) | Critical | 9.8 | Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js. | Sep 15, 2022 |
| CVE-2022-38788(opens NVD record) | Medium | 4.3 | An issue was discovered in Nokia FastMile 5G Receiver 5G14-B 1.2104.00.0281. Bluetooth on the Nokia ODU uses outdated pairing mechanisms, allowing an attacker to passively intercept a paring handshake and (after offline cracking) retrieve the PIN and LTK (long-term key). | Sep 15, 2022 |
| CVE-2022-0029(opens NVD record) | Medium | 5.5 | An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the system with elevated privileges when generating a tech support file. | Sep 14, 2022 |
| CVE-2021-38924(opens NVD record) | High | 7.5 | IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 210163. | Sep 14, 2022 |
| CVE-2022-3202(opens NVD record) | High | 7.1 | A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This could allow a local attacker to crash the system or leak kernel internal information. | Sep 14, 2022 |
| CVE-2022-40626(opens NVD record) | Medium | 4.8 | An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in order to create a fake account with predefined login, password and role in Zabbix Frontend. | Sep 14, 2022 |
| CVE-2022-39821(opens NVD record) | High | 7.5 | In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical information, such as cleartext user credentials, in world-readable files in the filesystem. | Sep 13, 2022 |
| CVE-2022-39819(opens NVD record) | High | 8.8 | In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This allows authenticated users to execute commands on the operating system. | Sep 13, 2022 |
| CVE-2022-39817(opens NVD record) | High | 8.8 | In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker. Through the injection of arbitrary SQL statements, a potential authenticated attacker can modify query syntax and perform unauthorized (and unexpected) operations against the remote database. | Sep 13, 2022 |
| CVE-2022-39816(opens NVD record) | Medium | 6.5 | In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit configuration page. Exploitation requires an authenticated attacker. | Sep 13, 2022 |
| CVE-2022-39815(opens NVD record) | Critical | 9.8 | In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated users to execute commands on the operating system. | Sep 13, 2022 |
| CVE-2022-39814(opens NVD record) | Medium | 6.1 | In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter. | Sep 13, 2022 |
| CVE-2022-36768(opens NVD record) | High | 7.8 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to obtain root privileges. IBM X-Force ID: 232014. | Sep 13, 2022 |
| CVE-2022-35637(opens NVD record) | Medium | 6.5 | IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service after entering a malformed SQL statement into the Db2expln tool. IBM X-Force ID: 230823. | Sep 13, 2022 |
| CVE-2022-34356(opens NVD record) | High | 7.8 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to obtain root privileges. IBM X-Force ID: 230502. | Sep 13, 2022 |
| CVE-2022-34336(opens NVD record) | Medium | 5.4 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229714. | Sep 13, 2022 |
| CVE-2022-22483(opens NVD record) | Medium | 6.5 | IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized access caused by improper privilege management when CREATE OR REPLACE command is used. IBM X-Force ID: 225979. | Sep 13, 2022 |
| CVE-2022-22330(opens NVD record) | Medium | 5.3 | IBM Control Desk 7.6.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 219126. | Sep 13, 2022 |
| CVE-2022-22329(opens NVD record) | Medium | 4.3 | IBM Control Desk 7.6.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 219124. | Sep 13, 2022 |
| CVE-2022-3205(opens NVD record) | Medium | 4.6 | Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection | Sep 13, 2022 |
| CVE-2022-38020(opens NVD record) | High | 7.3 | Visual Studio Code Elevation of Privilege Vulnerability | Sep 13, 2022 |
| CVE-2022-38019(opens NVD record) | High | 7.8 | AV1 Video Extension Remote Code Execution Vulnerability | Sep 13, 2022 |
| CVE-2022-38013(opens NVD record) | High | 7.5 | .NET Core and Visual Studio Denial of Service Vulnerability | Sep 13, 2022 |
| CVE-2022-38012(opens NVD record) | High | 7.7 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Sep 13, 2022 |
| CVE-2022-38011(opens NVD record) | High | 7.3 | Raw Image Extension Remote Code Execution Vulnerability | Sep 13, 2022 |
| CVE-2022-38010(opens NVD record) | High | 7.8 | Microsoft Office Visio Remote Code Execution Vulnerability | Sep 13, 2022 |
| CVE-2022-38009(opens NVD record) | High | 8.8 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Sep 13, 2022 |
| CVE-2022-38008(opens NVD record) | High | 8.8 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Sep 13, 2022 |
| CVE-2022-38007(opens NVD record) | High | 7.8 | Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability | Sep 13, 2022 |
| CVE-2022-38006(opens NVD record) | Medium | 6.5 | Windows Graphics Component Information Disclosure Vulnerability | Sep 13, 2022 |
| CVE-2022-38005(opens NVD record) | High | 7.8 | Windows Print Spooler Elevation of Privilege Vulnerability | Sep 13, 2022 |
| CVE-2022-38004(opens NVD record) | High | 7.8 | Windows Fax Service Remote Code Execution Vulnerability | Sep 13, 2022 |
| CVE-2022-37969(opens NVD record) | High | 7.8 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Sep 13, 2022 |
| CVE-2022-37964(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | Sep 13, 2022 |
| CVE-2022-37963(opens NVD record) | High | 7.8 | Microsoft Office Visio Remote Code Execution Vulnerability | Sep 13, 2022 |
| CVE-2022-37962(opens NVD record) | High | 7.8 | Microsoft PowerPoint Remote Code Execution Vulnerability | Sep 13, 2022 |
| CVE-2022-37961(opens NVD record) | High | 8.8 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Sep 13, 2022 |
| CVE-2022-37959(opens NVD record) | Medium | 6.5 | Network Device Enrollment Service (NDES) Security Feature Bypass Vulnerability | Sep 13, 2022 |
| CVE-2022-37958(opens NVD record) | High | 8.1 | SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | Sep 13, 2022 |
| CVE-2022-37957(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | Sep 13, 2022 |
| CVE-2022-37956(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | Sep 13, 2022 |
| CVE-2022-37955(opens NVD record) | High | 7.8 | Windows Group Policy Elevation of Privilege Vulnerability | Sep 13, 2022 |
| CVE-2022-37954(opens NVD record) | High | 7.8 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | Sep 13, 2022 |
| CVE-2022-35841(opens NVD record) | High | 8.8 | Windows Enterprise App Management Service Remote Code Execution Vulnerability | Sep 13, 2022 |
| CVE-2022-35840(opens NVD record) | High | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Sep 13, 2022 |
| CVE-2022-35838(opens NVD record) | High | 7.5 | HTTP V3 Denial of Service Vulnerability | Sep 13, 2022 |
| CVE-2022-35837(opens NVD record) | Medium | 6.5 | Windows Graphics Component Information Disclosure Vulnerability | Sep 13, 2022 |