Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
71,857 matching · page 1331/1438Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-31237(opens NVD record) | Low | 3.3 | Dell PowerScale OneFS, versions 9.2.0 up to and including 9.2.1.12 and 9.3.0.5 contain an improper preservation of permissions vulnerability in SyncIQ. A low privileged local attacker may potentially exploit this vulnerability, leading to limited information disclosure. | Aug 22, 2022 |
| CVE-2022-28598(opens NVD record) | Medium | 6.1 | Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. | Aug 22, 2022 |
| CVE-2022-2873(opens NVD record) | Medium | 5.5 | An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way a user triggers the I2C_SMBUS_BLOCK_DATA (with the ioctl I2C_SMBUS) with malicious input data. This flaw allows a local user to crash the system. | Aug 22, 2022 |
| CVE-2021-3659(opens NVD record) | Medium | 5.5 | A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user closes the LR-WPAN connection. This flaw allows a local user to crash the system. The highest threat from this vulnerability is to system availability. | Aug 22, 2022 |
| CVE-2021-3590(opens NVD record) | High | 8.8 | A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | Aug 22, 2022 |
| CVE-2021-3586(opens NVD record) | Critical | 9.8 | A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allowing access to all ports on these resources from any pod. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | Aug 22, 2022 |
| CVE-2021-3513(opens NVD record) | High | 7.5 | A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality. | Aug 22, 2022 |
| CVE-2021-3442(opens NVD record) | Medium | 5.4 | A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated user to inject scripts into some text boxes leading to a XSS attack. The highest threat from this vulnerability is to data confidentiality. | Aug 22, 2022 |
| CVE-2020-27836(opens NVD record) | Critical | 9.8 | A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker to access resources that would otherwise be restricted to specified IP ranges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.. | Aug 22, 2022 |
| CVE-2022-35554(opens NVD record) | Medium | 6.1 | Multiple reflected XSS vulnerabilities occur when handling error message of BPC SmartVista version 3.28.0 allowing an attacker to execute javascript code at client side. | Aug 19, 2022 |
| CVE-2022-36233(opens NVD record) | Medium | 5.5 | Tenda AC9 V15.03.2.13 is vulnerable to Buffer Overflow via httpd, form_fast_setting_wifi_set. httpd. | Aug 19, 2022 |
| CVE-2022-22489(opens NVD record) | Critical | 9.1 | IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 226339. | Aug 19, 2022 |
| CVE-2022-36263(opens NVD record) | High | 7.3 | StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute arbitrary code via a crafted .exe file. | Aug 19, 2022 |
| CVE-2022-35201(opens NVD record) | Critical | 9.8 | Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability. | Aug 19, 2022 |
| CVE-2022-34624(opens NVD record) | Medium | 5.9 | Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request. | Aug 19, 2022 |
| CVE-2022-2075(opens NVD record) | High | 7.5 | In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service targeting the build information request validation. | Aug 19, 2022 |
| CVE-2022-2074(opens NVD record) | High | 7.5 | In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service using the Variable Project Template. | Aug 19, 2022 |
| CVE-2022-2049(opens NVD record) | High | 7.5 | In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service via the package upload function. | Aug 19, 2022 |
| CVE-2022-1901(opens NVD record) | Medium | 5.3 | In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview. | Aug 19, 2022 |
| CVE-2022-35167(opens NVD record) | High | 8.8 | Printix Cloud Print Management v1.3.1149.0 for Windows was discovered to contain insecure permissions. | Aug 19, 2022 |
| CVE-2022-36947(opens NVD record) | Critical | 9.8 | Unsafe Parsing of a PNG tRNS chunk in FastStone Image Viewer through 7.5 results in a stack buffer overflow. | Aug 18, 2022 |
| CVE-2022-37049(opens NVD record) | High | 7.8 | The component tcpprep in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in parse_mpls at common/get.c:150. NOTE: this is different from CVE-2022-27942. | Aug 18, 2022 |
| CVE-2022-37048(opens NVD record) | High | 7.8 | The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_l2len_protocol at common/get.c:344. NOTE: this is different from CVE-2022-27941. | Aug 18, 2022 |
| CVE-2022-37047(opens NVD record) | High | 7.8 | The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_ipv6_next at common/get.c:713. NOTE: this is different from CVE-2022-27940. | Aug 18, 2022 |
| CVE-2022-2568(opens NVD record) | Medium | 6.5 | A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remove the superuser privileges. | Aug 18, 2022 |
| CVE-2022-21793(opens NVD record) | Medium | 5.5 | Insufficient control flow management in the Intel(R) Ethernet 500 Series Controller drivers for VMWare before version 1.11.4.0 and in the Intel(R) Ethernet 700 Series Controller drivers for VMWare before version 2.1.5.0 may allow an authenticated user to potentially enable a denial of service via local access. | Aug 18, 2022 |
| CVE-2021-33060(opens NVD record) | High | 7.8 | Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access. | Aug 18, 2022 |
| CVE-2022-2625(opens NVD record) | High | 8.0 | A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser. | Aug 18, 2022 |
| CVE-2022-37025(opens NVD record) | High | 7.8 | An improper privilege management vulnerability in McAfee Security Scan Plus (MSS+) before 4.1.262.1 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack. This could result in the user gaining elevated permissions and being able to execute arbitrary code due to lack of an integrity check of the configuration file. | Aug 18, 2022 |
| CVE-2022-23764(opens NVD record) | High | 8.8 | The vulnerability causing from insufficient verification procedures for downloaded files during WebCube update. Remote attackers can bypass this verification logic to update both digitally signed and unauthorized files, enabling remote code execution. | Aug 17, 2022 |
| CVE-2020-14394(opens NVD record) | Low | 3.2 | An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service. | Aug 17, 2022 |
| CVE-2022-22455(opens NVD record) | Critical | 9.8 | IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 224989. | Aug 17, 2022 |
| CVE-2020-14379(opens NVD record) | Medium | 5.6 | A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and information disclosure. | Aug 16, 2022 |
| CVE-2021-39087(opens NVD record) | Medium | 6.5 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow an authenticated user to obtain sensitive information due to improper permission controls. IBM X-Force ID: 216109. | Aug 16, 2022 |
| CVE-2021-39086(opens NVD record) | Medium | 5.3 | IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 215889. | Aug 16, 2022 |
| CVE-2021-39085(opens NVD record) | Critical | 9.8 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 215888. | Aug 16, 2022 |
| CVE-2021-39035(opens NVD record) | Medium | 5.4 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213965. | Aug 16, 2022 |
| CVE-2022-36530(opens NVD record) | Medium | 6.1 | An issue was discovered in rageframe2 2.6.37. There is a XSS vulnerability in the user agent related parameters of the info.php page. | Aug 16, 2022 |
| CVE-2021-30490(opens NVD record) | High | 7.8 | upsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binary that enable an Authenticated User to modify files, allowing for privilege escalation. | Aug 16, 2022 |
| CVE-2022-35822(opens NVD record) | High | 7.1 | Windows Defender Credential Guard Security Feature Bypass Vulnerability | Aug 15, 2022 |
| CVE-2022-34711(opens NVD record) | High | 7.8 | Windows Defender Credential Guard Elevation of Privilege Vulnerability | Aug 15, 2022 |
| CVE-2020-21642(opens NVD record) | Critical | 9.8 | Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code. | Aug 15, 2022 |
| CVE-2020-21641(opens NVD record) | High | 7.5 | Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via crafted XML license file. | Aug 15, 2022 |
| CVE-2022-24654(opens NVD record) | Medium | 5.4 | Authenticated stored cross-site scripting (XSS) vulnerability in "Field Server Address" field in INTELBRAS ATA 200 Firmware 74.19.10.21 allows attackers to inject JavaScript code through a crafted payload. | Aug 15, 2022 |
| CVE-2022-36526(opens NVD record) | High | 7.5 | D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Authentication Bypass via function phpcgi_main in cgibin. | Aug 15, 2022 |
| CVE-2022-36524(opens NVD record) | High | 7.5 | D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh. | Aug 15, 2022 |
| CVE-2022-36262(opens NVD record) | Critical | 9.8 | An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying config.php. | Aug 15, 2022 |
| CVE-2022-38221(opens NVD record) | Critical | 9.8 | A buffer overflow in the FTcpListener thread in The Isle Evrima (the dedicated server on Windows and Linux) 0.9.88.07 before 2022-08-12 allows a remote attacker to crash any server with an accessible RCON port, or possibly execute arbitrary code. | Aug 15, 2022 |
| CVE-2022-2622(opens NVD record) | Medium | 6.5 | Insufficient validation of untrusted input in Safe Browsing in Google Chrome on Windows prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a crafted file. | Aug 12, 2022 |
| CVE-2022-37042(opens NVD record) | Critical | 9.8 | Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925. | Aug 12, 2022 |